WO2016201734A1 - 应用程序的运行控制方法、系统和终端 - Google Patents
应用程序的运行控制方法、系统和终端 Download PDFInfo
- Publication number
- WO2016201734A1 WO2016201734A1 PCT/CN2015/082951 CN2015082951W WO2016201734A1 WO 2016201734 A1 WO2016201734 A1 WO 2016201734A1 CN 2015082951 W CN2015082951 W CN 2015082951W WO 2016201734 A1 WO2016201734 A1 WO 2016201734A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- application
- specified type
- network channel
- data interaction
- communication network
- Prior art date
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/46—Multiprogramming arrangements
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
Definitions
- the present invention relates to the field of terminal technologies, and in particular, to an operation control method for an application program, an operation control system for an application program, and a terminal.
- a terminal device such as a mobile phone or the like accesses a core network (generally including a mobile cellular network channel and a Wi-Fi network channel, etc.) and supports a network mode of a virtual private network channel
- the terminal device is connected to After the virtual private network channel, all applications interact with the core network through the virtual private network channel, and after the terminal device disconnects from the virtual private network channel, all applications pass through the shared channel of the core network.
- the current application's operational control scheme significantly increases the network load, and is not conducive to ensuring the data security of the application.
- the present invention is based on at least one of the above technical problems, and proposes a new convenient and safer application running control scheme and a terminal, which can pass the virtual private network by judging whether the application is of a specified type.
- the channel implements data interaction between the specified type of application and the corresponding communication network, reducing network load and improving the security of the specified type of application.
- an operation control method of an application program including: after obtaining a request instruction for running the application, determining the Whether the application belongs to the specified type; when it is determined that the application belongs to the specified type, controlling the application of the specified type to perform data interaction with the first communication network through a virtual private network channel, wherein the request instruction includes The identification information of the application.
- the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, improving the specified type of application.
- the security of the program by determining whether the application is a specified type, the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, improving the specified type of application.
- the designated type may be an application with high security requirements set by the user, or the terminal device identifies an application having a running password, and the first communication network is an intranet created by the core network, that is, a specified type.
- the application data realizes the data interaction process with the intranet through the virtual private network channel, thereby improving data security.
- the method further includes: when determining that the application does not belong to the specified type, controlling the application to perform data interaction with a second communication network through a core network channel, where the core network
- the channel includes a Wi-Fi network channel and/or a mobile cellular network channel.
- data interaction is performed with the second communication network through the core network channel when determining that the application does not belong to the specified type, wherein the second communication network is a public network created based on the core network, and the security is low, but The network coverage is large. Therefore, the signaling interaction between the non-designated application and the second communication network through the core network channel can effectively slow down the load of the network channel of the core network, especially the virtual private network channel. The data interaction performance is improved. In addition, after the virtual private network channel cannot be accessed, the data interaction process between the application of the non-designated type and the core network is not affected.
- the method before acquiring the request instruction for running the application, the method further includes: acquiring, according to a user instruction, identification information to be divided into the specified type of application; storing the specified type of application Identification information to generate pre-stored identification information.
- the reliability and accuracy of the judgment application are improved by generating a pre-stored identifier for a specified type of application.
- controlling the application of the specified type to perform data interaction with the first communication network through a virtual private network channel including the following specific steps: Determining that the identification information belongs to the pre-stored identifier In the information, the application of the specified type is controlled to perform data interaction with the first communication network through the virtual private network channel.
- controlling the application to perform data interaction with the second communication network through the core network channel including the following specific steps: determining the When the identification information does not belong to the pre-stored identification information, the application is controlled to perform data interaction with the second communication network through the core network channel.
- data interaction between the core network channel and the second communication network reduces the load of the network channel of the core network, especially the virtual private network channel, thereby improving the load.
- Data interaction performance does not affect the data interaction process between the non-designated application and the core network after the virtual private network channel cannot be accessed.
- an operation control system for an application comprising: a determining unit, configured to determine, after obtaining a request instruction for running the application, whether the application belongs to a specified type a control unit, configured to, when determining that the application belongs to the specified type, control an application of the specified type to perform data interaction with a first communication network through a virtual private network channel, wherein the request instruction includes the Identification information for the application.
- the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, improving the specified type of application.
