Method, apparatus, computing device, and computer storage medium for application reinforcement

By combining the secure SDK with the application source code, precompiling, encapsulating and binding, forming reinforced security components, the problem that existing SDK reinforcement solutions cannot flexibly combine applications, achieving stronger reinforcement effects and better compatibility.

CN109960509BActive Publication Date: 2025-07-04JIANGSU PAYEGIS INFORMATION SECURITY TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN201910168499.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-03-06
Publication Date
2025-07-04
Estimated Expiration
2039-03-06

AI Technical Summary

Technical Problem

The existing SDK reinforcement solutions cannot be flexibly combined with applications, resulting in incomplete protection and cannot meet high-level security needs.

Method used

Insert the security SDK into the program source code of the application to be reinforced for pre-compilation, extract effective information for encapsulation, and bind it to the program source code to form a reinforced security component and export the reinforced application file.

Benefits of technology

The reinforcement effect is enhanced. By combining the encapsulated effective information and the secure SDK, the application's tamper-proof ability is improved, the compatibility is better, and it can be combined with the application more flexibly.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN109960509B_ABST
    Figure CN109960509B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, computing device and computer storage medium for application reinforcement. Among them, the method includes: when receiving a to-be-reinforced application selected by a user, inserting a security SDK into the program source code of the to-be-reinforced application and performing pre-compilation to generate an archive file; extracting valid information of the to-be-reinforced application from the archive file and performing encapsulation processing on the valid information; forming a reinforced security component with the encapsulated valid information and the security SDK, and binding the reinforced security component to the program source code; after binding, exporting the program file of the to-be-reinforced application to complete the reinforcement of the to-be-reinforced application. The solution of the present invention can perform integrated reinforcement on the basis of the application source code, which can be combined with the application more flexibly and has better compatibility; and, forming a reinforced security component with the security SDK and the encapsulated valid information together can combine the reinforcement function of the SDK with the application anti-tampering packaging function, and the reinforcement effect is stronger.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of application security technology, and particularly to a method, device, computing device and computer storage medium for application reinforcement. Background Art

[0002] With the rapid development of mobile Internet technology, application security problems emerge in an endless stream, such as remote control, traffic loss, application counterfeiting, privacy data theft, etc., which seriously damage the vital interests of application manufacturers and end users. In order to address these security problems, the information security level protection has also entered the 2.0 era from 1.0, with higher-level requirements for the security system, and the security of mobile Internet has attracted more and more attention from enterprises.

[0003] Many existing Internet companies, while considering product security, will seek help from enterprises with security qualifications from third parties due to considerations of input-output ratio and interests. At the same time, due to the characteristics of convenient integration and flexible use of SDK reinforcement, such enterprises will provide SDKs uniformly to carry out batch protection in the face of large-scale demands.

[0004] However, when the inventor implemented the embodiments of the present invention, it was found that the existing SDK reinforcement solutions had incomplete protection and could not be flexibly combined with applications. Summary of the Invention

[0005] In view of the above problems, the present invention is proposed to provide a method, device, computing device and computer storage medium for application reinforcement that can overcome or at least partially solve the above problems.

[0006] According to one aspect of the present invention, a method for application reinforcement is provided, including:

[0007] When a to-be-reinforced application selected by a user is received, insert a security SDK into the program source code of the to-be-reinforced application and perform pre-compilation to generate an archive file;

[0008] Extract the valid information of the to-be-reinforced application from the archive file, and perform encapsulation processing on the valid information; form a reinforced security component with the encapsulated valid information and the security SDK, and bind the reinforced security component to the program source code;

[0009] After binding, export the program file of the to-be-reinforced application to complete the reinforcement of the to-be-reinforced application.

[0010] According to another aspect of the present invention, a device for application reinforcement is provided, including:

[0011] A pre-compilation module, adapted to insert a security SDK into the program source code of the application to be fortified when receiving the application to be fortified selected by the user and perform pre-compilation to generate an archive file;

[0012] An effective information extraction module, adapted to extract the effective information of the application to be fortified from the archive file and perform encapsulation processing on the effective information;

[0013] A binding module, adapted to form a fortified security component by binding the encapsulated effective information and the security SDK, and bind the fortified security component to the program source code;

[0014] A fortification module, adapted to export the program file of the application to be fortified after binding to complete the fortification of the application to be fortified.

