WO2015135366A1 - 应用防卸载方法及设备 - Google Patents

应用防卸载方法及设备 Download PDF

Info

Publication number
WO2015135366A1
WO2015135366A1 PCT/CN2014/095391 CN2014095391W WO2015135366A1 WO 2015135366 A1 WO2015135366 A1 WO 2015135366A1 CN 2014095391 W CN2014095391 W CN 2014095391W WO 2015135366 A1 WO2015135366 A1 WO 2015135366A1
Authority
WO
WIPO (PCT)
Prior art keywords
application
verification code
device manager
deactivate
manager
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2014/095391
Other languages
English (en)
French (fr)
Inventor
镡云宇
范国峰
黄铮
闫学松
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Original Assignee
Beijing Qihoo Technology Co Ltd
Qizhi Software Beijing Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CN201410086128.4A external-priority patent/CN103824016A/zh
Application filed by Beijing Qihoo Technology Co Ltd, Qizhi Software Beijing Co Ltd filed Critical Beijing Qihoo Technology Co Ltd
Publication of WO2015135366A1 publication Critical patent/WO2015135366A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/51Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/50Service provisioning or reconfiguring
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/61Installation
    • G06F8/62Uninstallation
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/445Program loading or initiating
    • G06F9/44594Unloading
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04MTELEPHONIC COMMUNICATION
    • H04M1/00Substation equipment, e.g. for use by subscribers
    • H04M1/72Mobile telephones; Cordless telephones, i.e. devices for establishing wireless links to base stations without route selection
    • H04M1/724User interfaces specially adapted for cordless or mobile telephones
    • H04M1/72403User interfaces specially adapted for cordless or mobile telephones with means for local support of applications that increase the functionality