- the security of the program by determining whether the application is a specified type, the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, improving the specified type of application.
- the designated type may be an application with high security requirements set by the user, or the terminal device identifies an application having a running password, and the first communication network is an intranet created by the core network, that is, a specified type.
- the application data realizes the data interaction process with the intranet through the virtual private network channel, thereby improving data security.
- control unit is further configured to: determine the application When the program does not belong to the specified type, the application is controlled to perform data interaction with the second communication network through the core network channel, where the core network channel includes a Wi-Fi network channel and/or a mobile cellular network channel.
- data interaction is performed with the second communication network through the core network channel when determining that the application does not belong to the specified type, wherein the second communication network is a public network created based on the core network, and the security is low, but The network coverage is large. Therefore, the signaling interaction between the non-designated application and the second communication network through the core network channel can effectively slow down the load of the network channel of the core network, especially the virtual private network channel. The data interaction performance is improved. In addition, after the virtual private network channel cannot be accessed, the data interaction process between the application of the non-designated type and the core network is not affected.
- the method further includes: a dividing unit, configured to acquire, according to a user instruction, identification information to be divided into the application of the specified type; and a storage unit, configured to store an identifier of the specified type of application Information to generate pre-stored identification information.
- the reliability and accuracy of the judgment application are improved by generating a pre-stored identifier for a specified type of application.
- control unit is further configured to: when determining that the identifier information belongs to the pre-stored identifier information, control an application of the specified type to pass the virtual private network channel and the first A communication network performs data interaction.
- control unit is further configured to: when determining that the identification information does not belong to the pre-stored identification information, control the application to communicate with the second communication through the core network channel The network performs data interaction.
- data interaction between the core network channel and the second communication network reduces the load of the network channel of the core network, especially the virtual private network channel, thereby improving the load.
- Data interaction performance does not affect the data interaction process between the non-designated application and the core network after the virtual private network channel cannot be accessed.
- a terminal comprising an operation control system of an application program according to any of the above aspects.
- the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, upgrading the specified type of application. Security.
- FIG. 1 shows a schematic flow chart of an operation control method of an application according to an embodiment of the present invention
- FIG. 2 shows a schematic block diagram of an operational control system of an application in accordance with an embodiment of the present invention
- Figure 3 shows a schematic block diagram of a terminal in accordance with one embodiment of the present invention
- FIG. 4 shows a schematic block diagram of a terminal in accordance with another embodiment of the present invention.
- FIG. 1 shows a schematic flow chart of an operation control method of an application according to an embodiment of the present invention.
- an operation control method of an application includes: Step 102: After obtaining a request instruction for running the application, determining whether the application belongs to a specified type; When it is determined that the application belongs to the specified type, the application of the specified type is controlled to perform data interaction with the first communication network through a virtual private network channel, wherein the request instruction includes identification information of the application.
- the network channel is used to implement data interaction between the specified type of application and the corresponding communication network, which reduces the network load and, in addition, improves the security of the specified type of application.
- the designated type may be an application with high security requirements set by the user, or the terminal device identifies an application having a running password, and the first communication network is an intranet created by the core network, that is, a specified type.
- the application data realizes the data interaction process with the intranet through the virtual private network channel, thereby improving data security.
- the method further includes: when determining that the application does not belong to the specified type, controlling the application to perform data interaction with a second communication network through a core network channel, where the core network
- the channel includes a Wi-Fi network channel and/or a mobile cellular network channel.
- data interaction is performed with the second communication network through the core network channel when determining that the application does not belong to the specified type, wherein the second communication network is a public network created based on the core network, and the security is low, but The network coverage is large. Therefore, the signaling interaction between the non-designated application and the second communication network through the core network channel can effectively slow down the load of the network channel of the core network, especially the virtual private network channel. The data interaction performance is improved. In addition, after the virtual private network channel cannot be accessed, the data interaction process between the application of the non-designated type and the core network is not affected.
- the method before acquiring the request instruction for running the application, the method further includes: acquiring, according to a user instruction, identification information to be divided into the specified type of application; storing the specified type of application Identification information to generate pre-stored identification information.
- the reliability and accuracy of the judgment application are improved by generating a pre-stored identifier for a specified type of application.
