Code obfuscation method, electronic device, storage medium, and program product
By using a pre-defined mapping table to decompile identifiers into unrecognizable form in Java code and adding reflection code templates that have no actual function, the problem of bytecode being easily decompiled is solved, thus improving code security.
Patent Information
- Application Number
- CN202511032637.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-25
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2045-07-25
AI Technical Summary
Bytecode generated during Java language development is easily decompiled into source code. While existing code renaming methods reduce readability, the code logic remains intact and visible, resulting in lower code security.
By obtaining the first code, the identifier is decompiled and made unrecognizable based on a preset mapping table, and a reflection code template with no actual function is added to the second code to generate the third code.
It improves code security, makes decompilation errors and renders the code unreadable, and enhances the code's protection.
Smart Images

Figure CN120541813B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, and particularly relates to a code obfuscation method, an electronic device, a storage medium and a program product. BACKGROUND
[0002] In the development process of JAVA (Java Programming Language), the generated byte code is easy to be decompiled into source code.
[0003] In the related art, the class name, the method name and the function name in the source code can be renamed, for example, the "user service" is replaced by a symbol "A", so that the attacker is difficult to guess the real value through the method of renaming, so as to reduce the readability of the code. However, in the above method, although the renaming can reduce the readability, the code logic is still complete and visible, and the attacker can infer the real intention of the code in combination with the context, so that the security of the code is low. SUMMARY
[0004] The present application provides a code obfuscation method, an electronic device, a storage medium and a program product to at least solve the problem of low security of the code.
[0005] The present application provides a code obfuscation method, comprising:
[0006] obtaining a first code, the first code comprising a plurality of first identifiers;
[0007] performing decompilation-unrecognizable processing on the plurality of first identifiers based on a preset mapping table to obtain a second code, the preset mapping table comprising a plurality of corresponding relationships between identifiers and symbols, and the symbols being decompilation-unrecognizable symbols;
[0008] determining a plurality of reflection code templates without actual functions;
[0009] adding the plurality of reflection code templates to the second code to obtain a third code.
[0010] The present application also provides a code obfuscation device, comprising a first obtaining module, a processing module, a first determining module and a second obtaining module, wherein:
[0011] The first obtaining module is configured to obtain a first code, the first code comprising a plurality of first identifiers;
[0012] The processing module is configured to perform decompilation-unrecognizable processing on the plurality of first identifiers based on a preset mapping table to obtain a second code, the preset mapping table comprising a plurality of corresponding relationships between identifiers and symbols, and the symbols being decompilation-unrecognizable symbols;
[0013] The first determining module is configured to determine a plurality of reflection code templates without actual functions.
[0014] The second obtaining module is configured to add the plurality of reflection code templates in the second code to obtain a third code.
[0015] The present application further provides an electronic device, comprising a memory configured to store a computer program, and a processor configured to execute the computer program to implement the steps of any of the code obfuscation methods.
[0016] The present application further provides a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of any of the code obfuscation methods.
[0017] The present application further provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the steps of any of the code obfuscation methods.
[0018] According to the present application, when code obfuscation is needed, a first code is obtained, the first code comprises a plurality of first identifiers; the plurality of first identifiers are processed to be unrecognized by a decompiler based on a preset mapping table to obtain a second code, the preset mapping table comprises a plurality of corresponding relationships between identifiers and symbols, and the symbols are symbols that are unrecognized by the decompiler; a plurality of reflection code templates without actual functions are determined; and the plurality of reflection code templates are added in the second code to obtain a third code. In this way, the first identifiers in the first code are processed to be unrecognized by the decompiler according to the preset mapping table, so that the decompilation is wrong, and the reflection code templates without actual functions are added, so that the code obtained by the decompilation loses readability without affecting normal compilation, and the security of the code is improved. BRIEF DESCRIPTION OF DRAWINGS
[0019] In order to more clearly illustrate the embodiments of the present application, the drawings needed in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0020] Figure 1 The system architecture schematic diagram provided for the embodiments of the present application;
[0021] Figure 2 The flowchart of the code obfuscation method provided for the embodiments of the present application;
[0022] Figure 3 The schematic diagram of adding a plurality of reflection code templates in the second code provided for the embodiments of the present application;
[0023] Figure 4 Another schematic diagram of adding a plurality of reflection code templates in the second code for the embodiments of the present application is provided;
[0024] Figure 5 A schematic diagram of a target position determination process for the embodiments of the present application is provided;
[0025] Figure 6 A schematic diagram of determining a target position for the embodiments of the present application is provided;
[0026] Figure 7 Another schematic diagram of determining a target position for the embodiments of the present application is provided;
[0027] Figure 8 A schematic diagram of an authorization process of the third code for the embodiments of the present application is provided;
[0028] Figure 9 A structural schematic diagram of a code obfuscation device for the embodiments of the present application is provided;
[0029] Figure 10 Another structural schematic diagram of a code obfuscation device for the embodiments of the present application is provided;
[0030] Figure 11 A structural schematic diagram of an electronic device provided by the present application is provided. DETAILED DESCRIPTION
[0031] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0032] It should be noted that, in the description of the present application, the terms “include”, “contain” or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or includes elements inherent to such process, method, article or device. The terms “first”, “second” and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence.
