Mobile application hot update method and device based on React Native framework, medium, program product and terminal

Through the mobile application hot update method based on the React Native framework, the encryption signature mechanism of the version detection and content distribution network is used to solve the security and compatibility problems in the hot update of mobile application, data integrity verification and tamper-proof, and the security and stability of updates are improved.

CN120428996APending Publication Date: 2025-08-05BEIJING DIANFU TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510581250.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

The existing mobile application hot update technology has significant flaws in terms of security and cross-platform compatibility, especially the code is prone to tampering and decompiling, resulting in a decrease in application security, and the differences between different devices and systems increase the complexity of the update process.

Method used

The mobile application hot update method based on the React Native framework is adopted to generate encrypted hot update packages through version detection and content distribution network packaging, and signature verification and decryption operations are performed on the mobile terminal, combining multiple hashing algorithms and dynamic adaptation strategies to ensure data integrity and security.

Benefits of technology

It realizes data integrity verification and tamper-proof protection during the thermal update process, reduces the adaptation complexity of multi-device and multi-system environments, improves the security and stability of updates, and ensures the security, controllability and compatibility of applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120428996A_ABST
    Figure CN120428996A_ABST
Patent Text Reader

Abstract

The invention provides a mobile application hot update method and device based on a React Native framework, a medium, a program product and a terminal, and constructs a multi-level security protection system comprising version detection, encryption transmission, signature verification and dynamic decryption through a cooperation mechanism of a mobile terminal, a gateway and a content distribution network. In a program starting stage, version configuration information is obtained through a gateway, an encrypted hot update package packaged by React Native is pulled from a content distribution network, and signature verification, decryption verification and differential installation operation are sequentially executed. The problems that codes are easy to tamper and the decompilation risk is high in a traditional hot update mechanism are effectively solved, meanwhile, through a standardized packaging process and a dynamic adaptation mechanism, the compatibility complexity of multiple devices and multiple system versions is remarkably reduced, and unified improvement of safety and stability is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer updates, and in particular to a method, device, medium, program product, and terminal for hot updating mobile applications based on the React Native framework. Background Art

[0002] In the current mobile app development ecosystem, native Android and iOS development faces numerous technical challenges. With the rapid iteration of the mobile internet, developers urgently need to improve app development efficiency and maintain a consistent user experience across platforms. Traditional app update models are constrained by the strict review mechanisms of app stores, resulting in lengthy update cycles and high costs. This has led to the emergence of app hot update technology, a key technological innovation that addresses the pain points of version iteration.

[0003] Technical solutions for mobile app hot updates have diversified, primarily including JavaScript hot updates, Native Code hot updates, and resource-level hot updates. However, existing technologies still face numerous key challenges, particularly in security and cross-platform compatibility.

[0004] Traditional hot update mechanisms present serious security risks. Dynamic code delivery allows attackers to exploit malicious code, and update packages are easily decompiled and tampered with, significantly reducing overall application security. Furthermore, differences between operating system versions and devices complicate the hot update process. These inherent flaws severely hinder the widespread adoption and further development of hot update technology in practical applications. Summary of the Invention

[0005] In view of the shortcomings of the existing technology described above, the purpose of this application is to provide a mobile application hot update method, device, medium, program product and terminal based on the React Native framework, which is used to solve the problems of existing mobile application hot update technology in security, cross-platform compatibility and implementation complexity.

[0006] To achieve the above-mentioned purpose and other related purposes, the first aspect of the present application provides a mobile application hot update method based on the React Native framework, the method being applied to a mobile terminal, the mobile terminal being communicatively connected to a gateway and a content distribution network respectively, comprising: in response to program startup, sending a version detection request to the gateway through a version detection interface, and receiving version configuration information corresponding to the version detection request returned by the gateway; according to the version configuration information, obtaining a hot update package from the content distribution network and performing a signature verification operation, the hot update package being generated by the content distribution network based on the React Native framework; performing a decryption operation on the hot update package that passes the signature verification; after the decryption operation is successful, performing a hot update package installation operation.

[0007] In some embodiments of the first aspect of the present application, the process of the content distribution network packaging and generating the hot update package based on the React Native framework includes: obtaining upgrade parameter information sent by the server through an auxiliary tool, and using Jenkins to perform a build operation on the upgrade parameters to generate a source code package; performing a packaging operation on the source code package based on the ReactNative framework scaffolding to generate a target file, performing an encryption signature operation on the target file to generate a hot update package, and publishing the hot update package to the content distribution network for download by the mobile terminal.