Definitions

  • the present invention relates to the field of Internet applications, and in particular, to an application anti-unloading method and device.
  • the present invention has been made in order to provide an application anti-unloading method and a corresponding application anti-unloading device that overcome the above problems or at least partially solve the above problems.
  • an application anti-offloading method comprising: activating a device manager for a current application, and setting a first verification code required to deactivate a device manager of the application; receiving a deactivation When the request of the device manager of the application is requested, the verification code input box is output; the input second verification code is received in the verification code input box, and the first verification code and the second verification code are matched, and determined according to the matching result. Whether to deactivate the device manager of the application; after deactivating the device manager of the application, the application is allowed to be uninstalled in response to an uninstall request for the application.
  • determining, according to the matching result, whether to allow the device manager of the application to be deactivated comprising: when the first verification code and the second verification code match, allowing the device manager of the application to be deactivated; When the first verification code and the second verification code do not match, the device manager of the application is deactivated.
  • the application is triggered to deactivate the device manager of the application.
  • the method further includes: locking the current screen, and rejecting operations other than the verification code input.
  • the operations other than the verification code input include: deactivating an operation of the device manager of the application; managing a deletion operation of the specified application by the software; and a system command to delete the specified application.
  • the system command is an Android debug bridge adb command.
  • an application anti-offloading device comprising: a verification code configurator configured to activate a device manager for a current application, and set a device manager required to deactivate the application a first verification code; the receiver configured to trigger an output when receiving a request to deactivate the device manager of the application; the output configured to output a verification code input box; the receiver is further configured Receiving an input second verification code in the verification code input box; the processor is configured to match the first verification code and the second verification code, and determine whether to allow deactivation of device management of the application according to the matching result
  • An unloader configured to allow the application to be uninstalled in response to an uninstall request for the application after deactivating the device manager of the application.
  • the processor is further configured to: when the first verification code and the second verification code match, allow to deactivate the device manager of the application; when the first verification code and the When the second verification code does not match, the device manager of the application is denied to be deactivated.
  • the processor is further configured to: when the first verification code matches the second verification code, trigger the application to deactivate the device manager of the application.
  • the application anti-unloading device further includes: a lock screen configured to lock the current screen when the output device outputs the verification code input box, and reject other operations than the verification code input.
  • the operations other than the verification code input include: deactivating an operation of the device manager of the application; managing a deletion operation of the specified application by the software; and a system command to delete the specified application.
  • the system command is an Android debug bridge adb command.
  • a computer program comprising computer readable code that, when executed on a computing device, causes the computing device to perform the application anti-offloading method described above.
  • a computer readable medium storing a computer program as described above is provided.
  • the device manager is activated for the current application, and the first verification code required for deactivating the device manager of the application is set, and when the request for deactivating the device manager of the application is received, the output verification is performed.
  • the code input box receives the input second verification code, matches the first verification code and the second verification code, and further determines whether to deactivate the device manager of the application according to the matching result. After deactivating the device manager, the application is allowed to be unloaded in response to an uninstall request for the application.
  • the device manager that deactivates the application needs to be verified before the application is uninstalled, and after the device manager of the application is deactivated, the application is uninstalled, which solves the problem that the application can pass the prior art.
  • the problem that the connection software between some devices is uninstalled and the system log input is not timely causes the application to be maliciously uninstalled, which reduces the chance of the application being maliciously uninstalled, improves the security of the application, and ensures the security of the user device.
  • the embodiment of the present invention enhances system compatibility, and is applicable not only to a higher version system but also to a lower version system, ensuring that more low version systems can also prevent the application from being maliciously uninstalled and improve the security of the user equipment.
  • FIG. 1 shows a process flow diagram of an application anti-offloading method in accordance with one embodiment of the present invention
  • FIG. 2 shows an interface diagram for opening an application anti-uninstall function according to an embodiment of the present invention
  • FIG. 3A shows an interface diagram of a boot device manager in accordance with one embodiment of the present invention
  • FIG. 3B illustrates an interface diagram of setting a graphical password in accordance with one embodiment of the present invention
  • FIG. 4 is a block diagram showing how to turn off the anti-unload function according to an embodiment of the present invention.
  • FIG. 5 illustrates an interface diagram for viewing application information in accordance with one embodiment of the present invention
  • FIG. 6 shows an interface diagram of applying anti-offloading according to an embodiment of the present invention
  • FIG. 7 shows an interface diagram of a cancel device manager according to an embodiment of the present invention
  • FIG. 8 shows an interface diagram of requesting input of a password according to an embodiment of the present invention
  • FIG. 9 is a flowchart showing a process of a background operation of applying an anti-offload method according to a preferred embodiment of the present invention.
  • FIG. 10 is a schematic structural diagram of an application anti-unloading device according to an embodiment of the present invention.
  • Figure 11 is a schematic block diagram of a computing device for performing an application anti-offloading method in accordance with the present invention.
  • Fig. 12 schematically shows a storage unit for holding or carrying program code implementing the application anti-unloading method according to the present invention.
  • the downloaded application is easily uninstalled, and the anti-offload application can be easily uninstalled through the connection application between some devices, and the system log input is used to prevent the application from being uninstalled due to system log output. Inaccurate, it is easy to cause the problem of intercepting malicious uninstallation is not timely.
  • the anti-offload function of the application can only be applied to a system with a higher version. The lower version system does not have this function, and therefore the application cannot be easily uninstalled.
  • FIG. 1 shows a process flow diagram of an application anti-offloading method in accordance with one embodiment of the present invention. As shown in Figure 1, the process includes at least steps S102 to step S108.
  • Step S102 Activate the device manager for the current application, and set a first verification code required to deactivate the device manager of the application.
  • Step S104 When receiving the request to deactivate the device manager of the application, output a verification code input box.
  • Step S106 Receive the input second verification code in the verification code input box, match the first verification code and the second verification code, and determine whether to allow the device manager of the application to be deactivated according to the matching result.
  • Step S108 after deactivating the device manager of the application, allowing the application to be uninstalled in response to the uninstall request for the application.
  • the device manager is activated for the current application, and the first verification code required for deactivating the device manager of the application is set, and when the request for deactivating the device manager of the application is received, the output verification is performed.
  • the code input box receives the input second verification code, matches the first verification code and the second verification code, and further determines whether to deactivate the device manager of the application according to the matching result. After deactivating the device manager, the application is allowed to be unloaded in response to an uninstall request for the application.
  • the device manager that deactivates the application needs to be verified before the application is uninstalled, and after the device manager of the application is deactivated, the application is uninstalled, which solves the problem that the application can pass the prior art.
  • the problem that the connection software between some devices is uninstalled and the system log input is not timely causes the application to be maliciously uninstalled, which reduces the chance of the application being maliciously uninstalled, improves the security of the application, and ensures the security of the user device.
  • the embodiment of the present invention enhances system compatibility, and is applicable not only to a higher version system but also to a lower version system, ensuring that more low version systems can also prevent the application from being maliciously uninstalled and improve the security of the user equipment.
  • the application anti-offloading method of the embodiment of the present invention starts at step S102, activates the device manager for the current application, and sets a first verification code required for deactivating the device manager of the application.
  • a request for the application activation device manager is sent from the application to the system, and the related operation is requested to be performed by the device manager, for example, requesting monitoring the number of screen unlocks, requesting a lock screen, and requesting a setting rule for the verification code.
  • the setting and other related operations to prevent the illegal operation of the device from causing the device to be maliciously uninstalled, and the like, are not limited in this embodiment of the present invention.
  • the requesting device manager monitors the number of screen unlockings.
  • the device can be locked or deleted.
  • the criminals use other means to unlock the device and obtain information such as data in the device, which poses a threat to the user's property security.
  • the rule of the verification code can be set. For example, set the verification code to a combination of numbers and letters and specify the number of digits and letters in the verification code (if the verification code includes 3 digits and 3 letters, such as 367xyz). For another example, set the verification code to a combination of numbers and uppercase letters and specify the number of numbers and uppercase letters respectively. For example, if the number in the verification code is 2, the uppercase letter is 5 (such as 23WERTY).
  • the number and combination of the verification codes set in the above examples are only examples.
  • the verification code set in the actual application may be a combination of any characters, and may be any number, which is not limited by the embodiment of the present invention.
  • the verification code required to deactivate the device manager of the application can be set by default by the system, for example, the password used by the user for the application, etc., for example, the application is a mobile guard, where the user is Mobile guard has been set
  • the system hereby sets the first verification code of the device manager of the deactivated mobile guard application to be consistent with the anti-theft password of the mobile guard.
  • embodiments of the present invention are capable of transmitting a request to the system to activate the device manager for the application, requesting that the related operations be performed by the device manager.
  • the code to send the request you need to declare the required "receiver" in the AndroidManifest.xml of the project.
  • the code example is as follows:
  • the "@xml/device_admin_sample” in the code example mentioned above can indicate the permission details requested by the application when it activates the device manager.
  • Intent intent new Intent(DevicePolicyManager.ACTION_ADD_DEVICE_ADMIN);
  • an interface pops up for the user to confirm activation of the device manager for the application. After the user manually confirms, the system responds to the request and activates the device manager for the application.
  • the first verification code configured for the device manager used for uninstalling the application is used.
  • the first verification code may be fixed or may be updated periodically or irregularly.
  • the first verification code is periodically updated.
  • the first verification code is non-fixed, and the old first verification code is prevented from being stolen because the first verification code is not updated in time, which further causes the application to be maliciously uninstalled.
  • the mobile phone anti-theft function when used in the mobile guard, if the mobile phone is stolen, the thief uses the verification code that is not updated in time to maliciously uninstall the mobile guard, which causes the owner to fail to mark the stolen mobile phone in time, resulting in property loss.
  • the deactivated device manager can receive the notification from the system, notify the application, and the current user is trying to deactivate the device management. Operation of the device.
  • step S104 is performed to output a verification code input box. It is guaranteed that the verification code input box is popped up before the user completes the operation of deactivating the device manager, and the deactivation operation is blocked until it is determined that the first verification code matches the second verification code.
  • the embodiment of the present invention may also lock the current screen when outputting the verification code input box, and reject other operations than the verification code input, so as to ensure that if the current input verification code cannot input and match the first verification code, The second verification code cannot be used to deactivate the device manager using any other operation, and the application cannot be maliciously deleted or uninstalled.
  • the other operations that it rejects may be the operation of deactivating the device manager of the application, which may be the deletion operation of the specified application by the management software, or may be a system command, such as an Android debugging bridge (The Android Debug Bridge (hereinafter referred to as the adb command) performs the deletion operation on the specified application, and ensures that the embodiment of the present invention can only deactivate the device manager by inputting the matching verification code, thereby uninstalling the current application to prevent other malicious operations from being caused.
  • the app is uninstalled.
  • the screen of the device can be locked in a plurality of manners, which is not limited by the embodiment of the present invention.
  • step S106 is executed, the input second verification code is received in the verification code input box, the first verification code and the second verification code are matched, and whether the device manager of the deactivated application is run is determined according to the matching result. Specifically, when the first verification code and the second verification code do not match, the device manager of the application is deactivated, and the deactivation failure is displayed, prompting to re-enter the second verification code. Preferably, when the second verification code input error reaches a predetermined number of times (eg, 5 times), an anti-theft alarm or other processing may be initiated.
  • a predetermined number of times eg, 5 times
  • the embodiment of the present invention may display an interface asking the user whether to cancel the activation of the device manager, and prompting the user to deactivate the device manager may cause the application to be maliciously uninstalled.
  • the device automatically deactivates the device manager in the background. That is, in the embodiment of the present invention, after the application successfully activates the device manager, any application other than the application itself cannot deactivate the device manager.
  • the device manager may be deactivated directly in the background by the application without further inquiry and prompting.
  • step S106 if the first verification code matches the second verification code, the device manager of the application can be successfully deactivated.
  • step S108 is performed to allow the application to be uninstalled in response to the uninstall request for the application.
  • a matching result is obtained to determine whether to deactivate the device manager of the application, and further determining whether to respond to the uninstall request for the application.
  • the application is uninstalled to ensure that the application cannot be maliciously uninstalled through connection software between devices such as mobile assistants and pea pods.
  • the application anti-offloading method provided by the embodiment of the present invention can prevent some illegal elements who master Android technology from using the adb command to maliciously uninstall the application, improve the security of the application, and thereby ensure the security of the user equipment and the data in the device. user experience.
  • FIG. 2 to FIG. 8 are diagrams showing an interface of a process for applying an anti-unloading method according to a preferred embodiment of the present invention, which is used to support any of the above-mentioned application anti-unloading methods, and to explain the above-mentioned application anti-unloading method more clearly and easily.
  • FIG. 2 illustrates an interface diagram for opening an application anti-unload function according to an embodiment of the present invention.
  • 3A shows an interface diagram of a boot device manager in accordance with one embodiment of the present invention.
  • FIG. 3B illustrates an interface diagram for setting a graphical password in accordance with one embodiment of the present invention.
  • 4 shows an interface diagram of how to turn off the anti-unload function in accordance with one embodiment of the present invention.
  • FIG. 1 illustrates an interface diagram for opening an application anti-unload function according to an embodiment of the present invention.
  • 3A shows an interface diagram of a boot device manager in accordance with one embodiment of the present invention.
  • FIG. 3B illustrates an
  • FIG. 5 shows an interface diagram for viewing application information in accordance with one embodiment of the present invention.
  • Figure 6 shows an interface diagram for applying anti-offloading in accordance with one embodiment of the present invention.
  • FIG. 7 shows an interface diagram of a cancel device manager in accordance with one embodiment of the present invention.
  • Figure 8 shows an interface diagram requesting the input of a password in accordance with one embodiment of the present invention.
  • the mobile guard in the mobile phone prompts the user. If the anti-uninstall function of the mobile guard is activated, the mobile guard must be unprotected before the mobile guard is uninstalled, so that the security of the mobile phone is improved. Ask the user if the anti-uninstall feature is turned on immediately. After the user confirms that the protection function is enabled, the mobile phone pops up the interface diagram of the device manager as shown in FIG. 3A, and prompts the user to enable the anti-uninstall function, and needs to activate the device manager, and allows the mobile guard to perform "set password rules" and "monitor". The number of screen unlock attempts and the operation of "lock screen", and at the same time, ask the user whether to activate the device manager.
  • the password rules can be set (ie, the first verification code is set).
  • the password may be a character password (such as a number or a letter).
  • the password rule is a combination of numbers and letters and specifies the number of digits and letters in the password (for example, the password includes three digits and 3 letters, such as 367xyz).
  • the password rule is set to a combination of numbers and uppercase letters and specifies the number of numbers and uppercase letters respectively.
  • the number in the setting password is 2, and the uppercase letter is 5 (such as 23WERTY).
  • the number and combination of the passwords set in the above examples are only examples, and the passwords set in the actual application may be any combination of characters, and may be any number, which is not limited by the embodiment of the present invention.