[0015] According to another aspect of the present invention, there is provided a computing device, including: a processor, a memory, a communication interface, and a communication bus, and the processor, the memory, and the communication interface complete communication with each other through the communication bus;

[0016] The memory is used to store at least one executable instruction, and the executable instruction causes the processor to perform operations corresponding to the method for application fortification described above.

[0017] According to still another aspect of the present invention, there is provided a computer storage medium, in which at least one executable instruction is stored, and the executable instruction causes a processor to perform operations corresponding to the method for application fortification described above.

[0018] According to the method, device, computing device, and computer storage medium for application fortification of the present invention, the user only needs to select the application to be fortified, and the client can automatically complete the following entire fortification process: insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to make the extracted effective information consistent with that at the final runtime; extract the effective information and perform encryption and encapsulation, bind the encapsulated effective information and the security SDK as a fortified security component for protecting the security of the application to be fortified, so that an attacker cannot crack the application by cracking the SDK or the effective information alone; bind the fortified security component to the program source code of the application to be fortified, and further combine the fortification function of the security SDK (such as running environment detection) with the application anti-tampering packaging function to enhance the fortification effect. In addition, the solution of the present invention is based on the program source code of the application, and operations such as integrated encapsulation and extraction are performed on the basis of the source code, and thus can be more flexibly combined with the application, and has better compatibility.

[0019] The above description is only an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are given below. Description of the Drawings

[0020] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0021] Figure 1 Shows a flowchart of a method for application hardening according to an embodiment of the present invention;

[0022] Figure 2 Shows a flowchart of a method for application hardening according to another embodiment of the present invention;

[0023] Figure 3 Shows a flowchart of application hardening in a specific embodiment of the present invention;

[0024] Figure 4 Shows a functional block diagram of an apparatus for application hardening according to an embodiment of the present invention;

[0025] Figure 5 Shows a structural schematic diagram of a computing device according to an embodiment of the present invention. Detailed Embodiments

[0026] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art.

[0027] Before implementing the embodiments of the present invention, the following concepts involved in this article are first clarified:

[0028] Workspace: Workstation, compilation directory, and multiple projects share one compilation directory;

[0029] Project: Project program, which contains multiple products (Targets);

[0030] Scheme: A set of all configurations for building a product (Target);

[0031] A workspace can contain multiple projects, and a project can contain multiple targets. Scheme represents different configurations for compiling a target, and each set of configurations corresponds to a scheme.

[0032] In addition, the solution of the present invention can be widely applied to the application hardening of various systems. In the following, the application hardening of the IOS system is mainly used for illustration. Those skilled in the art should understand that the present invention is not limited thereto.

[0033] Figure 1 The flowchart of the method for application hardening according to an embodiment of the present invention is shown. As Figure 1 shown, the method includes:

[0034] Step S101: When receiving the application to be hardened selected by the user, insert the security SDK into the program source code of the application to be hardened and perform pre-compilation to generate an archive file.

[0035] In the present invention, after the hardening client is started, the user can select the application to be hardened according to the protection requirements. And after receiving the application to be hardened selected by the user, the subsequent hardening process can be completely automatic, that is, one-key hardening can be achieved.

[0036] Specifically, receive the application to be hardened selected by the user, the client imports and links the security SDK, inserts the security SDK into the program source code of the application to be hardened, and during pre-compilation, the data of the security SDK will be packaged into the executable file of the project together, so that the application binary files before and after hardening remain consistent, and thus it can be ensured that the executable binary information (the effective information in the following text) extracted subsequently is consistent with the final running version, which is beneficial to the accurate judgment of the hardened application at the anti-tampering level. And, after pre-compilation, an archive file is generated, that is: an archive file.