[0008] In some embodiments of the first aspect of the present application, the process of the content distribution network performing an encryption signature operation on the target file includes: calculating a first MD5 value of the encrypted target file; performing an encryption operation on the first MD5 value using a preset private key to generate a digital signature value; combining the digital signature value with a corresponding hot package parameter to generate a signature and metadata information; packaging the encrypted target file together with the signature and metadata information, and performing a compression operation to generate a hot update package with an encrypted signature.

[0009] In some embodiments of the first aspect of the present application, the process of the mobile terminal performing the signature verification operation includes: reading the encrypted target file contained in the hot update package and calculating the second MD5 value of the encrypted target file; extracting the digital signature value and the corresponding hot package parameter combination from the encrypted and signed hot update package, and performing a verification operation on the digital signature value based on a preset public key to obtain a third MD5 value; comparing the second MD5 value with the third MD5 value; if the comparison results are consistent, the signature verification is determined to be successful; otherwise, the signature verification is determined to be unsuccessful.

[0010] In some embodiments of the first aspect of the present application, the process of the mobile terminal performing the hot update package installation operation includes: when the hot update package is detected, loading the React Native Bundle file in the hot update package; searching for JavaScript code corresponding to the target page in the React Native Bundle file; in response to finding the JavaScript code corresponding to the target page, loading and running the JavaScript code; in response to not finding the JavaScript code corresponding to the target page, loading and running the JavaScript code of the target network from the React Native Bundle of the application main package.

[0011] In some embodiments of the first aspect of the present application, after executing the hot update package installation operation, the following steps are also performed: in response to the successful installation of the hot update package, the latest version number is obtained, and the version detection interface is called again until no new version configuration information is detected.

[0012] To achieve the above-mentioned purpose and other related purposes, the second aspect of the present application provides a mobile application hot update device based on the React Native framework, including: a version detection module: used to send a version detection request to the gateway through a version detection interface in response to program startup, and receive version configuration information corresponding to the version detection request returned by the gateway; a hot update package acquisition module: used to obtain a hot update package from the content distribution network according to the version configuration information and perform a signature verification operation, wherein the hot update package is generated by the content distribution network based on the React Native framework; a hot update package installation module: used to perform a decryption operation on the hot update package that has passed the signature verification; after the decryption operation is successful, perform a hot update package installation operation.

[0013] To achieve the above-mentioned objectives and other related objectives, the third aspect of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the mobile application hot update method based on the React Native framework.

[0014] To achieve the above-mentioned objectives and other related objectives, the fourth aspect of the present application provides a computer program product, which includes computer program code. When the computer program code is run on a computer, the computer implements the mobile application hot update method based on the React Native framework.

[0015] To achieve the above-mentioned objectives and other related objectives, the fifth aspect of the present application provides an electronic terminal, comprising a memory, a processor, and a computer program stored in the memory; the processor executes the computer program to implement the mobile application hot update method based on the React Native framework.

[0016] As described above, the mobile application hot update method, device, medium, program product and terminal based on the React Native framework of the present application have the following beneficial effects: through the dual security mechanism of digital signature verification and encrypted transmission, a data integrity verification and anti-tampering protection system is constructed in the entire link of hot update package transmission, effectively resisting the risks of malicious code injection and man-in-the-middle attacks; adopting React Native standardized packaging combined with a dynamic adaptation strategy, through the collaborative mechanism of version configuration information and content distribution network, the complexity of environmental adaptation of multiple devices and multiple system versions is significantly reduced; based on the integrity check mechanism of decryption verification and installation operations, the version confusion problem caused by update interruption or data corruption in traditional solutions is avoided, while ensuring the safety and controllability of the hot update process, the update success rate and operation stability are improved, providing technical support for the dynamic iteration of mobile applications that takes into account both security and compatibility. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 The figure shows a flow chart of an embodiment of a method for hot updating a mobile application based on the React Native framework of the present application.

[0018] Figure 2 The figure shows the interactive signaling diagram between the mobile terminal, the gateway and the content distribution network in an embodiment of the mobile application hot update method based on the React Native framework of the present application.

[0019] Figure 3 The figure shows a flow chart of the hot update process in an embodiment of a hot update method for a mobile application based on the React Native framework of the present application.

