Dynamic Link Library File Decryption Method, Encryption Method, and Decryption Device

By adding and encrypting specific section areas and functions in dynamic link library files, and using decryption devices for decryption, the problem of low security in the prior art is solved, and a high security effect against inverse is achieved.

CN112989291BActive Publication Date: 2025-06-17VIVO MOBILE COMM CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110272176.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-12
Publication Date
2025-06-17
Estimated Expiration
2041-06-17

AI Technical Summary

Technical Problem

In the prior art, the encrypted files are relatively low in security and are easily reverse cracked.

Method used

By adding and encrypting the first target section and anti-reverse function in the dynamic link library file, the target dynamic link library file is generated, and the file is decrypted using the decryption device to achieve anti-reverse measures.

Benefits of technology

It improves the security of encrypted files, makes reverse engineering a dead-cycle proposition, and increases the time and difficulty of cracking and restoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112989291B_ABST
    Figure CN112989291B_ABST
Patent Text Reader

Abstract

The present application discloses a method for decrypting a dynamic link library file, an encryption method, and a decryption device, belonging to the field of information security. The method includes obtaining a target dynamic link library file from an encryption device, where the target dynamic link library file is generated by the encryption device; decrypting a second target section included in the target dynamic link library file to obtain a first target section; decrypting an encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function; and generating a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function. In the embodiments of the present application, since the data in the target dynamic link library file to be decrypted has been processed, that is, it includes a second target section and an encrypted anti-reverse function, and the dynamic link library file can be obtained only after decryption, it is difficult to perform static analysis to achieve reverse modification, thus improving the security of the encrypted file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security, and particularly relates to a method for decrypting a dynamic link library file, an encryption method, and a decryption device. Background Art

[0002] Currently, anti-cracking technologies mainly focus on increasing the reverse engineering difficulty for crackers. After obtaining a dynamic library file, reverse engineering can perform static analysis and dynamic debugging to modify the logic of the target program, thereby achieving reverse cracking.

[0003] Although the VMP (VMProtect) virtual machine method can maximize the cracking difficulty, as long as the target file that can be reverse engineered is extracted, cracking is only a matter of time.

[0004] In the process of implementing this application, the inventors found that in the existing technical solutions, there is a problem of low security for encrypted files. Summary of the Invention

[0005] The purpose of the embodiments of this application is to provide a method for decrypting a dynamic link library file, an encryption method, a decryption device, an encryption device, an electronic device, and a readable storage medium, which can improve the security of encrypted files.

[0006] To solve the above technical problems, this application is implemented as follows:

[0007] In a first aspect, an embodiment of this application provides a method for decrypting a dynamic link library file, which is applied to a decryption device. The method includes:

[0008] Obtain a target dynamic link library file, where the target dynamic link library file is generated by an encryption device;

[0009] Decrypt a second target section included in the target dynamic link library file to obtain a first target section;

[0010] Decrypt an encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function;

[0011] Generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function.

[0012] In a second aspect, an embodiment of this application provides a method for encrypting a dynamic link library file, which is applied to an encryption device. The method includes:

[0013] Receive a dynamic link library file to be processed;

[0014] Add a first target section to the dynamic link library file;

[0015] Encrypt the first target section using a first preset algorithm to obtain a second target section;

[0016] Encrypt the anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain an encrypted anti-reverse function;

[0017] Generate a target dynamic link library file, where the target dynamic link library file includes the second target section and the encrypted anti-reverse function.

[0018] Thirdly, an embodiment of the present application provides a decryption device, which includes:

[0019] An acquisition module, configured to acquire a target dynamic link library file, where the target dynamic link library file is generated by an encryption device;

[0020] A decryption module, configured to decrypt the second target section included in the target dynamic link library file to obtain a first target section;

[0021] The decryption module is further configured to decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function;

[0022] A generation module, configured to generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function.

[0023] Fourthly, an embodiment of the present application provides an encryption device, which includes:

[0024] A receiving module, configured to receive a dynamic link library file to be processed;

[0025] An adding module, configured to add a first target section to the dynamic link library file;

[0026] An encryption module, configured to encrypt the first target section using a first preset algorithm to obtain a second target section;

[0027] The encryption module is further configured to encrypt the anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain an encrypted anti-reverse function;

[0028] A generation module, configured to generate a target dynamic link library file, where the target dynamic link library file includes the second target section and the encrypted anti-reverse function.