- controlling the application of the specified type to perform data interaction with the first communication network through a virtual private network channel including the following specific steps:
- the application of the specified type is controlled to perform data interaction with the first communication network by using the virtual private network channel.
- the application of the specified type is implemented by the virtual private network channel to perform data communication with the corresponding communication network.
- Mutual reducing network load and, in addition, improving the security of specified types of applications.
- controlling the application to perform data interaction with the second communication network through the core network channel including the following specific steps: determining the When the identification information does not belong to the pre-stored identification information, the application is controlled to perform data interaction with the second communication network through the core network channel.
- data interaction between the core network channel and the second communication network reduces the load of the network channel of the core network, especially the virtual private network channel, thereby improving the load.
- Data interaction performance does not affect the data interaction process between the non-designated application and the core network after the virtual private network channel cannot be accessed.
- FIG. 2 shows a schematic block diagram of an operational control system of an application in accordance with an embodiment of the present invention.
- the operation control system 200 of the application includes: a determining unit 202, configured to determine whether the application belongs to a specified type after acquiring a request instruction for running the application
- the control unit 204 is configured to, when determining that the application belongs to the specified type, control the application of the specified type to perform data interaction with the first communication network through a virtual private network channel, where the request instruction includes The identification information of the application.
- the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, improving the specified type of application.
- the security of the program by determining whether the application is a specified type, the application of the specified type of application interacts with the corresponding communication network through the virtual private network channel, thereby reducing the network load and, in addition, improving the specified type of application.
- the designated type may be an application with high security requirements set by the user, or the terminal device identifies an application having a running password, and the first communication network is an intranet created by the core network, that is, a specified type.
- the application data realizes the data interaction process with the intranet through the virtual private network channel, thereby improving data security.
- control unit 204 is further configured to: when determining that the application does not belong to the specified type, control the application to perform data interaction with the second communication network through the core network channel, Wherein the core network channel includes a Wi-Fi network channel and / or mobile cellular channel.
- data interaction is performed with the second communication network through the core network channel when determining that the application does not belong to the specified type, wherein the second communication network is a public network created based on the core network, and the security is low, but The network coverage is large. Therefore, the signaling interaction between the non-designated application and the second communication network through the core network channel can effectively slow down the load of the network channel of the core network, especially the virtual private network channel. The data interaction performance is improved. In addition, after the virtual private network channel cannot be accessed, the data interaction process between the application of the non-designated type and the core network is not affected.
- the method further includes: a dividing unit 206, configured to acquire, according to a user instruction, identification information to be divided into the specified type of application; and a storage unit 208, configured to store the specified type of application Identification information to generate pre-stored identification information.
- the reliability and accuracy of the judgment application are improved by generating a pre-stored identifier for a specified type of application.
- control unit 204 is further configured to: when determining that the identifier information belongs to the pre-stored identifier information, control, by the virtual private network channel, the specified type of application The first communication network performs data interaction.
- control unit 204 is further configured to: when determining that the identifier information does not belong to the pre-stored identifier information, control the application to pass the core network channel and the second The communication network performs data interaction.
- data interaction between the core network channel and the second communication network reduces the load of the network channel of the core network, especially the virtual private network channel, thereby improving the load.
- Data interaction performance does not affect the data interaction process between the non-designated application and the core network after the virtual private network channel cannot be accessed.
- Figure 3 shows a schematic block diagram of a terminal in accordance with one embodiment of the present invention.
- a terminal 300 includes any of the above The operational control system 200 of the application described in the technical solution.
- FIG. 4 shows a schematic block diagram of a terminal in accordance with another embodiment of the present invention.
- a terminal 400 includes: a communication module 402 for creating a communication connection with a core network; and a data connection management module 402 for managing a connection state of the communication connection;
- the module 406 is configured to manage the type of the application, and the channel isolation module 408 is configured to isolate the virtual private network channel from the core network channel according to the type of the application.
- the application control process of the application includes:
- the peripheral terminal is connected to the core network through the communication module 402, and creates a core network channel;
- the peripheral terminal sends a request to the base station through the data connection management module 404 to connect to the virtual private network channel;
- the channel management module 406 acquires the type of the application and identifies the application of the specified type;
- the channel isolation module 408 is used to isolate the virtual private network channel from the core network channel, and the specified type of application performs data interaction through the virtual private network channel, and other non-designated types of applications pass through the core network channel. Perform data interaction.
