WO2016202204A1 - 一种下载应用的方法和装置 - Google Patents

一种下载应用的方法和装置 Download PDF

Info

Publication number
WO2016202204A1
WO2016202204A1 PCT/CN2016/085213 CN2016085213W WO2016202204A1 WO 2016202204 A1 WO2016202204 A1 WO 2016202204A1 CN 2016085213 W CN2016085213 W CN 2016085213W WO 2016202204 A1 WO2016202204 A1 WO 2016202204A1
Authority
WO
WIPO (PCT)
Prior art keywords
download
application
downloading
information
channel
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/085213
Other languages
English (en)
French (fr)
Inventor
李佳佳
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Alibaba Group Holding Ltd
Original Assignee
Alibaba Group Holding Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Alibaba Group Holding Ltd filed Critical Alibaba Group Holding Ltd
Priority to KR1020187000738A priority Critical patent/KR102147026B1/ko
Priority to EP16810945.2A priority patent/EP3313041B1/en
Priority to ES16810945T priority patent/ES2811330T3/es
Priority to PL16810945T priority patent/PL3313041T3/pl
Priority to JP2017565768A priority patent/JP6793667B2/ja
Priority to SG11201710305PA priority patent/SG11201710305PA/en
Publication of WO2016202204A1 publication Critical patent/WO2016202204A1/zh
Priority to US15/840,572 priority patent/US10693845B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/34Network arrangements or protocols for supporting network services or applications involving the movement of software or configuration parameters 
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/123Applying verification of the received information received data contents, e.g. message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • H04L67/125Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks involving control of end-device applications over a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/2866Architectures; Arrangements
    • H04L67/30Profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
    • H04L69/16Implementation or adaptation of Internet protocol [IP], of transmission control protocol [TCP] or of user datagram protocol [UDP]
    • H04L69/161Implementation details of TCP/IP or UDP/IP stack architecture; Specification of modified or new header fields
    • H04L69/162Implementation details of TCP/IP or UDP/IP stack architecture; Specification of modified or new header fields involving adaptations of sockets based mechanisms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/12Transmitting and receiving encryption devices synchronised or initially set up in a particular manner

