Mobile application authentication method and device, electronic equipment and storage medium

By configuring the authorization code solution algorithm in the SDK and verifying that the package name and security parameters of the mobile application match, the problem of improper authentication of the mobile SDK in offline scenarios is solved, and the security of vehicle control operations is improved.

CN120744897APending Publication Date: 2025-10-03ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510818875.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

The authentication mechanism of existing mobile SDKs cannot work effectively in offline scenarios and poses security risks. For example, malicious applications may steal legitimate authorization codes and illegally use the SDK.

Method used

By configuring the authorization code solution algorithm in the SDK, it is possible to directly verify whether the package name and security parameters of the mobile application match, thereby performing authentication in offline mode and ensuring the legitimacy of the authorization information.

Benefits of technology

It realizes effective authentication of mobile applications in offline state, prevents illegal users from stealing authorization codes, and improves the security of vehicle control operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744897A_ABST
    Figure CN120744897A_ABST
Patent Text Reader

Abstract

The invention provides a mobile application authentication method and device, electronic equipment and a storage medium, and is applied to an SDK (Software Development Kit) with an off-line function interface, and the method comprises the following steps: responding to an authentication request initiated by a mobile application; resolving an authorization code provided by the mobile application program to obtain authorization information of the mobile application program, wherein the authorization information comprises a first package name and a first security parameter; obtaining a second package name and a second security parameter of the mobile application program maintained by the mobile terminal operating system from the mobile terminal operating system to which the mobile application program belongs; and under the condition that the first package name is consistent with the second package name and the first safety parameter is consistent with the second safety parameter, allowing the mobile application program to call the vehicle control SDK through the offline function interface to execute remote vehicle control operation. Therefore, when the software development kit SDK is in the off-line state mode, the mobile application program can be authenticated, and after the authentication is passed, the mobile application program is allowed to call the off-line function interface.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present disclosure relate to the field of software development technology, and in particular, to a mobile application authentication method, device, electronic device, and storage medium. Background Art

[0002] In the existing technology, mobile SDK (Software Development Kit) serves as a functional extension component of mobile applications. It authorizes and authenticates mobile applications to confirm their legal rights to use SDK functions, preventing unauthorized third-party mobile applications from abusing these functions, thereby ensuring security.

[0003] Specifically, the mobile SDK's authentication mechanism primarily generates an authorization code based on the mobile application's parameters. When an application needs to use the SDK, it typically communicates with a backend server, which verifies the validity of the authorization code by verifying whether a corresponding issuance record exists on the server.

[0004] However, this approach has certain limitations: on the one hand, it is not suitable for offline scenarios without network connection; on the other hand, there are security risks, such as malicious mobile applications may steal legitimate authorization codes and illegally use the SDK. Summary of the Invention

[0005] To address the problem in related art that authentication through authorization codes of mobile applications is limited to an online environment and that authorization codes may be misused, resulting in inaccurate authentication, the present disclosure provides a mobile application authentication method, which is applied to a vehicle control software development kit (SDK) that opens an offline functional interface. The method includes:

[0006] In response to an authentication request initiated by a mobile application, solving an authorization code provided by the mobile application to obtain authorization information of the mobile application, the authorization information including a first package name and a first security parameter;

[0007] Obtaining, from the mobile terminal operating system to which the mobile application belongs, a second package name and a second security parameter of the mobile application maintained by the mobile terminal operating system;

[0008] When the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter, the mobile application is allowed to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations.

[0009] Optionally, the vehicle control SDK further opens an online function interface, the authorization information further includes a product function identifier, and the method further includes:

[0010] If the vehicle control SDK is online, the product function identifier is sent to the backend server, and the interface authorization information returned by the backend server is received;

[0011] Determine the authorized functional interface corresponding to the product function identifier represented by the interface authorization information, and in response to the call request initiated by the mobile application for the authorized functional interface, execute the remote vehicle control operation associated with the authorized functional interface, wherein the authorized functional interface includes at least the online functional interface.

