WO2017113584A1 - 一种终端容器安全的控制方法与系统 - Google Patents
一种终端容器安全的控制方法与系统 Download PDFInfo
- Publication number
- WO2017113584A1 WO2017113584A1 PCT/CN2016/084103 CN2016084103W WO2017113584A1 WO 2017113584 A1 WO2017113584 A1 WO 2017113584A1 CN 2016084103 W CN2016084103 W CN 2016084103W WO 2017113584 A1 WO2017113584 A1 WO 2017113584A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- terminal
- container
- preset
- vpdn
- sim card
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
Definitions
- the present invention relates to the field of terminal information security, and in particular to a method and system for controlling terminal container security.
- the main object of the present invention is to provide a method and system for controlling the security of a terminal container, which can provide a safe container for a mobile phone application and ensure the operational safety of the application in the container.
- the present invention provides a method for controlling the security of a terminal container, including:
- the SIM card information of the terminal will be verified in response to the SIM card information. Passing the VPDN channel to the preset security authentication server to verify whether the SIM card of the terminal has a registration record on the preset security authentication server;
- the target application After receiving the verification pass message of the preset security authentication server, the target application is entered, and the preset secure container policy is invoked.
- the secure container policy comprises:
- the determining whether the target application is an entry application to enter the secure container comprises:
- the responding to the SIM card information verification instruction, before transmitting the SIM card information of the terminal to the preset security authentication server by using the VPDN channel further includes:
- the preset disable device functions include a camera function, a pasteboard function, an SD card function, a screen capture function, a screen recording function, and a GPS function.
- the secure container policy further includes:
- the configuration information of the hidden APN includes:
- the invention also provides a terminal container safety control system, comprising:
- a container internal and external discriminating module configured to determine whether the target application is an entry application to enter the secure container in response to a click instruction to the target application, and if yes, enter the secure container;
- the security authentication module is configured to respond to the VPDN creation command, disconnect the Internet, create a VPDN and connect; after determining that the VPDN connection is successful, respond to the SIM card information verification command, and transmit the SIM card information of the terminal to the preset security authentication server through the VPDN channel. Determining whether the SIM card of the terminal has a registration record on the preset security authentication server;
- the in-container policy invoking module is configured to enter the target application after receiving the verification pass message of the preset secure authentication server, and invoke a preset secure container policy.
- the secure container policy comprises:
- the preset disable device functions include a camera function, a pasteboard function, an SD card function, a screen capture function, a screen recording function, and a GPS function.
- a terminal container security control method and system provided by the present invention is used to determine whether a target application is an entry application for entering a secure container, and if so, enter a secure container; disconnect the Internet, create a VPDN and connect; and determine that the VPDN connection is successful, Passing the SIM card information of the terminal to the preset security authentication server through the VPDN channel, and verifying whether the SIM card of the terminal has a registration record on the preset security authentication server; after the verification is passed, entering the target application,
- the preset security policy can be used to provide a secure container for applications that need to protect customer privacy. All applications can run in the same system without having to allocate additional memory and space, which can easily and efficiently protect the data security of the end user.
- Embodiment 1 is a flowchart of Embodiment 1 of a method for controlling safety of a terminal container according to the present invention
- FIG. 2 is a schematic diagram showing the detailed principle of a first embodiment of a terminal container security control method according to the present invention
- FIG. 3 is a schematic diagram of still another detailed principle of a first embodiment of a method for controlling the security of a terminal container according to the present invention
- FIG. 4 is a schematic diagram of still another detailed principle of a first embodiment of a method for controlling the security of a terminal container according to the present invention
- FIG. 5 is a schematic structural diagram of Embodiment 2 of a terminal container safety control system according to the present invention.
- the terminal of the present invention includes, but is not limited to, a smartphone, a tablet, and the like.
- Embodiment 1 is a diagrammatic representation of Embodiment 1:
- FIG. 1 is a flow chart showing an embodiment of a method for controlling the security of a terminal container according to the present invention, including:
- Step S101 responsive to the click instruction of the target application, determining whether the target application is an entry application to enter the secure container, and if yes, entering the secure container;
- a container refers to the operating environment of a group of applications. This group of applications can be distributed to devices from the MDM mobile management platform.
