Ó¦ÓÃÉ̵êÈÏÖ¤ÌåϵµÄµ×²ãÂß¼
ÔÚiosϵͳ¼Ü¹¹ÖУ¬ÆóÒµ¼¶Ö¤ÊéÇ©Ãû£¨Enterprise Certificate Signing£©ÊÇÈ·±£Ó¦ÓÃÄþ¾²µÄ½¹µã·ÀÏß¡£Ã¿¿î¹Ù·½ÈÏÖ¤Èí¼þ¶¼Ðèͨ¹ýÆ»¹ûɳºÐ»úÖÆµÄ°ËÖØÄþ¾²¼ì²â£¬Éæ¼°¶¯Ì¬´úÂëɨÃè¡¢ÄÚ´æÊ¹Óüà²âµÈÒªº¦¼¼Êõ²ã¡£ÓëÖ®Ïà¶Ô£¬²¿ÃÅδ¾ÑéÖ¤µÄËùν"¹Ù·½Õý°æ"°²×°°ü³£ÈƹýApp StoreÉóºËÌåϵ£¬Æä°üÂ޵ĶñÒâSDK¿ÉÄÜÇÔÈ¡Óû§Òþ˽Êý¾Ý¡£Æ¾¾Ý2023ÄêÒÆ¶¯Äþ¾²Ä걨ͳ¼Æ£¬´ËÀà·Ç·¨ÇþµÀÏÂÔØÓ¦ÓõÄϵͳȨÏÞÀÄÓð¸Àýͬ±ÈÉÏÉý37%¡£
µÚÈý·½Æ½Ì¨µÄÄþ¾²Òþ»¼Æ×ϵ
·Ç¹Ù·½·Ö·¢ÇþµÀ´æÔڵļ¼Êõ·çÏÕ·ºÆð¶àÔª»¯ÌØÕ÷¡£Í¨¹ýÄæÏò¹¤³Ì²âÊÔ·¢ÏÖ£¬²¿Ãű»ÆÆ½âµÄipaÎļþ£¨iOS Application Package£©±»Ö²ÈëÔ¶³Ì¿ØÖÆÄ£¿é£¬ÆäͨѶÐÒé¶Ë¿Ú¾³£Î´°´Apple¿ª·¢Õ߹淶ÉèÖüÓÃÜËíµÀ¡£¸üÖµµÃ¾¯ÌèµÄÊÇ£¬ÕâЩ¾¹ý¶þ´Î°ü×°µÄ°²×°°ü»áαÔìÈí¼þÊý×ÖÇ©Ãû£¨Code Signature£©£¬ÔÚÉ豸ÈÕÖ¾ÖÐÏÔʾΪ"ÒÑÑéÖ¤"״̬£¬ÊµÖÊÈ´¿ªÆôÁËÏà»ú¡¢Âó¿Ë·çµÈÃô¸ÐÓ²¼þµÄµ×²ãµ÷ÓÃȨÏÞ¡£
É豸Äþ¾²·À»¤¼¼ÊõÉý¼¶Â·¾¶
iOS 17ϵͳ×îÐÂÒýÈëµÄÒþ˽ȨÏÞ×·Ëݹ¦Ð§£¨Privacy Tracing Module£©ÄÜÓÐЧʶ±ðÒì³£ºǫ́Ô˶¯¡£Óû§¿ÉÔÚÉèÖÃÖеÄ"Òþ˽·ÖÎö"Ä£¿é²éÔĸ÷Ó¦ÓõÄϵͳµ÷ÓÃÈÕÖ¾£¬µ±¼ì²âµ½¸ßƵ¶¨Î»ÇëÇó»òͨѶ¼¶ÁÈ¡ÐÐΪʱ£¬ÏµÍ³»á×Ô¶¯´¥·¢Äþ¾²¸ôÀë»úÖÆ¡£ÅäºÏÉ豸ÖÎÀíÆ÷£¨Mobile Device Management£©µÄÅäÖÃÕ½ÂÔ£¬¿ÉÇ¿ÖÆ×è¶Ïδ¾ÑéÖ¤Ö¤ÊéµÄÓ¦Ó÷¨Ê½ÔËÐС£
Õýµ±°²×°Í¾¾¶µÄ¼¼ÊõÑéÖ¤ÒªÁì
·Ö±æ¹Ù·½À´Ô´Ó¦ÓÃÐè¹Ø×¢Èý¸ö¼¼Êõά¶È£ºÊǼì²éÓ¦ÓÃÃèÊöÎļþµÄÖ¤Êé·¢±í»ú¹¹£¬Õý°æÈí¼þÖ¤Êé¾ùÏÔʾΪApple Worldwide Developer Relations£»Ó¦ºË¶Ô°²×°°üµÄ¹þÏ£Öµ£¨SHA-256 Checksum£©£¬¿ÉÔÚÆ»¹û¿ª·¢Õß¹ÙÍøÑéÖ¤±àÒë²úÎïµÄΨһÐÔ£»ÐèÁôÒâÓ¦ÓÃÊ×´ÎÆô¶¯Ê±µÄ¹«Ö¤ÑéÖ¤£¨Notarization£©Ê±³¤£¬Í¨¹ý¶ñÒâ´úÂë×¢ÈëµÄαӦÓÃÍùÍùȱ·¦ÍêÕûµÄ¹«Ö¤Á÷³Ì¡£