[0020] Figure 4 The figure shows a schematic diagram of the structure of an embodiment of a mobile application hot update device based on the React Native framework of the present application.

[0021] Figure 5 The figure shows a schematic diagram of the structure of an embodiment of a mobile application hot update terminal based on the React Native framework of the present application. DETAILED DESCRIPTION

[0022] The following describes the embodiments of the present application through specific examples. Those skilled in the art can easily understand the other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific embodiments. The details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other unless they conflict.

[0023] Before further explaining the present invention in detail, the nouns and terms involved in the embodiments of the present invention are explained. The nouns and terms involved in the embodiments of the present invention are subject to the following interpretations:

[0024] <1> React Native framework: React Native framework is an open source cross-platform mobile application development framework that allows developers to build native mobile applications using JavaScript and React. It supports iOS and Android platforms and converts JavaScript code into native UI components and logic through bridging technology.

[0025] <2> Hot update: Hot update refers to the technology of dynamically replacing or updating part of the application code or resources while the application is running, without having to reinstall or update the entire application. It is often used to quickly fix problems or update functions, improving user experience and development efficiency.

[0026] <3> Mobile terminal: Mobile terminal refers to the application scenario or field that uses mobile devices (such as smartphones, tablets, etc.) as the operating platform, emphasizing the adaptability, interactivity and portability of applications on mobile devices, especially providing users with various functions and services in the form of APP (application).

[0027] <4> Gateway: In the network architecture, a gateway is a node for communication between different networks or subnets. It is responsible for converting and forwarding between different protocols, data formats or communication environments, and plays the role of routing, security control and protocol conversion.

[0028] <5> Content Delivery Network: A Content Delivery Network (CDN) is a distributed network architecture that reduces the load on content source servers, lowers latency, and improves user access speed and network performance by caching and distributing content at edge nodes close to users.

[0029] <6> Version configuration information: Version configuration information is detailed data used to manage different versions of code, resources, and dependencies in software development. It includes version numbers, change records, dependent library versions, etc., and is used to ensure the stability and traceability of the software.

[0030] <7> Jenkins: Jenkins is an open source automation server for continuous integration and continuous delivery (CI / CD). It supports automated building, testing, deployment, and release of software projects to improve development efficiency and quality.

[0031] <8> MD5 value: An MD5 value is a 128-bit hash value generated based on the MD5 algorithm. It is used to verify data integrity and consistency. By mapping input data into a unique string of fixed length, it detects whether the data has been tampered with during transmission or storage.

[0032] <9> Digital signature value: A digital signature value is a signature generated by an encryption algorithm for data. It is used to verify the source and integrity of the data, ensure that the data has not been tampered with during transmission, and verify the identity of the sender.

[0033] <10> Signature and metadata information: Signature and metadata information refers to the signature data contained in software or files to verify its legitimacy and source, as well as additional information describing the software version, author, purpose, etc., which is used for security verification and management.

[0034] <11> React Native Bundle file: The React Native Bundle file is a packaged file of a React Native application, which contains the application's JavaScript code and resources. It is used to load and run React Native applications on mobile devices and is an important part of the application building and deployment process.

[0035] To facilitate understanding of the embodiments of this application, first Figure 1 Detailed description. Figure 1 The following is a flow chart of a method for hot updating a mobile application based on the React Native framework in an embodiment of the present invention. In this embodiment, the mobile terminal is connected to the gateway and the content distribution network respectively. Figure 2 The interactive signaling diagram between the mobile terminal, gateway, and content distribution network in this embodiment is shown. The mobile application hot update method based on the React Native framework in this embodiment mainly includes the following steps:

[0036] Step S11: In response to program startup, a version detection request is sent to the gateway through a version detection interface, and version configuration information corresponding to the version detection request is received from the gateway.

[0037] like Figure 2As shown, this embodiment involves a mobile terminal, a gateway, and a content delivery network (CDN). The mobile terminal refers to a handheld or portable computing device used by a user. The gateway serves as a network interface and is responsible for data forwarding and protocol conversion. The mobile terminal device communicates with the backend service through the gateway. A content delivery network (CDN) is a distributed server network used to efficiently distribute content. In response to program startup, the mobile terminal device sends a version detection request to the gateway through the version detection interface and receives version configuration information returned by the gateway.