  • the password rule may also be set as a graphic password.
  • FIG. 3B an interface diagram of a commonly used graphic password is displayed on the device screen to display three touchable points of 3 times 3, and the user can Preferences such as setting a personality graphic as a password on nine touchable points.
  • FIG. 3B shows that an "L" shaped pattern is set as a graphic password.
  • the setting of the password rule in the embodiment of the present invention may also be any other password setting method, such as a fingerprint password, which is not limited by the embodiment of the present invention.
  • the password rule required to deactivate the device manager of the application may be set by the system by default, for example, the password used by the user for the application, etc., for example, the application is a mobile guard, where the user is In the case that the anti-theft password has been set in the mobile guard, the system hereby sets the first verification code of the device manager of the deactivated mobile guard application to be consistent with the anti-theft password of the mobile guard.
  • the mobile phone pops up an interface diagram as shown in FIG. 4, prompting the user to prevent the uninstall function from being successfully opened, and prompting the user to first uninstall the anti-uninstall function when uninstalling the mobile guard, or to the system settings. Find related options to deactivate device manager.
  • the mobile phone has an anti-theft password, turning off the anti-uninstall function requires verification of the anti-theft password.
  • the information about the mobile guard in the device manager is shown in Figure 5.
  • the version of the mobile guard and the other information of the mobile guard are displayed in the mobile phone, such as the total storage capacity of the mobile guard, the storage data of the mobile guard, and the storage space occupied by the mobile guard in the mobile storage, and the like, and as shown in FIG. 5 It can be said that the mobile phone cannot directly stop and uninstall the mobile guard directly in the application information, that is, the mobile phone cannot directly uninstall the mobile guard.
  • the forced stop and uninstall two operation indicators are gray (the gray display effect is not shown in Figure 5), indicating that it is inoperable, even if the storage space or capacity is available, the user clicks on both, and will not enter the subsequent operation. Process.
  • the mobile phone inputs the Android debug bridge command adb, the mobile phone will pop up an interface prompting the application to prevent the uninstallation failure, that is, the preferred embodiment can prevent the criminals who are familiar with the Android technology from maliciously uninstalling the mobile guard by the system command.
  • the mobile phone guard When the mobile phone receives a request to uninstall, for example, the mobile guardian application, the mobile phone guard cannot be uninstalled, and the device manager needs to be managed.
  • a request to uninstall for example, the mobile guardian application
  • the mobile phone guard cannot be uninstalled, and the device manager needs to be managed.
  • an interface diagram as shown in FIG. 6 is popped up, prompting the user that the mobile guard anti-offload function has been turned on, and if the anti-offload function is turned off, the anti-theft password needs to be verified.
  • the mobile phone pops up an interface diagram as shown in FIG.
  • the mobile phone pops up the verification code input interface as shown in FIG. 8, and determines whether to deactivate the device manager according to whether the received verification code matches the first verification code configured by the application.
  • the verification code received by the mobile phone ie, the second verification code
  • an interface is displayed to ask the user whether to cancel the activation of the device manager, when the user confirms that the device manager is to be deactivated. , cancel the activation of the device manager.
  • the display fails to be unlocked, so that the user re-enters the verification code.
  • the monitoring screen attempts to unlock the number of times, and when the number of input errors reaches a predetermined number of times, the process of locking the mobile phone, clearing the mobile phone data, and starting the burglar alarm is performed to ensure the security of the user information.
  • FIG. 9 shows a process flow diagram of a background operation of applying an anti-offload method in accordance with a preferred embodiment of the present invention.
  • the preferred embodiment includes at least steps S902 to S912.
  • Step S902 setting a broadcast receiver.
  • the anti-uninstallation purpose is achieved by activating the device manager, and the application is uninstalled by deactivating the device manager. Therefore, in this example, a BroadcastReceiver that listens for changes to the device manager is declared in the AndroidManifest.xml of the application (the manifest file in the Android project). BroadcastReceiver is a broadcast receiver. That is, when a person broadcasts a plurality of parties to the same message by broadcasting, the BroadcastReceiver can receive the information of the broadcast.
  • DeviceAdminReceiver is a system-specific custom broadcast receiver that inherits the BroadcastReceiver feature.
  • the DeviceAdminReceiver can receive information that the normal broadcast receiver cannot receive, such as whether the user's mobile phone password input is correct and the user's password modification.
  • an XDeviceAdminReceiver that inherits the DeviceAdminReceiver feature is obtained. That is, the user can generate a customized subtype by inheriting DeviceAdminReceiver to achieve the desired customization function.
  • the code example is as follows:
  • Step S904 acquiring a management object.
  • Step S906 determining whether the user chooses to activate the device manager.
  • the device manager is a receiver for system specific information.
  • the device manager in this example is the XDeviceAdminReceiver mentioned above.
  • the user in the Android system calls the relevant function to send a subclass of the specified DeviceAdminReceiver (that is, the receiver that broadcasts the special information) to the system, and the system receives the relevant information of the subclass of DeviceAdminReceiver, it is considered that there is a receiving of the special message of the monitoring system.
  • the system defaults to the receiver as a device manager.
  • the system displays the device manager to the device manager The page, and describes what kind of special information the device manager receives (such as the device manager to monitor whether the user's mobile phone password input is correct, whether the unlocking is successful or not).
  • the device manager dependent application cannot be uninstalled directly until the device manager is closed.
  • an example of determining whether the user selects to activate the specified device manager is as follows:
  • the XDeviceAdminReceiver is the specified device manager, that is, the BroadcastReceiver registered in the AndroidManifest.xml in step S902.
  • Step S908 According to the determination result of step S906, if the user selects that the device manager is not currently activated, the user is prompted to activate the device manager, and by activating the device manager, the purpose of preventing malicious uninstallation can be achieved.
  • Step S910 According to the determination result of step S906, if the user chooses to activate the device manager, the background device performs at least the following steps A to F to activate the specified device manager:
  • Intent intent new Intent(DevicePolicyManager.ACTION_ADD_DEVICE_ADMIN)
  • Step B Add the Intent declared in Step A to the broadcast receiver specified above:
  • the meaning of the specified device manager refers to what event the specified device manager listens on in the system.
  • the code example is as follows:
  • ResolveInfo resolveInfo context.getPackageManager().resolveActivity(intent, PackageManager.MATCH_DEFAULT_ONLY)
  • resolveInfo When the system supports the device manager, it can be determined that resolveInfo will not be null, and thus can call the device manager for activation.
  • the code example is as follows:
  • step E After it is determined in step E that the device manager can be called to activate, the system pops up a page activated by the device manager, prompting the user to activate the device manager. When the user clicks Activate, the device manager is activated successfully.
  • Step S912 After the device manager is successfully activated, when the user needs to uninstall the application, the device manager needs to be deactivated.
  • the code example is as follows:
  • the manager is the management object of the acquired device manager.
  • FIG. 10 is a block diagram showing the construction of an anti-unloading device according to an embodiment of the present invention.
  • the application anti-offloading device of the embodiment of the present invention includes at least a verification code configurator 1010, a receiver 1020, an outputter 1030, a processor 1040, and an unloader 1050.
  • the captcha configurator 1010 is configured to activate the device manager for the current application and set a first verification code required to deactivate the device manager of the application.
  • the receiver 1020 is configured to trigger the outputter 1030 upon receiving a request to deactivate the device manager of the application, and receive the input second verification code in the verification code input box.
  • the outputter 1030 coupled to the receiver 1020, is configured to output a verification code input box.
  • the processor 1040 is respectively coupled to the verification code configurator 1010 and the receiver 1020, configured to match the first verification code and the second verification code, and determine whether to allow the device manager of the application to be deactivated according to the matching result.
  • the unloader 1050 coupled to the processor 1040, is configured to allow the application to be unloaded in response to an offload request for the application after deactivating the device manager of the application.
  • the device manager is activated for the current application, and the first verification code required for deactivating the device manager of the application is set, and when the request of the device manager for deactivating the application is received, the verification code is output.
  • the input box receives the input second verification code, matches the first verification code and the second verification code, and further determines whether to deactivate the device manager of the application according to the matching result. After deactivating the device manager, the application is allowed to be unloaded in response to an uninstall request for the application.
  • the device manager that deactivates the application needs to be verified before the application is uninstalled, and after the device manager of the application is deactivated, the application is uninstalled, which solves the problem that the application can pass the prior art.
  • the problem that the connection software between some devices is uninstalled and the system log input is not timely causes the application to be maliciously uninstalled, which reduces the chance of the application being maliciously uninstalled, improves the security of the application, and ensures the security of the user device.
  • the verification code configurator 1010 in the application anti-offload device shown in FIG. 10 activates the device manager for the current application and sets a first verification code required to deactivate the device manager of the application.
  • a request for the application activation device manager is sent from the application to the system, and the related operation is requested to be performed by the device manager, for example, requesting monitoring the number of screen unlocks, requesting a lock screen, and requesting a setting rule for the verification code.
  • the setting and other related operations to prevent the illegal operation of the device from causing the device to be maliciously uninstalled, and the like, are not limited in this embodiment of the present invention.
  • the number of times the monitoring screen is unlocked is requested. If the current screen is unlocked more than a certain number of times (for example, 3 times) and the unlocking is still successful, the device can be locked or the data in the device can be deleted to avoid illegality.
  • the numerator unlocks the device by other means to obtain information such as data in the device, which poses a threat to the user's property security.
  • embodiments of the present invention are capable of transmitting a request to the system to activate the device manager for the application, requesting that the related operations be performed by the device manager.
  • the code that sends the request needs to be in the project AndroidManifest.xml first declares the required "receiver", the code example is as follows:
  • the "@xml/device_admin_sample” in the code example mentioned above can indicate the permission details requested by the application when it activates the device manager.
  • Intent intent new Intent(DevicePolicyManager.ACTION_ADD_DEVICE_ADMIN);
  • an interface pops up for the user to confirm activation of the device manager for the application. After the user manually confirms, the system responds to the request and activates the device manager for the application.
  • the first verification code configured for the device manager used for uninstalling the application is used.
  • the first verification code can be fixed The same, it can also be updated regularly.
  • the first verification code is periodically updated.
  • the first verification code is non-fixed, and the old first verification code is prevented from being stolen because the first verification code is not updated in time, which further causes the application to be maliciously uninstalled.
  • the mobile phone anti-theft function when used in the mobile guard, if the mobile phone is stolen, the thief uses the verification code that is not updated in time to maliciously uninstall the mobile guard, which causes the owner to fail to mark the stolen mobile phone in time, resulting in property loss.
  • the deactivated device manager itself can receive the notification from the system and notify by the notification. Know that the current user is trying to deactivate the device manager.
  • the application captures the above notification, the receiver 1020 triggers the outputter 1030, and the outputter 1030 outputs a verification code input box. It is guaranteed that the verification code input box is popped up before the user completes the operation of deactivating the device manager, and the deactivation operation is blocked until it is determined that the first verification code matches the second verification code.
  • the lock screen 1060 may lock the current screen when the output unit 1030 outputs the verification code input box, and reject other operations than the verification code input.
  • other operations that it rejects may be the operation of deactivating the device manager of the application, which may be a deletion operation of the management application for the specified application, or a system command, such as an Android adb command pair.
  • the deletion operation of the application is specified to ensure that the current application can be uninstalled only by inputting the matching verification code to prevent the application from being uninstalled by other malicious operations.
  • the lock screen device 1060 can lock the screen of the device in various manners, which is not limited by the embodiment of the present invention.
  • the lock screen device 1060 directly locks the screen, prompting that a verification code is required to unlock the device, and the lock screen device 1060 can also set the current screen display to unlock the device without inputting a verification code, but the screen is performed in the background. Locking, reducing the vigilance of criminals, and more effectively ensuring the safety of applications in equipment.
  • the first verification code configured by the verification code configurator 1010 by the processor 1040 matches the second verification code received by the receiver 1020. If the first verification code does not match the second verification code by the matching operation of the processor 1040, the processor 1040 refuses to deactivate the device manager of the application to prevent the application from being maliciously uninstalled. Preferably, after the processor 1040 refuses to deactivate the device manager of the application, the embodiment of the present invention may also display a deactivation failure, prompting to re-enter the second verification code for matching.
  • the embodiment of the present invention can initiate an anti-theft alarm or other processing to prevent the application from being maliciously uninstalled.
  • the processor 1040 allows the device manager of the application to be deactivated.
  • an interface may be displayed to ask the user whether to cancel the activation of the device manager, and prompting the user to deactivate the device manager may cause the application to be maliciously uninstalled.
  • the processor 1040 triggers the application.
  • the app deactivates the device manager itself in the background. That is, in the embodiment of the present invention, after the application successfully activates the device manager, any application other than the application itself cannot deactivate the device manager. In addition, in the embodiment of the present invention, after the first verification code is matched with the second verification code, the device manager may be deactivated directly in the background by the application without further inquiry and prompting.
  • the device manager of the application is allowed to be deactivated.
  • the unloader 1050 coupled to the processor 1040 allows for corresponding The application is uninstalled for the uninstall request of the app.
  • a matching result is obtained to determine whether to reject the device manager of the deactivated application, and further determining whether to respond to the uninstall request for the application.
  • the application is uninstalled to ensure that the application cannot be uninstalled maliciously through the connection software between the devices such as the mobile phone assistant and the pea pod.
  • the application anti-unloading method provided by the embodiment of the present invention can prevent some criminals who master the Android technology from using the adb.
  • the embodiment of the present invention can achieve the following beneficial effects:
  • the device manager is used to prevent malicious uninstallation of the application.
  • the embodiment of the present invention needs to cancel the activation of the device manager.
  • the embodiment of the present invention needs to perform matching between the input verification code and the verification code of the application configuration, and determines whether to cancel the activation of the device manager according to the matching result, thereby ensuring that the verification code is not known.
  • the numerator cannot maliciously uninstall the application, improve the security of the application, and further improve the security of the user equipment.
  • modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
  • the modules or units or components of the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
  • any combination of the features disclosed in the specification, including the accompanying claims, the abstract and the drawings, and any methods so disclosed, or All processes or units of the device are combined.
  • Each feature disclosed in this specification (including the accompanying claims, the abstract and the drawings) may be replaced by alternative features that provide the same, equivalent or similar purpose.
  • the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
  • a microprocessor or digital signal processor may be used in practice to implement some or all of the functionality of some or all of the components of the anti-offload device in accordance with embodiments of the present invention.
  • the invention can also be implemented as a device or device program (e.g., a computer program and a computer program product) for performing some or all of the methods described herein.
  • a program implementing the invention may be stored on a computer readable medium or may be in the form of one or more signals. Such signals may be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
  • Figure 11 illustrates a computing device that can implement an application anti-offloading method in accordance with the present invention.
  • the computing device conventionally includes a processor 1110 and a computer program product or computer readable medium in the form of a memory 1120.
  • the memory 1120 may be an electronic memory such as a flash memory, an EEPROM (Electrically Erasable Programmable Read Only Memory), an EPROM, a hard disk, or a ROM.
  • Memory 1120 has a memory space 1130 for program code 1131 for performing any of the method steps described above.
  • the storage space 1130 for program code may include respective program codes 1131 for implementing various steps in the above methods, respectively.
  • the program code can be read from or written to one or more computer program products.
  • Such computer program products include program code carriers such as hard disks, compact disks (CDs), memory cards or floppy disks.
  • Such a computer program product is typically a portable or fixed storage unit as described with reference to FIG.
  • the storage unit may have a storage segment, a storage space, and the like that are similarly arranged to the storage 1120 in the computing device of FIG.
  • the program code can be compressed, for example, in an appropriate form.
  • the storage unit includes computer readable code 1131 ', ie, code readable by a processor, such as, for example, 1110, which when executed by a computing device causes the computing device to perform each of the methods described above step.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Stored Programmes (AREA)