[0012] Optionally, sending the product function identifier to a backend server and receiving interface authorization information returned by the backend server includes:

[0013] Sending the product function identifier to a backend server so that the backend server can verify whether there is a historical issuance record for the product function identifier;

[0014] If there is a historical issuance record of the product function identifier in the back-end server, the interface authorization information returned by the back-end server is received.

[0015] Optionally, the method further includes:

[0016] If there is no historical issuance record of the product function identifier in the back-end server, the interface authorization information returned by the back-end server cannot be received.

[0017] Optionally, each authorization code is generated by the back-end server through a combined encryption algorithm based on the package name, security parameters and product function identifier for the software development kit sent by each mobile application.

[0018] Optionally, the method further includes:

[0019] If the first package name is inconsistent with the second package name, or the first security parameter is inconsistent with the second security parameter, the calling request of the mobile application for any functional interface will not be responded to, so as not to perform the vehicle control operation specified by any functional interface.

[0020] Optionally, the first security parameter and the second security parameter respectively include corresponding packaging certificate signatures.

[0021] The present disclosure also provides a mobile application authentication device, which is applied to a vehicle control software development kit (SDK) with an open offline function interface. The device includes:

[0022] a solving unit, configured to solve, in response to an authentication request initiated by a mobile application, an authorization code provided by the mobile application to obtain authorization information of the mobile application, the authorization information including a first package name and a first security parameter;

[0023] an acquiring unit, configured to acquire, from a mobile terminal operating system to which the mobile application belongs, a second package name and a second security parameter of the mobile application maintained by the mobile terminal operating system;

[0024] A calling unit is used to allow the mobile application to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations when the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter.

[0025] The present disclosure further provides an electronic device, comprising a communication interface, a processor, a memory, and a bus, wherein the communication interface, the processor, and the memory are interconnected via the bus;

[0026] The memory stores machine-readable instructions, and the processor executes the above method by calling the machine-readable instructions.

[0027] The present disclosure also provides a machine-readable storage medium, wherein the machine-readable storage medium stores machine-readable instructions, and when the machine-readable instructions are called and executed by a processor, the above method is implemented.

[0028] Through the embodiments of the present disclosure, an authorization code resolution algorithm corresponding to the generated authorization code is configured in the software development kit itself. When the software development kit responds to the authentication request initiated by the mobile application, the authorization code provided by the mobile application is resolved to obtain the authorization information of the mobile application, and the authorization information includes a first package name and a first security parameter; further, the second package name and second security parameter of the mobile application maintained by the mobile operating system to which the mobile application belongs are obtained; finally, when the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter, the mobile application is allowed to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations.

[0029] Through the above method, the technical solution disclosed in the present invention can realize the authentication of mobile applications by itself when the software development kit is in offline mode and cannot communicate with the server. The authentication process needs to verify that the package name of the mobile application is consistent with the package name in the authorization code provided by the mobile application, and the security parameters of the mobile application are consistent with the security parameters in the authorization code provided by the mobile application. This ensures that only when the same mobile application published by the same mobile application publisher uses the authorization code, the source of the mobile application requesting to call the vehicle control SDK is determined to be legal, and the mobile application is allowed to call the offline function interface, thereby preventing illegal users from stealing the authorization code to use the software development kit and improving the security of vehicle control operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0031] Figure 1 This is a flow chart showing a method for authenticating a mobile application according to an exemplary embodiment;

[0032] Figure 2 This is a schematic diagram of a method for generating an authorization code, shown in an exemplary embodiment;

[0033] Figure 3 is a flow chart illustrating another mobile application authentication method according to an exemplary embodiment;

[0034] Figure 4 is a hardware structure diagram of an electronic device shown in an exemplary embodiment;

[0035] Figure 5 The figure is a block diagram of a mobile application authentication device according to an exemplary embodiment. DETAILED DESCRIPTION

[0036] In order to enable those skilled in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present disclosure.