[0038] In one embodiment of the present application, the hot update package in the present application is developed in a hybrid mode of React Native server-side and native-side. React Native on the server-side is used to build the interface and business logic of the application part, and the application side serves as the native side as the host of the application. Specifically, the server-side is deployed with a service for managing React Native deployment packages, which stores different versions of deployment packages, including version configuration information of each version, including but not limited to version number, update time, update content description and other information. At the same time, the server can receive version check requests sent by the APP and push update notifications to the APP. For example, the server-side can use Node.js combined with the above-mentioned Express service, and use the MongoDB database to store deployment package information and version records.

[0039] Furthermore, the application side (APP side) sends a version detection request to the server side when it starts up. The version detection request contains the version number of the current React Native business module. When the server side receives the version detection request, it compares the latest version number stored in the server side with the version number sent by the APP, and pushes an update notification to the application side when it detects that a new version number is stored. After the application side receives the update notification, it starts the corresponding download task in the background and uses the network request library to download the React Native deployment package to be updated. Among them, the APP side of the Android platform can use the OkHttp request library, and the APP side of the IOS platform can use the AFNetworking request library. After the download is complete, the new deployment package is stored in a specific directory of the application. When the APP is started next time, the native side will check whether there is a new deployment package in the directory. If so, the new deployment package will be loaded to achieve dynamic updates.

[0040] Step S12: According to the version configuration information, a hot update package is obtained from the content distribution network and a signature verification operation is performed. The hot update package is generated by the content distribution network based on the React Native framework.

[0041] In one embodiment of the present application, the process of the content distribution network packaging and generating the hot update package based on the React Native framework includes: obtaining upgrade parameter information sent by the server through an auxiliary tool, and using the upgrade parameters to perform a build operation through Jenkins to generate a source code package; performing a packaging operation on the source code package based on the React Native framework scaffolding to generate a target file, performing an encryption and signing operation on the target file to generate a hot update package, and publishing the hot update package to the content distribution network for download by the mobile terminal.

[0042] Figure 3 The hot update process diagram of this embodiment is shown on the right side of the image. First, an auxiliary tool is used to obtain the upgrade parameter information sent by the server. The auxiliary tool includes but is not limited to a custom Python script that calls the API interface provided by the server through an HTTP request to obtain the upgrade configuration, such as the version number and the list of files to be updated.

[0043] The acquired upgrade parameters are then used to execute a build operation on Jenkins to generate a source code package. It should be noted that Jenkins is a continuous integration / continuous deployment tool. In this solution, Jenkins checks out the corresponding code from a version control system (such as Git) based on the parameter information and performs the corresponding preprocessing and compilation operations to generate a source code package containing the latest code and resources.

[0044] Subsequently, a packaging operation is performed based on the source code package and the React Native framework scaffold (such as the Metro bundler) to generate the target files. The Metro bundler packages the JavaScript code and related resource files into one or more bundle files for hot update. Subsequently, an encryption and signing operation is performed on the target files to generate the final hot update package.

[0045] Preferably, the bundle file is encrypted using an encryption algorithm (such as AES) and signed using a digital signature technology (such as RSA signature) to ensure the security and integrity of the hot update package. Finally, the generated hot update package is published to the content delivery network (CDN). The CDN is used to distribute the hot update package to edge node servers located throughout the country, so that the mobile user can verify, download, and install it from the nearest server, thereby achieving fast and reliable updates.

[0046] In one embodiment of the present application, the process of the content distribution network performing an encryption signature operation on the target file includes: calculating a first MD5 value of the encrypted target file; performing an encryption operation on the first MD5 value using a preset private key to generate a digital signature value; combining the digital signature value with corresponding hot package parameters to generate a signature and metadata information; packaging the encrypted target file together with the signature and metadata information, and performing a compression operation to generate a hot update package with an encryption signature.

[0047] In this embodiment, a first MD5 value is calculated for the encrypted target file. MD5 (Message-Digest Algorithm 5) is a cryptographic hash function that includes a 128-bit hash value (also known as a fingerprint or digest). By calculating the MD5 value of the encrypted file, it is ensured that the signature is valid for the encrypted file content. Subsequently, the first MD5 value is encrypted using a preset private key to generate a digital signature value.

[0048] It should be noted that the above data encryption operation is an asymmetric encryption process, which uses a private key held only by the signer to encrypt the MD5 hash value. The generated encryption result is the digital signature. This digital signature can prove the origin and integrity of the data.