Abstract

一种应用防卸载方法及设备,其中,该应用防卸载方法包括:针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码;接收到取消激活所述应用的设备管理器的请求时,输出验证码输入框;在验证码输入框接收输入的第二验证码,匹配第一验证码和第二验证码,根据匹配结果确定是否允许取消激活应用的设备管理器;在取消激活应用的设备管理器之后,允许响应于针对应用的卸载请求对应用进行卸载。能够达到减少应用被恶意卸载的机会,提高应用安全性,从而保证用户设备的安全的有益效果。

Description

应用防卸载方法及设备 技术领域
本发明涉及互联网应用领域,特别是涉及一种应用防卸载方法及设备。
背景技术
随着信息社会的发展,移动设备在人们生活中的地位也日益重要,同时,移动设备的防盗问题也越来越受到人们的重视。由于移动设备自身防盗的局限性,很多用户选择下载安全软件保证移动设备以及移动设备内资料的安全性。例如,人们经常在手机中下载不同的手机安全应用,保证手机内存储的资料的安全或者在手机丢失之后,利用手机安全应用防止偷盗者进行刷机操作之后将手机二次出售。
现有技术中,人们下载的应用很容易被卸载。例如现有技术中有些手机中的安全软件采用监视系统日志输入的方式来达到防止被恶意卸载的目的,但这种做法很容易被破解,当手机与电脑连接之后,能够通过一些连接助手将应用卸载,另外,采用这种方式防止应用被恶意卸载的时候,很多系统日志输出不准确,容易错失拦截应用被恶意卸载的机会。同时,很多安全应用只在特定版本中提供防卸载功能。
发明内容
鉴于上述问题,提出了本发明以便提供一种克服上述问题或者至少部分地解决上述问题的应用防卸载方法和相应的应用防卸载设备。
依据本发明的一个方面,提供了一种应用防卸载方法,包括:针对当前应用激活设备管理器,并设置取消激活所述应用的设备管理器所需的第一验证码;接收到取消激活所述应用的设备管理器的请求时,输出验证码输入框;在所述验证码输入框接收输入的第二验证码,匹配所述第一验证码和所述第二验证码,根据匹配结果确定是否允许取消激活所述应用的设备管理器;在取消激活所述应用的设备管理器之后,允许响应于针对所述应用的卸载请求对所述应用进行卸载。
可选地,根据匹配结果确定是否允许取消激活所述应用的设备管理器,包括:当所述第一验证码和所述第二验证码匹配时,允许取消激活所述应用的设备管理器;当所述第一验证码和所述第二验证码不匹配时,拒绝取消激活所述应用的设备管理器。
可选地,当所述第一验证码与所述第二验证码匹配时,触发所述应用自行取消激活所述应用的设备管理器。
可选地,所述输出验证码输入框时,还包括:锁定当前屏幕,拒绝除验证码输入以外的其他操作。
可选地,所述除验证码输入以外的其他操作,包括:取消激活该应用的设备管理器的操作;管理软件对所述指定应用的删除操作;系统命令对所述指定应用的删除操作。
可选地,所述系统命令为安卓调试桥adb命令。
依据本发明实施例的另一个方面,还提供了一种应用防卸载设备,包括:验证码配置器,配置为针对当前应用激活设备管理器,并设置取消激活所述应用的设备管理器所需的第一验证码;接收器,配置为接收到取消激活所述应用的设备管理器的请求时,触发输出器;所述输出器,配置为输出验证码输入框;所述接收器,还配置为在所述验证码输入框接收输入的第二验证码;处理器,配置为匹配所述第一验证码和所述第二验证码,根据匹配结果确定是否允许取消激活所述应用的设备管理器;卸载器,配置为在取消激活所述应用的设备管理器之后,允许响应于针对所述应用的卸载请求对所述应用进行卸载。
可选地,所述处理器还配置为:当所述第一验证码和所述第二验证码匹配时,允许取消激活所述应用的设备管理器;当所述第一验证码和所述第二验证码不匹配时,拒绝取消激活所述应用的设备管理器。
可选地,所述处理器还配置为:当所述第一验证码与所述第二验证码匹配时,触发所述应用自行取消激活所述应用的设备管理器。
可选地,所述应用防卸载设备还包括:锁屏器,配置为所述输出器输出验证码输入框时,锁定当前屏幕,拒绝除验证码输入以外的其他操作。
可选地,所述除验证码输入以外的其他操作,包括:取消激活该应用的设备管理器的操作;管理软件对所述指定应用的删除操作;系统命令对所述指定应用的删除操作。
可选地,所述系统命令为安卓调试桥adb命令。
根据本发明的又一个方面,提供了一种计算机程序,其包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行上述的应用防卸载方法。
根据本发明的再一个方面,提供了一种计算机可读介质,其中存储了如上述的计算机程序。
本发明的有益效果为:
在本发明实施例中,针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码,在接收到取消激活所述应用的设备管理器的请求时,输出验证码输入框,接收输入的第二验证码,匹配第一验证码和第二验证码,进而根据匹配结果确定是否取消激活所述应用的设备管理器。当对设备管理器取消激活之后,允许响应于针对应用的卸载请求对应用进行卸载。由此可见,本发明实施例在卸载应用之前需要对取消激活应用的设备管理器进行验证,并在取消激活应用的设备管理器之后,对应用进行卸载,解决了现有技术中将应用能够通过一些设备间的连接软件被卸载以及监视系统日志输入不及时导致应用被恶意卸载的问题,达到了减少应用被恶意卸载的机会,提高应用安全性,从而保证用户设备的安全的有益效果。另外,本发明实施例增强了系统兼容性,不但适用于高版本的系统,也适用于低版本的系统,保证更多低版本的系统也能够防止应用被恶意卸载,提高用户设备的安全性。
上述说明仅是本发明技术方案的概述,为了能够更清楚了解本发明的技术手段,而 可依照说明书的内容予以实施,并且为了让本发明的上述和其它目的、特征和优点能够更明显易懂,以下特举本发明的具体实施方式。
附图说明
通过阅读下文优选实施方式的详细描述,各种其他的优点和益处对于本领域普通技术人员将变得清楚明了。附图仅用于示出优选实施方式的目的,而并不认为是对本发明的限制。而且在整个附图中,用相同的参考符号表示相同的部件。在附图中:
图1示出了根据本发明一个实施例的应用防卸载方法的处理流程图;
图2示出了根据本发明一个实施例的开启应用防卸载功能的界面图;
图3A示出了根据本发明一个实施例的启动设备管理器的界面图;
图3B示出了根据本发明一个实施例的设置图形密码的界面图;
图4示出了根据本发明一个实施例的如何关闭防卸载功能的界面图;
图5示出了根据本发明一个实施例的查看应用程序信息的界面图;
图6示出了根据本发明一个实施例的应用防卸载的界面图;
图7示出了根据本发明一个实施例的取消设备管理器的界面图;
图8示出了根据本发明一个实施例的请求输入密码的界面图;
图9示出了根据本发明一个优选实施例的应用防卸载方法的后台操作的处理流程图;以及
图10示出了根据本发明一个实施例的应用防卸载设备的结构示意图;
图11示意性地示出了用于执行根据本发明的应用防卸载方法的计算设备的框图;以及
图12示意性地示出了用于保持或者携带实现根据本发明的应用防卸载方法的程序代码的存储单元。
具体实施方式
下面将参照附图更详细地描述本公开的示例性实施例。虽然附图中显示了本公开的示例性实施例,然而应当理解,可以以各种形式实现本公开而不应被这里阐述的实施例所限制。相反,提供这些实施例是为了能够更透彻地理解本公开,并且能够将本公开的范围完整的传达给本领域的技术人员。
相关技术中提及,人们下载的应用很容易被卸载,防卸载应用通过一些设备间的连接应用软件能够被轻易卸载,采用监视系统日志输入的方式来防止应用被卸载的时候,由于系统日志输出不准确,容易导致拦截恶意卸载不及时的问题。另外,对于安卓系统或者其他操作系统而言,通常,应用的防卸载功能仅能适用于版本较高的系统,低版本系统不具备这一功能,因此也无法避免应用被轻易卸载。
为解决上述技术问题,本发明实施例提供了一种应用防卸载方法。图1示出了根据本发明一个实施例的应用防卸载方法的处理流程图。如图1所示,该流程至少包括步骤 S102至步骤S108。
步骤S102、针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码。
步骤S104、接收到取消激活所述应用的设备管理器的请求时,输出验证码输入框。
步骤S106、在验证码输入框接收输入的第二验证码,匹配第一验证码和第二验证码,根据匹配结果确定是否允许取消激活应用的设备管理器。
步骤S108、在取消激活应用的设备管理器之后,允许响应于针对应用的卸载请求对应用进行卸载。
在本发明实施例中,针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码,在接收到取消激活所述应用的设备管理器的请求时,输出验证码输入框,接收输入的第二验证码,匹配第一验证码和第二验证码,进而根据匹配结果确定是否取消激活所述应用的设备管理器。当对设备管理器取消激活之后,允许响应于针对应用的卸载请求对应用进行卸载。由此可见,本发明实施例在卸载应用之前需要对取消激活应用的设备管理器进行验证,并在取消激活应用的设备管理器之后,对应用进行卸载,解决了现有技术中将应用能够通过一些设备间的连接软件被卸载以及监视系统日志输入不及时导致应用被恶意卸载的问题,达到了减少应用被恶意卸载的机会,提高应用安全性,从而保证用户设备的安全的有益效果。另外,本发明实施例增强了系统兼容性,不但适用于高版本的系统,也适用于低版本的系统,保证更多低版本的系统也能够防止应用被恶意卸载,提高用户设备的安全性。
本发明实施例的应用防卸载方法起始于步骤S102,针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码。本发明实施例中,从该应用向系统发送针对本应用激活设备管理器的请求,请求通过设备管理器执行相关操作,例如,请求监控屏幕解锁次数,请求锁定屏幕、请求对验证码的设置规则进行设置以及其他避免不法分子对设备执行不当操作导致应用被恶意卸载的相关操作,等等,本发明实施例对此并不加以限定。例如,本发明实施例中,请求设备管理器监控屏幕解锁次数,若当前屏幕被解锁次数超过一定次数(例如3次),仍旧未能成功解锁,则能够锁定设备或者删除设备中的数据,避免不法分子通过其他途径将设备解锁后获取设备内的数据等信息,对用户的财产安全造成威胁。另外,本发明实施例中,能够设置验证码的规则。例如,设置验证码为数字与字母的组合并规定在验证码中数字以及字母的个数(如规定验证码中包括3个数字以及3个字母,如367xyz)。再例如,设置验证码为数字与大写字母的组合并规定数字与大写字母分别的个数,如设置验证码中数字为2个,大写字母为5个(如23WERTY)。
上述举例中设置的验证码的个数及组合仅为示例,实际应用中设置的验证码可以为任意字符的组合,并且可以为任意个数,本发明实施例对此并不加以限定。另外,取消激活该应用的设备管理器所需的验证码可以由系统来默认地设置,例如设置为用户对于该应用已设置的使用密码等,以该应用为手机卫士为例,在用户在该手机卫士中已设置 有防盗密码的情况下,此处系统默认地将该取消激活手机卫士应用的设备管理器的第一验证码设置为与该手机卫士的防盗密码一致。