[0037] It should be noted that in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this disclosure. In some other embodiments, the method may include more or fewer steps than those described in this disclosure. In addition, a single step described in this disclosure may be broken down into multiple steps for description in other embodiments; and multiple steps described in this disclosure may be combined into a single step for description in other embodiments.

[0038] In the existing technology, mobile SDK (Software Development Kit) serves as a functional extension component of mobile applications. It authorizes and authenticates mobile applications to confirm their legal rights to use SDK functions, preventing unauthorized third-party mobile applications from abusing these functions, thereby ensuring security.

[0039] Specifically, the mobile SDK's authentication mechanism primarily generates an authorization code based on the mobile application's parameters. When an application needs to use the SDK, it typically communicates with a backend server, which verifies the validity of the authorization code by verifying whether a corresponding issuance record exists on the server.

[0040] However, this approach has certain limitations: on the one hand, it is not suitable for offline scenarios without network connection; on the other hand, there are security risks, such as malicious mobile applications may steal legitimate authorization codes and illegally use the SDK.

[0041] In view of this, the present disclosure aims to propose a technical solution for directly verifying whether the mobile application package name and security parameters used when generating the authorization code match the mobile application currently requesting authentication, thereby authenticating the mobile application software toolkit in offline mode.

[0042] This technical solution configures an authorization code resolution algorithm corresponding to the generated authorization code in the software development kit itself. When the software development kit responds to the authentication request initiated by the mobile application, it resolves the authorization code provided by the mobile application to obtain the authorization information of the mobile application, and the authorization information includes a first package name and a first security parameter; further, the second package name and second security parameter of the mobile application maintained by the mobile operating system to which the mobile application belongs are obtained; finally, when the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter, the mobile application is allowed to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations.

[0043] For example, a mobile application from automaker A runs on a user's mobile device (such as a phone). It integrates a digital key SDK. When a user needs to use the digital key SDK, the mobile application enters an authorization code into the digital key SDK. The digital key SDK then decrypts the authorization code and obtains the mobile application's authorization information, including the package name of the mobile application that generated the authorization code (such as com.A.car.key) and security parameters (such as the packaged certificate signature digest "abc123"). The SDK then uses the interface provided by the iOS operating system on the mobile device where the mobile application resides to obtain the actual package name (such as com.A.car.key) and actual security parameters (such as the packaged certificate signature digest "abc123"). Finally, the decrypted package name is compared with the actual package name, and the security parameters are compared with the actual security parameters. If both match, the digital key SDK allows the mobile application to call its own offline function interface to perform remote vehicle control operations, such as connecting to and controlling the vehicle via Bluetooth.

[0044] Through the above method, the technical solution disclosed in the present invention can realize the authentication of mobile applications by itself when the software development kit is in offline mode and cannot communicate with the server. The authentication process needs to verify that the package name of the mobile application is consistent with the package name in the authorization code provided by the mobile application, and the security parameters of the mobile application are consistent with the security parameters in the authorization code provided by the mobile application. This ensures that only when the same mobile application published by the same mobile application publisher uses the authorization code, the source of the mobile application requesting to call the vehicle control SDK is determined to be legal, and the mobile application is allowed to call the offline function interface, thereby preventing illegal users from stealing the authorization code to use the software development kit and improving the security of vehicle control operations.

[0045] The present disclosure is described below through specific embodiments in combination with specific application scenarios.

[0046] See Figure 1 , Figure 1 This is a flow chart showing a method for authenticating a mobile application according to an exemplary embodiment. The method may perform the following steps:

[0047] Step 102: In response to the authentication request initiated by the mobile application, the authorization code provided by the mobile application is resolved to obtain authorization information of the mobile application, where the authorization information includes a first package name and a first security parameter.

[0048] For example, a mobile application of a car company A runs on the user's handheld mobile terminal (such as a mobile phone). It integrates a vehicle control SDK (such as a digital key SDK). When the user needs to use the digital key SDK function, the mobile application inputs the authorization code to the digital key SDK. The digital key SDK solves the authorization code and obtains the authorization information of the mobile application, including the package name of the mobile application that generates the authorization code (such as com.A.car.key) and security parameters (such as the package certificate signature summary "abc123").