[0037] It should be noted here that in the present invention, the source of the security SDK is not limited, and the hardening functions included in the security SDK are not limited. During specific implementation, those skilled in the art can flexibly select the source of the security SDK, flexibly select the SDKs including different hardening functions, and flexibly turn on or off the hardening options in the default security SDK.

[0038] Step S102: Extract the effective information of the application to be hardened from the archive file and perform encapsulation processing on the effective information.

[0039] The solution of the present invention not only relies on the security SDK to protect the application, but also extracts the effective information of the application to be hardened to achieve application anti-tampering by comparing the effective information.

[0040] Specifically, extract the effective information of the application to be fortified from the archived file obtained after pre-compilation, where the effective information is consistent with the information of the finally running un-tampered application, and perform encrypted packaging on the effective information so that the effective information cannot be easily obtained and tampered with by attackers.

[0041] Moreover, the present invention does not limit the information items of the effective information. During specific implementation, those skilled in the art can flexibly select the information items of the extracted effective information. Optionally, the effective information may include the application name (Bundle Name), signature information, etc.

[0042] After extracting the effective information and performing packaging on the effective information through the above steps S101 and S102, the effective information is used for application anti-tampering detection.

[0043] Step S103: Form a fortified security component by binding the packaged effective information and the security SDK, and bind the fortified security component to the program source code.

[0044] After binding the packaged effective information and the security SDK, they are used as the fortified security component to protect the security of the application to be fortified, so that attackers cannot solely crack the application by cracking the SDK or the effective information.

[0045] Moreover, bind the fortified security component to the program source code so that the security fortified component can be used to detect the running environment of the application to be fortified and the effective information.

[0046] Step S104: After binding, export the program file of the application to be fortified to complete the fortification of the application to be fortified.

[0047] After completing the above binding, compile, package, and export the program file of the application to be fortified. The exported program file is the fortified application program file.

[0048] According to the application hardening method provided in this embodiment, the user only needs to select the application to be hardened, and the client can automatically complete the following entire hardening process: insert the security SDK into the program source code of the application to be hardened and perform pre-compilation to make the extracted effective information consistent with that at the final runtime; extract the effective information and perform encryption and encapsulation, bind the encapsulated effective information and the security SDK as a hardened security component to protect the security of the application to be hardened, so that attackers cannot crack the application by simply cracking the SDK or the effective information; bind the hardened security component to the program source code of the application to be hardened, and then the hardening function of the security SDK (such as runtime environment detection) and the application anti-tampering packaging function can be combined to enhance the hardening effect. In addition, the solution of the present invention is based on the program source code of the application, and operations such as integrated encapsulation and extraction are performed on the basis of the source code, and thus it can be more flexibly combined with the application and has better compatibility.

[0049] Figure 2 The flowchart of the application hardening method according to another embodiment of the present invention is shown. As Figure 2 shown, the method includes:

[0050] Step S201: When receiving the application to be hardened selected by the user, receive the hardening items selected by the user, and enable the corresponding function items of the security SDK according to the hardening items selected by the user.

[0051] In this embodiment, when receiving the application to be hardened selected by the user, the user is further allowed to select hardening items. For example, by checking the jailbreak detection, it is determined that jailbreak detection is required, making the configuration of the entire hardening function more flexible to overcome the defect in the prior art that a customized hardening solution cannot be provided for different applications.

[0052] Specifically, start the hardening client, the user selects the program source code to be hardened and the hardening items, and enable the corresponding function items of the security SDK according to the user's selection. In a specific embodiment of the present invention, all function items of the security SDK are enabled by default, and then the user selects to turn off the function items that do not need to be hardened. Among them, the function items of the security SDK include but are not limited to at least one of the following: running autostart item, re-signing detection item, dynamic library injection detection item, debugger injection detection item, dynamic debugging monitoring item, tampering monitoring item, runtime environment detection item, and string decryption item. Among them, the runtime environment monitoring further includes jailbreak detection, network proxy monitoring, and screenshot monitoring. It should be noted here that in specific implementation, the hardening functions included in the security SDK are not limited to the function items listed above, and those skilled in the art can flexibly add or delete the hardening functions of the security SDK to meet the corresponding detection requirements.

