Electronic device and operating method for exectuting application package
By verifying and storing signature values for application packages, the electronic device ensures only authorized installations and updates, safeguarding against unauthorized modifications and maintaining service integrity.
Patent Information
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- SAMSUNG ELECTRONICS CO LTD
- Filing Date
- 2021-01-13
- Publication Date
- 2026-07-21
AI Technical Summary
Electronic devices face issues with unauthorized modification and forgery of application packages, as updates can occur without authentication, compromising the integrity of services provided by enterprise-specific devices.
The electronic device includes a processor that verifies application packages upon initial boot and subsequent mode changes, storing signature values to ensure authenticity, and only allows updates when signature values match, preventing unauthorized alterations.
This approach ensures that only verified and authorized application packages are installed and updated, maintaining the intended services and preventing forgery, thereby securing the device's functionality.
Smart Images

Figure 112021004664085-PAT00002_ABST
Abstract
Description
Technology Field
[0001] Various embodiments according to the present disclosure are techniques for verifying an application package executed on an electronic device and preventing forgery and / or alteration of the application package. Background Technology
[0002] Recently, as the development of the information technology (IT) industry accelerates, the business environment is also changing rapidly. Portable electronic devices such as smartphones, tablet PCs, and laptops utilizing mobile communication and processing technologies are being widely used.
[0003] An electronic device can use a launcher program to install applications and provide an environment where users can run or manage the applications they want.
[0004] In this document, an application package refers to an application software package, and the application package may include all data related to the application. For example, the application package may include images, videos, and / or text files of the application. For example, the application package may be a file in APK format. An electronic device may execute the application or install the application on the electronic device using the application package. Depending on various embodiments, the application package may represent an application installation file.
[0005] The electronic device may install application packages that meet specific purposes in accordance with the requirements of the enterprise providing services using the electronic device. For example, in the case of a children's smartphone, a separate electronic device for child users may be represented. A children's smartphone, also known as a "kids phone," may install application packages that include applications usable by children and images, videos, and / or text files customized for children. The problem to be solved
[0006] In the case of electronic devices distributed by an enterprise, services tailored to a specific purpose can be provided based on application packages provided by the enterprise. Electronic devices provided by the enterprise for specific purposes may offer services designated by the enterprise within a limited scope. Therefore, customized application packages designed to provide these designated services must be installed through an application package module certified by the enterprise.
[0007] Furthermore, since electronic devices are intended to provide designated services within a limited scope, it is necessary to prevent application packages installed on the devices from being forged or altered without permission. In particular, application packages distributed by companies for specific purposes must be protected from unauthorized modification. Nevertheless, if the package names of application packages installed on electronic devices are identical, updates are possible without a separate authentication process, which allows the application packages to be forged and / or altered without authorization.
[0008] The technical problems to be solved in this disclosure are not limited to those mentioned above, and other unmentioned technical problems will be clearly understood by those skilled in the art from the description below. means of solving the problem
[0009] An electronic device in one embodiment includes a communication circuit, a display, a memory for storing an application package received through the communication circuit in response to the electronic device being booted for the first time, and at least one processor electrically connected to the communication circuit and the memory, wherein the at least one processor determines whether the application package is installed in the electronic device in response to the electronic device being executed in a first mode for the first time, verifies the application package based on the determination result, and stores a first signature value corresponding to the application package in the memory based on the verification result.
[0010] In one embodiment, a method of operation of an electronic device that stores an application package received through a communication circuit in memory in response to initial booting may include an operation of determining whether the application package is installed in the electronic device in response to the electronic device first executing a first mode, an operation of verifying the application package stored in memory based on the determination result, and an operation of storing a first signature value corresponding to the application package in memory based on the verification result.
[0011] An electronic device in one embodiment includes a communication circuit, a memory storing a first application package and a second application package, and at least one processor electrically connected to the communication circuit and the memory. In response to the electronic device first executing a second mode while executing a first mode, the at least one processor determines whether a second application package corresponding to the second mode is installed in the electronic device, verifies the second application package corresponding to the second mode based on the determination result, and stores a second signature value corresponding to the second application package in the memory based on the second application package verification result. Effects of the invention
[0012] An electronic device according to various embodiments of the present disclosure can install a verified application package. For example, the electronic device can verify whether the application package is installed based on an authenticated installer or whether the application package is developed based on an authorized software development kit.
[0013] An electronic device according to various embodiments of the present disclosure may allow installation limited to authorized application package updates when an application package is updated. Accordingly, the electronic device may prevent forgery and / or alteration of the application package.
[0014] The effects obtainable from the present disclosure are not limited to those mentioned above, and other unmentioned effects will be clearly understood by those skilled in the art to which the present disclosure belongs from the description below. Brief explanation of the drawing
[0015] FIG. 1 is a diagram showing a system in which an external device according to one embodiment transmits an application package to a plurality of electronic devices through a network. FIG. 2 is a block diagram illustrating the configuration of an electronic device according to one embodiment. FIG. 3 is a flowchart of a process in which an electronic device according to one embodiment stores a signature value corresponding to an application package. FIG. 4 is a flowchart of a process for an electronic device to verify an application package according to one embodiment. FIG. 5 is a flowchart of a process in which another electronic device updates an application package in one embodiment. FIG. 6 is a flowchart of a process in which an electronic device according to one embodiment selects one of a plurality of execution modes and stores a signature value corresponding to an application package based on the execution mode. FIG. 7 is a drawing for explaining a UI based on an application package according to one embodiment. FIG. 8 is a diagram illustrating a UI based on an update to an application package according to one embodiment. FIG. 9 is a block diagram of an electronic device in a network environment according to various embodiments. In relation to the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Specific details for implementing the invention
[0016] FIG. 1 is a diagram showing a system in which an external device according to one embodiment transmits an application package to a plurality of electronic devices through a network.