[0033] First, the terms involved in the present application are explained:
[0034] Decompilation: Decompilation is a process of converting a compiled computer program (such as binary files, bytecode) back to its source code or a form close to the source code. In contrast to compilation (converting source code into machine executable code), decompilation aims to reverse the high-level language representation of the original program by analyzing the structure, instructions and logic of the target code. This technique is often used for software analysis, bug fixing, learning from others' code, or system maintenance when source code is not available.
[0035] Software license authorization: Software license authorization refers to the legal behavior of software copyright owners granting specific rights and permissions to others to use their software through a license agreement. The license agreement clearly specifies how the authorized party can use the software (such as personal use, commercial use, modification or distribution), the scope of use (such as the number of installed devices, the number of users), time limitations and conditions to be met (such as copyright reservation, prohibition of reverse engineering).
[0036] In the related art, the class name, method name and function name in the source code can be renamed, for example, the "user service" is replaced by symbol "A", so that through the method of renaming, it is difficult for the attacker to guess the real value, thereby reducing the readability of the code. However, in the above method, although the renaming can reduce the readability, the code logic is still complete and visible, and the attacker can infer the real intention of the code in combination with the context, thereby resulting in low security of the code.
[0037] To solve the above problems, in the embodiments of the present application, when code obfuscation is needed, a first code is obtained, the first code includes a plurality of first identifiers; the plurality of first identifiers are processed to be decompilation-unrecognizable based on a preset mapping table to obtain a second code, the preset mapping table includes a plurality of corresponding relationships between identifiers and symbols, and the symbols are decompilation-unrecognizable symbols; a plurality of reflection code templates without actual functions are determined; a plurality of target positions are determined in the second code, the target positions are associated with code of non-critical steps corresponding to the second code; and the plurality of reflection code templates are added in the plurality of target positions to obtain a third code. In this way, through the above method, the first identifiers in the first code can be processed to be decompilation-unrecognizable according to the preset mapping table, so that the decompilation is wrong, and the reflection code templates without actual functions can be added in the non-critical positions of the second code, so that the code obtained by decompilation loses readability without affecting normal compilation, thereby improving the security of the code.
[0038] In order for those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0039] This section describes the specific application environment architecture or hardware architecture that the code obfuscation method depends on. (References) Figure 1 , Figure 1 This is a schematic diagram of the system architecture provided for an embodiment of this application. Please refer to [link / reference]. Figure 1 This includes a development terminal 101 and a user terminal 102. The development terminal 101 can be a terminal device for code developers, and the user terminal 102 can be a terminal device for users who use the code. The user terminal 102 can also be a terminal device for running the code developed on the development terminal 101. Developers can develop code on the development terminal 101, obfuscate the code, and send the obfuscated code to the user terminal 102. After receiving the code, the user terminal 102 can run it.
[0040] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0041] Figure 2 This is a flowchart illustrating the code obfuscation method provided in an embodiment of this application, as shown below. Figure 2 As shown, embodiments of this application provide a code obfuscation method, which is described in detail below:
[0042] S201, Obtain the first code.
[0043] The execution subject of this application embodiment can be a terminal device or a code obfuscation device installed in the terminal device. The code obfuscation device can be implemented by software or by a combination of software and hardware.
[0044] The first code can refer to the code written by the developers and ready for obfuscation. The first code can be code written in the Java language.