Definitions

  • the present application relates to the field of network communication technologies, and in particular, to a method and apparatus for downloading an application.
  • An application is a computer program that is developed to run on an operating system in order to complete a particular task or tasks.
  • the application runs in user mode, which can interact directly with the user, and the general application has a visual user interface.
  • user mode which can interact directly with the user
  • the general application has a visual user interface.
  • the existing solution After receiving the user's installation of a new application or upgrading the old application, the existing solution uses an HTTP (Hypertext Transfer Protocol) channel to download the application package corresponding to the instruction, and installs the downloaded application package.
  • HTTP Hypertext Transfer Protocol
  • the data transmission based on the HTTP channel is transparent on the network, and the malicious person can easily tamper with the data in the HTTP channel, which seriously affects the stability of the application download.
  • the user's above instruction is a download instruction of the A application, and the result is that the installation package of the B application is downloaded.
  • the existing solution also uses the verification information of the application package to verify the application package downloaded to the local device. If the verification fails, the application package corresponding to the above instruction is re-downloaded until the verification succeeds. . Since the probability of data being hijacked in the HTTP channel is high, in practice, multiple loop downloads are required to obtain an application package that matches the above instructions, and the above multiple downloads undoubtedly consume a large amount of traffic data.
  • the technical problem to be solved by the embodiments of the present application is to provide a method for downloading an application, which can reduce the traffic data required for downloading an application.
  • the embodiment of the present application further provides a device for downloading an application, which is used to ensure implementation and application of the foregoing method.
  • the present application discloses a method for downloading an application, including:
  • the first application package corresponding to the download address information is downloaded by using an HTTP channel.
  • the downloading the description information further includes downloading the verification information, the method further comprising:
  • the first application package downloaded to the local device is verified according to the download verification information.
  • the method further includes:
  • the second application package corresponding to the download address information is downloaded by using an HTTPS channel.
  • the step of downloading the description information of the application by using the HTTPS channel includes:
  • the download description information corresponding to the download condition is downloaded by using the HTTPS channel.
  • the method further includes:
  • the download description information corresponding to the download condition corresponding application is stored locally;
  • step of downloading the first application package corresponding to the download address information by using an HTTP channel specifically, downloading, by using an HTTP channel, the first application package corresponding to the downloaded download address information.
  • the downloading condition comprises one or more of the following conditions: when the application downloading tool is started, when the application is started, and when the synchronization request of the server is received.
  • the downloading condition is that when the application downloading tool is started, the downloading condition corresponding application comprises a preset application; wherein the preset application comprises at least one of a popular application and a user configuration application.
  • the application also discloses an apparatus for downloading an application, including:
  • a first downloading module configured to download, by using an HTTPS channel, download description information of the application, where the download description information includes: download address information;
  • the second downloading module is configured to download the first application package corresponding to the download address information by using an HTTP channel.
  • the downloading the description information further includes downloading the verification information, the device further comprising:
  • the first verification module is configured to perform verification on the first application package downloaded to the local device according to the download verification information.
  • the device further comprises:
  • the third downloading module is configured to download the second application package corresponding to the download address information by using an HTTPS channel when the verification fails.
  • the first downloading module includes:
  • a fourth downloading submodule configured to download, by using an HTTPS channel, the download description information of the application corresponding to the download instruction in response to the download instruction of the user;
  • a fifth downloading submodule configured to download the download description information of the downloading condition corresponding application by using an HTTPS channel when the download condition is met.
  • the device further comprises:
  • a storage module configured to: before the second downloading module downloads the first application package corresponding to the download address information by using an HTTP channel, storing the download description information of the downloading condition corresponding application locally;
  • a reading module configured to read, according to a download instruction of the user, the download description information of the download instruction corresponding application from the local;
  • the second downloading module is specifically configured to download, by using an HTTP channel, the first application package corresponding to the downloaded download address information.
  • the downloading condition comprises one or more of the following conditions: when the application downloading tool is started, when the application is started, and when the synchronization request of the server is received.
  • the downloading condition is that when the application downloading tool is started, the downloading condition corresponding application comprises a preset application; wherein the preset application comprises at least one of a popular application and a user configuration application.
  • the embodiments of the present application include the following advantages:
  • the embodiment of the present application first downloads the download address information of the application by using the HTTPS channel, and then downloads the first application package corresponding to the download address information by using an HTTP channel.
  • the HTTPS channel is a security-oriented HTTP channel, it is relative to HTTP.
  • the channel has a higher security. Therefore, the embodiment of the present application can reduce the probability that the download address information is hijacked, that is, the accuracy of downloading the address information, by using the HTTP channel to download the downloaded address information of the application. Therefore, the accuracy of the first application package downloaded to the local device can be improved, and the high-accuracy application package can reduce the number of times of the cyclic download until the verification succeeds.
  • the embodiment of the present application can reduce the traffic data required for downloading the application;
  • the download address information of the application since the download address information of the application only needs to occupy a small number of bytes, the effect of the encrypted download address information on the data transmission length and the encryption process of downloading the address information have less impact on time consumption. Therefore, downloading the application's download address information using the HTTPS channel will not increase. Load the flow data required by the application.
  • FIG. 1 is a flow chart showing the steps of a first embodiment of a method for downloading an application according to the present application
  • FIG. 2 is a flow chart of steps of a second embodiment of a method for downloading an application according to the present application
  • FIG. 3 is a flow chart of steps of a third embodiment of a method for downloading an application according to the present application
  • FIG. 4 is a flow chart of steps of a fourth embodiment of a method for downloading an application of the present application
  • FIG. 5 is a structural block diagram of an apparatus embodiment for downloading an application of the present application.
  • the specific process of downloading an application package by using an HTTP channel is to download the download address information and the application package of the application by using an HTTP channel in turn.
  • the address information and application are downloaded in the HTTP channel.
  • the package may be hijacked and tampered with; if the user specifies that the downloaded application is an A application, the HTTP channel downloaded in the existing solution may be the download address of the B application, and the download address is downloaded if the download address itself is incorrect.
  • the probability of A application is very small.
  • HTTPS Hypertext Transfer Protocol over Secure Socket Layer
  • SSL Secure Sockets Layer
  • SSL Secure Sockets Layer
  • encryption and decryption operations require SSL assistance.
  • the HTTPS channel In the process of data transmission using the HTTPS channel, since the HTTPS channel needs to encrypt the original data, the encrypted data is larger than the original data, and the encryption process of the original data takes a certain time, and in addition, the HTTPS channel is established.
  • the process may specifically include a process of exchanging certificates; therefore, the HTTPS channel has a certain security disadvantage with respect to the HTTP channel, but has certain disadvantages in terms of data size and time consumption.
  • One of the core concepts of the embodiment of the present application is that the download process of the application package is decomposed into two steps, and the two steps are performed by using different transmission protocol channels, wherein the first step is for downloading the application by using the HTTPS channel.
  • the address information is downloaded, and the second part is used to download the first application package corresponding to the download address information obtained in the first step by using an HTTP channel;
  • the HTTPS channel is a security-targeted HTTP channel, it has an HTTP channel relative to the HTTP channel.
  • the security of the downloaded address information can be reduced, and the accuracy of the downloaded address information can be improved, so that the accuracy of the downloaded address information can be improved, and the accuracy of the downloaded address information can be improved.
  • the accuracy of the first application package downloaded to the local area is improved, and the high-accuracy application package will reduce the number of times of the cyclic download until the verification succeeds.
  • the embodiment of the present application can reduce the traffic data required for downloading the application; If the application to be downloaded is the A application, the HTTPS channel used in the embodiment of the present application downloads the download address of the A application, so that the accuracy of the application package downloaded to the local A application can be improved, thereby reducing the cyclic download until the verification. The number of successes.
  • the download address information of the application since the download address information of the application only needs to occupy a small number of bytes, the effect of the encrypted download address information on the data transmission length and the encryption process of downloading the address information have less impact on time consumption. Therefore, downloading the application's download address information using the HTTPS channel does not substantially increase the traffic data required to download the application.
  • FIG. 1 a flow chart of steps in a method for downloading an application of the present application is shown. Specifically, the method may include the following steps:
  • Step 101 Download the download description information of the application by using an HTTPS channel, where the download description information may specifically include: download address information;
  • Step 102 Download the first application package corresponding to the download address information by using an HTTP channel.
  • the embodiment of the present application can be applied to an application downloading tool with an application downloading function, such as an application market and a mobile phone management assistant.
  • an application downloading function such as an application market and a mobile phone management assistant.
  • the embodiment of the present application can reduce the required application for downloading the application package.
  • Traffic data; the application package here may specifically include: an installation package or an upgrade package of the application.
  • the technical solution 1 can download the download description information of the download instruction corresponding application by using an HTTPS channel in response to the download instruction of the user. For example, if the user clicks the download button of the application A in the application downloading tool, the user can be considered to trigger the download instruction for the application A, and the download description information corresponding to the application A of the download instruction is downloaded by using the HTTPS channel. It is to be understood that the user may trigger the above-mentioned downloading instruction in any manner, and the above-mentioned triggering instruction may correspond to any one or more applications.
  • the specific triggering instruction and the triggering manner thereof are not limited in the embodiment of the present application.
  • the technical solution 2 may download the download description information of the application corresponding to the download condition by using an HTTPS channel when the download condition is met.
  • the method may further include: downloading the download condition corresponding to the download description of the application
  • the information is stored locally; in response to the download instruction of the user, the download description information of the download instruction corresponding to the application is read locally, and the step 102 of downloading the first application package corresponding to the download address information by using an HTTP channel is specifically performed.
  • the first application package corresponding to the downloaded download address information may be downloaded by using an HTTP channel.
  • the download description information of the download application corresponding to the download instruction can be directly read directly from the local, so that the response efficiency and the download efficiency for the download instruction can be improved.
  • the downloading condition may specifically include one or more of the following conditions: when the application downloading tool is started, when the application is started, and when the synchronization request of the server is received.
  • the downloading condition may be that when the application downloading tool is started, the downloading condition corresponding application may include a preset application, and the preset application may specifically include: a popular application and a user configuration application. At least one of them.
  • the popular application can be used to indicate an application that has been paid attention to in the recent period of time, for example, it can be one or more applications that are searched, downloaded, installed, or recommended most by the user.
  • the user configuration application can be used to represent an application that the user has configured through the interface of the application download tool.
  • the client of the application downloading tool may send a first download request carrying the preset application information to the server to download the download description information of the preset application by using an HTTPS channel, and download the The download description information of the preset application is stored locally, because the user has not triggered the download instruction when the application download tool is started, so that when the download instruction of the user is received, the pre-stored download instruction can be directly read directly from the local.
  • the download description information of the application it is possible to improve the response efficiency and download efficiency for the download instruction.