[0053] Step S202: Insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archive file.

[0054] Specifically, by modifying the link flag information in the program source code, insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archive file. The client imports and links the security SDK, and calls the xcodebuild command to perform pre-compilation to generate an archive file. This pre-compilation operation can ensure that the user's current source code is a complete version that can be normally compiled and packaged, and can provide data support for subsequent extraction of valid information. Moreover, modifying the link flag information of the application's configuration project file includes, but is not limited to, modifying the library file link flag (OTHER_LDFLAGS) and the header file link flag (GCC_PREFIX_HEADER), thereby ensuring that the security SDK can work preferentially.

[0055] Furthermore, the security SDK is provided with position identifiers for multiple checkpoints in the program source code. During pre-compilation, when the program source code runs to the checkpoints corresponding to the position identifiers, the security SDK is called. Before inserting the security SDK, multiple checkpoints are set, that is, security detection is called at the positions of these multiple checkpoints in the program source code. Here, when pre-compiling, the security SDK is called at multiple checkpoints, which is also to ensure that the subsequent extracted executable binary information (the valid information in the following text) is consistent with the final running version. And in step S205 below, during the process of re-compiling and packaging, when the program source code runs to the checkpoints corresponding to the position identifiers, the security SDK is called, which can achieve the fortification of multiple checkpoint positions, so that even if an attacker attacks one of them, the fortification effect can still be used normally.

[0056] In addition, in an optional embodiment of the present invention, in order to prevent code pollution, the program source code of the application to be fortified is copied to obtain a copy sample of the program source code, that is, a backup of the program source code is made; then, when inserting and compiling the SDK, the security SDK is inserted into the copy sample of the program source code and pre-compiled. Even if an exception occurs during the fortification process, it will not affect the program source code and prevent code pollution.

[0057] Step S203: Extract the valid information of the application to be fortified from the archive file and perform encapsulation processing on the valid information.

[0058] Among them, the valid information includes, but is not limited to, at least one of the following: package name (Bundle Identifier), application name (Bundle Name), terminal display name (Bundle DisplayName), version number (App Version), resource files (such as PNG, JPEG, avi, etc.), and signature information.

[0059] Specifically, unzip the archive file of the application to be fortified, filter out the valid information, which is consistent with the information of the finally running unmodified application, and seal and package the valid information to reduce the possibility of the application being cracked, so that the valid information cannot be easily obtained and tampered with by attackers, bypassing the detection means in fortification, and at the same time providing security guarantees for the security SDK. In addition, the valid information can also provide data backup for the application and can check whether the application uses private APIs, which helps to improve the passing rate of store reviews.

[0060] In some specific embodiments of the present invention, considering that in the prior art, the main detection of re-packaging is the Bundle Identifier in the Info.plist file. If an attacker uses enterprise signing, they can easily bypass the re-packaging detection and achieve the purpose of re-signing and installing. Correspondingly, in these specific embodiments, not only the Bundle Identifier in the Info.plist file is sealed and packaged, but also the signature information segment is sealed and packaged. When performing detection, various re-packagings can be effectively intercepted.

[0061] Step S204: Form a fortified security component from the packaged valid information and the security SDK, and add the string encryption package to the fortified security component.

[0062] In this embodiment, the fortified security component includes, in addition to the packaged valid information and the security SDK, a string encryption package, that is, integrating the string encryption package into the security SDK or the program source code for work, which can further ensure the security of application data.

[0063] Among them, the string encryption package includes an encryption script and a decryption script. The encryption script is used to extract specific strings from the program source code and encrypt the specific strings, and the decryption script is used to decrypt the ciphertext. Among them, the specific strings include: hard-coded keywords, communication server addresses, data request interfaces, and / or parameter information.

[0064] Step S205: Bind the fortified security component to the program source code.

[0065] Specifically, the fortified security component is added to the program source code through parametric configuration modification and recompiled and packaged again to complete the automatic linking of the security SDK and the automatic linking of header files. And when performing the recompilation and packaging again, the string encryption package in the fortified security component is called to encrypt the specific strings in the program source code, ensuring that the strings in the compiled and packaged application have been encrypted and protected, and coordinating with the string decryption script in the security fortification component to ensure data security.