- the present invention provides an operation control method for an application program, an operation control system for an application program, and a terminal, which can realize a specified type of application through a virtual private network channel by determining whether the application program is of a specified type.
- the corresponding communication network performs data interaction, which reduces the network load and, in addition, improves the security of the specified type of application.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephonic Communication Services (AREA)
Abstract
一种应用程序的运行控制方法、系统和终端,其中,所述应用程序的运行控制方法,包括:在获取运行所述应用程序的请求指令后,判断所述应用程序是否属于指定类型(102);在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息(104)。通过上述技术方案,对于不同类型的应用程序的运行过程进行智能控制,在保证应用程序正常运行的同时,提升了指定类型的应用程序进行数据交互的安全性和可靠性。
Description
本申请要求于2015年06月16日提交中国专利局,申请号为201510334375.6、发明名称为“应用程序的运行控制方法、系统和终端”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明涉及终端技术领域,具体而言,涉及一种应用程序的运行控制方法、一种应用程序的运行控制系统和一种终端。
在相关技术中,在终端设备(如手机等)接入核心网(通常包括如移动蜂窝网通道和Wi-Fi网络通道等),且支持虚拟专用网通道的网络制式时,终端设备在连接至虚拟专用网通道后,所有的应用程序都通过虚拟专用网通道与核心网进行数据交互,而在终端设备断开与虚拟专用网通道的连接后,所有的应用程序都通过核心网的共用通道进行数据交互,当前的应用程序的运行控制方案明显增加了网络负荷,也不利于保证应用程序的数据安全。
因此,如何设计一种便捷地、更为安全的应用程序的运行控制方案成为亟待解决的技术问题。
发明内容
本发明正是基于上述技术问题至少之一,提出了一种新的便捷地、更为安全的应用程序的运行控制方案和一种终端,通过判断应用程序是否是指定类型,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
有鉴于此,根据本发明的第一方面的实施例,提出了一种应用程序的运行控制方法,包括:在获取运行所述应用程序的请求指令后,判断所述
应用程序是否属于指定类型;在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息。
在该技术方案中,通过判断应用程序是否是指定类型,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
其中,指定类型可以是用户设定的安全要求高的应用程序,或者终端设备识别有运行密码的应用程序等,第一通信网络是基于核心网创建的企业内网等,也即,指定类型的应用数据通过虚拟专用网通道实现与企业内网的数据交互过程,从而提高数据安全性。
在上述技术方案中,优选地,还包括:在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,其中,所述核心网通道包括Wi-Fi网络通道和/或移动蜂窝网通道。
在该技术方案中,通过在判定应用程序不属于指定类型时,通过核心网通道与第二通信网络进行数据交互,其中,第二通信网络是基于核心网创建的公用网络,安全性低,但是网络覆盖范围大,因此,通过核心网通道实现非指定类型的应用程序与第二通信网络之间的信令交互,可以有效地减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
在上述技术方案中,优选地,在获取运行所述应用程序的请求指令前,还包括:根据用户指令获取待划分为所述指定类型的应用程序的标识信息;存储所述指定类型的应用程序的标识信息,以生成预存标识信息。
在该技术方案中,通过对指定类型的应用程序生成预存储标识,提升了判断应用程序的可靠性和准确性。
在上述技术方案中,优选地,在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,包括以下具体步骤:在判定所述标识信息属于所述预存标识
信息时,控制所述指定类型的应用程序通过所述虚拟专用网通道与所述第一通信网络进行数据交互。
在该技术方案中,通过预设标识信息和标识信息的从属关系,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
在上述技术方案中,优选地,在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,包括以下具体步骤:在判定所述标识信息不属于所述预存标识信息时,控制所述的应用程序通过所述核心网通道与所述第二通信网络进行数据交互。
在该技术方案中,通过在判定标识信息不属于预存标识信息时,通过核心网通道与第二通信网络进行数据交互,减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