[0017] Referring to FIG. 1, an external device (100) can communicate with a plurality of electronic devices (110, 120, 130) through a network (140). The first electronic device (110), the second electronic device (120), and / or the third electronic device (130) may be wearable devices such as tablets, smartwatches, or smart glasses in addition to smartphones. According to one embodiment, the external device (100) can control services provided through the plurality of electronic devices (110, 120, 130).
[0018] According to one embodiment, the external device (100) may include a processor (101), memory (102), and / or a communication circuit (105). In one embodiment, the memory (102) may include an SDK module (103) and / or an application package distribution module (104). In one embodiment, the SDK module (103) may be a module for providing a software development kit (SDK) capable of developing an application package that can be run on a plurality of electronic devices (110, 120, 130). In one embodiment, the application package distribution module (104) may be a module for providing an application package to a plurality of electronic devices (110, 120, 130) via a network (140) using the communication circuit (105). According to one embodiment, the SDK module (103) and the application package distribution module (104) stored in the memory (102) may store instructions. Accordingly, the processor (101) can execute instructions corresponding to the SDK module (103) and the application package distribution module (104) stored in memory (102).
[0019] According to one embodiment, the processor (101) can develop an application package by executing instructions included in the SDK module (103). According to one embodiment, the processor (101) can develop an application package by executing instructions included in the SDK module (103) and utilizing an authenticated dedicated software development kit (SDK). The authenticated dedicated software development kit may include source and tool packages for developing applications. According to one embodiment, the external device (100) can develop an application package to be installed on a plurality of electronic devices (110, 120, 130). In one embodiment, the external device (100) can develop an application package to provide a designated service (e.g., a service for children, a service for enterprises) to a plurality of electronic devices (110, 120, 130) through the SDK module (103).
[0020] According to one embodiment, an external device (100) can control a plurality of electronic devices (110, 120, 130) through a network (140). In one embodiment, the external device (100) can configure the plurality of electronic devices (110, 120, 130) using a customer-customized configuration service (e.g., Knox™ configure) that may be provided through the network (140). In one embodiment, the external device (100) can transmit and receive data with the network (140) using a communication circuit (105). In one embodiment, the service may be one of various services provided to control the plurality of electronic devices (110, 120, 130) according to the intended use. For example, depending on the settings of the external device (100), a service can be provided to control at least one of the configuration of the application, the background screen, the home screen, and the setting values of the electronic device stored in a plurality of electronic devices (110, 120, 130).
[0021] According to one embodiment, the processor (101) can execute instructions included in the application package distribution module (104) to configure multiple electronic devices (110, 120, 130) through the network (140). According to one embodiment, the processor (101) can execute instructions included in the application package distribution module (104) to execute instructions included in the SDK module (103) to enable the application package created to be loaded onto multiple electronic devices (110, 120, 130). According to one embodiment, the application package created through the external device (100) can be loaded onto multiple electronic devices (110, 120, 130) through the network (140). According to one embodiment, the multiple electronic devices (110, 120, 130) loaded with the application package can be operated in a mode based on the loaded application package. According to one embodiment, the external device (100) may perform the operation described above on only one of the plurality of electronic devices (110, 120, 130). According to one embodiment, the plurality of electronic devices (110, 120, 130) may each be an electronic device (200) described later with reference to FIG. 2.
[0022] FIG. 2 is a block diagram illustrating the configuration of an electronic device according to one embodiment.
[0023] Referring to FIG. 2, the electronic device (200) may include a processor (210), a communication circuit (220), a memory (230), and a display (240), or a combination thereof. In various embodiments, the electronic device (200) may include additional components in addition to the components shown in FIG. 2, or at least one of the components shown in FIG. 2 may be omitted.
[0024] According to one embodiment, the processor (210) may be electrically or operatively connected to a communication circuit (220), a memory (230), and a display (240). According to one embodiment, the processor (210) may execute operations or data processing regarding the control and / or communication of at least one other component of the electronic device (200) using instructions stored in the memory (230). According to one embodiment, the processor (210) may include at least one of a central processing unit (CPU), a graphics processing unit (GPU), a microcontroller unit (MCU), a sensor hub, a supplementary processor, a communication processor, an application processor, an application specific integrated circuit (ASIC), and a field programmable gate array (FPGA), and may have multiple cores.
[0025] According to one embodiment, the communication circuit (220) may be configured to be connected to an external server to transmit and receive data. For example, the communication circuit (220) may transmit and receive application packages with an external server. The communication circuit (220) may receive data regarding updates to application packages from the external server.
[0026] According to one embodiment, the memory (230) may store instructions that allow the processor (210) to process data or control components of the electronic device (200) to perform operations of the electronic device (200) when executed. The memory (230) may include a secure area or a separate secure storage medium (e.g., a secure memory area accessible only through a secure OS (e.g., a trust zone)). According to one embodiment, the memory (230) may include memory areas corresponding to applications running on the electronic device (200). In one embodiment, the memory areas corresponding to applications may store data based on each application.
[0027] According to one embodiment, the memory (230) may include memory regions corresponding to various modes that can be executed in the electronic device (200). According to one embodiment, the memory (230) may store various application packages corresponding to various modes that can be executed in the electronic device (200) in each of the memory regions. According to one embodiment, the application packages may include data (e.g., applications, images, videos, and text files) for providing services corresponding to each mode. According to one embodiment, the application package may be installed in the electronic device (200) to provide services within a specified range at the time of manufacturing the electronic device (200). For example, if the electronic device (200) is a device configured as a children's terminal, the application package may include an application package for providing children's applications or children's services within a specified range.
[0028] According to one embodiment, the display (240) can display various contents (e.g., text, images, videos, icons, and / or symbols, etc.). According to one embodiment, the display (240) may include a liquid crystal display (LCD), a light-emitting diode (LED) display, or an organic light-emitting diode (OLED) display.