[0049] Among them, mobile applications are also called App (Application) or client. The authorization code is a credential generated by combining parameters such as the package name and security parameters of the mobile application according to specific rules (such as string splicing) and encrypting (such as the Advanced Encryption Standard AES algorithm), which is used to verify the identity of the mobile application and the functional permissions for the SDK. The package name is a unique identifier of the mobile application in the operating system (similar to a file path) and is used to distinguish different mobile applications. Security parameters are used to confirm the identity of the publisher of the mobile application to avoid illegal compilation and packaging of mobile applications impersonating legitimate applications. The authorization code can be included in the authentication request initiated by the mobile application to the on-board SDK, or it can be sent to the on-board SDK separately after the authentication request is initiated. This disclosure does not limit this.

[0050] Step 104: Obtain, from the mobile terminal operating system to which the mobile application belongs, the second package name and the second security parameter of the mobile application maintained by the mobile terminal operating system.

[0051] For example, the actual package name (such as com.A.car.key) and actual security parameters (such as the package certificate signature digest "abc123") of the current mobile application are obtained through the interface provided by the mobile iOS operating system where the current mobile application is located.

[0052] Among them, the mobile operating system interface refers to the API interface provided by the operating system for obtaining metadata of mobile applications. The actual security parameters refer to the real signature information verified and stored by the application store or operating system when the mobile application is installed. The operating systems include Apple's iOS operating system, Android operating system, and Huawei's Harmony system. The signature information obtained through the native interface of the operating system cannot be tampered with by the mobile application itself (because full control permission of the system is required), ensuring the credibility of the verification data. For example, even if malicious logic is injected into the mobile application code, its signature information remains in its original state. The operating system interface call does not require a network and is suitable for environments without a network, such as underground garages.

[0053] In one embodiment shown, the first security parameter and the second security parameter each include a corresponding packaged certificate signature.

[0054] For example, a developer at automaker A needs to integrate a vehicle control SDK (SDK) into their mobile app to control smart car functions. To ensure security, the mobile app must be signed with an official certificate. The resulting signature digest serves as a security parameter for generating an authorization code for the vehicle control SDK.

[0055] Among them, the package certificate signature digest is an encrypted hash value used to confirm the identity of the mobile application publisher. The package certificate signature digest is generated by the developer using his private key to sign the entire APK (Android Package, Android installation package) or IPA (iOS App Store Package, iOS Application Store package) file of the mobile application. This process ensures that only developers with the correct private key can generate a legal signature, so that it can be verified that the mobile application is indeed published by a specific developer and has not been tampered with. Depending on specific needs, security parameters may also include additional information, such as hardware feature codes, geographic location information, etc., to enhance security. This disclosure does not limit the specific content of the security parameters.

[0056] Step 106: When the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter, the mobile application is allowed to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations.

[0057] For example, by comparing the solved package name with the actual package name, and comparing the security parameters with the actual security parameters, if both are consistent, the digital key SDK allows the current mobile application to call its own offline function interface to perform remote vehicle control operations, such as connecting and controlling the vehicle via Bluetooth.

[0058] Among them, when comparing the package names, it is necessary to compare the strings of the two package names character by character (each character must be exactly the same). When comparing security parameters, it is necessary to compare the actual signature digest of the obtained mobile application with the signature digest of the packaged certificate calculated in the authorization code. The offline function interface refers to the functions provided by the SDK that do not require real-time network verification, such as Bluetooth communication, local data storage, etc. For example, the digital key SDK can communicate with the vehicle's electronic control unit through the BLE (Bluetooth LowEnergy) protocol in an offline state to achieve unlocking / starting functions. After authorization is passed, the SDK can store temporary tokens locally, such as JWT (JSON Web Token) with a validity period of 10 minutes, for quick verification of subsequent operations.