ϵͳ¼¶Äþ¾²·À»¤µÄ¼¼Êõʵ¼ù
½¨ÒéÓû§¿ªÆôϵͳÍêÕûÐÔÑÚ»¤£¨System Integrity Protection£©¹¦Ð§£¬¸Ã»úÖÆÍ¨¹ýÄں˼¶·À»¤ËøËÀÃô¸ÐϵͳĿ¼¡£µ±¼ì²âµ½Î´¾ÊÚȨµÄ´úÂëÐÞ¸Äʱ£¬ÏµÍ³»á×Ô¶¯»Ö»Ø¸´Ê¼Îļþ½á¹¹¡£ÅäºÏApp´«ÊäÄþ¾²£¨ATS£©ÐÒéµÄÇ¿ÖÆÊµÊ©£¬ÄÜÓÐЧÀ¹½ØÍ¨¹ýαװµÄÖмäÈ˹¥»÷£¨MITM Attack£©£¬È·±£Ó¦ÓÃͨÐÅÀú³ÌµÄÊý¾Ý¼ÓÃÜÇ¿¶È¡£
ÔÚÊý×ÖÄþ¾²·À»¤ÁìÓò£¬ÏµÍ³¼Ü¹¹µÄ·À»¤ÄÜÁ¦ÓëÓû§µÄÄþ¾²ÒâʶͬµÈÖØÒª¡£iOSÉú̬ͨ¹ý¶à²ã¼¼ÊõÑéÖ¤¹¹ÖþÓ¦ÓÃÄþ¾²·ÀÏߣ¬µ«ÈËΪ¹æ±Ü¹Ù·½ÈÏÖ¤»úÖÆÈÔ¿ÉÄÜ´ò¿ªÏµÍ³·À»¤È±¿Ú¡£½¨ÒéÖÕ¶ËÓû§ÑϸñÖ´ÐÐϵͳ¸üÐÂÕ½ÂÔ£¬ÉÆÓÃÉ豸×Ô´øµÄÄþ¾²·ÖÎö¹¤¾ß£¬ÅäºÏά»¤Òƶ¯Ó¦ÓÃÉú̬µÄÁ¼ÐÔÉú³¤¡£Ó¦ÓÃÉ̵êÈÏÖ¤ÌåϵµÄµ×²ãÂß¼
ÔÚiosϵͳ¼Ü¹¹ÖУ¬ÆóÒµ¼¶Ö¤ÊéÇ©Ãû£¨Enterprise Certificate Signing£©ÊÇÈ·±£Ó¦ÓÃÄþ¾²µÄ½¹µã·ÀÏß¡£Ã¿¿î¹Ù·½ÈÏÖ¤Èí¼þ¶¼Ðèͨ¹ýÆ»¹ûɳºÐ»úÖÆµÄ°ËÖØÄþ¾²¼ì²â£¬Éæ¼°¶¯Ì¬´úÂëɨÃè¡¢ÄÚ´æÊ¹Óüà²âµÈÒªº¦¼¼Êõ²ã¡£ÓëÖ®Ïà¶Ô£¬²¿ÃÅδ¾ÑéÖ¤µÄËùν"¹Ù·½Õý°æ"°²×°°ü³£ÈƹýApp StoreÉóºËÌåϵ£¬Æä°üÂ޵ĶñÒâSDK¿ÉÄÜÇÔÈ¡Óû§Òþ˽Êý¾Ý¡£Æ¾¾Ý2023ÄêÒÆ¶¯Äþ¾²Ä걨ͳ¼Æ£¬´ËÀà·Ç·¨ÇþµÀÏÂÔØÓ¦ÓõÄϵͳȨÏÞÀÄÓð¸Àýͬ±ÈÉÏÉý37%¡£
µÚÈý·½Æ½Ì¨µÄÄþ¾²Òþ»¼Æ×ϵ
·Ç¹Ù·½·Ö·¢ÇþµÀ´æÔڵļ¼Êõ·çÏÕ·ºÆð¶àÔª»¯ÌØÕ÷¡£Í¨¹ýÄæÏò¹¤³Ì²âÊÔ·¢ÏÖ£¬²¿Ãű»ÆÆ½âµÄipaÎļþ£¨iOS Application Package£©±»Ö²ÈëÔ¶³Ì¿ØÖÆÄ£¿é£¬ÆäͨѶÐÒé¶Ë¿Ú¾³£Î´°´Apple¿ª·¢Õ߹淶ÉèÖüÓÃÜËíµÀ¡£¸üÖµµÃ¾¯ÌèµÄÊÇ£¬ÕâЩ¾¹ý¶þ´Î°ü×°µÄ°²×°°ü»áαÔìÈí¼þÊý×ÖÇ©Ãû£¨Code Signature£©£¬ÔÚÉ豸ÈÕÖ¾ÖÐÏÔʾΪ"ÒÑÑéÖ¤"״̬£¬ÊµÖÊÈ´¿ªÆôÁËÏà»ú¡¢Âó¿Ë·çµÈÃô¸ÐÓ²¼þµÄµ×²ãµ÷ÓÃȨÏÞ¡£