[0029] According to one embodiment, the processor (210) may receive data related to a mode to be executed on the electronic device (200) and an application package corresponding to the mode through a communication circuit (220) in response to the electronic device (200) being booted for the first time. For example, the processor (210) may store installation data related to a mode to be executed on the electronic device (200) and installation data for an application package corresponding to the mode in memory (230) in response to the electronic device (200) being booted for the first time. Additionally, the processor (210) may use the installation data stored in memory (230) to install a mode to be executed on the electronic device (200) and an application corresponding to the mode on the electronic device (200).
[0030] According to one embodiment, the electronic device (200) can be executed in various modes through the processor (210). According to one embodiment, the various modes may represent modes executed by a launcher program. According to one embodiment, the electronic device (200) can control the configuration of an application, the home screen, and the execution screen of an application by executing various modes, namely the launcher program. According to one embodiment, the processor (210) can recognize the mode that is executed first in the electronic device (200) (e.g., a first mode). For example, it can be assumed that the first mode is executed first in the electronic device (200).
[0031] According to one embodiment, the processor (210) can verify an application package based on the first mode being executed. An operation to verify an application package according to one embodiment will be described in detail later with reference to FIG. 4.
[0032] According to one embodiment, the processor (210) may store a signature value corresponding to an application package in memory (230) based on the verification result of the application package. In one embodiment, if the application package is not a verified application package, the processor (210) may not store a signature value corresponding to the application package and may cancel the execution of the corresponding mode. For example, the processor (210) may cancel the execution of the first mode if the application package corresponding to the first mode is an unverified application package. In another embodiment, if the application package is verified, the processor (210) may store a signature value corresponding to the application package in the memory (230) area corresponding to the first mode. Additionally, the electronic device (200) may be operated in a first mode based on the verified application package.
[0033] According to one embodiment, the processor (210) can receive a signature value corresponding to an application package through a communication circuit (220). For example, the signature value may be included in the application package received when the electronic device (200) is first booted. In one embodiment, the processor (210) can receive a signature value corresponding to an application package from the Android™ platform through the communication circuit (220). For example, the processor (210) can receive package information (packageinfo) for the application package through the communication circuit (220) using a service provided by the Android™ platform, and store the signature value included in the received package information in memory (230). In one embodiment, the processor (210) can obtain the signature value through the package manager API of the Android™ platform. However, the Android™ platform is merely an example presented to explain one embodiment and is not limited thereto. In one embodiment, the processor (210) may store a signature value in a memory area of an execution mode corresponding to an application package corresponding to the signature value contained in memory (230). According to various embodiments, the signature value may be expressed in one of various forms. For example, the signature value may be expressed in the form of a security key (e.g., c8a2e9bccf579). For convenience of explanation, the signature value has been expressed in the form of a security key stream data, but according to various embodiments, the form of the signature value is not limited thereto. According to one embodiment, the signature value may include information assigned to each business operator that developed the application package.
[0034] According to one embodiment, the electronic device (200) may be executed in one of a plurality of execution modes. According to one embodiment, the processor (210) may determine whether an application package provided in another mode is installed in the electronic device (200) when another mode is executed for the first time, even if one mode is running in the electronic device (200). Additionally, the processor may verify the application package provided in the other mode and store a signature value corresponding to the application package in memory. For example, when a second mode is executed for the first time in the electronic device (200) running in the first mode, the processor (210) may determine whether a second application package provided in the second mode is installed. According to one embodiment, the second application package may be an application package received through a communication circuit (220) in response to the electronic device booting for the first time. In one embodiment, if the second application package is a verified application package, the processor (210) may store a second signature value corresponding to the second application package in memory (230). According to one embodiment, the memory (230) may include a memory area corresponding to the second mode for data based on a second application package provided in the second mode. In one embodiment, the second signature value may be stored in the memory area. That is, according to one embodiment, the second signature value may be stored in the memory (230) in association with the second mode.
[0035] As described above, an electronic device according to one embodiment (e.g., the electronic device (200) of FIG. 2) comprises a communication circuit (e.g., the communication circuit (220) of FIG. 2), a display (e.g., the display (240) of FIG. 2), a memory (e.g., the memory (230) of FIG. 2) that stores an application package received through the communication circuit in response to the electronic device being booted for the first time, and at least one processor (e.g., the processor (210) of FIG. 2) electrically connected to the communication circuit and the memory, and the at least one processor may determine whether the application package is installed on the electronic device in response to the electronic device being executed in a first mode for the first time, verify the application package based on the determination result, and store a first signature value corresponding to the application package in the memory based on the verification result.
[0036] According to one embodiment, the at least one processor determines whether there is an update to the application package, and in response to the identification of the update, compares the first signature value with a second signature value corresponding to the updated application package, and in response to the comparison result that the first signature value and the second signature value correspond, performs an update operation for the application package.
[0037] In one embodiment, the at least one processor can control the display to output a notification about an update of the application package.
[0038] According to one embodiment, the at least one processor may not perform the update operation in response to a discrepancy between the first signature value and the second signature value as a result of the comparison.
[0039] According to one embodiment, the at least one processor can verify the application package based on at least one of whether the application package is installed based on a specified installer or whether the application package was developed by an authenticated software development kit (SDK).
[0040] According to one embodiment, the at least one processor can determine whether it was developed by the certified software development kit based on metadata included in the application package.
[0041] In one embodiment, the at least one processor can control the display to output an execution screen of the first mode corresponding to the application package based on at least one of configuration information, an image, a video, text, and setting information of the electronic device of the application included in the application package.
[0042] According to one embodiment, the application package may be installed in the electronic device to provide services within a specified range.
[0043] In one embodiment, the first mode may include an operation mode that provides a home screen for executing an application corresponding to the installed application package based on a launcher program corresponding to the first mode.
[0044] According to one embodiment, the at least one processor may store a second signature value corresponding to another application package in the memory in association with the second mode in response to the first execution of the second mode.
[0045] According to one embodiment, the at least one processor can recognize an update of the application package based on package version information included in the updated application package.