  • the downloading condition may be when the application is started, and the downloading condition corresponding application may include: launching an application or an application associated with the launching application, where an application having an association relationship It can be determined by a person skilled in the art according to the actual situation that the application having the association relationship may be the same category application, the same development application or the process association application, etc.; for example, the WeChat APP (Application, Application) is the same as the developer of the QQ APP, The two have an associated relationship; for example, the landlord APP and the tractor APP belong to the chess category, and the two have an associated relationship; for example, if the shopping APP needs to use the payment APP, the two may have an associated relationship, such as Jingdong.
  • the APP has an association relationship with the Alipay APP, etc., and it can be understood that the specific application of the present application does not limit the specific relationship and the specific application with the associated relationship.
  • the download condition may be when a synchronization request of the server is received
  • the downloading condition corresponding application may include: an application corresponding to the synchronization request, and the like.
  • the server when detecting a new application uploaded by the developer or an application updated by the developer, the server may send the synchronization request to the client, and carry the information of the new application or the updated application in the synchronization request, thereby The client may download the download description information of the application corresponding to the synchronization request by using an HTTPS channel.
  • the embodiment of the present application first downloads the download address information of the application by using an HTTPS channel, and then downloads the first application package corresponding to the download address information by using an HTTP channel.
  • the HTTPS channel is a security-oriented HTTP channel, which has a higher security than the HTTP channel. Therefore, the download address information of the HTTP channel download application is compared with the existing solution, and the embodiment of the present application can be reduced.
  • the probability that the download address information is hijacked that is, the accuracy of downloading the address information, can improve the accuracy of downloading the first application package to the local, and the high-accuracy application package will reduce the cyclic download until the verification succeeds.
  • the number of times therefore, the embodiment of the present application can reduce the traffic data required to download an application;
  • the download address information of the application since the download address information of the application only needs to occupy a small number of bytes, the effect of the encrypted download address information on the data transmission length and the encryption process of downloading the address information have less impact on time consumption. Therefore, downloading the application's download address information using the HTTPS channel does not substantially increase the traffic data required to download the application.
  • FIG. 2 a flow chart of the steps of the second embodiment of the method for downloading an application of the present application is shown, which may specifically include the following steps:
  • Step 201 Download the download description information of the application by using the HTTPS channel, where the download description information may specifically include: download address information and download verification information;
  • Step 202 Download the first application package corresponding to the download address information by using an HTTP channel.
  • Step 203 Perform verification on the first application package downloaded to the local according to the download verification information.
  • the download verification information content is added to the download description information, and the first application package downloaded to the local device is verified according to the download verification information. step;
  • the download verification information of the HTTP channel download application is used, and the embodiment can reduce the probability that the download address information and the download verification information are hijacked, that is, the matching degree between the download address information and the download address verification information can be improved.
  • the high-matching download address information and the download address check information will reduce the number of times the loop download is performed until the check succeeds. Therefore, the embodiment of the present application can further reduce the traffic data required for downloading the application;
  • the user specifies that the downloaded application is an A application.
  • the existing solution may use the HTTP channel to download the B.
  • the download address of the application and the download verification information of the C application, and the probability of downloading the A application is very small when the download address itself is incorrect, and the download verification information (application C) and the download address information (application B) are downloaded.
  • the probability of successful verification in the case of mismatch is very small, which greatly increases the number of cyclic downloads;
  • the HTTPS channel is used to download the download address of the A application and the download verification information of the A application, which can improve the accuracy of the application package downloaded to the local A application, and can improve the probability of successful verification. Therefore, the number of times of cyclic downloading until the verification is successful can be greatly reduced.
  • the download description information of the application may be obtained from the server by using an HTTPS channel, where the download description information may specifically include: a URL of the application (a uniform resource locator, Uniform Resoure Locator), summary information or signature information of the application, and download verification information; then, the first application package corresponding to the URL may be downloaded by using an HTTP channel, and after downloading, according to MD5 (Message Digest Algorithm Fifth Edition)
  • MD5 Message Digest Algorithm Fifth Edition
  • the message digest algorithm (5) performs a digest operation on the first application package downloaded to the local device, or performs a signature operation on the first application package by using a signature algorithm, and then uses the digest operation result and the download description information in the downloading description information.
  • the summary information is compared, or the signature operation result is compared with the signature information of the application in the download description information. If the comparison result is consistent, the verification is successful, and if the comparison result is inconsistent, the verification fails. It can be understood that the above-mentioned download verification information and the corresponding verification process are only examples. The specific download verification information and the corresponding verification process are not limited in the embodiment of the present application.
  • the embodiment can improve the matching degree between the download address information and the download address check information, and the high-matching download address information and the download address check information will reduce the number of times of cyclic downloading until the verification succeeds.
  • the application embodiment can further reduce the traffic data required to download an application.
  • FIG. 3 a flow chart of steps in a third embodiment of a method for downloading an application of the present application is shown, which may specifically include the following steps:
  • Step 301 Download the download description information of the application by using an HTTPS channel, where the download description information may specifically include: download address information and download verification information;
  • Step 302 Download the first application package corresponding to the download address information by using an HTTP channel.
  • Step 303 Perform verification on the first application package downloaded to the local device according to the download verification information.
  • Step 304 When the verification fails, the second application package corresponding to the download address information is downloaded by using an HTTPS channel.
  • the HTTPS channel may also be used. Loading a second application package corresponding to the download address information
  • the embodiment uses the HTTPS channel to download the second application package corresponding to the download address information.
  • the security of the HTTPS channel can be exploited to be downloaded.
  • the number of times is controlled twice (the first time is to download the first application package corresponding to the download address information by using the HTTP channel, and the second time is to download the second application corresponding to the download address information by using the HTTPS channel when the verification fails.
  • Package which uses the HTTP channel to cyclically download the application package multiple times compared to the existing solution, which can reduce the number of downloads, thereby saving the traffic data required to download the application.
  • the data in the HTTP channel is hijacked as an event of probability.
  • the embodiment of the present application can successfully download the application by using the first download;
  • the embodiment of the present application can successfully download the application only after the first download and the second download. Therefore, the embodiment of the present application can save the download to the maximum while ensuring the download success rate. Apply the required traffic data.
  • FIG. 4 a flow chart of steps of a fourth embodiment of a method for downloading an application of the present application is shown, which may specifically include the following steps:
  • Step 401 Download the download description information of the application by using the HTTPS channel, where the download description information may specifically include: download address information and download verification information;
  • Step 402 Download the first application package corresponding to the download address information by using an HTTP channel.
  • Step 403 according to the download verification information to verify the first application package downloaded to the local, if the verification is successful, step 406 is performed, if the verification fails, step 404 is performed;
  • Step 404 When the verification fails, the second application package corresponding to the download address information is downloaded by using an HTTPS channel.
  • Step 405 according to the download verification information, the second application package downloaded to the local is verified, if the verification is successful, step 406 is performed;
  • Step 406 ending the download process.
  • step 405 the process of verifying the second application package that is downloaded to the local device according to the download verification information is similar to the verification process of step 403. Therefore, the description is not repeated here.
  • step 405 may be repeatedly performed until the verification is successful.
  • FIG. 5 a structural block diagram of an apparatus for downloading an application of the present application is shown, which may specifically include the following modules:
  • the first downloading module 501 is configured to download download description information of the application by using an HTTPS channel, where the download description information includes: download address information;
  • the second downloading module 502 is configured to download the first application package corresponding to the download address information by using an HTTP channel.
  • the downloading the description information may further include downloading the verification information
  • the apparatus may further include:
  • the first verification module is configured to perform verification on the first application package downloaded to the local device according to the download verification information.
  • the device may further include:
  • the third downloading module is configured to download the second application package corresponding to the download address information by using an HTTPS channel when the verification fails.
  • the first downloading module 501 may further include:
  • a fourth downloading submodule configured to download, by using an HTTPS channel, the download description information of the application corresponding to the download instruction in response to the download instruction of the user;
  • a fifth downloading submodule configured to download the download description information of the downloading condition corresponding application by using an HTTPS channel when the download condition is met.
  • the apparatus may further include:
  • a storage module configured to store the download description information of the downloading condition corresponding application locally before the second downloading module 502 downloads the first application package corresponding to the download address information by using an HTTP channel;
  • a reading module configured to read, according to a download instruction of the user, the download description information of the download instruction corresponding application from the local;
  • the second downloading module 502 can be specifically configured to download the downloaded download address information by using an HTTP channel.
  • the first application package should be.
  • the downloading condition may specifically include one or more of the following conditions: when the application downloading tool is started, when the application is started, and when the synchronization request of the server is received.
  • the downloading condition may be: when the application downloading tool is started, the downloading condition corresponding application may specifically include a preset application; wherein the preset application may further include: At least one of an application and a user configuration application.
  • the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
  • embodiments of the embodiments of the present application can be provided as a method, apparatus, or computer program product. Therefore, the embodiments of the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Moreover, embodiments of the present application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.
  • computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
  • the computer device includes one or more processors (CPUs), input/output interfaces, network interfaces, and memory.
  • the memory may include non-persistent memory, random access memory (RAM), and/or non-volatile memory in a computer readable medium, such as read only memory (ROM) or flash memory.
  • RAM random access memory
  • ROM read only memory
  • Memory is an example of a computer readable medium.
  • Computer readable media includes both permanent and non-persistent, removable and non-removable media.
  • Information storage can be implemented by any method or technology. The information can be computer readable instructions, data structures, modules of programs, or other data.
  • Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory. (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disk read only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, Magnetic tape cartridges, magnetic tape storage or other magnetic storage devices or any other non-transportable media can be used to store information that can be accessed by a computing device.
  • computer readable media does not include non-persistent computer readable media, such as modulated data signals and carrier waves.
  • Embodiments of the present application are described with reference to flowcharts and/or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present application. It should be understood that flowcharts and/or blocks may be implemented by computer program instructions. Each of the processes and/or blocks in the figures, and combinations of flows and/or blocks in the flowcharts and/or block diagrams. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor or other programmable data processing terminal device to produce a machine such that instructions are executed by a processor of a computer or other programmable data processing terminal device Means are provided for implementing the functions specified in one or more of the flow or in one or more blocks of the flow chart.
  • the computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture comprising the instruction device.
  • the instruction device implements the functions specified in one or more blocks of the flowchart or in a flow or block of the flowchart.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Medical Informatics (AREA)
  • Information Transfer Between Computers (AREA)
  • Stored Programmes (AREA)