[0049] The digital signature value is then combined with the corresponding hot package parameters to generate a signature and metadata. Hot package parameters include, but are not limited to, the hot update package version, compatible application versions, and file lists. The digital signature and metadata are combined to form a structured data structure, allowing the mobile device to obtain the necessary information when verifying the signature.

[0050] Finally, the encrypted target file is packaged with the signature and metadata information and compressed to generate a cryptographically signed hot update package. Examples of compression algorithms that can be used include, but are not limited to, Zip or Gzip to reduce file size for easier network transmission and storage. The resulting hot update package is the cryptographically signed hot update package that the CDN distributes to the mobile device.

[0051] In one embodiment of the present application, the process of the mobile terminal performing the signature verification operation includes: reading the encrypted target file contained in the hot update package and calculating the second MD5 value of the encrypted target file; extracting the digital signature value and the corresponding hot package parameter combination from the encrypted and signed hot update package, and performing a verification operation on the digital signature value based on a preset public key to obtain a third MD5 value; comparing the second MD5 value with the third MD5 value; if the comparison results are consistent, the signature verification is determined to be successful; otherwise, the signature verification is determined to be unsuccessful.

[0052] In one embodiment of the present application, the mobile terminal reads the encrypted target file contained in the hot update package and calculates the second MD5 value of the encrypted target file, thereby obtaining the MD5 hash value of the downloaded encrypted update content as a basis for subsequent comparison. Subsequently, the digital signature value and the corresponding hot package parameter combination are extracted from the hot update package after the encryption signature. The hot package parameter combination is contained in the metadata part of the hot update package. Then, the digital signature value is verified based on the preset public key to obtain the third MD5 value based on which the signature was based. It should be noted that by verifying the validity of the signature through the public key, it is possible to confirm whether the signature is generated by the private key paired with the public key and restore the MD5 hash value of the original data at the time of signing. Finally, the second MD5 value (the MD5 of the encrypted file calculated by the mobile terminal) is compared with the third MD5 value (the MD5 obtained by verifying the signature through the public key). If the comparison results are consistent, the signature verification is determined to be successful, indicating that the content of the hot update package has not been tampered with during transmission and is indeed published by the legitimate party holding the private key. Otherwise, if the comparison results are inconsistent, it is determined that the signature verification fails. At this time, the mobile terminal should refuse to apply the hot update package to prevent malicious code injection or data damage.

[0053] In one embodiment of the present application, when the server generates a hot update package, it first calculates the MD5 value and SHA-256 value of the encrypted target file, combines the two to form a composite hash value, and then uses a preset private key to perform a digital signature operation on the composite hash value to generate a digital signature value, and encapsulates the digital signature value, the two hash values and the corresponding hot package parameter combination into the hot update package. The process of the mobile terminal performing a signature verification operation includes: reading the encrypted target file contained in the hot update package, calculating the MD5 value and SHA-256 value of the encrypted target file respectively, to form a local composite hash value; extracting the digital signature value, the two hash values and the corresponding hot package parameter combination from the encrypted and signed hot update package, performing a verification operation on the digital signature value based on the preset public key to obtain the composite hash value when the server signed; comparing the local composite hash value with the obtained composite hash value, if the comparison results are consistent, then the signature verification is determined to be successful, otherwise the signature verification is determined to be unsuccessful.

[0054] In the current mobile application development ecosystem, security and cross-platform compatibility are the two core challenges facing hot update technology. The traditional digital signature mechanism that relies solely on a single MD5 algorithm is threatened by collision attacks and is not secure enough, especially in scenarios where mobile applications frequently and sensitively update data, which can easily lead to malicious code injection and data tampering. To address this issue, this embodiment introduces a composite hash value of multiple hash algorithms as the underlying data of the digital signature, combining the advantages of MD5 and SHA-256, taking into account both computational efficiency and significantly improving anti-collision and anti-tampering capabilities. At the same time, the hot update package also contains an extended hot package parameter combination, introducing dynamic risk assessment fields such as device security level and operating environment status, enabling the mobile terminal to flexibly adjust the verification strategy based on environmental information to achieve more fine-grained security control. In addition, the optimization of local multiple hash calculations and support for hardware security modules (such as ARM TrustZone or iOS Secure Enclave) ensure the efficiency and security of signature verification, avoiding the delays and uncertainties caused by complex network interactions. This design not only strengthens the protection of the integrity and source of hot update packages, but also improves cross-platform compatibility and user experience. It is a major breakthrough in the traditional hot update security mechanism.