[0045] The first code may include multiple first identifiers, which can refer to names defined by developers for program elements (e.g., variables, functions, classes, interfaces, constants, etc.). Understandably, first identifiers can indicate the intent and function of the code; that is, they can improve code readability.
[0046] S202. Based on the preset mapping table, decompile multiple first identifiers to obtain unrecognizable code.
[0047] The preset mapping table can refer to a mapping table preset by a developer. The preset mapping table can include a plurality of identifier-symbol correspondence relationships, and the symbol is a symbol that cannot be recognized by decompilation, that is, the symbol will have an error or garbled code problem when being decompiled.
[0048] Optionally, in the identifier-symbol correspondence relationship, the symbol can be a single symbol or a combination of a plurality of symbols. The preset mapping table can be determined by the following method: determining a symbol set, the symbol set including a plurality of symbols that cannot be recognized by decompilation; for any one identifier, randomly selecting one or more symbols from the symbol set as a target set, and determining the target set as the symbol corresponding to the identifier.
[0049] For example, the preset mapping table can be as shown in Table 1, please refer to Table 1,
[0050] Table 1
[0051]
[0052] According to the preset mapping table shown in Table 1, it can be shown that the symbol corresponding to identifier 1 is "" ", the symbol corresponding to identifier 2 is "" ", the symbol corresponding to identifier 3 is "" ", and the symbol corresponding to identifier 4 is "" ".
[0053] The decompilation-unrecognizable processing can refer to: determining a plurality of first identifiers in the first code, for any one first identifier, determining a second identifier identical to the first identifier and a target symbol corresponding to the second identifier in the plurality of identifiers in the preset mapping table; and replacing the first identifier with the target symbol corresponding to the second identifier.
[0054] For example, assuming that the preset mapping table is as shown in Table 1, any one first identifier in the first code is identifier 3, then the second identifier can be determined as identifier 3 in the preset mapping table, and the target symbol corresponding to the second identifier is "" ", and the first identifier is replaced with the target symbol "" " corresponding to the second identifier.
[0055] The second code can refer to a code obtained by replacing the first identifier of the first code with the identifier and the symbol corresponding to the identifier according to the preset mapping table.
[0056] For example, assuming that the preset mapping table is as shown in Table 1, if the first code is "identifier 4=true", according to the preset mapping table, it can be determined that the symbol corresponding to identifier 4 is "" If the first identifier of the first code is replaced by the preset mapping table, the second code obtained is "a ".
[0057] S203, determining a plurality of reflection code templates without actual functions.
[0058] The reflection code template without actual functions can refer to a code set by a developer in advance and having no influence on a program running result.
[0059] For example, the reflection code template without actual functions can be a code of dynamically loading a non-existing class, a code of obtaining a non-existing method in the first code through reflection, a code of calling a meaningless method, a code of loading an empty loop, a code of loading a reflection logic not triggered, a code of loading a false reflection call, etc.
[0060] Determining the plurality of reflection code templates without actual functions further includes performing syntax legality detection on the plurality of reflection code templates to ensure that the plurality of reflection code templates can be normally compiled.
[0061] S204, adding the plurality of reflection code templates to the second code to obtain a third code.
[0062] The plurality of reflection code templates can be added to the second code in the following manner: determining a plurality of target positions in the second code; and adding the plurality of reflection code templates to the plurality of target positions to obtain the third code.
[0063] The target position is associated with a code of a non-key step corresponding to the second code. The non-key step can refer to an initialization block or a non-core logic branch of the first code. The initialization block can refer to a code running during class loading or object initialization. The non-core logic branch can refer to a secondary judgment, an empty judgment or an exception handling path in the program, i.e., the non-core logic branch is not the execution logic of the main function.
[0064] Next, the process of adding the reflection code template to the second code to obtain the third code is described in combination with Figure 3 and Figure 4 .
[0065] Figure 3 For the embodiment of the present application, a schematic diagram of adding the plurality of reflection code templates to the second code is provided, please refer to Figure 3 , which includes the second code, an initialization block and a target position. The second code includes the initialization block, and the target position is located in the initialization block, i.e., the reflection code template can be added to the target position in the initialization block.
[0066] Figure 4Another schematic diagram for adding multiple reflection code templates in the second code is provided in the embodiments of the present application, please refer to Figure 4 , including the second code, the non-core logic branch and the target position, wherein the second code includes the non-core logic branch, and the target position is located in the non-core logic branch, that is, the reflection code template can be added to the target position in the non-core logic branch.