- the MDM client belongs to the in-container application.
- the MDM mobile management platform can issue a container policy, that is, when the group of applications runs (the top-level activity is the application), the MDM client applies the policy (such as switching APNs and the like).
- a broadcast is sent.
- the broadcast ACTION is "com.pekall.action.TOP_PACKAGE" with the parameter Intent.putExtra("toppackage", current package name), ie the container change trigger is the top-level activity.
- the schematic diagram is shown in Figure 2.
- Step S102 respond to the VPDN creation instruction, disconnect the Internet, create a VPDN, and connect;
- the terminal will preset an application that creates and connects to vpdn.
- the vpdn configuration information is provided by the client.
- the network is automatically disconnected before the creation. If the vpdn is created successfully, the user prompts, otherwise the prompt fails, exits the application, and connects to the Internet.
- Step S103 After determining that the VPDN connection is successful, responding to the SIM card information verification command, transmitting the SIM card information of the terminal to the preset security authentication server through the VPDN channel, and verifying whether the SIM card of the terminal is in the preset security authentication service. There is a registration record at the end;
- the SIM card information can be obtained by scanning the two-dimensional code corresponding to the SIM card information of the terminal. After the vpdn connection is successful, the user is prompted to scan the QR code provided by the SIM vendor, and the scan information is transmitted to the preset security authentication service through the VPDN channel. Performing SIM card information verification comparison, verifying whether the SIM card of the terminal has a registration record on the preset security authentication server, and returning a success message after the verification is passed, and pushing the preset application and policy; otherwise, prompting the SIM card The identity information does not match, the application is quit, and the Internet is connected. The process is shown in Figure 3.
- Step S104 After receiving the verification pass message of the preset security authentication server, enter the target application and invoke a preset secure container policy;
- the secure container policy can include:
- the representative After receiving the verification pass message of the preset security authentication server, the representative completely enters the secure container, enters the target application that is initially clicked, and simultaneously invokes the security container preset policy:
- the VPDN is already configured and connected.
- a "Hidden” field is added to all APNs in the TelephonyProvider class, and the value is 0, which means the default display.
- assign a value of 1 to the "Hidden” field of the APN indicating that it is hidden.
- the Setting class will load the apn database. At this time, the "Hidden” field is determined. If the value is 1, it will not be displayed, and the VPDN configuration information is protected.
- the control steps are divided into system attribute setting and function control.
- the MDM application inside the container will immediately call the interface function that sets the system property value of the data connection.
- the inside of the container uses the server push installation application to install the application.
- the USB shielding method is the same as the data connection control, and the system attribute value is set and read. Take the implementation.
- the security control of the mobile phone device mainly includes the shielding of the camera, the paste version, the SD card, the screen capture, the screen recording, the GPS, etc., and blocks the inflow of the Trojan hacker from the hardware, thereby achieving the purpose of ensuring the security of the user information.
- the above four modules are encapsulated into corresponding strategies, namely application strategy: ApplicationPolicy getApplicationPolicy(); data connection strategy: PhoneRestrictionPolicy getPhoneRestrictionPolicy(); device control policy: RestrictionPolicy getRestrictionPolicy(); APN control strategy getAnpPolicy().
- the solution implementation within the strategy can be implemented according to the user, and has the characteristics of simple and easy to expand. It is suitable for most government and enterprise users.
- the security container strategy design is shown in Figure 4.