[0029] Fifthly, an embodiment of the present application provides an electronic device, which includes a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, it implements the steps of the method described in the first aspect, or implements the steps of the method described in the second aspect.

[0030] In a sixth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.

[0031] In a seventh aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is configured to run a program or instruction to implement the method described in the first aspect, or to implement the method described in the second aspect.

[0032] In an embodiment of the present application, first, a target dynamic link library file is obtained from an encryption device, where the target dynamic link library file is generated by the encryption device; then, a second target section included in the target dynamic link library file is decrypted to obtain a first target section; then, an encrypted anti-reverse function included in the target dynamic link library file is decrypted to obtain a decrypted anti-reverse function; finally, a decrypted dynamic link library file is generated according to the first target section and the decrypted anti-reverse function. Because a series of anti-reverse measures including decrypting the second target section and decrypting the anti-reverse function are implemented during the process of decrypting the target dynamic link library file, the code bytes can be protected from being extracted, so that reverse engineering becomes a dead-end proposition, improving the security of the encrypted file. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 is an interaction schematic diagram of encryption and decryption of a dynamic link library file provided by an embodiment of the present application;

[0034] Figure 2 is a display interface when a reverse engineering tool reads an encrypted library provided by an embodiment of the present application;

[0035] Figure 3 is a flowchart of a method for encrypting a dynamic link library file provided by an embodiment of the present application;

[0036] Figure 4 is a flowchart of a method for decrypting a dynamic link library file provided by an embodiment of the present application;

[0037] Figure 5 is a schematic structural diagram of an encryption device provided by an embodiment of the present application;

[0038] Figure 6 is a schematic structural diagram of a decryption device provided by an embodiment of the present application;

[0039] Figure 7 is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application;

[0040] Figure 8 It is a schematic diagram of the hardware structure of another electronic device provided by an embodiment of the present application. Specific embodiments

[0041] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present application.

[0042] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of the same category, and the number of objects is not limited. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally represents an "or" relationship between the associated objects before and after.

[0043] In view of the problems that occur in the related art, the embodiments of the present application provide a method for encrypting a dynamic link library file, a method for decrypting, a decryption device, an encryption device, an electronic device, and a readable storage medium. After receiving the dynamic link library file to be processed, a first target section is added to the dynamic link library file, and the first target section is encrypted using a first preset algorithm to obtain a second target section. Since adding the second target section obtained through encryption processing will make the target dynamic link library file become a defective library file, the target dynamic link library file cannot be opened by a static decompilation software, that is, an Interactive Disassembler (IDA), and an error will be reported when opened. Then, a second preset encryption algorithm is used to encrypt the anti-reverse function in the dynamic link library file to obtain an encrypted anti-reverse function. Finally, a target dynamic link library file including the second target section and the encrypted anti-reverse function is generated. Since the data in the generated target dynamic link library file has been processed, it is difficult to analyze and modify it statically, which improves the security of the encrypted file.

[0044] Next, in conjunction with the accompanying drawings, the method for encrypting a dynamic link library file, the method for decrypting, the decryption device, the encryption device, the electronic device, and the readable storage medium provided by the embodiments of the present application will be described in detail through specific embodiments and their application scenarios.

[0045] As an example, the dynamic link library file encryption method and decryption method provided in the embodiments of the present application can be applied to scenarios of terminal devices such as servers with computing capabilities, and the embodiments of the present application do not limit this here.

[0046] Figure 1 FIG. is an interactive schematic diagram of dynamic link library file encryption and decryption provided by the embodiments of the present application. As Figure 1 shown, the interactive process includes an encryption process of an encryption device and a decryption process of a decryption device. In this interactive process, the following steps may be included:

[0047] S101: The encryption device receives the dynamic link library file to be processed.

[0048] As an example, the received dynamic link library file refers to the Executable and Linkable Format (ELF).

[0049] Therefore, in the present application, the dynamic link library file in ELF format is taken as an example for illustration, but the embodiments are not limited to files in ELF format only, and other format files can also be replaced.

[0050] S102: The encryption device adds a first target section to the dynamic link library file.