[0059] In one embodiment shown, the vehicle control SDK also opens an online function interface, and the authorization information also includes a product function identifier. The method also includes: if the vehicle control SDK is in an online state, the product function identifier is sent to the back-end server, and the interface authorization information returned by the back-end server is received; the authorized function interface corresponding to the product function identifier represented by the interface authorization information is determined, and in response to the call request initiated by the mobile application for the authorized function interface, the remote vehicle control operation associated with the authorized function interface is executed, and the authorized function interface includes at least the online function interface.

[0060] For example, if a mobile application integrates the Digital Key SDK and needs to call the Digital Key SDK's online functional interfaces to remotely unlock a vehicle and download digital key information, the mobile application will pass an authorization code to the Digital Key SDK. The Digital Key SDK receives the authorization code and deciphers the package name com.A.car.key, security parameters abc123, and product function identifier AppID_001. If the Digital Key SDK confirms that the mobile device is online, it sends the product function identifier AppID_001 to the backend server. After receiving AppID_001, the backend server returns interface authorization information to the Digital Key SDK. The Digital Key SDK then determines the authorized functional interfaces corresponding to the product function identifier AppID_001 indicated in the interface authorization information. For example, AppID_001 is authorized to use the remote vehicle unlocking interface and the digital key information downloading interface. When the mobile application initiates calls to the remote vehicle unlocking interface and the digital key information downloading interface, the Digital Key SDK can perform the remote vehicle control operations associated with the corresponding interfaces, such as remote vehicle unlocking and digital key information downloading.

[0061] Among them, the authorized functional interface can include both the online functional interface of the vehicle control SDK and the offline functional interface of the vehicle control SDK. The authorized functional interface can be a functional interface of the vehicle control SDK or several functional interfaces of the vehicle control SDK. The present disclosure does not limit whether the authorized functional interface is an offline functional interface or an online functional interface, as well as the specific number of authorized functional interfaces. Each mobile application has a unique product function identifier (AppID) to distinguish the functional permissions of different mobile applications for the vehicle control SDK. The online functional interface requires the vehicle control SDK to be connected to the back-end server to be used. Online functions usually involve functions such as real-time vehicle data interaction and remote vehicle control.

[0062] In one embodiment shown, sending the product function identifier to the back-end server and receiving the interface authorization information returned by the back-end server includes: sending the product function identifier to the back-end server so that the back-end server verifies whether there is a historical issuance record for the product function identifier; if there is a historical issuance record for the product function identifier in the back-end server, receiving the interface authorization information returned by the back-end server.

[0063] For example, the Digital Key SDK confirms that the current mobile device is online and sends the product function identifier AppID_001 to the backend server. After receiving AppID_001, the backend server queries the database to determine whether there is a historical issuance record for the product function identifier AppID_001. If there is a historical issuance record for the product function identifier AppID_001 in the database, and there is a corresponding permission record indicating that the product function identifier has been authorized to use the functional interface for remote unlocking the vehicle, the interface authorization information corresponding to the product function identifier AppID_001 is returned to the Digital Key SDK, indicating that the product function identifier AppID_001 is authorized to use the functional interface for remote unlocking the vehicle.

[0064] Among them, when a service agreement is signed between a mobile application service provider and an in-vehicle SDK service provider, a product function identifier for the mobile application will be generated. The product function identifier is issued by the back-end server, and the product function identifier and the corresponding interface authorization information will be stored in the database of the back-end server. The database can be queried later to determine whether there is a historical issuance record of the product function identifier. In this embodiment, the in-vehicle SDK can detect whether the current mobile terminal device is connected to the Internet through a network status listener or a timed heartbeat packet. If the current mobile terminal device is connected to the Internet, it is considered that the in-vehicle SDK is online, and the in-vehicle SDK can send the product function identifier to the back-end server. When sending the product function identifier to the back-end server, the in-vehicle SDK can use an encrypted communication method to ensure the security of data transmission. The present disclosure does not limit the specific method of communication between the in-vehicle SDK and the back-end server.

[0065] In an illustrated embodiment, the method further includes: if there is no historical issuance record of the product function identifier in the back-end server, it is impossible to receive the interface authorization information returned by the back-end server.