- Embodiment 2 is a diagrammatic representation of Embodiment 1:
- FIG. 5 is a schematic structural view of an embodiment of a control system for terminal container security according to the present invention, including:
- the inside and outside of the container discriminating module 101 is configured to determine whether the target application is an entry application to enter the secure container in response to a click instruction to the target application, and if yes, enter the secure container;
- the security authentication module 102 is configured to respond to the VPDN creation instruction, disconnect the Internet, create a VPDN and connect; after determining that the VPDN connection is successful, respond to the SIM card information verification instruction, and transmit the SIM card information of the terminal to the preset security authentication service through the VPDN channel. End, verifying whether the SIM card of the terminal has a registration record on the preset security authentication server;
- the in-container policy invoking module 103 is configured to enter the target application after receiving the verification pass message of the preset secure authentication server, and simultaneously invoke a preset secure container policy;
- the secure container policy can include:
- the inside and outside container discriminating module 101 determines whether the target application is an entry application into the secure container, and if so, enters the secure container; the security authentication module 102 disconnects the Internet, creates a VPDN and After the VPDN connection is successful, the SIM card information of the terminal is transmitted to the preset security authentication server through the VPDN channel, and the SIM card of the terminal is verified to have a registration record on the preset security authentication server; Afterwards, the target application is entered, and the in-container policy invoking module 103 invokes a preset security policy, hides the APN configuration information, disables the data connection path, shields the USB function, and disables the terminal's preset disabled device function.
- Secure containers can be provided for applications that need to protect customer privacy. All applications can run on the same system without having to allocate extra memory and space, which can easily and efficiently protect end user data security.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Telephone Function (AREA)
- Telephonic Communication Services (AREA)
Abstract
一种终端容器安全的控制方法与系统,所述方法包括:响应对目标应用的点击指令,判断目标应用是否为进入安全容器的入口应用,若是,则进入安全容器(S101);响应VPDN创建指令,断开互联网,创建VPDN并连接(S102);确定VPDN连接成功后,响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录(S103);在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略(S104),可以为需要保护客户隐私的应用提供安全容器,所有的应用程序可在同一系统中运行,不必分配额外的内存和空间,可以简单高效的保护终端用户的数据安全。