Abstract

本申请实施例提供了一种下载应用的方法和装置,其中的方法具体包括:采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息包括:下载地址信息;采用HTTP通道下载所述下载地址信息对应的第一应用包。本申请实施例能够降低下载应用所需的流量数据。

Description

一种下载应用的方法和装置
本申请要求2015年06月16日递交的申请号为201510334074.3、发明名称为“一种下载应用的方法和装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及网络通信技术领域,特别是涉及一种下载应用的方法和装置。
背景技术
应用程序就是为了完成某项或某几项特定任务而被开发运行于操作系统之上的计算机程序。应用程序运行在用户模式下,其可以与用户直接交互,一般应用都具有可视的用户界面。随着智能终端种类和使用量的增加,用于其上的应用程序也越来越多,而智能终端的一大特点就是能够安装和升级应用程序;因此,如何让这些智能终端快捷、稳定地安装和升级应用程序是亟待满足的需求。
现有方案会在接收到用户的安装新应用或者升级旧应用的指令后,采用HTTP(超文本传输协议,Hypertext Transfer Protocol)通道下载所述指令对应的应用包,并通过安装下载完成的应用包实现应用的安装或升级。然而,基于HTTP通道的数据传输在网络上是透明的,恶意者可以便捷地对HTTP通道中数据进行篡改,这严重影响了应用下载的稳定性。例如,用户的上述指令为A应用的下载指令,结果下载了B应用的安装包等等。
为了提高应用下载的稳定性,现有方案还会利用应用包的校验信息对下载到本地的应用包进行校验,如果校验失败,则重新下载上述指令对应的应用包,直至校验成功。由于HTTP通道中数据被劫持的概率较高,在实际中需要多次循环下载才能得到与上述指令相匹配的应用包,上述多次下载无疑消耗了大量的流量数据。
发明内容
本申请实施例所要解决的技术问题是提供一种下载应用的方法,能够降低下载应用所需的流量数据。
相应的,本申请实施例还提供了一种下载应用的装置,用以保证上述方法的实现及应用。
为了解决上述问题,本申请公开了一种下载应用的方法,包括:
采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息包括:下载地址信息;
采用HTTP通道下载所述下载地址信息对应的第一应用包。
优选的,所述下载描述信息还包括下载校验信息,所述方法还包括:
依据所述下载校验信息对下载到本地的第一应用包进行校验。
优选的,所述方法还包括:
在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包。
优选的,所述采用HTTPS通道下载应用的下载描述信息的步骤,包括:
响应于用户的下载指令,采用HTTPS通道下载所述下载指令对应应用的下载描述信息;和/或
在满足下载条件时,采用HTTPS通道下载所述下载条件对应应用的下载描述信息。
优选的,在所述采用HTTP通道下载所述下载地址信息对应的第一应用包的步骤之前,所述方法还包括:
将所述下载条件对应应用的下载描述信息存储在本地;
响应于用户的下载指令,从本地读取所述下载指令对应应用的下载描述信息;
则所述采用HTTP通道下载所述下载地址信息对应的第一应用包的步骤,具体为采用HTTP通道下载所读取下载地址信息对应的第一应用包。
优选的,所述下载条件包括如下条件中的一项或多项:在应用下载工具启动时、在应用启动时和在接收到服务器的同步请求时。
优选的,所述下载条件为在应用下载工具启动时,则所述下载条件对应应用包括预置应用;其中,所述预置应用包括:热门应用和用户配置应用中的至少一种。
另一方面,本申请还公开了一种下载应用的装置,包括:
第一下载模块,用于采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息包括:下载地址信息;及
第二下载模块,用于采用HTTP通道下载所述下载地址信息对应的第一应用包。
优选的,所述下载描述信息还包括下载校验信息,所述装置还包括:
第一校验模块,用于依据所述下载校验信息对下载到本地的第一应用包进行校验。
优选的,所述装置还包括:
第三下载模块,用于在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包。
优选的,所述第一下载模块,包括:
第四下载子模块,用于响应于用户的下载指令,采用HTTPS通道下载所述下载指令对应应用的下载描述信息;和/或
第五下载子模块,用于在满足下载条件时,采用HTTPS通道下载所述下载条件对应应用的下载描述信息。
优选的,所述装置还包括:
存储模块,用于在所述第二下载模块采用HTTP通道下载所述下载地址信息对应的第一应用包之前,将所述下载条件对应应用的下载描述信息存储在本地;
读取模块,用于响应于用户的下载指令,从本地读取所述下载指令对应应用的下载描述信息;
则所述第二下载模块,具体用于采用HTTP通道下载所读取下载地址信息对应的第一应用包。
优选的,所述下载条件包括如下条件中的一项或多项:在应用下载工具启动时、在应用启动时和在接收到服务器的同步请求时。
优选的,所述下载条件为在应用下载工具启动时,则所述下载条件对应应用包括预置应用;其中,所述预置应用包括:热门应用和用户配置应用中的至少一种。
与现有技术相比,本申请实施例包括以下优点:
本申请实施例首先采用HTTPS通道下载应用的下载地址信息,然后采用HTTP通道下载上述下载地址信息对应的第一应用包;一方面,由于HTTPS通道是以安全为目标的HTTP通道,其相对于HTTP通道具有更高的安全性,因此,相对于现有方案采用HTTP通道下载应用的下载地址信息,本申请实施例能够降低下载地址信息被劫持的概率,也即能够提高下载地址信息的准确性,从而能够提高下载到本地的第一应用包的准确性,而高准确性的应用包将会减少循环下载直至校验成功的次数,因此,本申请实施例能够降低下载应用所需的流量数据;另一方面,由于应用的下载地址信息仅需占用较少的字节,因此,加密后的下载地址信息对数据传输长度的影响、以及下载地址信息的加密过程对于耗时的影响都比较小,因此,采用HTTPS通道下载应用的下载地址信息基本不会增加下载应用所需的流量数据。
附图说明
图1是本申请的一种下载应用的方法实施例一的步骤流程图;
图2是本申请的一种下载应用的方法实施例二的步骤流程图;
图3本申请的一种下载应用的方法实施例三的步骤流程图;
图4本申请的一种下载应用的方法实施例四的步骤流程图;以及
图5是本申请的一种下载应用的装置实施例的结构框图。
具体实施方式
为使本申请的上述目的、特征和优点能够更加明显易懂,下面结合附图和具体实施方式对本申请作进一步详细的说明。
现有方案采用HTTP通道下载应用包的具体过程为,依次采用HTTP通道下载应用的下载地址信息和应用包,然而由于HTTP通道中数据被劫持的概率较高,故HTTP通道中下载地址信息和应用包都有可能被劫持和篡改;假设用户指定下载的应用为A应用,则现有方案中采用HTTP通道下载的可能是B应用的下载地址,而在下载地址本身就有误的情况下下载得到A应用的概率非常小。
HTTPS(安全超文本传输协议,Hypertext Transfer Protocol over Secure Socket Layer)通道是以安全为目标的HTTP通道,简单而言是HTTP的安全版,具体地,在HTTP下加入SSL(安全套接层,Secure Socket Layer),HTTPS的安全基础便是SSL,加解密操作需要SSL协助完成。
在采用HTTPS通道进行数据传输的过程中,由于HTTPS通道需要对原始数据进行加密故加密后的数据要比原始数据大,并且,原始数据的加密过程需要耗费一定的时间,另外,建立HTTPS通道的过程具体可以包括交换证书等过程;因此,相对于HTTP通道,HTTPS通道虽然具有安全性高的优势,但在传输数据大小、耗时方面都具有一定的劣势。
本申请实施例的核心构思之一在于,将应用包的下载流程分解为两个步骤,并且采用不同的传输协议通道来执行该两个步骤,其中,第一步骤用于采用HTTPS通道下载应用的下载地址信息,第二部分用于采用HTTP通道下载第一步骤得到的下载地址信息对应的第一应用包;
一方面,由于HTTPS通道是以安全为目标的HTTP通道,其相对于HTTP通道具有 更高的安全性,因此,相对于现有方案采用HTTP通道下载应用的下载地址信息,本申请实施例能够降低下载地址信息被劫持的概率,也即能够提高下载地址信息的准确性,从而能够提高下载到本地的第一应用包的准确性,而高准确性的应用包将会减少循环下载直至校验成功的次数,因此,本申请实施例能够降低下载应用所需的流量数据;假设用户指定下载的应用为A应用,则本申请实施例中采用HTTPS通道下载的就是A应用的下载地址,因此能够提高下载到本地的A应用的应用包的准确性,从而能够减少循环下载直至校验成功的次数。