[0051] Specifically, the first target section refers to a section in the dynamic link library file in ELF format.

[0052] S103: The encryption device encrypts the first target section using a first preset algorithm to obtain a second target section.

[0053] In this step, the first preset algorithm refers to an encryption and obfuscation algorithm customized by a tool. The tool can be an elf processing tool customized in advance. That is to say, the second target section obtained by encrypting and obfuscating the first target section using the first preset algorithm is an encrypted and obfuscated section. Therefore, the target dynamic link library file generated according to the second target section is a defective library file, and thus cracking tools such as IDA cannot open it or will report an error when opened, improving the security of the target dynamic link library file.

[0054] After encrypting the first target section, in order to make the generated target dynamic link library file more secure, the anti-reverse function in the received dynamic link library file can also be encrypted, that is, S104 is executed.

[0055] S104: The encryption device encrypts the anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain the encrypted anti-reverse function.

[0056] Specifically, the second preset encryption algorithm may be an algorithm of a predefined encryption anti-reverse function included in the elf processing tool.

[0057] It should be further noted that the anti-reverse function may also be referred to as the anti-reverse core function and the function against reverse unpacking, so as to prevent being reverse unpacked and cracked, thereby improving the security of the target dynamic link library file.

[0058] After obtaining the second target section and the encrypted anti-reverse function, the target dynamic link library file can be generated, that is, S105 can be executed to generate the target dynamic link library file.

[0059] S105: The encryption device generates a target dynamic link library file, which includes the second target section and the encrypted anti-reverse function.

[0060] Specifically, in this process, the address of the first target section can be obtained and stored in an unused field in the header area of the target format of the dynamic link library file. In addition, the size of the first target section can be obtained and also stored in the unused field in the above header area. Since the addresses of the first target section and the second target section obtained after encryption remain unchanged, the subsequent process of decrypting the second target section according to this header area can be realized. And because the dynamic link library file specifically refers to the ELF format, the header area of the target format specifically refers to the elf head.

[0061] After that, the target dynamic link library file can be generated according to the header area of the target format, the second target section and the encrypted anti-reverse function. Since the generated target dynamic link library file is incomplete and encrypted, it cannot be opened and analyzed by static analysis tools such as IDA, improving the security of the target dynamic link library file.

[0062] Also, because the target dynamic link library file needs to be decrypted and restored to run when it is loaded into the process space, a decryption device is also required to perform decryption processing on the target dynamic link library file, that is, execute S106 - S109.

[0063] S106: The decryption device obtains the target dynamic link library file from the encryption device.

[0064] Specifically, when the decryption device obtains the target dynamic link library file from the encryption device, the entry function in the pre-configured init.array is first executed, and then the decryption process of S107 - S109 is executed.

[0065] S107: The decryption device decrypts the second target section included in the target dynamic link library file to obtain the first target section.

[0066] In one embodiment, it is possible to first prevent debugging and injection by using ptrace to attach to itself. If the ptrace attach fails or the TracerPid is not 0, the current decryption process is exited, so as to monitor debugging and injection operations at the beginning of the decryption process, thereby enhancing the security of data during the decryption process.

[0067] After determining that it is not being debugged and injected by using ptrace to attach to itself, the target original function of the decryption device can be replaced with a preset function by using a preset replacement algorithm. The preset replacement algorithm refers to an algorithm for HOOK operations. The target original functions include exported (dump) interface functions, such as write, fwrite, printf, fputs, puts, fprintf functions. In addition, the target original functions can also include device call functions such as inotify and ptrace. That is to say, in the replacement process, the interface functions and system call functions are replaced with preset functions, which include preset target interface functions and preset target system functions, so as to calculate the hash value based on the address of the preset function later to monitor whether other processes enter the memory of the decryption device and ensure the security of data during the decryption process.

[0068] During the process of monitoring based on the hash value, specifically, the hash value of the address of the preset function in the decryption device at this moment can be calculated in real time, and the real-time hash value is compared with the preset hash value of the address of the preset function calculated in advance. If the current hash value is the same as the preset hash value, then the second target section included in the target dynamic link library file can be decrypted to obtain the first target section.