根据本发明的第二方面的实施例,提出了一种应用程序的运行控制系统,包括:判断单元,用于在获取运行所述应用程序的请求指令后,判断所述应用程序是否属于指定类型;控制单元,用于在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息。
在该技术方案中,通过判断应用程序是否是指定类型,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
其中,指定类型可以是用户设定的安全要求高的应用程序,或者终端设备识别有运行密码的应用程序等,第一通信网络是基于核心网创建的企业内网等,也即,指定类型的应用数据通过虚拟专用网通道实现与企业内网的数据交互过程,从而提高数据安全性。
在上述技术方案中,优选地,所述控制单元还用于:在判定所述应用
程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,其中,所述核心网通道包括Wi-Fi网络通道和/或移动蜂窝网通道。
在该技术方案中,通过在判定应用程序不属于指定类型时,通过核心网通道与第二通信网络进行数据交互,其中,第二通信网络是基于核心网创建的公用网络,安全性低,但是网络覆盖范围大,因此,通过核心网通道实现非指定类型的应用程序与第二通信网络之间的信令交互,可以有效地减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
在上述技术方案中,优选地,还包括:划分单元,用于根据用户指令获取待划分为所述指定类型的应用程序的标识信息;存储单元,用于存储所述指定类型的应用程序的标识信息,以生成预存标识信息。
在该技术方案中,通过对指定类型的应用程序生成预存储标识,提升了判断应用程序的可靠性和准确性。
在上述技术方案中,优选地,所述控制单元还用于:在判定所述标识信息属于所述预存标识信息时,控制所述指定类型的应用程序通过所述虚拟专用网通道与所述第一通信网络进行数据交互。
在该技术方案中,通过预设标识信息和标识信息的从属关系,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
在上述技术方案中,优选地,所述控制单元还用于:在判定所述标识信息不属于所述预存标识信息时,控制所述的应用程序通过所述核心网通道与所述第二通信网络进行数据交互。
在该技术方案中,通过在判定标识信息不属于预存标识信息时,通过核心网通道与第二通信网络进行数据交互,减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
根据本发明的第三发明的实施例,还提出了一种终端,包括如上述任一项技术方案所述的应用程序的运行控制系统。
通过以上技术方案,通过判断应用程序是否是指定类型,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
图1示出了根据本发明的实施例的应用程序的运行控制方法的示意流程图;
图2示出了根据本发明的实施例的应用程序的运行控制系统的示意框图;
图3示出了根据本发明的一个实施例的终端的示意框图;
图4示出了根据本发明的另一个实施例的终端的示意框图。
为了能够更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用其他不同于在此描述的其他方式来实施,因此,本发明的保护范围并不受下面公开的具体实施例的限制。
图1示出了根据本发明的实施例的应用程序的运行控制方法的示意流程图。
如图1所示,根据本发明的实施例的应用程序的运行控制方法,包括:步骤102,在获取运行所述应用程序的请求指令后,判断所述应用程序是否属于指定类型;步骤104,在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息。
在该技术方案中,通过判断应用程序是否是指定类型,以通过虚拟专
用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
其中,指定类型可以是用户设定的安全要求高的应用程序,或者终端设备识别有运行密码的应用程序等,第一通信网络是基于核心网创建的企业内网等,也即,指定类型的应用数据通过虚拟专用网通道实现与企业内网的数据交互过程,从而提高数据安全性。
在上述技术方案中,优选地,还包括:在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,其中,所述核心网通道包括Wi-Fi网络通道和/或移动蜂窝网通道。
在该技术方案中,通过在判定应用程序不属于指定类型时,通过核心网通道与第二通信网络进行数据交互,其中,第二通信网络是基于核心网创建的公用网络,安全性低,但是网络覆盖范围大,因此,通过核心网通道实现非指定类型的应用程序与第二通信网络之间的信令交互,可以有效地减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
在上述技术方案中,优选地,在获取运行所述应用程序的请求指令前,还包括:根据用户指令获取待划分为所述指定类型的应用程序的标识信息;存储所述指定类型的应用程序的标识信息,以生成预存标识信息。
在该技术方案中,通过对指定类型的应用程序生成预存储标识,提升了判断应用程序的可靠性和准确性。
在上述技术方案中,优选地,在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,包括以下具体步骤:在判定所述标识信息属于所述预存标识信息时,控制所述指定类型的应用程序通过所述虚拟专用网通道与所述第一通信网络进行数据交互。
在该技术方案中,通过预设标识信息和标识信息的从属关系,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交
互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