[0066] For example, the Digital Key SDK confirms that the current mobile device is online and sends the product function identifier AppID_001 to the backend server. After receiving AppID_001, the backend server queries the database to determine whether there is a historical issuance record for the product function identifier AppID_001. If there is no historical issuance record for the product function identifier AppID_001 in the database, the backend server will not return the interface authorization information corresponding to the product function identifier AppID_001 to the Digital Key SDK, and the Digital Key SDK will not be able to receive any interface authorization information returned by the backend server.

[0067] Among them, if there is no historical issuance record for the product function identifier in the database, it means that the product function identifier does not correspond to any authorized functional interface of the vehicle SDK, so the back-end server will not return any interface authorization information. When the back-end server queries the database for whether there is an issuance record of the product function identifier, it can use an SQL query statement to search the database for the specified product function identifier. If the query result returns the corresponding data, it means that there is a historical issuance record for the product function identifier; if the query result is empty, it means that there is no historical issuance record. If multiple product function identifiers need to be verified at the same time, the back-end server can use batch queries to reduce the number of database connections and network delays. This disclosure does not limit the specific method of back-end server queries.

[0068] In one embodiment shown, each authorization code is generated by the backend server through a combined encryption algorithm based on the package name, security parameters, and product function identifier for the software development kit sent by each mobile application.

[0069] For example, see Figure 2 , Figure 2 FIG. 1 is a schematic diagram of a method for generating an authorization code according to an exemplary embodiment. Figure 2 As shown, the backend server combines the mobile application package name, mobile application security parameters, and product function identifier according to a combination rule, such as sequential concatenation. It then generates an authorization code based on specific calculation rules, such as encrypting the combined data using the Advanced Encryption Standard (AES) algorithm, to generate an authorization code for the vehicle control SDK. Finally, the generated authorization code for the vehicle control SDK is recorded in the server-side management system for subsequent authorization code management.

[0070] Among them, AES is a symmetric encryption algorithm that is widely used to protect the security of electronic data and is suitable for data encryption needs in various environments. Before generating the authorization code, the package name, security parameters and product function identifier of the mobile application need to be spliced ​​together in a certain order or combined in other ways. For example, they can be spliced ​​into a long string in order, or a more complex structured format (such as JSON format, etc.) can be used to represent this information, and then the information is encrypted. The present disclosure does not limit the specific combination of the package name, security parameters and product function identifier of the mobile application.

[0071] In one embodiment shown, the method also includes: if the first package name is inconsistent with the second package name, or the first security parameter is inconsistent with the second security parameter, then not responding to the mobile application's call request for any functional interface, so as not to execute the vehicle control operation specified by any functional interface.

[0072] For example, see Figure 3 , Figure 3 FIG. 1 is a flow chart of another mobile application authentication method according to an exemplary embodiment. Figure 3As shown, after receiving the authorization code from the mobile application, the vehicle control SDK applies the reverse decoding algorithm to the authorization code to obtain the combination that constitutes the authorization code. The vehicle control SDK then uses the reverse decoding algorithm to obtain the package name, security parameters, and product function identifier of the mobile application that constitutes the combination. The vehicle control SDK then performs offline mode verification using the calculated mobile application package name and security parameters. If the offline verification fails, the mobile application cannot use any vehicle control SDK functions. If the offline verification succeeds, it determines whether online mode verification can be performed, that is, whether communication with the backend server is possible. If online mode verification is not possible, the mobile application is only allowed to use the vehicle control SDK's offline functions. If online mode verification is possible, the product function identifier is sent to the backend server, which determines whether there is an issuance record for the product function identifier. If there is an issuance record for the product function identifier, the online mode verification succeeds, allowing the mobile application to use the vehicle control SDK's offline functions and the authorized online functions of the vehicle control SDK corresponding to the product function identifier. If there is no issuance record for the product function identifier, the mobile application cannot use any vehicle control SDK functions.