[0066] Step S206: After binding, export the program file of the application to be fortified to complete the fortification of the application to be fortified.

[0067] Use the signature tool built into Xcode to sign the archive file generated by compilation and packaging in Step S205, and export it as the final fortified program file, such as exporting an ipa file.

[0068] Figure 3 Shows the flowchart of application fortification in a specific embodiment of the present invention. Different from Figure 2 what is described in Figure 3 when determining the application to be fortified and its fortification items, it is necessary to determine whether the application is an application managed by the workstation. Since multiple applications can be managed simultaneously in the Xcode workstation, and some common plugins, resource libraries, etc. are shared among multiple applications. If it is an application managed by the workstation, its compilation script is different from that of a simple stand-alone application. After Figure 3 the fortification process, the user only needs to select the application and fortification items, and click the fortification button to automatically complete all subsequent operations, such as effective information screening, running environment monitoring, anti-reverse protection, important information encryption, etc. Among them, anti-reverse protection mainly makes the decompiled code expand, deform, and become blurred through methods such as code obfuscation and string encryption.

[0069] According to the application fortification method provided in this embodiment, on the basis of selecting the application to be fortified, the user can further select fortification items, and then can perform personalized detection settings for the application; in addition, the technical solution of the fortified client is used for product fortification. The client fortification takes the code as the origin, and on this basis, parameterized configuration, security component protection, and packaging integration are carried out, which can be more flexibly combined with the application and has better compatibility; by forming a complete fortified security component from the encapsulated effective information, security SDK, and string encryption package, while implementing the detection of the corresponding fortified items of the security SDK, such as running environment detection, it is also possible to prevent application tampering by comparing the encapsulated effective information, and to protect application data through encryption of key information (specific strings). It can be seen that using the fortified security component of this embodiment can further enhance the fortification effect.

[0070] Figure 4 Shows the functional block diagram of the application fortification device according to an embodiment of the present invention. As Figure 4 shown, the device includes:

[0071] A pre-compilation module 401, adapted to insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archive file when receiving the application to be fortified selected by the user;

[0072] The valid information extraction module 402 is adapted to extract the valid information of the application to be fortified from the archived file and encapsulate the valid information;

[0073] The binding module 403 is adapted to form a fortified security component by combining the encapsulated valid information and the security SDK, and bind the fortified security component to the program source code;

[0074] The fortification module 404 is adapted to export the program file of the application to be fortified after binding, and complete the fortification of the application to be fortified.

[0075] In an optional implementation manner, the device further includes:

[0076] The function item enabling module 405 is adapted to receive the fortified item selected by the user and enable the corresponding function item of the security SDK according to the fortified item selected by the user.

[0077] In an optional implementation manner, the function items of the security SDK include at least one of the following: running autostart item, re-signature detection item, dynamic library injection detection item, debugger injection detection item, dynamic debugging monitoring item, tampering monitoring item, running environment detection item, and string decryption item.

[0078] In an optional implementation manner, the device further includes:

[0079] The source code backup module 406 is adapted to copy the program source code of the application to be fortified to obtain a copy sample of the program source code;

[0080] The pre-compilation module 401 is further adapted to: insert the security SDK into the copy sample of the program source code and perform pre-compilation.

[0081] In an optional implementation manner, the pre-compilation module 401 is further adapted to:

[0082] Insert the security SDK into the program source code of the application to be fortified by modifying the link flag bit information in the program source code and perform pre-compilation to generate an archived file.

[0083] In an optional implementation manner, position identifiers of multiple detection points of the program source code are set in the security SDK;

[0084] The pre-compilation module 401 is further adapted to:

[0085] Insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archived file; wherein, during the pre-compilation process, when the program source code runs to the detection point corresponding to the position identifier, the security SDK is called.

[0086] In an alternative embodiment, the valid information includes at least one of the following: package name, application name, terminal display name, version number, resource file, and signature information.