另一方面,由于应用的下载地址信息仅需占用较少的字节,因此,加密后的下载地址信息对数据传输长度的影响、以及下载地址信息的加密过程对于耗时的影响都比较小,因此,采用HTTPS通道下载应用的下载地址信息基本不会增加下载应用所需的流量数据。
实施例一
参照图1,示出了本申请的一种下载应用的方法实施例一的步骤流程图,具体可以包括如下步骤:
步骤101、采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息具体可以包括:下载地址信息;
步骤102、采用HTTP通道下载所述下载地址信息对应的第一应用包。
本申请实施例可以应用于应用市场、手机管理助手等各种具有应用下载功能的应用下载工具中,在用户使用这些应用下载工具下载应用包时,本申请实施例可以降低下载应用包所需的流量数据;这里的应用包具体可以包括:应用的安装包或者升级包等等。
本申请实施例可以提供如下采用HTTPS通道下载应用的下载描述信息的技术方案:
技术方案一、
技术方案一可以响应于用户的下载指令,采用HTTPS通道下载所述下载指令对应应用的下载描述信息。例如,用户在应用下载工具中点击了应用A的下载按钮,则可以认为用户触发了针对应用A的下载指令,并采用HTTPS通道下载所述下载指令对应应用A的下载描述信息。可以理解,用户可以采用任意方式触发上述下载指令,并且,所述上述触发指令中可以对应于任意的一个或多个应用,本申请实施例对具体的触发指令及其触发方式不加以限制。
技术方案二
技术方案二可以在满足下载条件时,采用HTTPS通道下载所述下载条件对应应用的下载描述信息。
在本申请的一种优选实施例中,在所述采用HTTP通道下载所述下载地址信息对应的第一应用包的步骤之前,所述方法还可以包括:将所述下载条件对应应用的下载描述信息存储在本地;响应于用户的下载指令,从本地读取所述下载指令对应应用的下载描述信息,则所述采用HTTP通道下载所述下载地址信息对应的第一应用包的步骤102,具体可以为采用HTTP通道下载所读取下载地址信息对应的第一应用包。依据本优选实施例,在接收到用户的下载指令时,可以直接从本地直接读取预先存储的所述下载指令对应应用的下载描述信息,因此能够提高对于下载指令的响应效率和下载效率。
在具体实现中,所述下载条件具体可以包括如下条件中的一项或多项:在应用下载工具启动时、在应用启动时和在接收到服务器的同步请求时。
在本申请的一种应用示例中,所述下载条件可以为在应用下载工具启动时,则所述下载条件对应应用可以包括预置应用,该预置应用具体可以包括:热门应用和用户配置应用中的至少一种。其中,热门应用可用于表示最近一段时间内被热门关注的应用,例如,其可以为被用户搜索、下载、安装或者推荐次数最多的一个或多个应用。用户配置应用可用于表示用户通过应用下载工具的接口配置得到的应用。在应用下载工具启动时,应用下载工具的客户端可以向服务端发送携带有上述预置应用信息的第一下载请求,以采用HTTPS通道下载所述预置应用的下载描述信息,并将下载得到预置应用的下载描述信息存储到本地,由于在应用下载工具启动时,用户尚未触发下载指令,这样,在接收到用户的下载指令时,可以直接从本地直接读取预先存储的所述下载指令对应应用的下载描述信息,因此能够提高对于下载指令的响应效率和下载效率。
在本申请的另一种应用示例中,所述下载条件可以为在应用启动时,则所述下载条件对应应用可以包括:启动应用或者该启动应用所关联的应用,这里,具有关联关系的应用可由本领域技术人员依据实际情况确定,具有关联关系的应用可以为同类别应用、同开发应用或者流程关联应用等等;例如,微信APP(应用程序,Application)与QQ APP的开发商相同,则二者具有关联关系;又如,斗地主APP和拖拉机APP同属于棋牌类别,则二者具有关联关系;再如,购物类APP需要用到支付类APP,则二者可以具有关联关系,如京东APP与支付宝APP具有关联关系等等,可以理解,本申请实施例对具体的关联关系及具有关联关系的具体应用不加以限制。
在本申请的再一种应用示例中,所述下载条件可以为在接收到服务器的同步请求时, 则所述下载条件对应应用可以包括:所述同步请求所对应的应用等。在实际应用中,在检测到开发者上传的新应用、或者开发者更新的应用时,服务器可以向客户端发送上述同步请求,并在上述同步请求中携带新应用或者更新的应用的信息,从而客户端可以采用HTTPS通道下载所述同步请求所对应的应用的下载描述信息。
综上,本申请实施例首先采用HTTPS通道下载应用的下载地址信息,然后采用HTTP通道下载上述下载地址信息对应的第一应用包;
一方面,由于HTTPS通道是以安全为目标的HTTP通道,其相对于HTTP通道具有更高的安全性,因此,相对于现有方案采用HTTP通道下载应用的下载地址信息,本申请实施例能够降低下载地址信息被劫持的概率,也即能够提高下载地址信息的准确性,从而能够提高下载到本地的第一应用包的准确性,而高准确性的应用包将会减少循环下载直至校验成功的次数,因此,本申请实施例能够降低下载应用所需的流量数据;
另一方面,由于应用的下载地址信息仅需占用较少的字节,因此,加密后的下载地址信息对数据传输长度的影响、以及下载地址信息的加密过程对于耗时的影响都比较小,因此,采用HTTPS通道下载应用的下载地址信息基本不会增加下载应用所需的流量数据。
实施例二
参照图2,示出了本申请的一种下载应用的方法实施例二的步骤流程图,具体可以包括如下步骤:
步骤201、采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息具体可以包括:下载地址信息和下载校验信息;
步骤202、采用HTTP通道下载所述下载地址信息对应的第一应用包;
步骤203、依据所述下载校验信息对下载到本地的第一应用包进行校验。
相对于实施例一,本实施例在所述下载描述信息中增加了下载校验信息内容,以及在流程中增加了依据所述下载校验信息对下载到本地的第一应用包进行校验的步骤;
相对于现有方案采用HTTP通道下载应用的下载校验信息,本实施例能够降低下载地址信息和下载校验信息被劫持的概率,也即能够提高下载地址信息和下载地址校验信息的匹配度,而高匹配度的下载地址信息和下载地址校验信息将会减少循环下载直至校验成功的次数,因此,本申请实施例能够进一步降低下载应用所需的流量数据;
假设用户指定下载的应用为A应用,则现有方案中采用HTTP通道下载的可能是B 应用的下载地址和C应用的下载校验信息,而在下载地址本身就有误的情况下下载得到A应用的概率非常小,在下载校验信息(应用C)与下载地址信息(应用B)不匹配的情况下校验成功的概率非常微小,这大大增加了循环下载的次数;
而本实施例中采用HTTPS通道下载的就是A应用的下载地址和A应用的下载校验信息,既能够提高下载到本地的A应用的应用包的准确性,又能够提高校验成功的概率,因此能够大大减少循环下载直至校验成功的次数。
在本申请的一种应用示例中,在下载某应用之前,可以首先采用HTTPS通道从服务器获取该应用的下载描述信息,所述下载描述信息具体可以包括:该应用的URL(统一资源定位符,Uniform Resoure Locator)、该应用的摘要信息或者签名信息等下载校验信息;然后,可以采用HTTP通道下载上述URL对应的第一应用包,并在下载完毕后,根据MD5(消息摘要算法第五版,Message Digest Algorithm5)等摘要算法对下载到本地的第一应用包进行摘要运算,或者,利用签名算法对上述第一应用包进行签名运算,然后将摘要运算结果与上述下载描述信息中该应用的摘要信息进行比较,或者,将签名运算结果与上述下载描述信息中该应用的签名信息进行比较,若比较结果为一致则校验成功,若比较结果为不一致则校验失败。可以理解,上述下载校验信息及对应的校验过程只是作为示例,本申请实施例对具体的下载校验信息及对应的校验过程不加以限制。
综上,本实施例能够提高下载地址信息和下载地址校验信息的匹配度,而高匹配度的下载地址信息和下载地址校验信息将会减少循环下载直至校验成功的次数,因此,本申请实施例能够进一步降低下载应用所需的流量数据。
实施例三
参照图3,示出了本申请的一种下载应用的方法实施例三的步骤流程图,具体可以包括如下步骤:
步骤301、采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息具体可以包括:下载地址信息和下载校验信息;
步骤302、采用HTTP通道下载所述下载地址信息对应的第一应用包;
步骤303、依据所述下载校验信息对下载到本地的第一应用包进行校验;
步骤304、在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包。
相对于实施例二,本实施例在第一应用包的校验失败时,还可以采用HTTPS通道下 载所述下载地址信息对应的第二应用包;