上文提及,本发明实施例能够向系统发送针对本应用激活设备管理器的请求,请求通过设备管理器执行相关操作。其中,发送请求的代码中,需要在工程的AndroidManifest.xml里面先声明所需的“receiver”,代码示例如下:
<receiverandroid:name=".app.DeviceAdminSample$DeviceAdminSampleReceiver"
android:label="@string/sample_device_admin"
android:description="@string/sample_device_admin_description"
android:permission="android.permission.BIND_DEVICE_ADMIN">
<meta-data android:name="android.app.device_admin"
android:resource="@xml/device_admin_sample"/>
<intent-filter
<actionandroid:name="android.app.action.DEVICE_ADMIN_ENABLED"/>
</intent-filter>
</receiver>
上文提及的代码示例中的“@xml/device_admin_sample”能够指明应用申请激活设备管理器时所申请的权限明细。
具体地,一个申请全部设备管理器权限的代码示例如下:
<device-admin xmlns:android="http://schemas.android.com/apk/res/android">
<uses-policies>
<limit-password/>
<watch-login/>
<reset-password/>
<force-lock/>
<wipe-data/>
<expire-password/>
<encrypted-storage/>
<disable-camera/>
</uses-policies>
</device-admin>
另外,在Java代码中,代码示例如下:
Intent intent=new Intent(DevicePolicyManager.ACTION_ADD_DEVICE_ADMIN);
intent.putExtra(DevicePolicyManager.EXTRA_DEVICE_ADMIN,mDeviceAdminSampl e);
intent.putExtra(DevicePolicyManager.EXTRA_ADD_EXPLANATION,mActivity.getString(R.string.add_admin_extra_app_text));
startActivityForResult(intent,REQUEST_CODE_ENABLE_ADMIN)
需要说明的是,上文提及的代码仅为本发明实施例发送请求的部分代码示例,为将本发明实施例阐述得清楚简洁,对于本发明实施例发送请求的全部代码在此不作赘述。
在发送激活设备管理器的请求之后,弹出让用户确认针对该应用激活设备管理器的界面。当用户手动确认之后,系统对请求进行响应,激活针对该应用的设备管理器。
上文提及,本发明实施例中,激活设备管理器之后,为避免对设备管理器的恶意取消激活,为卸载应用所使用的设备管理器配置的第一验证码。该第一验证码可以是固定不变的,还可以是定期或不定期更新的。优选地,本发明实施例中,该第一验证码为定期更新的。本发明实施例中第一验证码为非固定的,防止因为第一验证码更新不及时导致旧的第一验证码被盗用,进一步导致应用程序被恶意卸载。例如,在手机卫士中使用手机防盗功能时,若手机被盗,偷窃者利用未及时更新的验证码将手机卫士恶意卸载,导致失主无法及时标记被盗手机,造成财产损失。
当接收到取消激活应用的设备管理器请求时,本发明实施例中,被取消激活的设备管理器针对的应用本身能够收到来自系统的通知,通知该应用,当前用户正在尝试取消激活设备管理器的操作。当该应用捕获到该通知,则执行步骤S104,输出验证码输入框。保证在用户完成取消激活设备管理器的操作之前弹出验证码输入框,阻止取消激活操作直至确定第一验证码与第二验证码匹配。为增加应用的安全性,本发明实施例还可以在输出验证码输入框时,锁定当前屏幕,并拒绝验证码输入以外的其他操作,保证若当前输入验证码者无法输入与第一验证码匹配的第二验证码,则无法使用其他任意操作对设备管理器进行取消激活,进而无法恶意删除或者卸载应用。当本发明实施例锁定当前屏幕时,其拒绝的其他操作可以是取消激活该应用的设备管理器的操作,可以是管理软件对指定应用的删除操作,也可以是系统命令,例如安卓调试桥(Android Debug Bridge,以下简称adb命令)对指定应用的删除操作,保证本发明实施例仅能通过输入匹配的验证码进行取消激活设备管理器的操作,进而对当前应用进行卸载,防止其他恶意操作导致的应用被卸载。本发明实施例中,可以通过多种方式对设备的屏幕进行锁定,本发明实施例对此并不加以限定。例如,直接对屏幕进行锁定,提示需要输入验证码对设备进行解锁,还可以设置当前屏幕显示无需输入验证码即可对设备进行解锁操作,但在后台对屏幕进行锁定,降低不法分子的警惕心,更加有效保证设备中应用的安全性。
验证码输入框输出之后,执行步骤S106,在验证码输入框接收输入的第二验证码,匹配第一验证码和第二验证码,并根据匹配结果确定是否运行取消激活应用的设备管理器。具体地,当第一验证码和第二验证码不匹配时,拒绝取消激活应用的设备管理器,并显示取消激活失败,提示重新输入第二验证码。优选地,当第二验证码输入错误达到预定次数(如5次)时,可以启动防盗警报或者其他处理。当第一验证码和第二验证码匹配时,本发明实施例可以显示询问用户是否取消对设备管理器的激活的界面,提示用户取消激活该设备管理器可能导致应用被恶意卸载。当用户确认取消激活该设备管理器时,由该应用在后台自行取消激活设备管理器。即,本发明实施例中,当应用成功激活设备管理器之后,除应用本身之外的其他任何应用均无法取消激活设备管理器。另外,本发明实施例中,当第一验证码与第二验证码匹配之后,还可以不做进一步询问与提示,由该应用直接在后台自行取消激活设备管理器。
根据步骤S106,若第一验证码与第二验证码匹配,能够成功取消激活应用的设备管理器。在取消激活应用的设备管理器之后,执行步骤S108,允许响应于针对应用的卸载请求对应用进行卸载。本发明实施例通过对为设备管理器配置的第一验证码以及输入的第二验证码进行匹配,得到匹配结果确定是否取消激活应用的设备管理器,进一步确定是否响应于针对应用的卸载请求对应用进行卸载,保证应用无法通过一些如手机助手、豌豆荚等设备间的连接软件被恶意卸载。另外,采用本发明实施例提供的应用防卸载方法能够防止一些掌握安卓技术的不法分子利用adb命令对应用进行恶意卸载,提高应用的安全性,进而保证用户设备以及设备内资料的安全性,提高用户体验。
现以具体实施例对本发明实施例提供的应用防卸载方法进行说明。
实施例一
图2至图8示出了根据本发明一个优选实施例的应用防卸载方法的处理流程的界面图,用于支持上述任意一个应用防卸载方法,将上述应用防卸载方法阐述得更加清晰易懂。具体地,图2示出了根据本发明一个实施例的开启应用防卸载功能的界面图。图3A示出了根据本发明一个实施例的启动设备管理器的界面图。图3B示出了根据本发明一个实施例的设置图形密码的界面图。图4示出了根据本发明一个实施例的如何关闭防卸载功能的界面图。图5示出了根据本发明一个实施例的查看应用程序信息的界面图。图6示出了根据本发明一个实施例的应用防卸载的界面图。图7示出了根据本发明一个实施例的取消设备管理器的界面图。图8示出了根据本发明一个实施例的请求输入密码的界面图。需要说明的是,为将本优选实施例阐述得更加清晰易懂,本优选实施例中,选择手机卫士作为被卸载应用,选择手机为安装有手机卫士的设备。
现介绍将手机卫士从手机中卸载的过程。
如图2所示,当用户要求开启应用防卸载功能,手机中的手机卫士提示用户,若开启手机卫士的防卸载功能,则卸载手机卫士之前必须先解除保护,使手机的安全性提高,并询问用户是否立即开启防卸载功能。当用户确认开启保护功能之后,手机弹出如图3A所示的开启设备管理器的界面图,并提示用户开启防卸载功能需要激活设备管理器,并允许手机卫士执行“设置密码规则”、“监视屏幕解锁尝试次数”以及“锁定屏幕”的操作,同时,询问用户是否要激活设备管理器。
当用户选择激活设备管理器之后,可以对密码规则进行设置(即设置第一验证码)。本发明实施例中,密码可以是字符密码(如数字或者字母),例如,设置密码规则为数字与字母的组合并规定在密码中数字以及字母的个数(如规定密码中包括3个数字以及3个字母,如367xyz)。再例如,设置密码规则为数字与大写字母的组合并规定数字与大写字母分别的个数,如设置密码中数字为2个,大写字母为5个(如23WERTY)。上述举例中设置的密码的个数及组合仅为示例,实际应用中设置的密码可以为任意字符的组合,并且可以为任意个数,本发明实施例对此并不加以限定。
本发明实施例中,还可以设置密码规则为图形密码。如图3B示出的一个常用设置图形密码的界面图,在设备屏幕显示3乘以3的排列的九个可触碰点,用户可以根据个人 喜好等在九个可触碰点上设置出个性图形作为密码。例如,图3B示出了设置一个“L”形图案作为图形密码。本发明实施例中对于密码规则的设置还可以是其他任意密码设置方法,如指纹密码等,本发明实施例对此并不加以限定。
另外,取消激活该应用的设备管理器所需的密码规则可以由系统来默认地设置,例如设置为用户对于该应用已设置的使用密码等,以该应用为手机卫士为例,在用户在该手机卫士中已设置有防盗密码的情况下,此处系统默认地将该取消激活手机卫士应用的设备管理器的第一验证码设置为与该手机卫士的防盗密码一致。
当激活设备管理器成功之后,手机弹出如图4所示的界面图,提示用户防卸载功能开启成功,并提示用户当需要卸载手机卫士时,需要首先将防卸载功能关闭,或者到系统设置中查找相关选项取消对设备管理器的激活。另外,若手机开启了防盗密码,关闭防卸载功能需要验证防盗密码。
手机开启防卸载功能之后,在设备管理器中查询手机卫士的相关信息如图5所示。参见图5,在手机中显示手机卫士的版本以及手机卫士的其他信息,如手机卫士的存储总量、手机卫士的存储数据以及手机卫士在手机存储内占用存储空间等等,并且如图5所示,手机无法直接在应用程序信息中直接对手机卫士进行强制停止以及卸载,即手机无法直接卸载手机卫士。其中,强制停止以及卸载两个操作标识为灰色(图5中未示出灰色显示效果),示意不可操作,即使在存储空间或容量可用的情况下,用户点击两者,也不会进入后续操作流程。另外,当手机输入安卓调试桥命令adb时,手机将弹出界面提示应用防卸载失败,即采用本优选实施例能够防止熟悉安卓技术的不法分子通过系统命令对手机卫士进行恶意卸载。