[0046] As described above, a method of operation for an electronic device that stores an application package received through a communication circuit in memory in response to initial booting may include: an operation of determining whether the application package is installed in the electronic device in response to the electronic device first executing a first mode; an operation of verifying the application package stored in the memory based on the determination result; and an operation of storing a first signature value corresponding to the application package in the memory based on the verification result.
[0047] According to one embodiment, the method of operating the electronic device may further include: determining whether there is an update to the application package; comparing the first signature value with the second signature value corresponding to the updated application package in response to the identification of the update; and updating the application package in response to the result of the comparison in which the first signature value and the second signature value correspond.
[0048] According to one embodiment, the method of operation of the electronic device may further include an operation of outputting a notification regarding an update of the application package.
[0049] In one embodiment, the operation of determining whether the application package is authenticated may be based on at least one of the operation of determining whether the application package is installed based on a specified installer or determining whether it was developed by an authenticated software development kit.
[0050] According to one embodiment, the first mode may include an operation mode that provides a home screen for executing an application corresponding to the installed application package based on a launcher program corresponding to the first mode.
[0051] According to one embodiment, the method of operating the electronic device may further include, upon performing the operation of installing the application package on the electronic device, an operation of outputting an execution screen of the first mode corresponding to the application package based on at least one of configuration information, an image, a video, text, and setting information of the electronic device included in the application package.
[0052] As described above, the electronic device comprises a communication circuit, a memory storing a first application package and a second application package, and at least one processor electrically connected to the communication circuit and the memory. The at least one processor can determine whether the second application package corresponding to the second mode is installed in the electronic device in response to the electronic device first executing the second mode while executing the first mode, verify the second application package corresponding to the second mode based on the determination result, and store a second signature value corresponding to the second application package in the memory based on the second application package verification result.
[0053] According to one embodiment, the memory can store signature values based on application packages corresponding to each of a plurality of execution modes executed in the electronic device, associated with each of the plurality of execution modes.
[0054] According to one embodiment, the at least one processor may determine whether there is an update to the second application package, and in response to the identification of the update, compare the second signature value with a third signature value corresponding to the updated application package, and perform an update operation of the second application package based on the result of the comparison.
[0055] FIG. 3 is a flowchart of a process in which an electronic device according to one embodiment stores a signature value corresponding to an application package.
[0056] Referring to FIG. 3, the processor (210) can recognize that the first mode is executed for the first time in the electronic device (200) in operation 301. For example, the processor (210) can determine that the first mode is executed for the first time among the modes that can be executed in the electronic device (200). According to one embodiment, the mode may be a mode executed based on a launcher program. According to one embodiment, in operation 303, the processor (210) can determine whether the application package provided in the first mode is installed in the electronic device (200). For example, the processor (210) can determine whether the application package is installed in the electronic device (200) through data (e.g., metadata) indicating whether the application package provided in the first mode exists.
[0057] According to one embodiment, in response to the first boot of the electronic device (200), the application package provided in the first mode can be installed on the electronic device (200) by receiving remote control from an external server via a communication circuit (220), storing application package installation data in memory (230), and using the installation data stored in memory (230).
[0058] According to one embodiment, the processor (210) can verify the application package in operation 305 when the application package is installed in the electronic device (200). That is, as the first mode is executed for the first time, the processor (210) can verify whether the application package provided in the first mode is an authenticated application package.
[0059] According to one embodiment, the processor (210) may execute various instructions stored in memory (230) to verify an application package provided in a first mode. The operation of the processor (210) verifying the application package will be described in detail later with reference to FIG. 4.
[0060] According to one embodiment, the processor (210) may store a signature value corresponding to an application package in memory (230) in response to the application package being a verified application package in operation 307. For example, the processor (210) may store a first signature value corresponding to an application package according to a first mode in memory (230). According to one embodiment, the processor (210) may store a first signature value corresponding to an application package in memory (230) in relation to the first mode. For example, the processor (210) may store the first signature value in a memory area corresponding to the first mode.
[0061] According to one embodiment, the processor (210) can obtain a signature value corresponding to an application package through a communication circuit (220). According to one embodiment, the processor (210) can receive package information (packageinfo) for an application package using a service provided by the Android platform, and obtain a first signature value corresponding to an application package included in the received package information.
[0062] According to one embodiment, the electronic device (200) can execute an application package installed based on a first mode. For example, the electronic device (200) can display a home screen provided in the first mode to include an icon for executing an installed application.
[0063] FIG. 4 is a flowchart (400) of a process for an electronic device to verify an application package according to one embodiment.
[0064] Referring to FIG. 4, in operation 401, the processor (210) can determine whether the application package mounted on the electronic device (100) is an application package installed based on a designated installer in order to verify the application package. For example, the processor (210) can determine whether the application package is based on a designated installer based on the first mode being executed for the first time on the electronic device (200). The processor (210) can verify the application package corresponding to the first mode based on whether the application package is installed based on a designated installer. According to one embodiment, the designated installer may be determined as one of various installers by the external device (100) described with reference to FIG. 1. In one embodiment, the processor (210) can determine whether the development device that developed the application package has mounted the application package on the electronic device (200) using a designated installer. For example, the specified installer may represent a specified service provided through an external server (e.g., Knox™ configure).
[0065] According to one embodiment, the processor (210) can verify the application package by determining that it is an application package loaded by a designated installer.
[0066] According to one embodiment, the processor (210) may determine, in operation 403, whether the application package was developed by an authorized software development kit in order to verify the application package. For example, the processor (210) may determine whether the application package was developed by an authorized software development kit based on the first mode being executed for the first time in the electronic device (200). According to one embodiment, the processor (210) may verify the application package corresponding to the first mode based on whether the application package was developed by an authorized software development kit. According to one embodiment, the authorized software development kit may represent an authorized software development kit. For example, information about the software development kit used to develop the application may be included in the application package as metadata of the application package. According to one embodiment, the processor (210) may determine whether the application package was developed using an authorized software development kit based on the information about the software development kit included in the metadata of the application package. According to one embodiment, the processor (210) can determine whether the external device (100) has utilized an authorized software development kit when developing an application package, and can verify the application package based on the result of the determination.