在上述技术方案中,优选地,在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,包括以下具体步骤:在判定所述标识信息不属于所述预存标识信息时,控制所述的应用程序通过所述核心网通道与所述第二通信网络进行数据交互。
在该技术方案中,通过在判定标识信息不属于预存标识信息时,通过核心网通道与第二通信网络进行数据交互,减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
图2示出了根据本发明的实施例的应用程序的运行控制系统的示意框图。
如图2所示,根据本发明的实施例的应用程序的运行控制系统200,包括:判断单元202,用于在获取运行所述应用程序的请求指令后,判断所述应用程序是否属于指定类型;控制单元204,用于在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息。
在该技术方案中,通过判断应用程序是否是指定类型,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
其中,指定类型可以是用户设定的安全要求高的应用程序,或者终端设备识别有运行密码的应用程序等,第一通信网络是基于核心网创建的企业内网等,也即,指定类型的应用数据通过虚拟专用网通道实现与企业内网的数据交互过程,从而提高数据安全性。
在上述技术方案中,优选地,所述控制单元204还用于:在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,其中,所述核心网通道包括Wi-Fi网络通道和
/或移动蜂窝网通道。
在该技术方案中,通过在判定应用程序不属于指定类型时,通过核心网通道与第二通信网络进行数据交互,其中,第二通信网络是基于核心网创建的公用网络,安全性低,但是网络覆盖范围大,因此,通过核心网通道实现非指定类型的应用程序与第二通信网络之间的信令交互,可以有效地减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
在上述技术方案中,优选地,还包括:划分单元206,用于根据用户指令获取待划分为所述指定类型的应用程序的标识信息;存储单元208,用于存储所述指定类型的应用程序的标识信息,以生成预存标识信息。
在该技术方案中,通过对指定类型的应用程序生成预存储标识,提升了判断应用程序的可靠性和准确性。
在上述技术方案中,优选地,所述控制单元204还用于:在判定所述标识信息属于所述预存标识信息时,控制所述指定类型的应用程序通过所述虚拟专用网通道与所述第一通信网络进行数据交互。
在该技术方案中,通过预设标识信息和标识信息的从属关系,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
在上述技术方案中,优选地,所述控制单元204还用于:在判定所述标识信息不属于所述预存标识信息时,控制所述的应用程序通过所述核心网通道与所述第二通信网络进行数据交互。
在该技术方案中,通过在判定标识信息不属于预存标识信息时,通过核心网通道与第二通信网络进行数据交互,减缓了核心网的网络通道尤其是虚拟专用网通道的负荷,从而提升了数据交互性能,另外,在无法接入虚拟专用网通道后,并不影响非指定类型的应用程序与核心网之间的数据交互过程。
图3示出了根据本发明的一个实施例的终端的示意框图。
如图3所示,根据本发明的一个实施例的终端300,包括如上述任一
项技术方案所述的应用程序的运行控制系统200。
图4示出了根据本发明的另一个实施例的终端的示意框图。
如图4所示,根据本发明的另一个实施例的终端400,包括:通信模块402,用于创建与核心网的通信连接;数据连接管理模块402,用于管理通信连接的连接状态;管理模块406,用于对应用程序的类型进行管理;通道隔离模块408,用于对根据应用程序的类型进行虚拟专用网通道与核心网通道的隔离。
具体地,应用程序的运行控制过程包括:
(1)外设终端通过通信模块402连接至核心网,并创建核心网通道;
(2)外设终端通过数据连接管理模块404向基站发出请求连接至虚拟专用网通道;
(3)在虚拟专用网通道连接成功后,通道管理模块406获取应用程序的类型,并对指定类型的应用程序进行标识;
(4)根据标识信息,通过通道隔离模块408实现虚拟专用网通道与核心网通道的隔离,指定类型的应用程序通过虚拟专用网通道进行数据交互,而其他非指定类型的应用程序通过核心网通道进行数据交互。
以上结合附图详细说明了本发明的技术方案,考虑到如何设计一种便捷地、更为安全的应用程序的运行控制方案的技术问题。因此,本发明提出了一种应用程序的运行控制方法、一种应用程序的运行控制系统和一种终端,通过判断应用程序是否是指定类型,以通过虚拟专用网通道实现指定类型的应用程序与相应的通信网络进行数据交互,减小了网络负荷,另外,提升了指定类型的应用程序的安全性。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。
Claims (11)
- 一种应用程序的运行控制方法,其特征在于,包括:在获取运行所述应用程序的请求指令后,判断所述应用程序是否属于指定类型;在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息。
- 根据权利要求1所述的应用程序的运行控制方法,其特征在于,还包括:在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,其中,所述核心网通道包括Wi-Fi网络通道和/或移动蜂窝网通道。
- 根据权利要求1或2所述的应用程序的运行控制方法,其特征在于,在获取运行所述应用程序的请求指令前,还包括:根据用户指令获取待划分为所述指定类型的应用程序的标识信息;存储所述标识信息,以生成预存标识信息。
- 根据权利要求3所述的应用程序的运行控制方法,其特征在于,在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,包括以下具体步骤:在判定所述标识信息属于所述预存标识信息时,控制所述指定类型的应用程序通过所述虚拟专用网通道与所述第一通信网络进行数据交互。