[0087] In an alternative embodiment, the binding module 403 is further adapted to:

[0088] Add the fortified security component to the program source code through parametric configuration modification and recompile and package it to complete the automatic linking of the security SDK and the automatic linking of header files.

[0089] In an alternative embodiment, the device further includes: an adding module 407, adapted to add a string encryption package to the fortified security component;

[0090] Wherein, the string encryption package includes an encryption script for extracting specific strings in the program source code and encrypting the specific strings, and a decryption script for decrypting the ciphertext;

[0091] The binding module 403 is further adapted to: when performing the recompile and package, call the string encryption package in the fortified security component to encrypt specific strings in the program source code.

[0092] In an alternative embodiment, the specific strings include: hard-coded keywords, communication server addresses, data request interfaces, and / or parameter information.

[0093] The embodiments of the present application provide a non-volatile computer storage medium, and the computer storage medium stores at least one executable instruction, and the computer executable instruction can execute the application fortification method in any of the above method embodiments.

[0094] Figure 5 The structural schematic diagram of a computing device according to an embodiment of the present invention is shown, and the specific implementation of the computing device is not limited in the specific embodiments of the present invention.

[0095] As Figure 5 shown, the computing device may include: a processor 502, a communication interface 504, a memory 506, and a communication bus 508.

[0096] Wherein:

[0097] The processor 502, the communication interface 504, and the memory 506 communicate with each other through the communication bus 508.

[0098] The communication interface 504 is used to communicate with network elements of other devices such as clients or other servers.

[0099] A processor 502 is configured to execute a program 510, and specifically can execute relevant steps in the method embodiments of the above application hardening.

[0100] Specifically, the program 510 may include program code, and the program code includes computer operation instructions.

[0101] The processor 502 may be a central processing unit (CPU), or a specific integrated circuit (ASIC) (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present invention. One or more processors included in the computing device may be of the same type of processor, such as one or more CPUs; or may be of different types of processors, such as one or more CPUs and one or more ASICs.

[0102] A memory 506 is configured to store the program 510. The memory 506 may include a high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory.

[0103] The program 510 is specifically configured to cause the processor 502 to perform the following operations:

[0104] When receiving a to-be-hardened application selected by a user, insert a security SDK into the program source code of the to-be-hardened application and perform pre-compilation to generate an archive file;

[0105] Extract valid information of the to-be-hardened application from the archive file, and perform encapsulation processing on the valid information; form a hardened security component with the encapsulated valid information and the security SDK, and bind the hardened security component to the program source code;

[0106] After binding, export the program file of the to-be-hardened application to complete the hardening of the to-be-hardened application.

[0107] In an optional implementation manner, the program 510 is specifically further configured to cause the processor 502 to perform the following operations: receive a hardened item selected by a user, and enable a corresponding function item of the security SDK according to the hardened item selected by the user.

[0108] In an optional implementation manner, the function items of the security SDK include at least one of the following: a running self-start item, a re-signature detection item, a dynamic library injection detection item, a debugger injection detection item, a dynamic debugging monitoring item, a tampering monitoring item, a running environment detection item, and a string decryption item.

[0109] In an alternative embodiment, the program 510 may specifically be further configured to cause the processor 502 to perform the following operations: copy the program source code of the application to be fortified to obtain a copy sample of the program source code;

[0110] Insert the security SDK into the copy sample of the program source code and perform pre-compilation.

[0111] In an alternative embodiment, the program 510 may specifically be further configured to cause the processor 502 to perform the following operations: insert the security SDK into the program source code of the application to be fortified by modifying the link flag information in the program source code and perform pre-compilation to generate an archive file.

[0112] In an alternative embodiment, position identifiers of multiple detection points of the program source code are set in the security SDK; the program 510 may specifically be further configured to cause the processor 502 to perform the following operations: insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archive file; wherein, during the pre-compilation process, when the program source code runs to the detection point corresponding to the position identifier, the security SDK is called.

[0113] In an alternative embodiment, the valid information includes at least one of the following: package name, application name, terminal display name, version number, resource file, and signature information.