[0069] It should be noted that if the current hash value is inconsistent with the preset hash value, then the current decryption process is also exited and the process is ended to prevent reverse behavior. Therefore, in this process, by comparing the hash values, it can be monitored whether other processes enter the memory of the decryption process, and then the decryption process can be executed without other processes entering, improving the security of data during the decryption process.

[0070] When monitoring whether other processes enter the memory of the decryption process by comparing hash values, the command-line tool inotify can also be used to monitor whether there are read and write operations on the memory information of proc / pid / mem and / proc / pid / pagemep of the process where the target dynamic link library file is located. If there are read and write operations, it means that other processes have entered the process memory of the decryption device, and then the current decryption process is also exited and the process is ended to prevent reverse behavior. Therefore, in this process, the decryption process can be executed without other processes entering, improving the security of data during the decryption process.

[0071] In this step, the target dynamic link library file includes a header area in the target format. The header area includes the address of the first target section area and may also include the size of the first target section area. In one embodiment, the process of decrypting the second target section area included in the target dynamic link library file to obtain the first target section area may specifically be: reading the address of the first target section area, or the address and size, from the header area in the target format of the target dynamic link library file; then determining the second target section area according to the address of the first target section area, or the address and size; finally, decrypting and restoring the second target section area to obtain the first target section area. Because in this embodiment, the second target section area is an encrypted and obfuscated section area, which will cause the target dynamic link library file generated according to the second target section area to be a defective library file, and further cause cracking tools such as IDA to be unable to open or report an error when opened. Therefore, during the decryption process, it is necessary to implement decryption and restoration according to the address and size of the first target section area stored in the header area, improving the security of the target dynamic link library file.

[0072] In addition, during the decryption process, not only the second target section area in the target dynamic link library file needs to be decrypted and restored, but also the encrypted anti-reverse function in the target dynamic link library file needs to be decrypted, that is, S108 is executed, in order to realize data unpacking and then obtain the decrypted dynamic link library file.

[0073] S108: The decryption device decrypts the encrypted anti-reverse function included in the target dynamic link library file to obtain the decrypted anti-reverse function.

[0074] It should be noted that the address and size of the encrypted anti-reverse function are also stored in the header area in the target format. Therefore, in this process, the address of the anti-reverse function can be obtained from the header area in the target format of the target dynamic link library file, and then the encrypted anti-reverse function is determined according to the address of the anti-reverse function; finally, the encrypted anti-reverse function is decrypted to obtain the decrypted anti-reverse function.

[0075] After obtaining the first target section area and the decrypted anti-reverse function, the decrypted dynamic link library file can be generated, that is, S109 is executed.

[0076] S109: The decryption device generates a decrypted dynamic link library file according to the first target section area and the decrypted anti-reverse function.

[0077] It should be noted that the target dynamic link library file also includes the address of the target interface, that is, the address of the Application Programming Interface (API). When decrypting and running the target dynamic link library file, the API call needs to be implemented by the program head table in the target dynamic link library file.

[0078] Therefore, in one embodiment, in order to timely clear the information of the target program head table in the target dynamic link library file and prevent it from being obtained by other processes, after the decryption device obtains the API address of the target dynamic link library file, that is, after obtaining the address of the target interface, it will send a target interface loading completion message to the encryption device for the encryption device to clear the target program head table in the target dynamic link library file, thereby preventing it from being obtained by other processes. In addition, even if the dynamic link library file is obtained by other processes, because the program head table in the dynamic link library file is missing at this time, even if the dynamic link library file is obtained, the API call cannot be realized. Therefore, this decryption process can improve the security of the target dynamic link library file.

[0079] In another embodiment, before replacing the target original function of the decryption device with a preset function through a preset replacement algorithm, the method can also send a loading feedback message to the encryption device based on the execution of a preset entry function, so that when the duration of the encryption device timing according to the loading feedback message exceeds a preset threshold, the target program head table in the target dynamic link library file is cleared, thereby preventing it from being obtained by other processes. Similarly, even if the dynamic link library file is obtained by other processes, because the program head table in the dynamic link library file is missing at this time, even if the dynamic link library file is obtained, the API call cannot be realized. Therefore, the security of the target dynamic link library file can be improved.

