Application Package Inspection via Inherent Attribute Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for distinguishing between application packages that have passed security authentication and those that have not rely on manual identification of developer identity, leading to low recognition rates and missed distinctions, as they can be easily bypassed.
Innovation Solution
An automated method and device for inspecting application packages by extracting inherent attribute identifiers and certificates, comparing them with authentication certificates stored in an information library, to determine if the package is authenticated or unauthenticated, using a processor and memory-based system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual distinction of developer identity is used to determine security authentication status, then the inspection process is simple to implement, but the recognition rate on unsecure application packages is low and can be easily skirted
Solution Approach 1:
The patent replaces manual distinction methods with automated technical verification. Instead of relying on manual identification of developer identity, the system automatically extracts inherent attribute identifiers and certificates from application packages, compares them against stored authentication certificates, and makes automated determination decisions. This substitution of manual mechanical processes with automated digital verification significantly improves recognition rate while maintaining implementation simplicity through standardized procedures.
2Measurement precision
If automated inspection using inherent attribute identifiers and certificates is implemented, then inspection accuracy is improved to 100%, but the system complexity increases
Solution Approach 1:
The patent extracts and stores only the essential authentication information (inherent attribute identifiers and corresponding certificates) from the complex application package verification process. By separating the authentication verification function from the overall inspection system and pre-storing the authentication certificates in an information library, the system achieves high accuracy while managing complexity through modular design. The extraction of critical authentication data allows for efficient comparison without requiring analysis of the entire application package structure.
Solution Approach 2:
The patent performs preliminary action by pre-storing authentication certificates in an information library before actual inspection occurs. This advance preparation allows the inspection process to simply compare extracted certificates against pre-verified stored data, rather than performing complex verification during inspection. The preliminary storage of authentication information enables fast, accurate inspection while reducing the complexity of the inspection process itself.
3Quantity of substance
If manual distinction methods are used, then the inspection process requires minimal resources, but it leads to missed distinctions and low recognition rates
Solution Approach 1:
The patent implements self-service by enabling the inspection system to automatically verify authentication status without requiring manual intervention. The system extracts inherent attribute identifiers and certificates from application packages, automatically compares them against stored authentication certificates, and makes independent determination decisions. This self-service capability maintains low resource consumption while significantly improving distinction reliability, as the automated process eliminates human error and maintains consistent, reliable verification.
Data Source
AI summary
An application package inspection method is provided. The method includes: obtaining a to-be-inspected application installation package; and extracting an inherent attribute identifier and a certificate of the to-be-inspected application package from the to-be-inspected application package. Further, an authentication certificate corresponding to the inherent attribute identifier of the to-be-inspected application package is obtained from an information library storing correspondence relationships between inherent attribute identifiers and authentication certificates. The method also includes comparing the certificate of the to-be-inspected application package with the authentication certificate to obtain an inspection result of the to-be-inspected application package.