[0055] This embodiment effectively enhances the anti-tampering capability and security of the hot update package during transmission and storage by adopting a hybrid signature verification technology with multiple hash algorithms, significantly reducing the security risks that may be brought by a single hash algorithm. The dynamic risk perception parameters introduced enable the mobile terminal to flexibly adjust the verification strategy according to the device security level and the operating environment status, achieving more fine-grained and intelligent security control. At the same time, through the optimization of multiple hash algorithms at the software level, the execution efficiency of the hot update package signature verification is improved, ensuring the smoothness and responsiveness of the user experience. Not only has it achieved a breakthrough in security, but it has also taken into account cross-platform compatibility and practicality, providing an efficient, robust and reliable solution for the development of mobile application hot update technology.

[0056] Step S13: performing a decryption operation on the hot update package that has passed the signature verification; after the decryption operation is successful, performing a hot update package installation operation.

[0057] In one embodiment of the present application, the process of the mobile terminal performing the hot update package installation operation includes: when the hot update package is detected, loading the React Native Bundle file in the hot update package; searching for JavaScript code corresponding to the target page in the React NativeBundle file; in response to finding the JavaScript code corresponding to the target page, loading and running the JavaScript code; in response to not finding the JavaScript code corresponding to the target page, loading and running the JavaScript code of the target network from the React Native Bundle of the application main package.

[0058] In this embodiment, when the mobile terminal detects that a hot update package is available, the application loads the React Native Bundle file in the hot update package. The Bundle file is generated during the packaging process based on the RN architecture and includes updated JavaScript code and resources. Subsequently, the JavaScript code corresponding to the target page is searched in the loaded React Native Bundle file. When the user navigates to or the application needs to load a specific page, the JavaScript module or code snippet for that page is searched in the Bundle file of the hot update package.

[0059] In response to finding the JavaScript code corresponding to the target page, the mobile terminal loads and runs the JavaScript code. At this time, the application program gives priority to using the latest version of the page code provided in the hot update package, thereby displaying new pages or new functions without completely updating the application. In response to not finding the JavaScript code corresponding to the target page, the mobile terminal loads and runs the JavaScript code of the target network from the React Native Bundle of the application's main package. If the hot update package does not contain the updated code for the currently required page, or the hot update package fails to load, the application program falls back to using the React Native Bundle file in the application's main package that comes with the installation to load the corresponding page code, ensuring the normal operation of the application and guaranteeing the user experience even in the event of a hot update failure or partial update.

[0060] In one embodiment of the present application, after executing the hot update package installation operation, the following steps are also performed: in response to the successful installation of the hot update package, the latest version number is obtained, and the version detection interface is called again until no new version configuration information is detected.

[0061] In this embodiment, in response to the successful installation of the hot update package, the mobile terminal obtains the latest version number. This version number is obtained from the metadata of the successfully installed hot update package, indicating the latest code version of the current application reached through the hot update. The mobile terminal then calls the version detection interface again to check whether a continuous hot update is available or to confirm that the current version is already the latest version.

[0062] The advantage of this embodiment is that it avoids the need for users to wait for the next scheduled check to obtain subsequent updates. The mobile terminal continuously calls the version detection interface until no new version configuration information is detected. This process forms an update loop. That is, after successfully installing a hot update package, the mobile terminal immediately checks whether the next version hot update is available. The loop terminates only when the version detection interface returns that there is no new version configuration information higher than the current version.

[0063] In the embodiments of this application, terms such as "first" and "second" are used to distinguish between identical or similar items with substantially the same function or effect. For example, the first MD5 value and the second MD5 value are used solely to distinguish different MD5 values and do not define their order. Those skilled in the art will understand that terms such as "first" and "second" do not define the quantity or execution order, and do not necessarily define differences between them.

[0064] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" represent examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0065] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can represent: a, b, c, ab, ac, bc or abc, where a, b, c can be single or multiple.

[0066] Figure 4: is a schematic block diagram of a mobile application hot update device based on the React Native framework provided in an embodiment of the present application. Figure 4 As shown, the device includes a version detection module 401 , a hot update package acquisition module 402 and a hot update package installation module 403 .