[0080] As can be seen from the above process of loading and decrypting, a series of anti-reverse measures are implemented when the encrypted dynamic link library is loaded into the process space and restored for operation, which can protect the code bytes from being extracted, thus making reverse engineering a dead-end proposition. Moreover, even if the dynamic link library file is reverse-engineered, the extracted dynamic link library file is very likely to be incomplete without a program head table, and it takes a lot of time to crack and restore, so the security of the target dynamic link library file is improved.

[0081] Moreover, through the actual tests of the inventor, reverse engineering tools cannot open the encrypted dynamic link library file for analysis and reverse engineering. As Figure 2 shown, an error is prompted when the readelf tool reads the encrypted library.

[0082] In the embodiment of the present application, after receiving the dynamic link library file to be processed, a first target section is added to the dynamic link library file, and the first target section is encrypted using a first preset algorithm to obtain a second target section. Since adding the second target section obtained through encryption processing will make the target dynamic link library file become a defective library file, the target dynamic link library file cannot be opened by IDA and an error will be reported when opened. Then, a second preset encryption algorithm is used to encrypt the anti-reverse function in the dynamic link library file to obtain the encrypted anti-reverse function, and finally a target dynamic link library file including the second target section and the encrypted anti-reverse function is generated. Since the data in the generated target dynamic link library file has been processed, it is difficult to perform static analysis for reverse modification, which improves the security of the encrypted file.

[0083] Figure 3 FIG. is a schematic flowchart of a method for encrypting a dynamic link library file provided by an embodiment of the present application. The method for encrypting a dynamic link library file is applied to an encryption device. As Figure 3 shown, the method includes S301-S305, and S301-S305 are specifically as follows:

[0084] S301: Receive the dynamic link library file to be processed.

[0085] As an example, the received dynamic link library file refers to the ELF format.

[0086] Therefore, in the present application, the dynamic link library file in the ELF format is used as an example for description, but this embodiment is not limited to files in the ELF format and can also be replaced with files in other formats.

[0087] S302: Add a first target section to the dynamic link library file.

[0088] Specifically, the first target section refers to the section in the dynamic link library file in the ELF format.

[0089] S303: Encrypt the first target section using the first preset algorithm to obtain the second target section.

[0090] In this step, the first preset algorithm refers to an encryption and obfuscation algorithm customized with a tool. The tool can be an elf processing tool customized in advance. That is to say, the second target section obtained by encrypting and obfuscating the first target section using the first preset algorithm is an encrypted and obfuscated section. Therefore, the target dynamic link library file generated according to the second target section is a defective library file, which makes it impossible for cracking tools such as IDA to open it or report an error when opened, improving the security of the target dynamic link library file.

[0091] After encrypting the first target section, in order to make the generated target dynamic link library file more secure, the anti-reverse function in the target dynamic link library file can also be encrypted, that is, execute S304.

[0092] S304: Encrypt the anti-reverse function in the dynamic link library file using the second preset encryption algorithm to obtain the encrypted anti-reverse function.

[0093] Specifically, the second preset encryption algorithm can be an algorithm for encrypting the anti-reverse function predefined in the elf processing tool.

[0094] It should be further noted that the anti-reverse function can also be called the anti-reverse core function and the function for combating reverse unpacking, so as to prevent reverse unpacking and cracking, thereby improving the security of the target dynamic link library file.

[0095] After obtaining the second target section and the encrypted anti-reverse function, the target dynamic link library file can be generated, that is, S305 can be executed to generate the target dynamic link library file.

[0096] S305: Generate the target dynamic link library file, where the target dynamic link library file includes the second target section and the encrypted anti-reverse function.

[0097] Specifically, in this process, the address of the first target section can be obtained, and the address and size are stored in the unused fields in the header area of the target format of the dynamic link library file. In addition, the size of the first target section can also be obtained and stored in the unused fields in the above header area. Since the address of the first target section and the second target section obtained after encryption remains unchanged, the process of decrypting the second target section according to the header area can be realized subsequently. And because the dynamic link library file specifically refers to the ELF format, the header area of the target format specifically refers to the elf head.

[0098] After that, the target dynamic link library file can be generated according to the header area of the target format, the second target section area, and the encrypted anti-reverse function. Since the generated target dynamic link library file is incomplete and encrypted, it cannot be opened and analyzed by static analysis tools such as IDA, improving the security of the target dynamic link library file.