[0114] In an alternative embodiment, the program 510 may specifically be further configured to cause the processor 502 to perform the following operations: add the fortified security component to the program source code through parametric configuration modification and perform re-compilation and packaging to complete the automatic linking of the security SDK and the automatic linking of the header file.

[0115] In an alternative embodiment, the program 510 may specifically be further configured to cause the processor 502 to perform the following operations: add a string encryption package to the fortified security component;

[0116] wherein, the string encryption package includes an encryption script for extracting specific strings in the program source code and encrypting the specific strings, and a decryption script for decrypting the ciphertext;

[0117] When performing the re-compilation and packaging, call the string encryption package in the fortified security component to encrypt specific strings in the program source code.

[0118] In an alternative embodiment, the specific strings include: hard-coded keywords, communication server addresses, data request interfaces, and / or parameter information.

[0119] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other apparatus. Various general-purpose systems may also be used in conjunction with the teachings based hereon. The structure required to construct such systems will be apparent from the above description. In addition, the present invention is not directed to any particular programming language. It should be appreciated that the teachings of the present invention described herein can be implemented in a variety of programming languages, and the description of specific languages above is for the purpose of disclosing the best mode of the present invention.

[0120] In the specification provided herein, numerous specific details are set forth. However, it can be understood that embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0121] Similarly, it should be understood that, in order to streamline this disclosure and assist in understanding one or more of the various inventive aspects, in the foregoing description of exemplary embodiments of the present invention, various features of the present invention are sometimes grouped together in a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as the following claims reflect, the inventive aspects lie in less than all the features of the preceding single embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the present invention.

[0122] Those skilled in the art will appreciate that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all the features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) can be replaced by an alternative feature providing the same, equivalent, or similar purpose.

[0123] In addition, those skilled in the art can understand that although some embodiments described herein include certain features included in other embodiments rather than other features, the combination of features of different embodiments means that it is within the scope of the present invention and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.

[0124] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the device for application hardening according to the embodiments of the present invention. The present invention can also be implemented as a device or device program (for example, a computer program and a computer program product) for executing part or all of the methods described herein. Such a program for implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0125] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the unit claims listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.

Claims

1. A method for application reinforcement, comprising: When receiving a to-be-reinforced application selected by a user, inserting a security SDK into the program source code of the to-be-reinforced application and performing pre-compilation to generate an archive file; wherein, position identifiers of multiple detection points of the program source code are set in the security SDK, and during pre-compilation, when the program source code runs to the detection point corresponding to the position identifier, the security SDK is called; Extracting valid information of the to-be-reinforced application from the archive file, and performing encapsulation processing on the valid information; forming a reinforced security component with the encapsulated valid information and the security SDK, and binding the reinforced security component to the program source code; The binding of the reinforced security component to the program source code further includes: Adding the reinforced security component to the program source code through parametric configuration modification and performing re-compilation and packaging again to complete the automatic linking of the security SDK and the automatic linking of header files; After binding, exporting the program file of the to-be-reinforced application to complete the reinforcement of the to-be-reinforced application; Wherein, before inserting the security SDK into the program source code of the to-be-reinforced application and performing pre-compilation, the method further includes: Copying the program source code of the to-be-reinforced application to obtain a copy sample of the program source code; The inserting the security SDK into the program source code of the to-be-reinforced application and performing pre-compilation specifically is: inserting the security SDK into the copy sample of the program source code and performing pre-compilation.

2. The method according to claim 1, wherein Before inserting the security SDK into the program source code of the to-be-reinforced application and performing pre-compilation, the method further includes: Receiving a reinforcement project selected by a user, and enabling corresponding function items of the security SDK according to the reinforcement project selected by the user.

3. The method according to claim 2, wherein, The function items of the security SDK include at least one of the following: a running self-start item, a re-signature detection item, a dynamic library injection detection item, a debugger injection detection item, a dynamic debugging monitoring item, a tampering monitoring item, a running environment detection item, and a string decryption item.