[0067] Optionally, after obtaining the third code, the security level of the third code can be determined, and the security level of the third code can be used to indicate the probability that the third code cannot be decompiled. It can be understood that the higher the security level of the third code, the higher the probability that the third code cannot be decompiled, that is, the third code is safer; the lower the security level of the third code, the higher the probability that the third code is decompiled, that is, the third code is less safe.
[0068] The security level of the third code can be determined by determining the target parameters corresponding to each target symbol, and the target parameters are used to indicate the distribution probability of the target symbol in the third code; and determining the security level of the third code according to the distribution probability.
[0069] Suppose, represents the ith target symbol, represents the distribution probability of the target symbol in the third code, represents the logarithm of the distribution probability of the target symbol in the third code, and the security level of the third code can be represented as:
[0070]
[0071] Optionally, after obtaining the third code, the preset corresponding relationship is obtained, the preset corresponding relationship is used to indicate the relationship between the bytecode instruction and the redundant bytecode, and the redundant bytecode can refer to the inserted illegal but syntax correct instruction; a plurality of bytecode instructions are determined in the third code, and the corresponding redundant bytecode is added after the bytecode instruction in the third code according to the preset corresponding relationship.
[0072] For example, if the bytecode instruction is “throw an exception (ATHROW)”, the corresponding redundant bytecode can be “jump (GOTO)”; if the bytecode instruction is “return (RETURN)”, the corresponding redundant bytecode can be “empty (NOP)”; and if the bytecode instruction is “enter synchronization block (MONITORENTER)”, the corresponding redundant bytecode can be “exit synchronization block (MONITOREXIT)”.
[0073] In this way, by adding redundant bytecode after the bytecode instruction, the code conforms to the syntax, but there is no actual meaning or effect in logic, even if the code can run normally, but when the attacker decompiles the code, it will cause the attacker to fail to correctly restore the original program structure, so as to cause the decompilation error or increase the difficulty of decompilation, thereby improving the security of the code.
[0074] In the embodiment of the application, when it is necessary to obfuscate the code, the first code can be obtained first, the first code can refer to the code written by the developer and to be obfuscated, the first code can include a plurality of first identifiers, the first identifier can refer to the name defined by the developer for the program element; the plurality of first identifiers are processed by the decompilation-uncognizable based on the preset mapping table to obtain the second code, the preset mapping table can refer to the mapping table preset by the developer, the preset mapping table can include a plurality of corresponding relationships between identifiers and symbols, the second code can refer to the code obtained by replacing the first identifiers of the first code with the symbols corresponding to the identifiers according to the preset mapping table; a plurality of reflection code templates without actual functions are determined, the reflection code template without actual function can refer to the code without influence on the program running result preset by the developer; a plurality of target positions are determined in the second code; the plurality of reflection code templates are added in the plurality of target positions to obtain the third code, wherein the target position is associated with the code of the non-critical step corresponding to the second code, and the non-critical step can refer to the initialization block or the non-core logic branch of the first code. In this way, by replacing the first identifier according to the preset mapping table, the attacker will report an error or display garbled code when decompiling, thereby improving the security of the code, and at the same time, adding the reflection code template without actual function to the target position of the second code can increase the invalid call, destroy the logic of the code, increase the difficulty of decompilation of the attacker, and thereby improve the security of the code.
[0075] On the basis of any one of the above embodiments, the following will be described in combination with Figure 5 The determination process of the target position is described in detail.
[0076] Figure 5 The schematic diagram of the determination process of the target position provided in the embodiment of the application is shown in FIG. 4. Figure 5 The method can include:
[0077] S501, obtaining code information of the second code.
[0078] The code information is used to indicate a plurality of execution steps corresponding to the second code.
[0079] The code information of the second code can be determined by determining a plurality of classes in the second code, determining a method body in each class, determining the method body as an execution step, and determining a plurality of execution steps as the code information of the second code.
[0080] The code information of the second code can also be determined by determining a plurality of basic blocks in the second code, the basic block being a sequential code segment without jump, determining the basic block as an execution step, and determining a plurality of execution steps as the code information of the second code.
[0081] S502, among the plurality of execution steps, a non-critical step is determined, and a fourth code associated with the non-critical step is determined in the second code.