[0073] Among them, the functional interface refers to the functional entrance exposed by the vehicle control SDK to the outside world, which is used to implement specific business logic, such as the "remote unlocking", "starting the air conditioner" and other functions in the vehicle control SDK. Functional interfaces are divided into two categories, one is the offline functional interface (can be executed without an Internet connection), and the other is the online functional interface (needs to connect to the back-end server to verify permissions). Vehicle control operations refer to the actual control actions of the vehicle called through the SDK, such as remote locking, unlocking, starting the engine, etc. These operations usually have high security requirements and must be strictly authenticated before they can be executed. The network status monitoring module can be integrated into the SDK to automatically determine whether online mode verification can be initiated.

[0074] Corresponding to the above-mentioned embodiment of the mobile application authentication method, the present disclosure also provides an embodiment of a mobile application authentication device.

[0075] See Figure 4 , Figure 4This is a hardware structure diagram of an electronic device shown in an exemplary embodiment. At the hardware level, the device includes a processor 402, an internal bus 404, a network interface 406, a memory 408, and a non-volatile memory 410, and of course may also include other required hardware. One or more embodiments of the present disclosure can be implemented based on software, such as the processor 402 reading the corresponding computer program from the non-volatile memory 410 into the memory 408 and then running it. Of course, in addition to software implementation, one or more embodiments of the present disclosure do not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0076] See Figure 5 , Figure 5 FIG. 5 is a block diagram of a mobile application authentication device according to an exemplary embodiment. The mobile application authentication device 500 can be applied to Figure 4 The electronic device shown in the figure is used to implement the technical solution of the present disclosure. The device is applied to a vehicle control software development kit SDK with an open offline function interface, and the device includes:

[0077] A solving unit 502 is configured to solve, in response to an authentication request initiated by a mobile application, an authorization code provided by the mobile application to obtain authorization information of the mobile application, the authorization information including a first package name and a first security parameter;

[0078] An acquiring unit 504 is configured to acquire, from the mobile terminal operating system to which the mobile application belongs, a second package name and a second security parameter of the mobile application maintained by the mobile terminal operating system;

[0079] The calling unit 506 is used to allow the mobile application to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations when the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter.

[0080] In some embodiments, the vehicle control SDK further opens an online function interface, the authorization information further includes a product function identifier, and the device further includes:

[0081] The sending unit 508 is configured to send the product function identifier to the backend server if the vehicle control SDK is online, and receive the interface authorization information returned by the backend server;

[0082] The execution unit 510 is used to determine the authorized functional interface corresponding to the product function identifier represented by the interface authorization information, and in response to the call request initiated by the mobile application for the authorized functional interface, execute the remote vehicle control operation associated with the authorized functional interface, and the authorized functional interface includes at least the online functional interface.

[0083] In some embodiments, sending the product function identifier to a backend server and receiving interface authorization information returned by the backend server includes:

[0084] Sending the product function identifier to a backend server so that the backend server can verify whether there is a historical issuance record for the product function identifier;

[0085] If there is a historical issuance record of the product function identifier in the back-end server, the interface authorization information returned by the back-end server is received.

[0086] In some embodiments, the apparatus further comprises:

[0087] The receiving unit 512 is configured to fail to receive the interface authorization information returned by the backend server if there is no historical issuance record of the product function identifier in the backend server.

[0088] In some embodiments, each authorization code is generated by the backend server through a combined encryption algorithm based on the package name, security parameters, and product function identifier for the software development kit sent by each mobile application.

[0089] In some embodiments, the apparatus further comprises:

[0090] The response unit 514 is used to not respond to the call request of the mobile application for any functional interface if the first package name is inconsistent with the second package name, or the first security parameter is inconsistent with the second security parameter, so as not to perform the vehicle control operation specified by any functional interface.

[0091] In some embodiments, the first security parameter and the second security parameter each include a corresponding packaging certificate signature.

[0092] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0093] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the disclosed solution. A person of ordinary skill in the art can understand and implement it without paying any creative work.

[0094] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email transceiver, game console, tablet computer, wearable device, or any combination of these devices.