Description
本申请要求于2015年12月31日提交中国专利局,申请号为201511031383.X、发明名称为“一种终端容器安全的控制方法与系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
本发明涉及终端信息安全领域,特别是涉及一种终端容器安全的控制方法与系统。
自从手机智能化和网络化介入之后,所带来功能和使用效率的提升,既为手机用户提供了非常大的帮助,同时也将一些安全隐患带到人们面前。
现有的手机安全方案较少,一些公司推出双系统方案,在独立的安全系统中实现手机的安全策略,保障用户的信息的安全,为安全系统预留单独的数据分区,同标准系统独立开来。该方法能够有效保障用户数据的独立性,保障用户数据的隐私,但是双系统同时运行不仅制造成本高,且需要为安全系统预分配内存,加大电量消耗,运行成本也较高,不能简单高效地保障手机用户数据安全。
发明内容
有鉴于此,本发明的主要目的在于提供一种终端容器安全的控制方法与系统,可以为手机应用提供安全容器,保障容器内应用的运行安全。
为实现上述目的,本发明提供了一种终端容器安全的控制方法,包括:
响应对目标应用的点击指令,判断所述目标应用是否为进入安全容器的入口应用,若是,则进入所述安全容器;
响应VPDN创建指令,断开互联网,创建VPDN并连接;
确定VPDN连接成功后,响应SIM卡信息核实指令将终端的SIM卡信息
通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;
在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略。
优选地,所述安全容器策略包括:
隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。
优选地,所述判断所述目标应用是否为进入安全容器的入口应用包括:
判断对所述目标应用的点击所发送的广播中的包名参数是否为所述安全容器预设的应用包名。
优选地,所述响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端前还包括:
响应所述终端的SIM卡信息对应的二维码的扫描指令,获取所述终端的SIM卡信息。
优选地,所述预设禁用设备功能包括照相机功能、粘贴板功能、SD卡功能、截屏功能、录屏功能和GPS功能。
优选地,所述安全容器策略还包括:
推送目标应用内预置应用的下载。
优选地,所述隐藏APN的配置信息包括:
对所述APN的配置信息进行预设的隐藏字段赋值。
本发明还提供了一种终端容器安全的控制系统,包括:
容器内外判别模块,用于响应对目标应用的点击指令,判断所述目标应用是否为进入安全容器的入口应用,若是,则进入所述安全容器;
安全认证模块,用于响应VPDN创建指令,断开互联网,创建VPDN并连接;确定VPDN连接成功后,响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;
容器内策略调用模块,用于在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略。
优选地,所述安全容器策略包括:
隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。
优选地,所述预设禁用设备功能包括照相机功能、粘贴板功能、SD卡功能、截屏功能、录屏功能和GPS功能。
应用本发明提供的一种终端容器安全的控制方法与系统,判断目标应用是否为进入安全容器的入口应用,若是,则进入安全容器;断开互联网,创建VPDN并连接;确定VPDN连接成功后,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;在验证通过后,进入所述目标应用,同时调用预设的安全策略,可以为需要保护客户隐私的应用提供安全容器,所有的应用程序可在同一系统中运行,不必分配额外的内存和空间,可以简单高效的保护终端用户的数据安全。
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据提供的附图获得其他的附图。
图1为本发明一种终端容器安全的控制方法实施例一的流程图;
图2为本发明一种终端容器安全的控制方法实施例一的详细原理示意图;
图3为本发明一种终端容器安全的控制方法实施例一的又一详细原理示意图;
图4为本发明一种终端容器安全的控制方法实施例一的又一详细原理示意图;
图5为本发明一种终端容器安全的控制系统实施例二的结构示意图。
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是
全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
本发明所述终端包括但不限于智能手机、平板电脑等。
实施例一:
本发明提供了一种终端容器安全的控制方法,图1示出了本发明终端容器安全的控制方法实施例的流程图,包括:
步骤S101:响应对目标应用的点击指令,判断所述目标应用是否为进入安全容器的入口应用,若是,则进入所述安全容器;
容器专指一组应用的运行环境,这组应用可以从MDM移动管理平台分发给设备,默认情况下,MDM客户端属于容器内应用。MDM移动管理平台可以下发容器策略,即当这组应用运行时(顶层活动为该应用),MDM客户端应用该策略(比如切换APN等行为)。当顶层活动发生变化时,会发送一个广播,广播的ACTION为“com.pekall.action.TOP_PACKAGE”,并且带参数Intent.putExtra(“toppackage”,当前包名),即容器变化触发者是顶层活动发生改变并且参数中“包名”为手机设定的“应用包名”的广播,判断所述目标应用是否为进入安全容器的入口应用即通过:判断对目标应用的点击所发送的广播中的包名参数是否为安全容器预设的应用包名来实现,原理图如图2所示。
步骤S102:响应VPDN创建指令,断开互联网,创建VPDN并连接;
终端会预置一个创建并连接vpdn的应用,vpdn配置信息由客户提供,创建前自动断开互联网,如果vpdn创建成功,给出用户提示,否则提示失败,退出应用,连接互联网。