[0067] According to one embodiment, the processor (210) can check a manifest file corresponding to the application package to determine whether the application package was developed using an authorized software development kit. The manifest file can declare components required for the execution of the application package, specify necessary libraries, and identify permissions for the adjustment of the application's permissions. The manifest file is a structured XML (eXtensible Markup Language) file and may exist in the application as 'AndroidManifest.xml'. According to one embodiment, the processor (210) can check metadata declarations included in the manifest file. For example, by checking the version information and development kit of the application package included in the metadata declarations, the processor (210) can determine whether the application package was developed using an authorized software development kit. According to one embodiment, the processor (210) can determine that an application package developed by an authorized software development kit is a verified application package.
[0068] For convenience of explanation, it has been described that the processor (210) performs operation 401 and operation 403, but the electronic device (200) according to the present disclosure is not limited thereto. For example, the processor (210) may perform operation 401 and operation 403 simultaneously to verify an application package, and in another embodiment, the processor (210) may perform operation 401 after performing operation 403. Additionally, the processor (210) may verify an application package based on at least one of operation 401 and operation 403.
[0069] FIG. 5 is a flowchart (500) of a process for another electronic device to update an application package in one embodiment.
[0070] Referring to FIG. 5, the processor (210) can determine whether there is an application package update in operation 501. According to one embodiment, an application package provided in a mode running on an electronic device (200) can be updated. For example, an external device (100) can update the application package by executing a command included in the SDK module (103) to update the application package.
[0071] According to one embodiment, an external device (100) can execute a command included in an application package distribution module (104) to distribute an updated application package to an electronic device (200) via a network (140). According to another embodiment, the external device (100) can update the application package and execute a command included in the application package distribution module (104). The external device (100) can distribute it via an application search app (e.g., Google's Play Store). According to one embodiment, the electronic device (200) can obtain information about the application package using a module of the Android platform. For example, the electronic device (200) can obtain information about the application package installed on the electronic device (200) from an external server using a package manager module. In one embodiment, the information about the application package may include version information of the application package. Accordingly, the electronic device (200) can determine whether the application package installed on the electronic device (200) has been updated by using version information of the application package. According to one embodiment, the processor (210) can determine whether the application package has been updated based on package information (packageinfo) included in the application package. According to various embodiments, the electronic device (200) can check whether the application package has been updated through various methods in addition to the method included in the present disclosure.
[0072] According to one embodiment, if there is an update to the application package, the processor (210) can compare a first signature value corresponding to the application package and a second signature value corresponding to the updated application package in operation 503. According to one embodiment, the processor (210) can receive the second signature value of the updated application package through a communication circuit (220). In one embodiment, the processor (210) can receive the signature value corresponding to the application package from the Android platform through the communication circuit (220). For example, the processor (210) can receive package information for the application package through the communication circuit (220) using a service provided by the Android platform, and store the second signature value included in the received package information in memory (230). In one embodiment, the processor (210) can obtain the signature value through the package manager API of the Android platform. According to one embodiment, the processor (210) can compare the first signature value stored in memory (230) with the obtained second signature value.
[0073] According to one embodiment, in operation 505, the processor (210) can determine whether the first signature value and the second signature value correspond based on the result of comparing the first signature value and the second signature value. For example, it can determine whether the first signature value and the second signature value are identical. According to various embodiments, the first signature value and the second signature value may correspond in various forms. According to one embodiment, if the updated application package is an authorized update, the first signature value and the second signature value stored in memory (230) may correspond. Accordingly, if the first signature value and the second signature value do not correspond, the processor (210) may determine that it is an unauthorized application package update and may not support an update to the application package. For example, if the first signature value and the second signature value do not match, the processor (210) may not perform an update operation to the application package. Accordingly, the electronic device (200) may be operated in the same way based on the application package included in the first mode that is currently running.
[0074] Depending on various embodiments, whether or not an application package is an authorized update may be determined by various causes. For example, if the update is by a device other than the external device (100) that developed the application package, or if the update is outside the range set by the initial external device (100), it may be determined to be an unauthorized update.
[0075] According to one embodiment, in operation 507, the processor (210) may perform an update operation on an application package based on the correspondence between a first signature value and a second signature value. According to one embodiment, an update operation on an authorized application package may be performed. In one embodiment, an electronic device (200) may be operated based on an application package updated via an external device (100) in accordance with the update operation on an authorized application package. The electronic device (200) according to the present disclosure may prevent forgery and / or alteration of the application package by verifying the signature value and performing the update when performing an update operation on the application package.
[0076] FIG. 6 is a flowchart (600) of a process in which an electronic device according to one embodiment selects one of a plurality of execution modes and stores a signature value corresponding to an application package based on the execution mode.
[0077] Referring to FIG. 6, the electronic device (200) may first execute a second mode among a plurality of execution modes in operation 601. For example, the electronic device (200) may be driven in an execution mode selected among a plurality of execution modes corresponding to each of the plurality of application packages stored in memory (230). According to one embodiment, a plurality of application packages corresponding to each of the plurality of execution modes may be mounted on the electronic device (200) through the method described with reference to FIG. 1. For example, a plurality of execution modes and a plurality of application packages corresponding to each of the plurality of execution modes may be installed on the electronic device (200) in response to the electronic device (200) being booted for the first time. According to one embodiment, the processor (210) may store installation data of a plurality of execution modes and application packages corresponding to each of the execution modes in memory (230) by receiving remote control from an external server through a communication circuit (220) in response to the electronic device (200) being booted for the first time. In one embodiment, the processor (210) can install a plurality of execution modes and application packages in the electronic device (200) using installation data stored in memory (230). According to one embodiment, the processor (210) can recognize that a second mode among the plurality of execution modes is executed first in the electronic device (200).