[0082] For example, the non-critical step can be determined by sequentially performing static analysis on the plurality of execution steps, determining a first keyword, a second keyword, and a third keyword, determining a first step corresponding to the first keyword, a second step corresponding to the second keyword, and a third step corresponding to the third keyword in the plurality of execution steps according to the first keyword, the second keyword, and the third keyword, and determining the first step, the second step, and the third step as the non-critical step.
[0083] The first keyword can be "log", the first step can be a log recording class step, that is, the first step only outputs and does not change the code state; the second keyword can be "test", the second step can be a debugging class step, that is, the second step is not actual business code; and the third keyword can be "try / catch", and the third step can be an exception capturing step, that is, the third step does not substantially change the actual program running.
[0084] For example, the non-critical step can also be determined by inputting the second code into a pre-trained preset model, the preset model being configured to determine the call frequency and call path of each execution step of the input code, and receiving the call frequency and call path of each execution step output by the preset model; and determining the non-critical step in each execution step according to the call frequency and call path of each execution step, wherein the non-critical step satisfies at least one of the following conditions: the call frequency of the non-critical step is less than a preset frequency, the call path of the critical step is not on the path of the main call chain, or the call path of the non-critical step only runs in the initialization phase.
[0085] The fourth code is associated with the non-critical step.
[0086] The fourth code can be determined by performing type identification on the non-critical step, determining a target type included in the non-critical step, the target type being a method body type, a loop body type, etc., and determining the fourth code according to the target type.
[0087] For example, if the non-key step contains a method body, i.e., the target type is a method body type, the fourth code can be the first sentence of the method body of the non-key step; if the non-key step contains a loop body, i.e., the target type is a loop body type, the fourth code can be the first sentence and / or the last sentence of the loop body of the non-key step.
[0088] S503, determining the target position according to the fourth code.
[0089] The target position can be determined by judging the position of the fourth code. If the fourth code is located at the first sentence, the target position is before the fourth code, i.e., the reflection code template is added before the fourth code. If the fourth code is located at the last sentence, the target position is after the fourth code, i.e., the reflection code template is added after the fourth code.
[0090] Next, the determination of the target position according to the fourth code will be described in combination with Figure 6 and Figure 7 through specific examples.
[0091] Figure 6 For the schematic diagram of determining the target position provided by the embodiments of the present application, please refer to Figure 6 , which includes a non-key step, the non-key step includes the fourth code, and the fourth code is located at the first sentence. It can be determined that the target position is before the fourth code, i.e., the reflection code template is added before the fourth code.
[0092] Figure 7 For another schematic diagram of determining the target position provided by the embodiments of the present application, please refer to Figure 7 , which includes a non-key step, the non-key step includes the fourth code, and the fourth code is located at the last sentence. It can be determined that the target position is after the fourth code, i.e., the reflection code template is added after the fourth code.
[0093] In Figure 5In the embodiment shown, when it is necessary to obfuscate the code, it is necessary to determine the target position for adding the reflection code template. Code information of the second code is obtained, the code information being used to indicate a plurality of execution steps corresponding to the second code; among the plurality of execution steps, a non-critical step is determined, and in the second code, a fourth code associated with the non-critical step is determined, wherein the fourth code is associated with the non-critical step. According to the fourth code, the target position is determined, which can be determined by judging the position of the fourth code. If the fourth code is located at the first sentence, the target position is before the fourth code, that is, the reflection code template is added before the fourth code. If the fourth code is located at the last sentence, the target position is after the fourth code, that is, the reflection code template is added after the fourth code. Through the above method, according to the code information of the second code, the non-critical execution step can be determined among the plurality of execution steps of the second code, that is, the reflection code template is added in the non-critical execution step, which can reduce the influence on the overall program running, so as to ensure the normal running of the program compilation. Moreover, according to the fourth code, the target position is determined, which further reduces the influence of adding the reflection code template on the overall program running. In this way, the code can be normally compiled and run, and the difficulty of reverse compilation by an attacker can be increased by adding the reflection code template, thereby improving the security of the code.
[0094] On the basis of any one of the above embodiments, the following will be described in combination with Figure 8 The authorization process of the third code is described in detail.
[0095] Figure 8 A schematic diagram of the authorization process of the third code provided by the embodiments of the present application is shown. Please refer to Figure 8 The method can include:
[0096] S801, after obtaining the third code, obtaining hardware information of a user terminal.