步骤S103:确定VPDN连接成功后,响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;
SIM卡信息可通过对终端SIM卡信息对应的二维码的扫描获取,在vpdn连接成功后,提示用户扫描SIM商提供的二维码,并且把扫描信息通过VPDN通道传递给预设安全认证服务端进行SIM卡信息核实比对,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录,验证通过则返回成功消息,并且推送预置的应用和策略;否则提示SIM卡身份信息不匹配,退出应用,连接互联网,流程如图3所示。
步骤S104:在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略;
所述安全容器策略可包括:
隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。
当收到预设的安全认证服务器的验证通过消息后,代表完全进入安全容器,进入最初点击的目标应用,并同时调用安全容器预设的策略:
(1)APN安全控制
为了保护用户的vpdn信息,需要对APN的配置信息进行隐藏处理。点击应用进入容器内部时,VPDN已经配置好并且连接上,为了方便控制APN的显示或者隐藏,在TelephonyProvider类中为所有APN添加一个”Hidden”字段,并且赋值为0,代表默认显示。在配置VPDN时,为该APN的”Hidden”字段赋值为1,表示隐藏。当用户点击设置页面去查看APN列表时,Setting类会去加载apn数据库,此时,进行”Hidden”字段判定,如果值为1就不予显示,达到对VPDN配置信息进行保护的目的。
(2)数据连接安全控制
为了防止用户隐私信息被木马获取,就需要截断所有木马流入的数据连接途径,包括wifi,Bluetooth,mms,sms。
控制的步骤分为系统属性设定和功能控制,当进入容器内部时,容器内部的MDM应用会立即调用设置数据连接的系统属性值的接口函数。它们的接口函数分别为:boolean allowOutgoingWifi(boolean allow),boolean allowOutgoingBluetooth(boolean allow),boolean allowOutgoingMms(boolean allow),boolean allowOutgoingSms(boolean allow);当数据功能被启动时,通过读取系统属性值来判断是否进行数据连接流程,比如wifi的属性“persist.yulong.mdm.wifi”=1,说明在容器内,不允许进行数据连接,立即返回,从而实现对数据连接的安全控制。
(3)应用安装安全控制
容器内部采用服务器推送安装应用的方式进行应用安装,通过屏蔽USB功能和应用来源判断阻止用户或者黑客在容器内部进行应用安装,USB屏蔽方法和数据连接控制一样,通过系统属性值的设定和读取实现。
(4)手机设备安全控制
手机设备的安全控制主要包括照相机、粘贴版、SD卡、截屏、录屏、GPS等设备的屏蔽,从硬件上阻断木马黑客的流入,从而到达保障用户信息安全性目的。为了便于方案的普及和扩展,把以上四个模块封装成相应的策略,分别是应用策略:ApplicationPolicy getApplicationPolicy();数据连接策略:PhoneRestrictionPolicy getPhoneRestrictionPolicy();设备控制策略:RestrictionPolicy getRestrictionPolicy();APN控制策略getAnpPolicy()。策略内部的方案实现可以根据用户具体实现,具有简单易扩展的特点,适用于大部分政企用户,安全容器策略设计如图4所示。
应用本实施例提供的一种终端容器安全的控制方法,判断目标应用是否为进入安全容器的入口应用,若是,则进入安全容器;断开互联网,创建VPDN并连接;确定VPDN连接成功后,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;在验证通过后,进入所述目标应用,同时调用预设的安全策略,隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。可以为需要保护客户隐私的应用提供安全容器,所有的应用程序可在同一系统中运行,不必分配额外的内存和空间,可以简单高效的保护终端用户的数据安全。
实施例二:
本发明还提供了一种终端容器安全的控制系统,图5示出了本发明终端容器安全的控制系统实施例结构示意图,包括:
容器内外判别模块101,用于响应对目标应用的点击指令,判断所述目标应用是否为进入安全容器的入口应用,若是,则进入所述安全容器;
安全认证模块102,用于响应VPDN创建指令,断开互联网,创建VPDN并连接;确定VPDN连接成功后,响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;
容器内策略调用模块103,用于在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略;
所述安全容器策略可包括:
隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。
应用本实施例提供的一种终端容器安全的控制系统,容器内外判别模块101判断目标应用是否为进入安全容器的入口应用,若是,则进入安全容器;安全认证模块102断开互联网,创建VPDN并连接;确定VPDN连接成功后,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;在验证通过后,进入所述目标应用,同时容器内策略调用模块103调用预设的安全策略,隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。可以为需要保护客户隐私的应用提供安全容器,所有的应用程序可在同一系统中运行,不必分配额外的内存和空间,可以简单高效的保护终端用户的数据安全。
需要说明的是,本说明书中的各个实施例均采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似的部分互相参见即可。对于系统类实施例而言,由于其与方法实施例基本相似,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