- 根据权利要求3所述的应用程序的运行控制方法,其特征在于,在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,包括以下具体步骤:在判定所述标识信息不属于所述预存标识信息时,控制所述的应用程序通过所述核心网通道与所述第二通信网络进行数据交互。
- 一种应用程序的运行控制系统,其特征在于,包括:判断单元,用于在获取运行所述应用程序的请求指令后,判断所述应 用程序是否属于指定类型;控制单元,用于在判定所述应用程序属于所述指定类型时,控制所述指定类型的应用程序通过虚拟专用网通道与第一通信网络进行数据交互,其中,所述请求指令包括所述应用程序的标识信息。
- 根据权利要求6所述的应用程序的运行控制系统,其特征在于,所述控制单元还用于:在判定所述应用程序不属于所述指定类型时,控制所述应用程序通过核心网通道与第二通信网络进行数据交互,其中,所述核心网通道包括Wi-Fi网络通道和/或移动蜂窝网通道。
- 根据权利要求6或7所述的应用程序的运行控制系统,其特征在于,还包括:划分单元,用于根据用户指令获取待划分为所述指定类型的应用程序的标识信息;存储单元,用于存储所述标识信息,以生成预存标识信息。
- 根据权利要求8所述的应用程序的运行控制系统,其特征在于,所述控制单元还用于:在判定所述标识信息属于所述预存标识信息时,控制所述指定类型的应用程序通过所述虚拟专用网通道与所述第一通信网络进行数据交互。
- 根据权利要求8所述的应用程序的运行控制系统,其特征在于,所述控制单元还用于:在判定所述标识信息不属于所述预存标识信息时,控制所述的应用程序通过所述核心网通道与所述第二通信网络进行数据交互。
- 一种终端,其特征在于,包括:如权利要求6至10中任一项所述的应用程序的运行控制系统。
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201510334375.6 | 2015-06-16 | ||
CN201510334375.6A CN105630584A (zh) | 2015-06-16 | 2015-06-16 | 应用程序的运行控制方法、系统和终端 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2016201734A1 true WO2016201734A1 (zh) | 2016-12-22 |
Family
ID=56045563
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2015/082951 WO2016201734A1 (zh) | 2015-06-16 | 2015-06-30 | 应用程序的运行控制方法、系统和终端 |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN105630584A (zh) |
WO (1) | WO2016201734A1 (zh) |
Families Citing this family (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107480983B (zh) * | 2017-08-29 | 2018-08-07 | 上海明心信息科技有限公司 | 一种防盗手机支付系统 |
CN111934972B (zh) * | 2020-08-12 | 2022-09-30 | 北京指掌易科技有限公司 | 应用程序vpn管理方法、装置及电子设备 |
CN115567897A (zh) * | 2022-09-22 | 2023-01-03 | 智达诚远科技有限公司 | 一种网络通道自动分配方法以及装置 |
CN117134932B (zh) * | 2023-04-06 | 2024-08-13 | 荣耀终端有限公司 | 数据流调度方法和电子设备 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101431713A (zh) * | 2007-11-09 | 2009-05-13 | 中国移动通信集团公司 | 一种资源访问方法及设备 |
CN102081722A (zh) * | 2011-01-04 | 2011-06-01 | 奇智软件(北京)有限公司 | 一种保护指定应用程序的方法及装置 |
CN102982275A (zh) * | 2012-11-14 | 2013-03-20 | 北京奇虎科技有限公司 | 一种运行应用程序的安全控制方法和装置 |
US20140282821A1 (en) * | 2013-03-15 | 2014-09-18 | Symantec Corporation | Systems and methods for identifying a secure application when connecting to a network |
Family Cites Families (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN201467150U (zh) * | 2009-05-25 | 2010-05-12 | 上海恩际恩网络科技有限公司 | 基于重叠网的网络游戏加速系统 |
CN104426735B (zh) * | 2013-08-30 | 2018-06-26 | 中国移动通信集团公司 | 一种建立虚拟专用网络连接的方法及装置 |
CN103618661A (zh) * | 2013-12-12 | 2014-03-05 | 四川迅游网络科技股份有限公司 | 一种数据分离方法及系统 |
-
2015
- 2015-06-16 CN CN201510334375.6A patent/CN105630584A/zh active Pending