É豸Äþ¾²·À»¤¼¼ÊõÉý¼¶Â·¾¶
iOS 17ϵͳ×îÐÂÒýÈëµÄÒþ˽ȨÏÞ×·Ëݹ¦Ð§£¨Privacy Tracing Module£©ÄÜÓÐЧʶ±ðÒì³£ºǫ́Ô˶¯¡£Óû§¿ÉÔÚÉèÖÃÖеÄ"Òþ˽·ÖÎö"Ä£¿é²éÔĸ÷Ó¦ÓõÄϵͳµ÷ÓÃÈÕÖ¾£¬µ±¼ì²âµ½¸ßƵ¶¨Î»ÇëÇó»òͨѶ¼¶ÁÈ¡ÐÐΪʱ£¬ÏµÍ³»á×Ô¶¯´¥·¢Äþ¾²¸ôÀë»úÖÆ¡£ÅäºÏÉ豸ÖÎÀíÆ÷£¨Mobile Device Management£©µÄÅäÖÃÕ½ÂÔ£¬¿ÉÇ¿ÖÆ×è¶Ïδ¾ÑéÖ¤Ö¤ÊéµÄÓ¦Ó÷¨Ê½ÔËÐС£
Õýµ±°²×°Í¾¾¶µÄ¼¼ÊõÑéÖ¤ÒªÁì
·Ö±æ¹Ù·½À´Ô´Ó¦ÓÃÐè¹Ø×¢Èý¸ö¼¼Êõά¶È£ºÊǼì²éÓ¦ÓÃÃèÊöÎļþµÄÖ¤Êé·¢±í»ú¹¹£¬Õý°æÈí¼þÖ¤Êé¾ùÏÔʾΪApple Worldwide Developer Relations£»Ó¦ºË¶Ô°²×°°üµÄ¹þÏ£Öµ£¨SHA-256 Checksum£©£¬¿ÉÔÚÆ»¹û¿ª·¢Õß¹ÙÍøÑéÖ¤±àÒë²úÎïµÄΨһÐÔ£»ÐèÁôÒâÓ¦ÓÃÊ×´ÎÆô¶¯Ê±µÄ¹«Ö¤ÑéÖ¤£¨Notarization£©Ê±³¤£¬Í¨¹ý¶ñÒâ´úÂë×¢ÈëµÄαӦÓÃÍùÍùȱ·¦ÍêÕûµÄ¹«Ö¤Á÷³Ì¡£
ϵͳ¼¶Äþ¾²·À»¤µÄ¼¼Êõʵ¼ù
½¨ÒéÓû§¿ªÆôϵͳÍêÕûÐÔÑÚ»¤£¨System Integrity Protection£©¹¦Ð§£¬¸Ã»úÖÆÍ¨¹ýÄں˼¶·À»¤ËøËÀÃô¸ÐϵͳĿ¼¡£µ±¼ì²âµ½Î´¾ÊÚȨµÄ´úÂëÐÞ¸Äʱ£¬ÏµÍ³»á×Ô¶¯»Ö»Ø¸´Ê¼Îļþ½á¹¹¡£ÅäºÏApp´«ÊäÄþ¾²£¨ATS£©ÐÒéµÄÇ¿ÖÆÊµÊ©£¬ÄÜÓÐЧÀ¹½ØÍ¨¹ýαװµÄÖмäÈ˹¥»÷£¨MITM Attack£©£¬È·±£Ó¦ÓÃͨÐÅÀú³ÌµÄÊý¾Ý¼ÓÃÜÇ¿¶È¡£
ÔÚÊý×ÖÄþ¾²·À»¤ÁìÓò£¬ÏµÍ³¼Ü¹¹µÄ·À»¤ÄÜÁ¦ÓëÓû§µÄÄþ¾²ÒâʶͬµÈÖØÒª¡£iOSÉú̬ͨ¹ý¶à²ã¼¼ÊõÑéÖ¤¹¹ÖþÓ¦ÓÃÄþ¾²·ÀÏߣ¬µ«ÈËΪ¹æ±Ü¹Ù·½ÈÏÖ¤»úÖÆÈÔ¿ÉÄÜ´ò¿ªÏµÍ³·À»¤È±¿Ú¡£½¨ÒéÖÕ¶ËÓû§ÑϸñÖ´ÐÐϵͳ¸üÐÂÕ½ÂÔ£¬ÉÆÓÃÉ豸×Ô´øµÄÄþ¾²·ÖÎö¹¤¾ß£¬ÅäºÏά»¤Òƶ¯Ó¦ÓÃÉú̬µÄÁ¼ÐÔÉú³¤¡£