[0097] The user terminal can refer to a terminal device of a user authorized to run the third code.
[0098] The hardware information of the user terminal can refer to the central processing unit serial number, disk serial number, mainboard serial number, etc. of the user terminal, which can indicate a unique user terminal.
[0099] S802, performing transformation processing on the hardware information to obtain a hardware fingerprint corresponding to the hardware information.
[0100] The transformation processing can refer to converting the hardware information into a standard format, and the transformation processing can be a hash processing on the hardware information.
[0101] The hardware fingerprint corresponding to the hardware information can be obtained by the following manner: obtaining the hardware information of the user terminal, performing string splicing processing on the hardware information to obtain a hardware information string, and performing hash processing on the hardware information string to obtain the hardware fingerprint, wherein the hash processing can refer to 256-bit hash function processing.
[0102] For example, assuming that the hardware information of the user terminal includes a central processor serial number, a disk serial number and a mainboard serial number, wherein the central processor serial number is AAAA, the disk serial number is BBBB, and the mainboard serial number is CCCC, the hardware information string obtained by performing string splicing processing on the hardware information is AAAABBBBCCCC.
[0103] For example, assuming that H represents hash function processing, C cpu represents the central processor serial number, D disk represents the disk serial number, and M motherboard represents the mainboard serial number, and ‖ represents string splicing processing, the hardware fingerprint K can be represented as:
[0104]
[0105] S803, obtaining a preset private key, and performing signature processing on the hardware fingerprint based on the preset private key to obtain signature information.
[0106] The preset private key can be a key agreed by the developer and the user in advance, and the preset private key can be stored in the authorization server.
[0107] Optionally, the preset private key can be a dynamic key. Assuming that K is the hardware fingerprint, timestamp is a dynamic timestamp, and KDF is a key derivation function, the preset private key K dynamic can be:
[0108]
[0109] The signature information can be encrypted data obtained by signing the hardware fingerprint using the preset private key.
[0110] The signature processing can refer to signature algorithms such as Elliptic Curve Digital Signature Algorithm (ECDSA) and Probabilistic Signature Scheme (RSA).
[0111] S804, determining authorization information of the third code according to the signature information.
[0112] The authorization information can be used to verify whether the user terminal has authorization to run the third code.
[0113] The authorization information can include the signature information, and the authorization information can further include authorized user information, which can include an authorization duration of the third code, an authorization version number of the third code, and the like.
[0114] Optionally, the user terminal can cache the result of the successful verification to a cache space after the authorization information is first verified, so as to avoid resource waste caused by repeated verification of the same terminal device each time the third code is run, and thus improve the running efficiency of the code.
[0115] In Figure 8 In the embodiment shown, when the third code after code obfuscation is obtained, the third code can be authorized. The hardware information of the user terminal is obtained, the user terminal can refer to the terminal device of the user authorized to run the third code, and the hardware information of the user terminal can refer to the central processing unit serial number, disk serial number, mainboard serial number, and the like of the user terminal, which can indicate a unique user terminal. The hardware information is processed to obtain the hardware fingerprint corresponding to the hardware information, and the processing can refer to converting the hardware information into a standard format. A preset private key is obtained, and the hardware fingerprint is signed based on the preset private key to obtain signature information, and the preset private key can be a key agreed upon by the developer and the user in advance. The authorization information of the third code is determined according to the signature information, and the authorization information can be used to verify whether the user terminal has authorization to run the third code. The authorization information can include the signature information, and the authorization information can further include authorized user information. In this way, the third code after obfuscation can be authorized through the above method, the hardware fingerprint capable of uniquely indicating the authorized user terminal is used to ensure the uniqueness of the authorization of one machine and one code, and the hardware fingerprint is encrypted by a dynamic key to prevent the authorization tampering problem caused by private key leakage, thereby improving the security of the code.
[0116] Figure 9 A structural diagram of a code obfuscation device provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, the code obfuscation device 10 provided by the embodiment of the present application includes a first obtaining module 11, a processing module 12, a first determining module 13, and a second obtaining module 14. Figure 9
[0117] The first obtaining module 11 is configured to obtain a first code, and the first code includes a plurality of first identifiers.