4. The method according to any one of claims 1 to 3, wherein The inserting the security SDK into the program source code of the to-be-reinforced application and performing pre-compilation to generate an archive file further includes: Inserting the security SDK into the program source code of the to-be-reinforced application and performing pre-compilation to generate an archive file by modifying the link flag bit information in the program source code.

5. The method according to claim 1, wherein The valid information includes at least one of the following: a package name, an application name, a terminal display name, a version number, a resource file, and signature information.

6. The method according to claim 1, wherein, The method further includes: When performing re-compilation and packaging again, calling a string encryption package in the reinforced security component to encrypt specific strings in the program source code; Wherein, the string encryption package includes an encryption script for extracting specific strings in the program source code and encrypting the specific strings, and a decryption script for decrypting the ciphertext.

7. The method according to claim 6, wherein, The specific strings include: hard-coded keywords, communication server addresses, data request interfaces, and / or parameter information.

8. An apparatus for application reinforcement, comprising: A pre-compilation module, adapted to insert a security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archive file when receiving the application to be fortified selected by the user; wherein, position identifiers of multiple detection points of the program source code are set in the security SDK, and during the pre-compilation process, when the program source code runs to the detection point corresponding to the position identifier, the security SDK is called; A source code backup module, adapted to copy the program source code of the application to be fortified to obtain a copy sample of the program source code; The pre-compilation module is further adapted to: insert the security SDK into the copy sample of the program source code and perform pre-compilation; An effective information extraction module, adapted to extract the effective information of the application to be fortified from the archive file and perform encapsulation processing on the effective information; A binding module, adapted to form a fortified security component with the encapsulated effective information and the security SDK, and bind the fortified security component to the program source code; The binding module is further adapted to: modify and add the fortified security component to the program source code through parametric configuration and perform re-compilation and packaging again to complete the automatic linking of the security SDK and the automatic linking of the header file; A fortification module, adapted to export the program file of the application to be fortified after binding to complete the fortification of the application to be fortified.

9. The device according to claim 8, wherein, The device further includes: A function item activation module, adapted to receive the fortified project selected by the user and activate the corresponding function item of the security SDK according to the fortified project selected by the user.

10. The device according to claim 9, wherein, The function items of the security SDK include at least one of the following: running self-start item, re-signature detection item, dynamic library injection detection item, debugger injection detection item, dynamic debugging monitoring item, tampering monitoring item, running environment detection item, and string decryption item.

11. The device according to any one of claims 8-10, wherein, The pre-compilation module is further adapted to: Insert the security SDK into the program source code of the application to be fortified and perform pre-compilation to generate an archive file by modifying the link flag bit information in the program source code.

12. The apparatus according to claim 8, wherein, The effective information includes at least one of the following: package name, application name, terminal display name, version number, resource file, and signature information.

13. The apparatus according to claim 8, wherein, The device further includes: an addition module, adapted to add a string encryption package to the fortified security component; Wherein, the string encryption package includes an encryption script for extracting specific strings in the program source code and encrypting the specific strings, and a decryption script for decrypting the ciphertext; The binding module is further adapted to: when performing re-compilation and packaging again, call the string encryption package in the fortified security component to encrypt specific strings in the program source code.

14. The apparatus according to claim 13, wherein, The specific strings include: hard-coded keywords, communication server addresses, data request interfaces, and / or parameter information.

15. A computing device, including: A processor, a memory, a communication interface, and a communication bus, and the processor, the memory, and the communication interface complete mutual communication through the communication bus; The memory is used to store at least one executable instruction, and the executable instruction enables the processor to perform the operations corresponding to the application fortification method according to any one of claims 1-7.

16. A computer storage medium storing at least one executable instruction that causes a processor to perform operations corresponding to the method for application hardening according to any one of claims 1-7.

Citation Information

Patent Citations

  • Application program reinforcing system and method based on ANDROID system

    CN105787306A

  • Mobile application security management apparatus and method, and mobile operation security protection system

    CN107766728A

  • Android reinforcement method based on DEX byte code extraction and mapping confusion

    CN108733379A

  • Authentication method and apparatus for reinforced software

    US20180204004A1

  • Reinforcing protection method and device for software installation package

    CN104021321A