由于本实施例优先采用HTTP通道下载所述下载地址信息对应的第一应用包,因此能够发挥HTTP通道的数据传输长度小和耗时小的优点,以尽量节省下载应用所需的流量数据;而在第一应用包的校验失败时,本实施例才采用HTTPS通道下载所述下载地址信息对应的第二应用包,此种情况下能够发挥HTTPS通道的安全性高的优点,以将下载的次数控制在二次(第一次为采用HTTP通道下载所述下载地址信息对应的第一应用包,第二次为在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包),这相对于现有方案多次采用HTTP通道循环下载应用包,能够减少下载次数,从而能够节省下载应用所需的流量数据。
在实际应用中,由于HTTP通道中数据被劫持为概率发生的事件,当HTTP通道中第一应用包未被劫持时,本申请实施例通过第一次下载即可成功下载应用;当HTTP通道中第一应用包被劫持时,本申请实施例仅需第一次下载和第二次下载即可成功下载应用,因此,本申请实施例能够在保证下载成功率的前提下,最大限度地节省下载应用所需的流量数据。
实施例四
参照图4,示出了本申请的一种下载应用的方法实施例四的步骤流程图,具体可以包括如下步骤:
步骤401、采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息具体可以包括:下载地址信息和下载校验信息;
步骤402、采用HTTP通道下载所述下载地址信息对应的第一应用包;
步骤403、依据所述下载校验信息对下载到本地的第一应用包进行校验,若校验成功,则执行步骤406,若校验失败,则执行步骤404;
步骤404、在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包;
步骤405、依据所述下载校验信息对下载到本地的第二应用包进行校验,若校验成功,则执行步骤406;
步骤406、结束下载流程。
对于步骤405,由于其依据所述下载校验信息对下载到本地的第二应用包进行校验的过程与步骤403的校验过程类似,故在此不做赘述,相互参照即可。
需要说明的是,当步骤405的校验结果为校验失败时,也可以重复执行步骤405直至校验成功。
需要说明的是,对于方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本申请实施例并不受所描述的动作顺序的限制,因为依据本申请实施例,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作并不一定是本申请实施例所必须的。
参照图5,示出了本申请的一种下载应用的装置实施例的结构框图,具体可以包括如下模块:
第一下载模块501,用于采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息包括:下载地址信息;及
第二下载模块502,用于采用HTTP通道下载所述下载地址信息对应的第一应用包。
在本申请的一种优选实施例中,所述下载描述信息还可以包括下载校验信息,所述装置还可以包括:
第一校验模块,用于依据所述下载校验信息对下载到本地的第一应用包进行校验。
在本申请的另一种优选实施例中,所述装置还可以包括:
第三下载模块,用于在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包。
在本申请的再一种优选实施例中,所述第一下载模块501,可以进一步包括:
第四下载子模块,用于响应于用户的下载指令,采用HTTPS通道下载所述下载指令对应应用的下载描述信息;和/或
第五下载子模块,用于在满足下载条件时,采用HTTPS通道下载所述下载条件对应应用的下载描述信息。
在本申请的又一种优选实施例中,所述装置还可以包括:
存储模块,用于在所述第二下载模块502采用HTTP通道下载所述下载地址信息对应的第一应用包之前,将所述下载条件对应应用的下载描述信息存储在本地;
读取模块,用于响应于用户的下载指令,从本地读取所述下载指令对应应用的下载描述信息;
则所述第二下载模块502,可具体用于采用HTTP通道下载所读取下载地址信息对 应的第一应用包。
在本申请的一种优选实施例中,所述下载条件具体可以包括如下条件中的一项或多项:在应用下载工具启动时、在应用启动时和在接收到服务器的同步请求时。
在本申请的一种优选实施例中,所述下载条件可以为在应用下载工具启动时,则所述下载条件对应应用具体可以包括预置应用;其中,所述预置应用可以进一步包括:热门应用和用户配置应用中的至少一种。
对于装置实施例而言,由于其与方法实施例基本相似,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
本说明书中的各个实施例均采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似的部分互相参见即可。
本领域内的技术人员应明白,本申请实施例的实施例可提供为方法、装置、或计算机程序产品。因此,本申请实施例可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请实施例可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
在一个典型的配置中,所述计算机设备包括一个或多个处理器(CPU)、输入/输出接口、网络接口和内存。内存可能包括计算机可读介质中的非永久性存储器,随机存取存储器(RAM)和/或非易失性内存等形式,如只读存储器(ROM)或闪存(flash RAM)。内存是计算机可读介质的示例。计算机可读介质包括永久性和非永久性、可移动和非可移动媒体可以由任何方法或技术来实现信息存储。信息可以是计算机可读指令、数据结构、程序的模块或其他数据。计算机的存储介质的例子包括,但不限于相变内存(PRAM)、静态随机存取存储器(SRAM)、动态随机存取存储器(DRAM)、其他类型的随机存取存储器(RAM)、只读存储器(ROM)、电可擦除可编程只读存储器(EEPROM)、快闪记忆体或其他内存技术、只读光盘只读存储器(CD-ROM)、数字多功能光盘(DVD)或其他光学存储、磁盒式磁带,磁带磁磁盘存储或其他磁性存储设备或任何其他非传输介质,可用于存储可以被计算设备访问的信息。按照本文中的界定,计算机可读介质不包括非持续性的电脑可读媒体(transitory media),如调制的数据信号和载波。
本申请实施例是参照根据本申请实施例的方法、终端设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框 图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理终端设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理终端设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理终端设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些计算机程序指令也可装载到计算机或其他可编程数据处理终端设备上,使得在计算机或其他可编程终端设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程终端设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
尽管已描述了本申请实施例的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例做出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本申请实施例范围的所有变更和修改。
最后,还需要说明的是,在本文中,诸如第一和第二等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者终端设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者终端设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者终端设备中还存在另外的相同要素。
以上对本申请所提供的一种下载应用的方法和一种下载应用的装置,进行了详细介绍,本文中应用了具体个例对本申请的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本申请的方法及其核心思想;同时,对于本领域的一般技术人员,依据本申请的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本申请的限制。