当手机接收到卸载例如手机卫士应用的请求时,提示手机卫士无法卸载,需要管理设备管理器。当用户点击管理设备管理器时,弹出如图6所示的界面图,提示用户手机卫士防卸载功能已开启,若关闭该防卸载功能需要验证防盗密码。当接收到关闭防卸载功能请求时,则手机弹出如图7所示的界面图,提示用户当前设备管理器已激活,并允许手机卫士执行“设置密码规则”、“监视屏幕解锁尝试次数”以及“锁定屏幕”的操作,另外,询问用户是否取消激活。当接收到取消激活请求,手机弹出如图8所示的验证码输入界面,并根据接收到的验证码与应用配置的第一验证码是否匹配确定是否取消激活设备管理器。当手机接收到的验证码(即第二验证码)与应用配置的第一验证码匹配,则显示询问用户是否取消对设备管理器的激活的界面,当用户确认要取消激活该设备管理器时,取消对该设备管理器的激活。当手机接收到的验证码与应用配置的第一验证码不匹配,则显示解锁失败,以便用户重新输入验证码。并且,本发明实施例中监视屏幕尝试解锁次数,在输入错误的次数达到预定次数时,执行锁定手机、清除手机数据、启动防盗警报等处理,保证用户信息安全。
上文介绍了将手机卫士从手机中卸载的过程,为将本优选实施例阐述得更加清楚明白,现对本优选实施例提供的应用防卸载方法的后台操作进行介绍。如图9示出了根据本发明一个优选实施例的应用防卸载方法的后台操作的处理流程图。参见图9,该优选实 施例至少包括步骤S902至步骤S912。
步骤S902、设置广播接收器。
在对本优选实施例提供的应用防卸载方法进行介绍时提及,本例中,通过激活设备管理器达到防卸载的目的,并通过取消激活设备管理器对应用进行卸载。因此,本例中,在应用的AndroidManifest.xml(安卓项目中的清单文件)中声明一个监听设备管理器变化的BroadcastReceiver。BroadcastReceiver是一种广播接收器。即当他人通过发广播通知多方同一消息时,BroadcastReceiver能够接收到该广播的信息。DeviceAdminReceiver是继承BroadcastReceiver特性的一种系统特殊定制的广播接收器。通过该DeviceAdminReceiver能够接收到通常广播接收器无法接收到的信息,如用户手机密码输入是否正确以及用户对手机密码的修改等信息。本发明实施例中,基于DeviceAdminReceiver进行扩展,得到继承DeviceAdminReceiver特性的XDeviceAdminReceiver。即用户能够通过继承DeviceAdminReceiver生成个性化定制的子类型,进而达到期望的定制功能。
代码示例如下:
Figure PCTCN2014095391-appb-000001
步骤S904、获取管理对象。
设置广播接收器成功之后,为监听(或者称之为控制)设备管理器,从系统中获取一个管理对象。代码示例如下:
DevicePolicyManager manager=(DevicePolicyManager)
context.getSystemService(Context.DEVICE_POLICY_SERVICE)
步骤S906、判断用户是否选择激活设备管理器。
设备管理器是一个系统特殊信息的接收器,本例中的设备管理器即为上文提及的XDeviceAdminReceiver。当用户在安卓系统中,调用相关函数发送一个指定的DeviceAdminReceiver的子类(即广播特殊信息的接收器)至系统,系统接收到DeviceAdminReceiver的子类的相关信息,则认为存在监听系统特殊消息的接收器,即系统默认该接收器为一个设备管理器。进一步,系统将该设备管理器展示至设备管理器的 页面,并且说明该设备管理器接收何种特殊信息(如该设备管理器监听用户手机密码输入是否正确、该次解锁是否成功等信息)。当设备管理器被激活,则设备管理器从属的应用无法直接进行卸载,直至设备管理器关闭。具体地,本发明实施例中,判断用户是否选择激活指定的设备管理器的代码示例如下:
String componentName=new ComponentName(context,XDeviceAdminReceiver.class);
boolean isAdminActive=manager.isAdminActive(componentName);
其中,XDeviceAdminReceiver,即为指定的设备管理器,即步骤S902中在AndroidManifest.xml中注册的那个BroadcastReceiver。
步骤S908、根据步骤S906的判断结果,若用户选择当前并不激活设备管理器,则提示用户能够激活设备管理器,并且,通过激活设备管理器,能够达到防止恶意卸载的目的。
步骤S910、根据步骤S906的判断结果,若用户选择激活设备管理器,则后台执行至少如下的步骤A至F将指定的设备管理器激活:
A、声明一个激活设备管理器的Intent:
Intent intent=new Intent(DevicePolicyManager.ACTION_ADD_DEVICE_ADMIN)
B、将步骤A中声明的Intent加入上文指定的广播接收器:
String componentName=new ComponentName(context,XDeviceAdminReceiver.class);
intent.putExtra(DevicePolicyManager.EXTRA_DEVICE_ADMIN,componentName)
C、在Intent中加入在设备管理器页面展示的、指定设备管理器的意义。其中,指定设备管理器的意义指该指定设备管理器在系统中监听何种事件。例如,当指定设备管理器的意义为监听解锁事件时,代码示例如下:
intent.putExtra(DevicePolicyManager.EXTRA_ADD_EXPLANATION,                     “我是一个设备管理器,我用来监听解锁事件”)
D、判断系统是否支持设备管理器的设置。代码示例如下:
ResolveInfo resolveInfo=context.getPackageManager().resolveActivity(intent,                     PackageManager.MATCH_DEFAULT_ONLY)
E、当系统支持设备管理器时,能够确定resolveInfo不会是null,进而能够呼叫设备管理器进行激活。代码示例如下:
if(resolveInfo!=null){                context.startActivity(intent);}
F、当步骤E中确定能够呼叫设备管理器进行激活之后,系统弹出设备管理器激活的页面,提示用户对设备管理器进行激活。当用户点击激活时,设备管理器激活成功。
步骤S912、成功激活设备管理器之后,当用户需要对应用进行卸载时,需要取消激活设备管理器。代码示例如下:
String componentName=new ComponentName(context,XDeviceAdminReceiver.class);manager.removeActiveAdmin(componentName)
其中,manager为获取的设备管理器的管理对象。
基于上文各优选实施例提供的应用防卸载方法,基于同一发明构思,本发明实施例提供了一种应用防卸载设备。图10示出了根据本发明一个实施例的应用防卸载设备的结构示意图。参见图10,本发明实施例的应用防卸载设备至少包括:验证码配置器1010、接收器1020、输出器1030、处理器1040以及卸载器1050。
现介绍本发明实施例的应用防卸载设备中的各器件或组成的功能以及各部分间的连接关系:
验证码配置器1010,配置为针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码。
接收器1020,配置为接收到取消激活应用的设备管理器的请求时,触发输出器1030,以及在验证码输入框接收输入的第二验证码。
输出器1030,与接收器1020相耦合,配置为输出验证码输入框。
处理器1040,与验证码配置器1010以及接收器1020分别耦合,配置为匹配第一验证码和第二验证码,根据匹配结果确定是否允许取消激活应用的设备管理器。
卸载器1050,与处理器1040相耦合,配置为在取消激活应用的设备管理器之后,允许响应于针对应用的卸载请求对应用进行卸载。
在本发明实施例中,针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码,并在接收到取消激活应用的设备管理器的请求时,输出验证码输入框,接收输入的第二验证码,匹配第一验证码和第二验证码,进而根据匹配结果确定是否取消激活应用的设备管理器。当对设备管理器取消激活之后,允许响应于针对应用的卸载请求对应用进行卸载。由此可见,本发明实施例在卸载应用之前需要对取消激活应用的设备管理器进行验证,并在取消激活应用的设备管理器之后,对应用进行卸载,解决了现有技术中将应用能够通过一些设备间的连接软件被卸载以及监视系统日志输入不及时导致应用被恶意卸载的问题,达到了减少应用被恶意卸载的机会,提高应用安全性,从而保证用户设备的安全的有益效果。另外,本发明实施例增强了系统兼容性,不但适用于高版本的系统,也适用于低版本的系统,保证更多低版本的系统也能够防止应用被恶意卸载,提高用户设备的安全性。如图10所示的应用防卸载设备中的验证码配置器1010针对当前应用激活设备管理器,并设置取消激活应用的设备管理器所需的第一验证码。本发明实施例中,从该应用向系统发送针对本应用激活设备管理器的请求,请求通过设备管理器执行相关操作,例如,请求监控屏幕解锁次数,请求锁定屏幕、请求对验证码的设置规则进行设置以及其他避免不法分子对设备执行不当操作导致应用被恶意卸载的相关操作,等等,本发明实施例对此并不加以限定。例如,本发明实施例中,请求监控屏幕被解锁的次数,若当前屏幕被解锁次数超过一定次数(例如3次),仍旧未能成功解锁,则能够锁定设备或者删除设备中的数据,避免不法分子通过其他途径将设备解锁后获取设备内的数据等信息,对用户的财产安全造成威胁。
上文提及,本发明实施例能够向系统发送针对本应用激活设备管理器的请求,请求通过设备管理器执行相关操作。其中,发送请求的代码中,需要在工程的 AndroidManifest.xml里面先声明所需的“receiver”,代码示例如下:
<receiverandroid:name=".app.DeviceAdminSample$DeviceAdminSampleReceiver"
android:label="@string/sample_device_admin"
android:description="@string/sample_device_admin_description"
android:permission="android.permission.BIND_DEVICE_ADMIN">
<meta-data android:name="android.app.device_admin"
android:resource="@xml/device_admin_sample"/>
<intent-filter
<actionandroid:name="android.app.action.DEVICE_ADMIN_ENABLED"/>
</intent-filter>
</receiver>