[0118] The processing module 12 is configured to perform anti-compile-identification processing on the plurality of first identifiers based on a preset mapping table to obtain a second code, and the preset mapping table includes a correspondence between a plurality of identifiers and symbols, and the symbols are anti-compile-identification symbols.
[0119] The first determining module 13 is configured to determine a plurality of reflection code templates without actual functions.
[0120] The second obtaining module 14 is configured to add a plurality of reflection code templates in the second code to obtain a third code.
[0121] The code obfuscation apparatus provided in the embodiments of the present application can execute the technical solutions shown in the method embodiments, and has similar implementation principles and beneficial effects, which will not be repeated here.
[0122] In a possible design, the second obtaining module 14 is specifically configured to:
[0123] determine a plurality of target positions in the second code, the target positions being associated with the code of the non-key step corresponding to the second code;
[0124] add the plurality of reflection code templates in the plurality of target positions to obtain the third code.
[0125] In a possible design, the second obtaining module 14 is specifically configured to:
[0126] obtain code information of the second code, the code information being used to indicate a plurality of execution steps corresponding to the second code;
[0127] determine the non-key step in the plurality of execution steps, and determine a fourth code associated with the non-key step in the second code;
[0128] determine the target position according to the fourth code.
[0129] In a possible design, the processing module 12 is specifically configured to:
[0130] determine a second identifier same as the first identifier and a target symbol corresponding to the second identifier in a plurality of identifiers in the preset mapping table;
[0131] replace the first identifier with the target symbol corresponding to the second identifier.
[0132] The code obfuscation apparatus provided in the embodiments of the present application can execute the technical solutions shown in the method embodiments, and has similar implementation principles and beneficial effects, which will not be repeated here.
[0133] Figure 10 Another structure diagram of a code obfuscation apparatus provided in the embodiments of the present application is shown in FIG. 2. As shown in FIG. 2, the code obfuscation apparatus 10 further includes a second determining module 15, wherein: Figure 9 Figure 10 The second determining module 15 is configured to obtain hardware information of the user terminal.
[0134] The second determining module 15 is configured to obtain hardware information of the user terminal.
[0135] According to the hardware information, authorization information of the third code is determined, and the authorization information is used for verifying a user obtaining the third code.
[0136] In a possible design, the second determining module 15 is specifically configured to,
[0137] The hardware information is processed to obtain a hardware fingerprint corresponding to the hardware information.
[0138] A preset private key is obtained, and the hardware fingerprint is processed by signing based on the preset private key to obtain signature information.
[0139] According to the signature information, authorization information of the third code is determined.
[0140] In a possible design, the second determining module 15 is further configured to,
[0141] A target parameter corresponding to each target symbol is determined, and the target parameter is used to indicate a distribution probability of the target symbol in the third code.
[0142] According to the distribution probability, a security level of the third code is determined.
[0143] The code obfuscation apparatus provided in the embodiments of the present application can execute the technical solutions shown in the method embodiments, and the implementation principles and beneficial effects are similar, and thus will not be described herein again.
[0144] Figure 11 The structure of the electronic device provided in the present application is shown in a schematic diagram. As shown in Figure 11 The electronic device 50 provided in the present embodiment includes at least one processor 501 and a memory 502. Optionally, the electronic device 50 further includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected through a bus.
[0145] In the implementation process, the at least one processor 501 executes the computer execution instructions stored in the memory 502, so that the at least one processor 501 executes the code obfuscation method embodiments described above.
[0146] The specific implementation process of the processor 501 can refer to the method embodiments described above, and the implementation principles and technical effects are similar, and thus will not be described herein again.
[0147] In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.
[0148] The memory can include a random access memory (RAM), and can also include a non-volatile memory (NVM), such as at least one disk memory.
[0149] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus, an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0150] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program, and the computer program is configured to execute the steps in any of the above code obfuscation method embodiments when running.
[0151] In an example embodiment, the above computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0152] The embodiments of the present application also provide a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the steps in any of the above code obfuscation method embodiments.
[0153] The embodiment of the present application further provides another computer program product, comprising a nonvolatile computer readable storage medium, the nonvolatile computer readable storage medium stores a computer program, the computer program is executed by a processor to implement the steps in any of the code obfuscation method embodiments.