Claims (14)

  1. 一种下载应用的方法,其特征在于,包括:
    采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息包括:下载地址信息;
    采用HTTP通道下载所述下载地址信息对应的第一应用包。
  2. 根据权利要求1所述的方法,其特征在于,所述下载描述信息还包括下载校验信息,所述方法还包括:
    依据所述下载校验信息对下载到本地的第一应用包进行校验。
  3. 根据权利要求2所述的方法,其特征在于,所述方法还包括:
    在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包。
  4. 根据权利要求1所述的方法,其特征在于,所述采用HTTPS通道下载应用的下载描述信息的步骤,包括:
    响应于用户的下载指令,采用HTTPS通道下载所述下载指令对应应用的下载描述信息;和/或
    在满足下载条件时,采用HTTPS通道下载所述下载条件对应应用的下载描述信息。
  5. 根据权利要求4所述的方法,其特征在于,在所述采用HTTP通道下载所述下载地址信息对应的第一应用包的步骤之前,所述方法还包括:
    将所述下载条件对应应用的下载描述信息存储在本地;
    响应于用户的下载指令,从本地读取所述下载指令对应应用的下载描述信息;
    则所述采用HTTP通道下载所述下载地址信息对应的第一应用包的步骤,具体为采用HTTP通道下载所读取下载地址信息对应的第一应用包。
  6. 根据权利要求4或5所述的方法,其特征在于,所述下载条件包括如下条件中的一项或多项:在应用下载工具启动时、在应用启动时和在接收到服务器的同步请求时。
  7. 根据权利要求6所述的方法,其特征在于,所述下载条件为在应用下载工具启动时,则所述下载条件对应应用包括预置应用;其中,所述预置应用包括:热门应用和用户配置应用中的至少一种。
  8. 一种下载应用的装置,其特征在于,包括:
    第一下载模块,用于采用HTTPS通道下载应用的下载描述信息;其中,所述下载描述信息包括:下载地址信息;及
    第二下载模块,用于采用HTTP通道下载所述下载地址信息对应的第一应用包。
  9. 根据权利要求8所述的装置,其特征在于,所述下载描述信息还包括下载校验信息,所述装置还包括:
    第一校验模块,用于依据所述下载校验信息对下载到本地的第一应用包进行校验。
  10. 根据权利要求9所述的装置,其特征在于,所述装置还包括:
    第三下载模块,用于在校验失败时,采用HTTPS通道下载所述下载地址信息对应的第二应用包。
  11. 根据权利要求8所述的装置,其特征在于,所述第一下载模块,包括:
    第四下载子模块,用于响应于用户的下载指令,采用HTTPS通道下载所述下载指令对应应用的下载描述信息;和/或
    第五下载子模块,用于在满足下载条件时,采用HTTPS通道下载所述下载条件对应应用的下载描述信息。
  12. 根据权利要求11所述的装置,其特征在于,所述装置还包括:
    存储模块,用于在所述第二下载模块采用HTTP通道下载所述下载地址信息对应的第一应用包之前,将所述下载条件对应应用的下载描述信息存储在本地;
    读取模块,用于响应于用户的下载指令,从本地读取所述下载指令对应应用的下载描述信息;
    则所述第二下载模块,具体用于采用HTTP通道下载所读取下载地址信息对应的第一应用包。
  13. 根据权利要求11或12所述的装置,其特征在于,所述下载条件包括如下条件中的一项或多项:在应用下载工具启动时、在应用启动时和在接收到服务器的同步请求时。
  14. 根据权利要求13所述的装置,其特征在于,所述下载条件为在应用下载工具启动时,则所述下载条件对应应用包括预置应用;其中,所述预置应用包括:热门应用和用户配置应用中的至少一种。
PCT/CN2016/085213 2015-06-16 2016-06-08 一种下载应用的方法和装置 Ceased WO2016202204A1 (zh)

Priority Applications (7)

Application Number Priority Date Filing Date Title
KR1020187000738A KR102147026B1 (ko) 2015-06-16 2016-06-08 애플리케이션 다운로드 방법 및 디바이스
EP16810945.2A EP3313041B1 (en) 2015-06-16 2016-06-08 Application download method and device
ES16810945T ES2811330T3 (es) 2015-06-16 2016-06-08 Procedimiento y dispositivo de descarga de aplicaciones
PL16810945T PL3313041T3 (pl) 2015-06-16 2016-06-08 Sposób i urządzenie do pobierania aplikacji
JP2017565768A JP6793667B2 (ja) 2015-06-16 2016-06-08 アプリケーションダウンロード方法及び装置
SG11201710305PA SG11201710305PA (en) 2015-06-16 2016-06-08 Application download method and device
US15/840,572 US10693845B2 (en) 2015-06-16 2017-12-13 Enhancing security of application downloads

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510334074.3 2015-06-16
CN201510334074.3A CN106257879B (zh) 2015-06-16 2015-06-16 一种下载应用的方法和装置

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/840,572 Continuation US10693845B2 (en) 2015-06-16 2017-12-13 Enhancing security of application downloads

Publications (1)

Publication Number Publication Date
WO2016202204A1 true WO2016202204A1 (zh) 2016-12-22

Family

ID=57544872

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/085213 Ceased WO2016202204A1 (zh) 2015-06-16 2016-06-08 一种下载应用的方法和装置

Country Status (9)