上文提及的代码示例中的“@xml/device_admin_sample”能够指明应用申请激活设备管理器时所申请的权限明细。
具体地,一个申请全部设备管理器权限的代码示例如下:
<device-admin xmlns:android="http://schemas.android.com/apk/res/android">
<uses-policies>
<limit-password/>
<watch-login/>
<reset-password/>
<force-lock/>
<wipe-data/>
<expire-password/>
<encrypted-storage/>
<disable-camera/>
</uses-policies>
</device-admin>
另外,在Java代码中,代码示例如下:
Intent intent=new Intent(DevicePolicyManager.ACTION_ADD_DEVICE_ADMIN);
intent.putExtra(DevicePolicyManager.EXTRA_DEVICE_ADMIN,mDeviceAdminSampl e);
intent.putExtra(DevicePolicyManager.EXTRA_ADD_EXPLANATION,mActivity.getString(R.string.add_admin_extra_app_text));
startActivityForResult(intent,REQUEST_CODE_ENABLE_ADMIN)
需要说明的是,上文提及的代码仅为本发明实施例发送请求的部分代码示例,为将本发明实施例阐述得清楚简洁,对于本发明实施例发送请求的全部代码在此不作赘述。
在发送激活设备管理器的请求之后,弹出让用户确认针对该应用激活设备管理器的界面。当用户手动确认之后,系统对请求进行响应,激活针对该应用的设备管理器。
上文提及,本发明实施例中,激活设备管理器之后,为避免对设备管理器的恶意取消激活,为卸载应用所使用的设备管理器配置的第一验证码。该第一验证码可以是固定 不变的,还可以是定期更新的。优选地,本发明实施例中,该第一验证码为定期更新的。本发明实施例中第一验证码为非固定的,防止因为第一验证码更新不及时导致旧的第一验证码被盗用,进一步导致应用程序被恶意卸载。例如,在手机卫士中使用手机防盗功能时,若手机被盗,偷窃者利用未及时更新的验证码将手机卫士恶意卸载,导致失主无法及时标记被盗手机,造成财产损失。
当如图10所示的应用防卸载设备中的接收器1020接收到取消激活应用的设备管理器请求时,被取消激活的设备管理器针对的应用本身能够收到来自系统的通知,并通过通知获知当前用户正在尝试取消激活设备管理器的操作。当该应用捕获到上述通知,则接收器1020触发输出器1030,由输出器1030输出验证码输入框。保证在用户完成取消激活设备管理器的操作之前弹出验证码输入框,阻止取消激活操作直至确定第一验证码与第二验证码匹配。本发明实施例中,为增加应用的安全性,锁屏器1060可以在输出器1030输出验证码输入框时,锁屏器1060锁定当前屏幕,并拒绝验证码输入以外的其他操作。当锁屏器1060锁定当前屏幕时,其拒绝的其他操作可以是取消激活该应用的设备管理器的操作,可以是管理软件对指定应用的删除操作,也可以是系统命令,例如安卓adb命令对指定应用的删除操作,保证本发明实施例仅能通过输入匹配的验证码对当前应用进行卸载,防止其他恶意操作导致的应用被卸载。本发明实施例中,锁屏器1060可以通过多种方式对设备的屏幕进行锁定,本发明实施例对此并不加以限定。例如,锁屏器1060直接对屏幕进行锁定,提示需要输入验证码对设备进行解锁,锁屏器1060还可以设置当前屏幕显示无需输入验证码即可对设备进行解锁操作,但在后台对屏幕进行锁定,降低不法分子的警惕心,更加有效保证设备中应用的安全性。
当接收器1020接收到第二验证码之后,由处理器1040对验证码配置器1010配置的第一验证码与接收器1020接收的第二验证码进行匹配。若经处理器1040的匹配操作,第一验证码与第二验证码不匹配,则处理器1040拒绝取消激活应用的设备管理器,防止应用被恶意卸载。优选地,处理器1040拒绝取消激活应用的设备管理器之后,本发明实施例还可以显示取消激活失败,提示重新输入第二验证码进行匹配。另外,当第二验证码输入错误达到预定次数(如5次)时,本发明实施例可以启动防盗警报或者其他处理,避免应用被恶意卸载。若经处理器1040的匹配操作,第一验证码与第二验证码相匹配,处理器1040允许取消激活应用的设备管理器。例如,本发明实施例中,当第一验证码与第二验证码匹配时,可以显示询问用户是否取消对设备管理器的激活的界面,提示用户取消激活该设备管理器可能导致应用被恶意卸载。当用户确认取消激活该设备管理器时,处理器1040触发该应用。应用在后台自行取消激活设备管理器。即,本发明实施例中,当应用成功激活设备管理器之后,除应用本身之外的其他任何应用均无法取消激活设备管理器。另外,本发明实施例中,当第一验证码与第二验证码匹配之后,还可以不做进一步询问与提示,由该应用直接在后台自行取消激活设备管理器。
若根据处理器1040,第一验证码与第二验证码匹配,允许取消激活应用的设备管理器。在取消激活应用的设备管理器之后,与处理器1040相耦合的卸载器1050允许相应 针对应用的卸载请求对应用进行卸载。本发明实施例通过对为设备管理器配置的第一验证码以及输入的第二验证码进行匹配,得到匹配结果确定是否拒绝取消激活应用的设备管理器,进一步确定是否响应于针对应用的卸载请求对应用进行卸载,保证应用无法通过一些如手机助手、豌豆荚等设备间的连接软件被恶意卸载,另外,采用本发明实施例提供的应用防卸载方法能够防止一些掌握安卓技术的不法分子利用adb命令对应用进行恶意卸载,提高应用的安全性,进而保证用户设备以及设备内资料的安全性,提高用户体验。
根据上述任意一个优选实施例或多个优选实施例的组合,本发明实施例能够达到如下有益效果:
本发明实施例中利用设备管理器防止对应用进行恶意卸载,当根据用户需求需要卸载应用时,本发明实施例需要取消对设备管理器的激活。当取消对设备管理器的激活时,本发明实施例需要进行输入验证码与应用配置的验证码的匹配,并根据匹配结果确定是否取消对设备管理器的激活,从而保证不知道验证码的不法分子无法对应用进行恶意卸载,提高应用的安全性,进一步提高用户设备的安全性。
在此处所提供的说明书中,说明了大量具体细节。然而,能够理解,本发明的实施例可以在没有这些具体细节的情况下实践。在一些实例中,并未详细示出公知的方法、结构和技术,以便不模糊对本说明书的理解。
类似地,应当理解,为了精简本公开并帮助理解各个发明方面中的一个或多个,在上面对本发明的示例性实施例的描述中,本发明的各个特征有时被一起分组到单个实施例、图、或者对其的描述中。然而,并不应将该公开的方法解释成反映如下意图:即所要求保护的本发明要求比在每个权利要求中所明确记载的特征更多的特征。更确切地说,如下面的权利要求书所反映的那样,发明方面在于少于前面公开的单个实施例的所有特征。因此,遵循具体实施方式的权利要求书由此明确地并入该具体实施方式,其中每个权利要求本身都作为本发明的单独实施例。
本领域那些技术人员可以理解,可以对实施例中的设备中的模块进行自适应性地改变并且把它们设置在与该实施例不同的一个或多个设备中。可以把实施例中的模块或单元或组件组合成一个模块或单元或组件,以及此外可以把它们分成多个子模块或子单元或子组件。除了这样的特征和/或过程或者单元中的至少一些是相互排斥之外,可以采用任何组合对本说明书(包括伴随的权利要求、摘要和附图)中公开的所有特征以及如此公开的任何方法或者设备的所有过程或单元进行组合。除非另外明确陈述,本说明书(包括伴随的权利要求、摘要和附图)中公开的每个特征可以由提供相同、等同或相似目的的替代特征来代替。
此外,本领域的技术人员能够理解,尽管在此所述的一些实施例包括其它实施例中所包括的某些特征而不是其它特征,但是不同实施例的特征的组合意味着处于本发明的范围之内并且形成不同的实施例。例如,在下面的权利要求书中,所要求保护的实施例的任意之一都可以以任意的组合方式来使用。
本发明的各个部件实施例可以以硬件实现,或者以在一个或者多个处理器上运行的软件模块实现,或者以它们的组合实现。本领域的技术人员应当理解,可以在实践中使用微处理器或者数字信号处理器(DSP)来实现根据本发明实施例的应用防卸载设备中的一些或者全部部件的一些或者全部功能。本发明还可以实现为用于执行这里所描述的方法的一部分或者全部的设备或者装置程序(例如,计算机程序和计算机程序产品)。这样的实现本发明的程序可以存储在计算机可读介质上,或者可以具有一个或者多个信号的形式。这样的信号可以从因特网网站上下载得到,或者在载体信号上提供,或者以任何其他形式提供。
例如,图11示出了可以实现根据本发明的应用防卸载方法的计算设备。该计算设备传统上包括处理器1110和以存储器1120形式的计算机程序产品或者计算机可读介质。存储器1120可以是诸如闪存、EEPROM(电可擦除可编程只读存储器)、EPROM、硬盘或者ROM之类的电子存储器。存储器1120具有用于执行上述方法中的任何方法步骤的程序代码1131的存储空间1130。例如,用于程序代码的存储空间1130可以包括分别用于实现上面的方法中的各种步骤的各个程序代码1131。这些程序代码可以从一个或者多个计算机程序产品中读出或者写入到这一个或者多个计算机程序产品中。这些计算机程序产品包括诸如硬盘,紧致盘(CD)、存储卡或者软盘之类的程序代码载体。这样的计算机程序产品通常为如参考图12所述的便携式或者固定存储单元。该存储单元可以具有与图11的计算设备中的存储器1120类似布置的存储段、存储空间等。程序代码可以例如以适当形式进行压缩。通常,存储单元包括计算机可读代码1131’,即可以由例如诸如1110之类的处理器读取的代码,这些代码当由计算设备运行时,导致该计算设备执行上面所描述的方法中的各个步骤。
本文中所称的“一个实施例”、“实施例”或者“一个或者多个实施例”意味着,结合实施例描述的特定特征、结构或者特性包括在本发明的至少一个实施例中。此外,请注意,这里“在一个实施例中”的词语例子不一定全指同一个实施例。
应该注意的是上述实施例对本发明进行说明而不是对本发明进行限制,并且本领域技术人员在不脱离所附权利要求的范围的情况下可设计出替换实施例。在权利要求中,不应将位于括号之间的任何参考符号构造成对权利要求的限制。单词“包含”不排除存在未列在权利要求中的元件或步骤。位于元件之前的单词“一”或“一个”不排除存在多个这样的元件。本发明可以借助于包括有若干不同元件的硬件以及借助于适当编程的计算机来实现。在列举了若干装置的单元权利要求中,这些装置中的若干个可以是通过同一个硬件项来具体体现。单词第一、第二、以及第三等的使用不表示任何顺序。可将这些单词解释为名称。
至此,本领域技术人员应认识到,虽然本文已详尽示出和描述了本发明的多个示例性实施例,但是,在不脱离本发明精神和范围的情况下,仍可根据本发明公开的内容直接确定或推导出符合本发明原理的许多其他变型或修改。因此,本发明的范围应被理解和认定为覆盖了所有这些其他变型或修改。