最后,还需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者设备中还存在另外的相同要素。
以上对本发明所提供的方法和系统进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的一般技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本发明的限制。
Claims (10)
- 一种终端容器安全的控制方法,其特征在于,包括:响应对目标应用的点击指令,判断所述目标应用是否为进入安全容器的入口应用,若是,则进入所述安全容器;响应VPDN创建指令,断开互联网,创建VPDN并连接;确定VPDN连接成功后,响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略。
- 根据权利要求1所述的终端容器安全的控制方法,其特征在于,所述安全容器策略包括:隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。
- 根据权利要求1所述的终端容器安全的控制方法,其特征在于,所述判断所述目标应用是否为进入安全容器的入口应用包括:判断对所述目标应用的点击所发送的广播中的包名参数是否为所述安全容器预设的应用包名。
- 根据权利要求1所述的终端容器安全的控制方法,其特征在于,所述响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端前还包括:响应所述终端的SIM卡信息对应的二维码的扫描指令,获取所述终端的SIM卡信息。
- 根据权利要求2所述的终端容器安全的控制方法,其特征在于,所述预设禁用设备功能包括照相机功能、粘贴板功能、SD卡功能、截屏功能、录屏功能和GPS功能。
- 根据权利要求2所述的终端容器安全的控制方法,其特征在于,所述安全容器策略还包括:推送目标应用内预置应用的下载。
- 根据权利要求2所述的终端容器安全的控制方法,其特征在于,所述隐藏APN的配置信息包括:对所述APN的配置信息进行预设的隐藏字段赋值。
- 一种终端容器安全的控制系统,其特征在于,包括:容器内外判别模块,用于响应对目标应用的点击指令,判断所述目标应用是否为进入安全容器的入口应用,若是,则进入所述安全容器;安全认证模块,用于响应VPDN创建指令,断开互联网,创建VPDN并连接;确定VPDN连接成功后,响应SIM卡信息核实指令,将终端的SIM卡信息通过VPDN通道传递给预设安全认证服务端,验证所述终端的SIM卡是否在所述预设安全认证服务端有注册记录;容器内策略调用模块,用于在收到所述预设安全认证服务器的验证通过消息后,进入所述目标应用,同时调用预设的安全容器策略。
- 根据权利要求8所述的终端容器安全的控制系统,所述安全容器策略包括:隐藏APN的配置信息,禁用数据连接途径,屏蔽USB功能以及禁用终端的预设禁用设备功能。
- 根据权利要求9所述的终端容器安全的控制系统,其特征在于,所述预设禁用设备功能包括照相机功能、粘贴板功能、SD卡功能、截屏功能、录屏功能和GPS功能。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201511031383.XA CN105550577A (zh) | 2015-12-31 | 2015-12-31 | 一种终端容器安全的控制方法与系统 |
| CN201511031383.X | 2015-12-31 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017113584A1 true WO2017113584A1 (zh) | 2017-07-06 |
Family
ID=55829764
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2016/084103 Ceased WO2017113584A1 (zh) | 2015-12-31 | 2016-05-31 | 一种终端容器安全的控制方法与系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN105550577A (zh) |
| WO (1) | WO2017113584A1 (zh) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105550577A (zh) * | 2015-12-31 | 2016-05-04 | 宇龙计算机通信科技(深圳)有限公司 | 一种终端容器安全的控制方法与系统 |
| US10650138B2 (en) * | 2017-01-27 | 2020-05-12 | Hewlett Packard Enterprise Development Lp | System call policies for containers |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050125661A1 (en) * | 2003-11-07 | 2005-06-09 | Nokia Corporation | Operator root cetificates |
| CN103581184A (zh) * | 2013-10-31 | 2014-02-12 | 中国电子科技集团公司第十五研究所 | 移动终端访问企业内网服务器的方法和系统 |
| CN103618736A (zh) * | 2013-12-09 | 2014-03-05 | 成都达信通通讯设备有限公司 | 移动终端自动切换不同通道联网接口的安全应用系统 |
| CN103619020A (zh) * | 2013-12-09 | 2014-03-05 | 成都达信通通讯设备有限公司 | 无线数据专网物理隔离互联网的移动支付安全系统 |
| CN105550577A (zh) * | 2015-12-31 | 2016-05-04 | 宇龙计算机通信科技(深圳)有限公司 | 一种终端容器安全的控制方法与系统 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20140108793A1 (en) * | 2012-10-16 | 2014-04-17 | Citrix Systems, Inc. | Controlling mobile device access to secure data |