[0078] According to one embodiment, the processor (210) can determine in operation 603 whether a second application package corresponding to the second mode is installed in the electronic device (200). For example, the processor (210) can determine whether an application package is installed in the electronic device (200) through data (e.g., metadata) indicating whether a second application package provided in the second mode exists.
[0079] According to one embodiment, the processor (210) can verify the second application package corresponding to the second mode in operation 605 when the second application package is installed in the electronic device (200). According to one embodiment, the verification operation for the second application package can be performed through an operation similar to the verification operation described with reference to FIGS. 3 and FIGS. 4. For example, the processor (210) can determine whether the second application package is an application package installed based on a specified installer. Additionally, the processor (210) can determine whether the second application package was developed by an authenticated software development kit. According to one embodiment, the processor (210) can determine whether the second application package is verified.
[0080] According to one embodiment, the processor (210) may, in operation 607, obtain a second signature value corresponding to a second application package and store the second signature value in memory (230) in association with a second mode. For example, memory (230) may store an application package corresponding to each of a plurality of execution modes executed in the electronic device (200) and store a signature value corresponding to the application package. In one embodiment, memory (230) may include memory regions corresponding to each of the plurality of execution modes. Accordingly, the processor (210) may store the second signature value corresponding to the second application package in association with a second mode.
[0081] According to one embodiment, the memory (230) can store multiple application packages corresponding to each of multiple execution modes executed in the electronic device (200). Accordingly, the processor (210) can provide a service based on the execution mode by using the application packages provided in the execution mode, based on the execution of one of the multiple execution modes.
[0082] According to one embodiment, the update operation described with reference to FIG. 5 may be applied in the same way to an update operation for at least one of a plurality of application packages. For example, the processor (210) may determine whether there is an update for the second application package. In one embodiment, the processor (210) may compare a second signature value with a third signature value corresponding to the updated second application package in response to the determination that there is an update for the second application package. In one embodiment, the processor (210) may compare the second signature value stored in memory (230) in association with the second mode with the third signature value obtained through the communication circuit (220). Through the method described with reference to FIG. 5, the processor (210) may obtain the third signature value. In one embodiment, the processor (210) may perform an update operation for the second application package based on the comparison result showing that the second signature value and the third signature value correspond.
[0083] According to various embodiments, even if one of the execution modes of a plurality of execution modes is operated in the electronic device (200), the operation of the electronic device (200) described with reference to FIGS. 1 to 5 may be the same.
[0084] FIG. 7 is a drawing for explaining a UI based on an application package according to one embodiment.
[0085] Referring to FIG. 7, an electronic device (200) according to one embodiment can provide various services through data included in an application package provided in an execution mode of the electronic device (200). According to one embodiment, the processor (210) can output a first mode initial execution screen (710) through a display (240) so as to provide various services through a corresponding application package provided in the first mode, based on a first mode that is first executed in the electronic device (200). For example, the processor (210) can output a first mode execution guide (711) through the display (240) stating that it will provide a service corresponding to the first mode.
[0086] According to one embodiment, the electronic device (200) can output an execution screen (720) of the first mode corresponding to the first mode based on the fact that the application package provided in the first mode is a verified application package. For example, the execution screen (720) of the first mode can be output based on at least one of the configuration information, image, video, text, and setting information of the electronic device (200) of the application included in the application package. For example, the processor (210) can output a first mode home screen (721) for executing an application corresponding to an installed application package based on a launcher program corresponding to the first mode through a display (240). For example, the first mode home screen (721) may include the configuration of the application based on the data included in the application package, an icon image, and a background screen.
[0087] According to one embodiment, the processor (210) may provide an application execution provided in a first mode. For example, the processor (210) may control the application execution (730) screen using data included in an application package corresponding to the first mode based on the execution of the first mode. In one embodiment, the processor (210) may control the display (240) to output an application screen (731) included in the application package corresponding to the first mode according to the application execution (730).
[0088] FIG. 8 is a diagram illustrating a UI based on an update to an application package according to one embodiment.
[0089] Referring to FIG. 8, a processor (210) according to one embodiment may control a display (240) to output a notification regarding an update of an application package. According to one embodiment, the processor (210) may output an update screen (810) indicating that an application package has been updated through the display (240) in various ways. For example, the processor (210) may control the display (240) to output an application search app screen (e.g., Google's Play Store) (811).
[0090] According to one embodiment, the processor (210) may compare the signature value of an updated application package with the signature value corresponding to the application package stored in memory (230), either automatically or based on user input to the update screen (810). According to one embodiment, the operation of comparing signature values was described above with reference to FIG. 5. According to one embodiment, the processor (210) may perform an update operation of the application package based on the fact that the signature value corresponding to the updated application package corresponds to the signature value stored in memory (230). According to one embodiment, the processor (210) may not perform an update operation of the application package based on the fact that the signature value corresponding to the updated application package does not correspond to the signature value stored in memory (230). According to one embodiment, the processor (210) may output a notification (820) regarding an update operation for the application package through the display (240). For example, the processor (210) according to one embodiment may output an update failure notification (821) through the display (240) if it does not perform an update operation of the application package based on the fact that the signature value corresponding to the updated application package and the signature value stored in memory (230) do not correspond.
[0091] FIG. 9 is a block diagram of an electronic device in a network environment according to various embodiments.
[0092] FIG. 9 is a block diagram of an electronic device (901) in a network environment (900) according to various embodiments. Referring to FIG. 9, in the network environment (900), the electronic device (901) may communicate with an electronic device (902) through a first network (998) (e.g., a short-range wireless communication network) or may communicate with at least one of an electronic device (904) or a server (908) through a second network (999) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (901) may communicate with the electronic device (904) through a server (908). According to one embodiment, the electronic device (901) may include a processor (920), memory (930), input module (950), sound output module (955), display module (960), audio module (970), sensor module (976), interface (977), connection terminal (978), haptic module (979), camera module (980), power management module (988), battery (989), communication module (990), subscriber identification module (996), or antenna module (997). In some embodiments, at least one of these components (e.g., connection terminal (978)) may be omitted from the electronic device (901), or one or more other components may be added. In some embodiments, some of these components (e.g., sensor module (976), camera module (980), or antenna module (997)) may be integrated into a single component (e.g., display module (960)).