Country Link
US (1) US10693845B2 (zh)
EP (1) EP3313041B1 (zh)
JP (1) JP6793667B2 (zh)
KR (1) KR102147026B1 (zh)
CN (1) CN106257879B (zh)
ES (1) ES2811330T3 (zh)
PL (1) PL3313041T3 (zh)
SG (1) SG11201710305PA (zh)
WO (1) WO2016202204A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112217880A (zh) * 2020-09-24 2021-01-12 北京火山引擎科技有限公司 应用程序激活的归因方法、装置、介质和电子设备

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109040191B (zh) * 2018-07-03 2021-11-09 平安科技(深圳)有限公司 文件下载方法、装置、计算机设备和存储介质
CN109120594B (zh) * 2018-07-13 2021-08-13 北京三快在线科技有限公司 流量劫持检测方法及装置
CN111343217B (zh) * 2018-12-18 2023-04-07 阿里巴巴集团控股有限公司 资源数据下载方法、装置、终端设备及计算机存储介质
CN112822241B (zh) * 2020-12-31 2022-08-26 北京安博通科技股份有限公司 基于https协议的app动态缓存实现方法及装置
CN114007276B (zh) * 2021-10-27 2024-11-29 杭州萤石软件有限公司 ZigBee网络的入网处理方法、装置、设备及系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6785719B1 (en) * 2002-08-06 2004-08-31 Digi International Inc. Distributed systems for providing secured HTTP communications over the network
CN103440281A (zh) * 2013-08-13 2013-12-11 北京卓易讯畅科技有限公司 一种用于获取下载文件的方法、装置与设备
CN103561040A (zh) * 2013-11-15 2014-02-05 中国科学院声学研究所 一种文件下载方法及系统
CN103841272A (zh) * 2014-03-25 2014-06-04 浙江翼信科技有限公司 一种发送语音消息的方法及装置

Family Cites Families (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3692290B2 (ja) * 2000-11-24 2005-09-07 株式会社エヌ・ティ・ティ・ドコモ データ取得方法および端末
JP2004102826A (ja) * 2002-09-11 2004-04-02 Ntt Data Corp コンテンツデータ処理方法、携帯電話端末およびサーバ装置
US7181572B2 (en) * 2002-12-02 2007-02-20 Silverbrook Research Pty Ltd Cache updating method and apparatus
JP4597551B2 (ja) * 2003-03-28 2010-12-15 株式会社リコー ソフトウェア更新装置、ソフトウェア更新システム、ソフトウェア更新方法及びプログラム
CN1853428A (zh) * 2003-09-19 2006-10-25 皮科特有限公司 用于自动更新无线网络的系统的装置和方法
JP2007018365A (ja) * 2005-07-08 2007-01-25 Matsushita Electric Ind Co Ltd 宣言型言語で記述された再生制御環境の起動条件を考慮した情報記録媒体およびその再生装置、再生方法。
KR101180199B1 (ko) * 2008-11-18 2012-09-05 한국전자통신연구원 다운로더블 제한수신시스템, 상기 다운로더블 제한수신시스템에서 단말과 인증 서버 간의 양방향 통신을 위한 채널 설정 방법 및 메시지 구조
US9083791B2 (en) * 2009-01-22 2015-07-14 Yahoo ! Inc. Web-hosted framework for mobile applications
CN101610290A (zh) * 2009-07-22 2009-12-23 深圳市茁壮网络股份有限公司 下载管理的方法和下载管理单元及下载系统
JP2011141867A (ja) * 2009-12-10 2011-07-21 Sharp Corp データ表示装置およびサーバ装置
US20110179268A1 (en) * 2010-01-20 2011-07-21 Microsoft Corporation Protecting applications with key and usage policy
CN101951402B (zh) * 2010-09-17 2013-02-20 山东中创软件工程股份有限公司 一种Web Service可用性跟踪检测方法、装置及系统
US8983076B2 (en) * 2011-12-22 2015-03-17 Adobe Systems Incorporated Methods and apparatus for key delivery in HTTP live streaming
US9443012B2 (en) * 2012-01-31 2016-09-13 Ncr Corporation Method of determining http process information
CN103020180A (zh) * 2012-11-28 2013-04-03 北京奇虎科技有限公司 一种基于控制节点部署程序的方法和装置

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6785719B1 (en) * 2002-08-06 2004-08-31 Digi International Inc. Distributed systems for providing secured HTTP communications over the network
CN103440281A (zh) * 2013-08-13 2013-12-11 北京卓易讯畅科技有限公司 一种用于获取下载文件的方法、装置与设备
CN103561040A (zh) * 2013-11-15 2014-02-05 中国科学院声学研究所 一种文件下载方法及系统
CN103841272A (zh) * 2014-03-25 2014-06-04 浙江翼信科技有限公司 一种发送语音消息的方法及装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112217880A (zh) * 2020-09-24 2021-01-12 北京火山引擎科技有限公司 应用程序激活的归因方法、装置、介质和电子设备

Also Published As

Publication number Publication date
KR20180018673A (ko) 2018-02-21
EP3313041A4 (en) 2019-01-09
CN106257879A (zh) 2016-12-28
SG11201710305PA (en) 2018-01-30
PL3313041T3 (pl) 2020-11-16
US10693845B2 (en) 2020-06-23
ES2811330T3 (es) 2021-03-11
EP3313041A1 (en) 2018-04-25
CN106257879B (zh) 2020-02-14
KR102147026B1 (ko) 2020-08-24
JP6793667B2 (ja) 2020-12-02
JP2018519596A (ja) 2018-07-19
US20180103016A1 (en) 2018-04-12
EP3313041B1 (en) 2020-08-05

Similar Documents

Publication Publication Date Title
CN109214168B (zh) 固件升级方法及装置
CN104756076B (zh) 配置文件更新器
WO2016202204A1 (zh) 一种下载应用的方法和装置
EP3044936B1 (en) Method and apparatus of downloading and installing a client
US8931069B2 (en) Authentication with massively pre-generated one-time passwords
TWI679550B (zh) 帳號登入方法及裝置
WO2019019344A1 (zh) 网页数据爬取方法、装置、用户终端及可读存储介质
CN106716957A (zh) 高效且可靠的认证
KR20170133463A (ko) 피어 투 피어 증명
CN106709324A (zh) 用于验证应用安全性的方法和设备
WO2017071207A1 (zh) 一种应用安装方法、相关装置及应用安装系统
CN104219198B (zh) 一种WebApp的防篡改方法
CN104011730A (zh) 外部代码安全机制
US20160330030A1 (en) User Terminal For Detecting Forgery Of Application Program Based On Hash Value And Method Of Detecting Forgery Of Application Program Using The Same
CN107888656A (zh) 服务端接口的调用方法和调用装置
CN106709281A (zh) 补丁发放和获取方法、装置
CN108564363A (zh) 一种交易处理方法、服务器、客户端及系统
US12267441B2 (en) System and method for securing operation of data processing systems during and after onboarding
US12488126B2 (en) Methods for dynamic platform security configuration
CN110705985A (zh) 用于存储信息的方法和装置
JP2017187963A (ja) 電子機器およびシステム
CN106156625A (zh) 一种插件签名的方法及电子设备
HK1231273B (zh) 一种下载应用的方法和装置
US20250330317A1 (en) Device onboarding in distributed systems using meta payloads
CN110019010B (zh) 处理方法、装置、设备和机器可读介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16810945

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 11201710305P

Country of ref document: SG

ENP Entry into the national phase

Ref document number: 2017565768

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 20187000738

Country of ref document: KR

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 2016810945

Country of ref document: EP