-
2015
- 2015-12-31 CN CN201511031383.XA patent/CN105550577A/zh active Pending
-
2016
- 2016-05-31 WO PCT/CN2016/084103 patent/WO2017113584A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050125661A1 (en) * | 2003-11-07 | 2005-06-09 | Nokia Corporation | Operator root cetificates |
| CN103581184A (zh) * | 2013-10-31 | 2014-02-12 | 中国电子科技集团公司第十五研究所 | 移动终端访问企业内网服务器的方法和系统 |
| CN103618736A (zh) * | 2013-12-09 | 2014-03-05 | 成都达信通通讯设备有限公司 | 移动终端自动切换不同通道联网接口的安全应用系统 |
| CN103619020A (zh) * | 2013-12-09 | 2014-03-05 | 成都达信通通讯设备有限公司 | 无线数据专网物理隔离互联网的移动支付安全系统 |
| CN105550577A (zh) * | 2015-12-31 | 2016-05-04 | 宇龙计算机通信科技(深圳)有限公司 | 一种终端容器安全的控制方法与系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105550577A (zh) | 2016-05-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11729594B2 (en) | Network access method, device, and system | |
| US20170317827A1 (en) | Electronic stamp system for security intensification, control method thereof, and non-transitory computer readable storage medium having computer program recorded thereon | |
| CN104092542B (zh) | 一种账号登录方法、装置及系统 | |
| US10623530B2 (en) | Device for supporting communication between multiple types of safety carriers and communication method therefor | |
| US11063934B2 (en) | Information pushing method, server, sharer client and third-party client | |
| CN104469737B (zh) | 一种嵌入式通用集成电路卡及其用户签约信息激活方法 | |
| CN103856446A (zh) | 一种登录方法、装置及开放平台系统 | |
| CN104967997A (zh) | 一种无线网路接入方法、Wi-Fi设备、终端设备及系统 | |
| EP3533247B1 (en) | Wireless network type detection method and electronic device | |
| CN104980448B (zh) | 一种远程监控方法、装置及系统 | |
| CN104794374A (zh) | 一种用于安卓系统的应用权限管理方法和装置 | |
| US9898600B2 (en) | Method and apparatus for managing application data of portable terminal | |
| CN105608349A (zh) | 终端模式切换方法及装置、终端 | |
| CN103533520A (zh) | 用于在通信网络环境中提供电子设备的远程通信的装置和方法 | |
| WO2017113584A1 (zh) | 一种终端容器安全的控制方法与系统 | |
| CN108494749B (zh) | Ip地址禁用的方法、装置、设备及计算机可读存储介质 | |
| WO2019071927A1 (zh) | 授权信息获取方法、装置、电子设备及可读存储介质 | |
| CN105095702B (zh) | 一种超级用户权限控制方法及装置 | |
| KR102054424B1 (ko) | 사용자 단말과의 복수 채널 인증을 지원하는 보안 서비스 제공 시스템 및 방법, 그리고 컴퓨터 프로그램이 기록된 비휘발성 기록매체 | |
| KR101961714B1 (ko) | 사용자 단말과의 복수 채널 인증 기반 보안 서비스 제공 시스템 및 방법, 그리고 컴퓨터 프로그램이 기록된 비휘발성 기록매체 | |
| WO2017148337A1 (zh) | 终端服务的提供、获取方法、装置及终端 | |
| US12170896B2 (en) | Cloud profile | |
| US20250071547A1 (en) | Cloud Profile | |
| KR102054421B1 (ko) | 복수 채널 인증을 지원하는 보안 서비스 제공 시스템 및 방법, 그리고 컴퓨터 프로그램이 기록된 비휘발성 기록매체 | |
| KR102399456B1 (ko) | 디지털 보조 장치를 이용한 음성 통화 서비스 시스템, 그 방법 및 컴퓨터 프로그램이 기록된 비휘발성 기록매체 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 16880392 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 16880392 Country of ref document: EP Kind code of ref document: A1 |