[0093] The processor (920) can control at least one other component (e.g., a hardware or software component) of the electronic device (901) connected to the processor (920) by executing software (e.g., a program (940)), and can perform various data processing or operations. According to one embodiment, as at least part of the data processing or operations, the processor (920) can store commands or data received from other components (e.g., a sensor module (976) or a communication module (990)) in volatile memory (932), process the commands or data stored in volatile memory (932), and store the resulting data in non-volatile memory (934). According to one embodiment, the processor (920) may include a main processor (921) (e.g., a central processing unit or an application processor) or an auxiliary processor (923) that can operate independently or together with it (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor). For example, if the electronic device (901) includes a main processor (921) and an auxiliary processor (923), the auxiliary processor (923) may be configured to use lower power than the main processor (921) or to be specialized for a designated function. The auxiliary processor (923) may be implemented separately from the main processor (921) or as part thereof.
[0094] The auxiliary processor (923) may control at least some of the functions or states associated with at least one component of the electronic device (901) (e.g., display module (960), sensor module (976), or communication module (990)) on behalf of the main processor (921) while the main processor (921) is in an inactive (e.g., sleep) state, or together with the main processor (921) while the main processor (921) is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor (923) (e.g., image signal processor or communication processor) may be implemented as part of another functionally related component (e.g., camera module (980) or communication module (990)). According to one embodiment, the auxiliary processor (923) (e.g., neural network processing unit) may include a hardware structure specialized for processing an artificial intelligence model. The artificial intelligence model may be generated through machine learning. Such learning may be performed, for example, on the electronic device (901) itself where the artificial intelligence model is executed, or through a separate server (e.g., server (908)). The learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model may include a plurality of artificial neural network layers.An artificial neural network may be a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to the hardware structure, the artificial intelligence model may include a software structure, either additionally or substantially.
[0095] The memory (930) can store various data used by at least one component of the electronic device (901) (e.g., processor (920) or sensor module (976)). The data may include, for example, software (e.g., program (940)) and input or output data for related commands. The memory (930) may include volatile memory (932) or non-volatile memory (934).
[0096] The program (940) may be stored as software in memory (930) and may include, for example, an operating system (942), middleware (944), or an application (946).
[0097] The input module (950) can receive commands or data to be used for a component of the electronic device (901) (e.g., processor (920)) from outside the electronic device (901) (e.g., user). The input module (950) may include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).
[0098] The sound output module (955) can output a sound signal to the outside of the electronic device (901). The sound output module (955) may include, for example, a speaker or a receiver. The speaker may be used for general purposes, such as multimedia playback or recording playback. The receiver may be used to receive incoming calls. According to one embodiment, the receiver may be implemented separately from the speaker or as part thereof.
[0099] The display module (960) can visually provide information to an external (e.g., user) of the electronic device (901). The display module (960) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling said device. According to one embodiment, the display module (960) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of the force generated by said touch.
[0100] The audio module (970) can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one embodiment, the audio module (970) can acquire sound through the input module (950) or output sound through the sound output module (955) or an external electronic device (e.g., electronic device (902)) (e.g., speaker or headphones) connected directly or wirelessly to the electronic device (901).
[0101] The sensor module (976) can detect the operating state of the electronic device (901) (e.g., power or temperature) or the external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the detected state. According to one embodiment, the sensor module (976) may include, for example, a gesture sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0102] The interface (977) may support one or more specified protocols that can be used for the electronic device (901) to be connected directly or wirelessly to an external electronic device (e.g., electronic device (902)). According to one embodiment, the interface (977) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
[0103] The connection terminal (978) may include a connector through which the electronic device (901) can be physically connected to an external electronic device (e.g., electronic device (902)). According to one embodiment, the connection terminal (978) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).
[0104] The haptic module (979) can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that the user can perceive through tactile or kinesthetic senses. According to one embodiment, the haptic module (979) may include, for example, a motor, a piezoelectric element, or an electric stimulation device.
[0105] The camera module (980) can capture still images and video. According to one embodiment, the camera module (980) may include one or more lenses, image sensors, image signal processors, or flashes.
[0106] The power management module (988) can manage power supplied to the electronic device (901). According to one embodiment, the power management module (988) can be implemented, for example, as at least part of a power management integrated circuit (PMIC).
[0107] The battery (989) can supply power to at least one component of the electronic device (901). According to one embodiment, the battery (989) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.
[0108] The communication module (990) can support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (901) and an external electronic device (e.g., electronic device (902), electronic device (904), or server (908)), and the performance of communication through the established communication channel. The communication module (990) may include one or more communication processors that operate independently of the processor (920) (e.g., application processor) and support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (990) may include a wireless communication module (992) (e.g., cellular communication module, short-range wireless communication module, or GNSS (global navigation satellite system) communication module) or a wired communication module (994) (e.g., LAN (local area network) communication module, or power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device (904) through a first network (998) (e.g., a short-range communication network such as Bluetooth, WiFi (wireless fidelity) direct, or IrDA (infrared data association)) or a second network (999) (e.g., a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (992) can identify or authenticate the electronic device (901) within a communication network such as the first network (998) or the second network (999) using subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module (996).
[0109] The wireless communication module (992) can support 5G networks and next-generation communication technologies following 4G networks, for example, new radio access technology. NR access technology can support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The wireless communication module (992) can support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The wireless communication module (992) can support various technologies for securing performance in the high-frequency band, such as beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large-scale antenna. The wireless communication module (992) can support various requirements specified in the electronic device (901), external electronic device (e.g., electronic device (904)), or network system (e.g., second network (999)). According to one embodiment, the wireless communication module (992) can support a Peak data rate (e.g., 20 Gbps or more) for realizing eMBB, loss coverage (e.g., 164 dB or less) for realizing mMTC, or U-plane latency (e.g., downlink (DL) and uplink (UL) each 0.5 ms or less, or round trip 1 ms or less) for realizing URLLC.