[0095] In a typical configuration, a computer includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0096] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0097] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information using any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, disk storage, quantum memory, graphene-based storage media or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0098] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0099] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0100] The foregoing description describes specific embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0101] The terms used in one or more embodiments of the present disclosure are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of the present disclosure. The singular forms "a," "the," and "the" used in one or more embodiments of the present disclosure and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0102] It should be understood that although the terms first, second, third, etc. may be used to describe various information in one or more embodiments of the present disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of one or more embodiments of the present disclosure, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0103] The above description is merely a preferred embodiment of one or more embodiments of the present disclosure and is not intended to limit one or more embodiments of the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of the present disclosure shall be included in the scope of protection of one or more embodiments of the present disclosure.

Claims

1. A mobile application authentication method, characterized in that: Applied to a vehicle control software development kit (SDK) that opens an offline functional interface, the method includes: In response to an authentication request initiated by a mobile application, solving an authorization code provided by the mobile application to obtain authorization information of the mobile application, the authorization information including a first package name and a first security parameter; Obtaining, from the mobile terminal operating system to which the mobile application belongs, a second package name and a second security parameter of the mobile application maintained by the mobile terminal operating system; When the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter, the mobile application is allowed to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations.

2. The method according to claim 1, characterized in that The vehicle control SDK also opens an online function interface, the authorization information also includes a product function identifier, and the method further includes: If the vehicle control SDK is online, the product function identifier is sent to the backend server, and the interface authorization information returned by the backend server is received; Determine the authorized functional interface corresponding to the product function identifier represented by the interface authorization information, and in response to the call request initiated by the mobile application for the authorized functional interface, execute the remote vehicle control operation associated with the authorized functional interface, wherein the authorized functional interface includes at least the online functional interface.

3. The method according to claim 2, characterized in that The sending of the product function identifier to the backend server and receiving the interface authorization information returned by the backend server includes: Sending the product function identifier to a backend server so that the backend server can verify whether there is a historical issuance record for the product function identifier; If there is a historical issuance record of the product function identifier in the back-end server, the interface authorization information returned by the back-end server is received.

4. The method according to claim 3, characterized in that The method further comprises: If there is no historical issuance record of the product function identifier in the back-end server, the interface authorization information returned by the back-end server cannot be received.

5. The method according to claim 2, characterized in that Each authorization code is generated by the backend server through a combined encryption algorithm based on the package name, security parameters and product function identifier for the software development kit sent by each mobile application.

6. The method according to claim 1, characterized in that The method further comprises: If the first package name is inconsistent with the second package name, or the first security parameter is inconsistent with the second security parameter, the calling request of the mobile application for any functional interface will not be responded to, so as not to perform the vehicle control operation specified by any functional interface.

7. The method according to any one of claims 1 to 6, characterized in that The first security parameter and the second security parameter respectively include corresponding packaging certificate signatures.

8. A mobile application authentication device, characterized in that: Applicable to a vehicle control software development kit (SDK) with an open offline functional interface, the device includes: a solving unit, configured to solve, in response to an authentication request initiated by a mobile application, an authorization code provided by the mobile application to obtain authorization information of the mobile application, the authorization information including a first package name and a first security parameter; an acquiring unit, configured to acquire, from a mobile terminal operating system to which the mobile application belongs, a second package name and a second security parameter of the mobile application maintained by the mobile terminal operating system; A calling unit is used to allow the mobile application to call the vehicle control SDK through the offline function interface to perform remote vehicle control operations when the first package name is consistent with the second package name and the first security parameter is consistent with the second security parameter.

9. An electronic device, characterized in that: It includes a communication interface, a processor, a memory and a bus, wherein the communication interface, the processor and the memory are interconnected via the bus; The memory stores machine-readable instructions, and the processor executes the method according to any one of claims 1 to 7 by calling the machine-readable instructions.

10. A machine-readable storage medium, characterized in that The machine-readable storage medium stores machine-readable instructions, and when the machine-readable instructions are called and executed by a processor, the method according to any one of claims 1 to 7 is implemented.