[0154] Those skilled in the art will further appreciate that the functions of the examples described herein, including any related steps of a method, can be implemented using electronic hardware, computer software, or any combination thereof. To clearly illustrate this interchangeability of hardware and software, various examples have been described herein in terms of their functionality, which has been described generally and symbolically in flow charts. Having thus described the functionality of the examples, a person of ordinary skill in the art will appreciate that these and / or other examples can be implemented by a combination of hardware and software, as will be appreciated by those skilled in the art, with the particular form of hardware and software being dependent on the particular application and design constraints imposed on the overall system. Those skilled in the art will appreciate that the functions of the examples described herein can be implemented using electronic hardware, computer software, or any combination thereof. To clearly illustrate this interchangeability of hardware and software, various examples have been described herein in terms of their functionality, which has been described generally and symbolically in flow charts. Having thus described the functionality of the examples, a person of ordinary skill in the art will appreciate that these and / or other examples can be implemented by a combination of hardware and software, as will be appreciated by those skilled in the art, with the particular form of hardware and software being dependent on the particular application and design constraints imposed on the overall system.
[0155] The above provides a code obfuscation method, an electronic device, a storage medium and a program product. The principles and implementation manners of the present application are described by applying specific examples. The above description of the examples is only used to help understand the method and its core idea. It should be pointed out that, for those skilled in the art, without departing from the principles of the present application, some improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A code obfuscation method, characterized in that, include: Obtain a first code, which includes multiple first identifiers; Based on a preset mapping table, the plurality of first identifiers are decompiled to become unrecognizable to obtain second code. The preset mapping table includes a correspondence between multiple identifiers and symbols, where the symbols are unrecognizable symbols after decompilation. Identify multiple reflection code templates that have no actual functionality; Add the multiple reflection code templates to the second code to obtain the third code; Obtain a preset correspondence, which is used to indicate the correspondence between bytecode instructions and redundant bytecode. The redundant bytecode is bytecode that is syntactically correct after insertion but has no actual meaning. The redundant bytecode includes at least one of adding a jump instruction after an exception throwing instruction, adding a null instruction after a return instruction, and adding an exit instruction after an entry into a synchronization block. The third code includes the bytecode instructions. In the third code, at least one bytecode instruction is determined, and according to the preset correspondence, redundant bytecode corresponding to the bytecode is added after the at least one bytecode instruction in the third code; Obtain hardware information from the user terminal; Based on the hardware information, the authorization information of the third code is determined. The authorization information includes a dynamic key generated based on a dynamic timestamp. The authorization information is used to verify the user who obtains the third code. Determine multiple symbols of the third code, wherein the multiple symbols are obtained by processing the multiple first identifiers based on the preset mapping table; Determine the target parameters corresponding to each symbol, wherein the target parameters are used to indicate the distribution probability of the symbol in the third code; The security level of the third code is determined based on the probability distribution.
2. The method according to claim 1, characterized in that, Adding the aforementioned multiple reflection code templates to the second code yields the third code, which includes: In the second code, multiple target locations are determined, and the target locations are associated with the code of the non-critical steps corresponding to the second code; The third code is obtained by adding the multiple reflection code templates at the multiple target locations.
3. The method according to claim 2, characterized in that, The second code identifies multiple target locations, including: Obtain code information for the second code, the code information being used to indicate multiple execution steps corresponding to the second code; In the plurality of execution steps, the non-critical steps are identified, and in the second code, a fourth code associated with the non-critical steps is identified; The target location is determined based on the fourth code.
4. The method according to any one of claims 1-3, characterized in that, For any first identifier; Based on a preset mapping table, the first identifier is decompiled to be unrecognizable, including: Among the multiple identifiers in the preset mapping table, a second identifier that is the same as the first identifier and the target symbol corresponding to the second identifier are determined; Replace the first identifier with the target symbol corresponding to the second identifier.
5. The method according to any one of claims 1-3, characterized in that, Based on the hardware information, the authorization information of the third code is determined, including: The hardware information is transformed to obtain the hardware fingerprint corresponding to the hardware information; Obtain a preset private key, and perform signature processing on the hardware fingerprint based on the preset private key to obtain signature information; Based on the signature information, the authorization information of the third code is determined.
6. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for implementing the code obfuscation method as described in any one of claims 1 to 5 when executing the computer program.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the code obfuscation method as described in any one of claims 1 to 5.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the code obfuscation method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Access method and device based on front-end code encryption, electronic equipment and medium
CN117390603A