- 2015-06-30 WO PCT/CN2015/082951 patent/WO2016201734A1/zh active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101431713A (zh) * | 2007-11-09 | 2009-05-13 | 中国移动通信集团公司 | 一种资源访问方法及设备 |
CN102081722A (zh) * | 2011-01-04 | 2011-06-01 | 奇智软件(北京)有限公司 | 一种保护指定应用程序的方法及装置 |
CN102982275A (zh) * | 2012-11-14 | 2013-03-20 | 北京奇虎科技有限公司 | 一种运行应用程序的安全控制方法和装置 |
US20140282821A1 (en) * | 2013-03-15 | 2014-09-18 | Symantec Corporation | Systems and methods for identifying a secure application when connecting to a network |
Also Published As
Publication number | Publication date |
---|---|
CN105630584A (zh) | 2016-06-01 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11089476B2 (en) | Network access control method and apparatus | |
KR102478442B1 (ko) | Pdu 유형 설정 방법, ue 정책 설정 방법 및 관련 엔티티 | |
US20190306688A1 (en) | Network Access Method, Device, and System | |
TWI332333B (en) | System and method for distributing wireless network access parameters | |
WO2019042427A1 (zh) | 选择amf的方法、amf、系统及计算机可读存储介质 | |
US9021005B2 (en) | System and method to provide remote device management for mobile virtualized platforms | |
CN104735814A (zh) | 自动接入WiFi网络的接入方法、系统、和相关装置 | |
US8621572B2 (en) | Method, apparatus and system for updating authentication, authorization and accounting session | |
WO2015157949A1 (zh) | 无线局域网络wlan的接入方法、终端及服务器 | |
US20200228981A1 (en) | Authentication method and device | |
US20150207774A1 (en) | Method and System of APP for Obtaining MAC Address of Terminal | |
WO2016201734A1 (zh) | 应用程序的运行控制方法、系统和终端 | |
WO2018045983A1 (zh) | 信息处理方法、装置以及网络系统 | |
CN114567880B (zh) | 通信方法、系统以及计算机可读存储介质 | |
CN101895587A (zh) | 防止用户私自修改ip地址的方法、装置和系统 | |
KR101988477B1 (ko) | 게이트웨이를 통한 m2m 네트워크의 디바이스 등록 방법 및 게이트웨이 장 | |
US10091205B2 (en) | Zeroconf profile transferring to enable fast roaming | |
WO2018090800A1 (zh) | 连接建立方法、设备及系统 | |
WO2019220002A1 (en) | Authentication in public land mobile networks comprising tenant slices | |
KR102266413B1 (ko) | 단말 제어 장치 및 방법 | |
US10785165B2 (en) | Method for controlling service data flow and network device | |
CN116782150A (zh) | 归属地网元确定方法、装置、通信设备和存储介质 | |
CN105282819B (zh) | 一种无线设备的接入方法、网关设备和无线网络 | |
WO2017215306A1 (zh) | 一种移动终端及其网络接入的方法 | |
CN115767584A (zh) | 核心网开通方法、装置和电子设备 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15895307 Country of ref document: EP Kind code of ref document: A1 |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 14.05.2018) |
|
122 | Ep: pct application non-entry in european phase |
Ref document number: 15895307 Country of ref document: EP Kind code of ref document: A1 |