[0110] An antenna module (997) can transmit a signal or power to or from an external source (e.g., an external electronic device). According to one embodiment, the antenna module (997) may include an antenna comprising a radiator made of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (997) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as a first network (998) or a second network (999), may be selected from the plurality of antennas, for example, by a communication module (990). A signal or power may be transmitted or received between the communication module (990) and an external electronic device through the selected at least one antenna. According to some embodiments, in addition to the radiator, other components (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as part of the antenna module (997).
[0111] According to various embodiments, the antenna module (997) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent to a first surface (e.g., bottom surface) of the printed circuit board and capable of supporting a specified high frequency band (e.g., mmWave band), and a plurality of antennas (e.g., array antennas) disposed on or adjacent to a second surface (e.g., top surface or side surface) of the printed circuit board and capable of transmitting or receiving a signal of the specified high frequency band.
[0112] At least some of the above components can be connected to each other via a communication method between peripheral devices (e.g., bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)) and exchange signals (e.g., commands or data) with each other.
[0113] According to one embodiment, commands or data may be transmitted or received between the electronic device (901) and an external electronic device (904) through a server (908) connected to a second network (999). Each of the external electronic devices (902, or 904) may be the same or a different type of device as the electronic device (901). According to one embodiment, all or part of the operations performed on the electronic device (901) may be performed on one or more of the external electronic devices (902, 904, or 908). For example, if the electronic device (901) needs to perform a function or service automatically or in response to a request from a user or another device, the electronic device (901) may request one or more external electronic devices to perform at least part of the function or service instead of performing the function or service itself or additionally. One or more external electronic devices that receive the above request may execute at least part of the requested function or service, or additional function or service related to the request, and transmit the result of the execution to the electronic device (901). The electronic device (901) may provide the result as is or additionally processed as at least part of the response to the request. For this purpose, for example, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used. The electronic device (901) may provide ultra-low latency services using, for example, distributed computing or mobile edge computing. In another embodiment, the external electronic device (904) may include an Internet of Things (IoT) device. The server (908) may be an intelligent server using machine learning and / or neural networks. According to one embodiment, the external electronic device (904) or the server (908) may be included within a second network (999).The electronic device (901) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.
[0114] The electronic device according to the various embodiments disclosed in this document may be a device of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronics device. The electronic device according to the embodiments of this document is not limited to the devices described above.
[0115] The various embodiments of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, each of phrases such as "A or B," "at least one of A and B," "at least one of A or B," "A, B or C," "at least one of A, B and C," and "at least one of A, B, or C" may include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as “first,” “second,” or “first” or “second” may be used simply to distinguish a component from another component and do not limit the components in any other aspect (e.g., importance or order). Where any (e.g., first) component is referred to as “coupled” or “connected” to another (e.g., second) component, with or without the terms “functionally” or “communicationally,” it means that said component may be connected to said other component directly (e.g., wired), wirelessly, or through a third component.
[0116] The term “module” as used in the various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit, for example. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0117] Various embodiments of the present document may be implemented as software (e.g., program (940)) comprising one or more instructions stored in a storage medium (e.g., internal memory (936) or external memory (938)) readable by a machine (e.g., electronic device (901)). For example, a processor (e.g., processor (920)) of the machine (e.g., electronic device (901)) may call at least one of the one or more instructions stored in the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' simply means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.
[0118] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or an application store (e.g., Play Store). TM It can be distributed online (e.g., downloaded or uploaded) through ) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.
[0119] According to various embodiments, each component (e.g., module or program) of the components described above may include a singular or multiple entities, and some of the multiple entities may be separated and placed in other components. According to various embodiments, one or more of the components or operations among the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to integration. According to various embodiments, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
Claims
Claim 1 An electronic device comprising: a communication circuit; a display; a memory for storing an application package received through the communication circuit in response to the electronic device being booted for the first time; and at least one processor electrically connected to the communication circuit and the memory, wherein the at least one processor determines whether the application package is installed in the electronic device in response to the electronic device being executed in a first mode for the first time, and, based on the result of the determination, verifies the application package based on at least one of whether the application package is installed based on a designated installer or whether the application package is developed by an authenticated software development kit (SDK), and, based on the result of the verification, stores a first signature value corresponding to the application package in the memory, wherein the first mode includes a mode executed based on a launcher program corresponding to the first mode, and the application package is intended to provide services within the range provided in the first mode. Claim 2 An electronic device according to claim 1, wherein at least one processor determines whether there is an update to the application package, compares the first signature value with the second signature value corresponding to the updated application package in response to the identification of the update, and performs an update operation to the application package in response to the result of the comparison that the first signature value and the second signature value correspond. Claim 3 In claim 2, the at least one processor is an electronic device that controls the display to output a notification for an update of the application package. Claim 4 An electronic device according to claim 2, wherein the at least one processor does not perform the update operation in response to a discrepancy between the first signature value and the second signature value as a result of the comparison. Claim 5 delete Claim 6 delete Claim 7 An electronic device according to claim 1, wherein the at least one processor controls the display to output an execution screen of the first mode corresponding to the application package based on at least one of configuration information, image, video, text, and setting information of the electronic device of the application included in the application package. Claim 8 delete Claim 9 An electronic device according to claim 1, wherein the first mode includes an operation mode for providing a home screen for executing an application corresponding to the installed application package. Claim 10 An electronic device according to claim 1, wherein the at least one processor stores a second signature value corresponding to another application package in the memory in association with the second mode in response to the first execution of the second mode. Claim 11 In claim 1, the at least one processor is an electronic device that recognizes an update of the application package based on package version information included in the application package. Claim 12 delete Claim 13 delete Claim 14 delete Claim 15 delete Claim 16 delete Claim 17 delete Claim 18 delete Claim 19 delete Claim 20 delete