[0067] Version detection module 401: configured to send a version detection request to the gateway through a version detection interface in response to program startup, and receive version configuration information corresponding to the version detection request returned by the gateway;

[0068] Hot update package acquisition module 402: used to obtain a hot update package from the content distribution network according to the version configuration information and perform a signature verification operation, wherein the hot update package is generated by the content distribution network based on the React Native framework;

[0069] The hot update package installation module 403 is configured to perform a decryption operation on the hot update package that has passed the signature verification; after the decryption operation is successful, perform a hot update package installation operation.

[0070] It should be understood that the specific process of each module executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.

[0071] It should also be understood that the division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.

[0072] Figure 5 : is a schematic block diagram of an electronic terminal provided in an embodiment of the present application. Figure 5 As shown, the electronic terminal includes: at least one processor 501, a memory 502, at least one network interface 503 and a user interface 505. The various components in the device are coupled together via a bus system 504. It is understood that the bus system 504 is used to achieve connection and communication between these components. In addition to including a data bus, the bus system 504 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, Figure 5 Various buses are labeled as bus systems.

[0073] The user interface 505 may include a display, a keyboard, a mouse, a trackball, a click gun, keys, buttons, a touch pad or a touch screen.

[0074] It will be appreciated that the memory 502 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM) or a programmable read-only memory (PROM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM) and synchronous static random access memory (SSRAM). The memory described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.

[0075] The memory 502 in the embodiment of the present invention is used to store various categories of data to support the operation of the electronic terminal 500. Examples of such data include: any executable program for operating on the electronic terminal 500, such as an operating system 5021 and an application 5022; the operating system 5021 includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application 5022 can include various applications, such as a media player (Media Player), a browser (Browser), etc., for implementing various application services. The mobile application hot update method based on the React Native framework provided in the embodiment of the present invention can be included in the application 5022.

[0076] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by processor 501. Processor 501 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in processor 501 or by software instructions. The above processor 501 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 501 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor 501 may be a microprocessor or any conventional processor. The steps of the accessory optimization method provided in conjunction with the embodiments of the present invention can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium located in a memory. The processor reads the information in the memory and, in conjunction with its hardware, completes the steps of the above method.

[0077] In an exemplary embodiment, the electronic terminal 500 may be configured to execute the aforementioned method using one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), or complex programmable logic devices (CPLDs).

[0078] According to the method provided in the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, which, when executed on a computer, enables the computer to execute the mobile application hot update method based on the React Native framework according to any of the embodiments shown above.

[0079] According to the method provided in the embodiments of the present application, the present application also provides a computer-readable storage medium, which stores program code. When the program code is run on a computer, the computer executes the mobile application hot update method based on the React Native framework according to any of the embodiments shown above.

[0080] As used in this specification, the terms "component," "module," "system," and the like are used to represent computer-related entities, hardware, firmware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a computing device and a computing device can be a component. One or more components can reside in a process and / or an execution thread, and a component can be located on a computer and / or distributed between two or more computers. In addition, these components can be executed from various computer-readable media having various data structures stored thereon. Components can communicate, for example, via local and / or remote processes based on signals having one or more data packets (e.g., data from two components interacting with another component on a local system, a distributed system, and / or a network, such as the Internet interacting with other systems via signals).

[0081] Those skilled in the art will appreciate that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0082] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0083] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0084] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0085] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0086] In the above embodiments, the functions of each functional unit can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions (programs). When the computer program instructions (program) are loaded and executed on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. Available media can be magnetic media (e.g., floppy disks, hard disks, tapes), optical media (e.g., high-density digital video discs (DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).

[0087] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0088] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

[0089] In summary, the present application provides a method, device, medium, program product and terminal for hot updating of mobile applications based on the React Native framework. Through the collaborative mechanism of the mobile terminal, gateway and content distribution network, a multi-level security protection system including version detection, encrypted transmission, signature verification and dynamic decryption is constructed. During the program startup phase, the version configuration information is obtained through the gateway, and the encrypted hot update package packaged by React Native is pulled from the content distribution network, and signature verification, decryption verification and differentiated installation operations are performed in sequence. It effectively solves the problems of easy code tampering and high risk of decompilation in the traditional hot update mechanism. At the same time, through the standardized packaging process and dynamic adaptation mechanism, the compatibility complexity of multiple devices and multiple system versions is significantly reduced, and the unified improvement of security and stability is achieved. Therefore, the present application effectively overcomes the various shortcomings in the existing technology and has a high industrial utilization value.