Claims (14)

  1. 一种应用防卸载方法,包括:
    针对当前应用激活设备管理器,并设置取消激活所述应用的设备管理器所需的第一验证码;
    接收到取消激活所述应用的设备管理器的请求时,输出验证码输入框;
    在所述验证码输入框接收输入的第二验证码,匹配所述第一验证码和所述第二验证码,根据匹配结果确定是否允许取消激活所述应用的设备管理器;
    在取消激活所述应用的设备管理器之后,允许响应于针对所述应用的卸载请求对所述应用进行卸载。
  2. 根据权利要求1所述的方法,其中,根据匹配结果确定是否允许取消激活所述应用的设备管理器,包括:
    当所述第一验证码和所述第二验证码匹配时,允许取消激活所述应用的设备管理器;
    当所述第一验证码和所述第二验证码不匹配时,拒绝取消激活所述应用的设备管理器。
  3. 根据权利要求2所述的方法,其中,当所述第一验证码与所述第二验证码匹配时,触发所述应用自行取消激活所述应用的设备管理器。
  4. 根据权利要求1至3任一项所述的方法,其中,所述输出验证码输入框时,还包括:锁定当前屏幕,拒绝除验证码输入以外的其他操作。
  5. 根据权利要求4所述的方法,其中,所述除验证码输入以外的其他操作,包括:
    取消激活该应用的设备管理器的操作;
    管理软件对所述指定应用的删除操作;
    系统命令对所述指定应用的删除操作。
  6. 根据权利要求5所述的方法,其中,所述系统命令为安卓调试桥adb命令。
  7. 一种应用防卸载设备,包括:
    验证码配置器,配置为针对当前应用激活设备管理器,并设置取消激活所述应用的设备管理器所需的第一验证码;
    接收器,配置为接收到取消激活所述应用的设备管理器的请求时,触发输出器;
    所述输出器,配置为输出验证码输入框;
    所述接收器,还配置为在所述验证码输入框接收输入的第二验证码;
    处理器,配置为匹配所述第一验证码和所述第二验证码,根据匹配结果确定是否允许取消激活所述应用的设备管理器;
    卸载器,配置为在取消激活所述应用的设备管理器之后,允许响应于针对所述应用的卸载请求对所述应用进行卸载。
  8. 根据权利要求7所述的设备,其中,所述处理器还配置为:
    当所述第一验证码和所述第二验证码匹配时,允许取消激活所述应用的设备管理器;
    当所述第一验证码和所述第二验证码不匹配时,拒绝取消激活所述应用的设备管理器。
  9. 根据权利要求8所述的设备,其中,所述处理器还配置为:
    当所述第一验证码与所述第二验证码匹配时,触发所述应用自行取消激活所述应用的设备管理器。
  10. 根据权利要求7至9任一项所述的设备,其中,还包括:
    锁屏器,配置为所述输出器输出验证码输入框时,锁定当前屏幕,拒绝除验证码输入以外的其他操作。
  11. 根据权利要求10所述的设备,其中,所述除验证码输入以外的其他操作,包括:
    取消激活该应用的设备管理器的操作;
    管理软件对所述指定应用的删除操作;
    系统命令对所述指定应用的删除操作。
  12. 根据权利要求11所述的设备,其中,所述系统命令为安卓调试桥adb命令。
  13. 一种计算机程序,包括计算机可读代码,当所述计算机可读代码在计算设备上运行时,导致所述计算设备执行根据权利要求1-6中的任一个所述的应用防卸载方法。
  14. 一种计算机可读介质,其中存储了如权利要求13所述的计算机程序。
PCT/CN2014/095391 2014-03-10 2014-12-29 应用防卸载方法及设备 Ceased WO2015135366A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410086128.4 2014-03-10
CN201410086128.4A CN103824016A (zh) 2013-11-28 2014-03-10 应用防卸载方法及设备

Publications (1)

Publication Number Publication Date
WO2015135366A1 true WO2015135366A1 (zh) 2015-09-17

Family

ID=54087052

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/095391 Ceased WO2015135366A1 (zh) 2014-03-10 2014-12-29 应用防卸载方法及设备

Country Status (1)

Country Link
WO (1) WO2015135366A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103383719A (zh) * 2012-05-02 2013-11-06 腾讯科技(深圳)有限公司 卸载程序的方法和设备
CN103824016A (zh) * 2013-11-28 2014-05-28 北京奇虎科技有限公司 应用防卸载方法及设备
CN103841192A (zh) * 2014-03-05 2014-06-04 天闻数媒科技(北京)有限公司 一种远程控制移动终端应用软件的方法和系统
US20140282971A1 (en) * 2013-03-14 2014-09-18 Bitium, Inc. System for managing remote software applications

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103383719A (zh) * 2012-05-02 2013-11-06 腾讯科技(深圳)有限公司 卸载程序的方法和设备
US20140282971A1 (en) * 2013-03-14 2014-09-18 Bitium, Inc. System for managing remote software applications
CN103824016A (zh) * 2013-11-28 2014-05-28 北京奇虎科技有限公司 应用防卸载方法及设备
CN103841192A (zh) * 2014-03-05 2014-06-04 天闻数媒科技(北京)有限公司 一种远程控制移动终端应用软件的方法和系统

Similar Documents

Publication Publication Date Title
US11941110B2 (en) Process privilege escalation protection in a computing environment
US9589139B2 (en) Method and device for altering a unified extensible firmware interface (UEFI) secure boot process in a computing device
CN104267994B (zh) 一种运行应用程序的装置和终端设备
US9197656B2 (en) Computer program, method, and system for preventing execution of viruses and malware
US10430592B2 (en) Integrity checking for computing devices
US8301910B2 (en) Intelligent, export/import restriction-compliant portable computer device
US11100242B2 (en) Restricted resource classes of an operating system
US11636219B2 (en) System, method, and apparatus for enhanced whitelisting
US20170098073A1 (en) Method and apparatus for identifying malicious operation in mobile terminal
CN104268476A (zh) 一种运行应用程序的方法
CN103824016A (zh) 应用防卸载方法及设备
CN104268475B (zh) 一种运行应用程序的系统
US11507675B2 (en) System, method, and apparatus for enhanced whitelisting
CN103984576A (zh) 用于防止应用卸载的方法和终端
CN105809055A (zh) 访问控制方法、装置及相关设备
CN105095758B (zh) 锁屏应用程序处理方法、装置以及移动终端
US11176224B2 (en) Security tool
CN104298924B (zh) 确保系统安全的方法、确保系统安全的装置和终端
US11275828B1 (en) System, method, and apparatus for enhanced whitelisting
CN113221103B (zh) 一种容器安全防护方法、系统及介质
CN106778173B (zh) 一种基于智能操作系统的应用锁设置的方法及装置
CN108334788A (zh) 文件防篡改方法及装置
US20170195425A1 (en) Method and Electronic Device for Remotely Locking a Mobile Terminal
US20200244461A1 (en) Data Processing Method and Apparatus
US20170070532A1 (en) Automated detection of unauthorized uninstall operations

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14885723

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14885723

Country of ref document: EP

Kind code of ref document: A1