[0090] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Anyone skilled in the art may modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, all equivalent modifications or alterations made by one of ordinary skill in the art without departing from the spirit and technical concepts disclosed in this application shall be covered by the claims of this application.

Claims

1. A mobile application hot update method based on the React Native framework, the method is applied to a mobile terminal, the mobile terminal is respectively connected to a gateway and a content distribution network, and is characterized in that: include: In response to program startup, sending a version detection request to the gateway through a version detection interface, and receiving version configuration information corresponding to the version detection request returned by the gateway; Obtaining a hot update package from the content distribution network according to the version configuration information and performing a signature verification operation, wherein the hot update package is generated by the content distribution network based on the React Native framework; A decryption operation is performed on the hot update package that has passed the signature verification; after the decryption operation is successful, an installation operation of the hot update package is performed.

2. The method for hot updating mobile applications based on the React Native framework according to claim 1, characterized in that: The process of generating the hot update package by the content distribution network based on the React Native framework includes: The upgrade parameter information sent by the server is obtained through an auxiliary tool, and the upgrade parameters are used to perform a build operation through Jenkins to generate a source code package; a packaging operation is performed on the source code package based on a React Native framework scaffold to generate a target file, an encryption signature operation is performed on the target file to generate a hot update package, and the hot update package is published to the content distribution network for download by the mobile terminal.

3. The method for hot updating mobile applications based on the React Native framework according to claim 2, characterized in that: The process of the content distribution network performing the encryption signature operation on the target file includes: Calculate the first MD5 value of the encrypted target file; Performing an encryption operation on the first MD5 value using a preset private key to generate a digital signature value; combining the digital signature value with corresponding hot package parameters to generate a signature and metadata information; The encrypted target file is packaged together with the signature and metadata information, and a compression operation is performed to generate an encrypted and signed hot update package.

4. The method for hot updating a mobile application based on the React Native framework according to claim 3, characterized in that: The process of the mobile terminal performing the signature verification operation includes: Reading the encrypted target file contained in the hot update package and calculating a second MD5 value of the encrypted target file; Extracting a digital signature value and a corresponding hot package parameter combination from the encrypted and signed hot update package, and performing a verification operation on the digital signature value based on a preset public key to obtain a third MD5 value; The second MD5 value is compared with the third MD5 value; if the comparison results are consistent, the signature verification is determined to be successful; otherwise, the signature verification is determined to be unsuccessful.

5. The method for hot updating mobile applications based on the React Native framework according to claim 1, wherein: The process of the mobile terminal performing the hot update package installation operation includes: When a hot update package is detected, the React Native Bundle file in the hot update package is loaded; Search the React Native Bundle file for the JavaScript code corresponding to the target page. In response to finding the JavaScript code corresponding to the target page, loading and running the JavaScript code; In response to not finding the JavaScript code corresponding to the target page, the JavaScript code of the target network is loaded and run from the React Native Bundle of the application main package.

6. The method for hot updating mobile applications based on the React Native framework according to claim 1, characterized in that: After executing the hot update package installation operation, the following steps are further executed: in response to the hot update package being successfully installed, the latest version number is obtained, and the version detection interface is called again until no new version configuration information is detected.

7. A mobile application hot update device based on the React Native framework, characterized in that: include: Version detection module: used for sending a version detection request to the gateway through the version detection interface in response to program startup, and receiving version configuration information corresponding to the version detection request returned by the gateway; A hot update package acquisition module is configured to acquire a hot update package from the content distribution network according to the version configuration information and perform a signature verification operation. The hot update package is generated by the content distribution network based on the React Native framework. The hot update package installation module is used to perform a decryption operation on the hot update package that has passed the signature verification; after the decryption operation is successful, perform a hot update package installation operation.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for hot updating a mobile application based on the React Native framework as described in any one of claims 1 to 6 is implemented.

9. A computer program product, characterized in that The computer program product includes computer program code, and when the computer program code is run on a computer, the computer is enabled to implement the mobile application hot update method based on the React Native framework as claimed in any one of claims 1 to 6.

10. An electronic terminal comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the mobile application hot update method based on the React Native framework as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Hot updating method and device

    CN110278115A

  • Data updating method, system and device, electronic equipment and computer storage medium

    CN111026416A

  • Hot update method based on React Native cross-platform framework

    CN119248310A