[0099] In the embodiment of the present application, after receiving the dynamic link library file to be processed, a first target section area is added to the dynamic link library file, and the first target section area is encrypted by using a first preset algorithm to obtain a second target section area. Since adding the second target section area obtained through encryption processing will make the target dynamic link library file become a defective library file, the target dynamic link library file cannot be opened by IDA and will report an error when opened. Then, the anti-reverse function in the dynamic link library file is encrypted by using a second preset encryption algorithm to obtain an encrypted anti-reverse function. Finally, a target dynamic link library file including the second target section area and the encrypted anti-reverse function is generated. Since the data in the generated target dynamic link library file has been processed, it is difficult to perform reverse modification through static analysis, improving the security of the encrypted file.

[0100] Figure 4 is a flowchart of a method for decrypting a dynamic link library file provided by an embodiment of the present application. The method for decrypting a dynamic link library file is applied to a decryption device, such as Figure 4 shown, the method includes S401-S405, and S401-S405 are specifically as follows:

[0101] S401: The decryption device obtains the target dynamic link library file from the encryption device.

[0102] Specifically, when the decryption device obtains the target dynamic link library file from the encryption device, first execute the entry function in the pre-configured init.array, and then execute the decryption process of S107-S109.

[0103] S402: The decryption device decrypts the second target section area included in the dynamic link library file to obtain the first target section area.

[0104] In one embodiment, it is possible to first prevent debugging and injection by ptrace attch itself. If the ptrace attch fails or the TracerPid is not 0, then exit the current decryption process, so as to monitor debugging and injection operations at the beginning of the decryption process, thereby improving the security of the data during the decryption process.

[0105] After determining that it is not being debugged and injected by ptrace attaching itself, the target original function of the decryption device can be replaced with a preset function through a preset replacement algorithm. Among them, the preset replacement algorithm refers to the algorithm used for HOOK operations. The target original functions include exported (dump) interface functions, such as write, fwrite, printf, fputs, puts, fprintf functions. In addition, the target original functions can also include system call functions such as inotify and ptrace. That is to say, in the replacement process, the interface functions and system call functions are replaced with preset functions, which include preset target interface functions and preset target system functions, so as to calculate the hash value according to the address of the preset function subsequently to monitor whether other processes enter the memory of the decryption device and ensure the security of data during the decryption process.

[0106] During the process of monitoring according to the hash value, specifically, the hash value of the address of the preset function in the decryption device at this moment can be calculated in real time, and the real-time hash value is compared with the preset hash value of the address of the preset function calculated in advance. If the current hash value is the same as the preset hash value, then the second target section included in the target dynamic link library file can be decrypted to obtain the first target section.

[0107] It should be noted that if the current hash value is inconsistent with the preset hash value, then the current decryption process is also exited and the process is ended to prevent reverse behavior. Therefore, in this process, by comparing the hash values, it can be monitored whether other processes enter the memory of the decryption process, and then the decryption process can be executed without other processes entering, improving the security of data during the decryption process.

[0108] When monitoring whether other processes enter the memory of the decryption process by comparing hash values, the command-line tool inotify can also be used to monitor whether there are read and write operations on the proc / pid / mem and / proc / pid / pagemep memory information of the process where the target dynamic link library file is located. If there are read and write operations, it means that other processes operate and enter the process memory of the decryption device, then the current decryption process is also exited and the process is ended to prevent reverse behavior. Therefore, in this process, the decryption process can be executed without other processes entering, improving the security of data during the decryption process.

[0109] In this step, the target dynamic link library file includes a header area in the target format. This header area includes the address of the first target section, and may also include the size of the first target section. In one embodiment, the process of decrypting the second target section included in the target dynamic link library file to obtain the first target section may specifically be: reading the address of the first target section, or the address and size, from the header area in the target format of the target dynamic link library file; then determining the second target section according to the address of the first target section, or the address and size; and finally decrypting and restoring the second target section to obtain the first target section. Because in this embodiment, the second target section is an encrypted and obfuscated section, which will cause the target dynamic link library file generated according to this second target section to be a defective library file, and further make cracking tools such as IDA unable to open it or report an error when opening it. Therefore, during the decryption process, it is necessary to implement decryption and restoration according to the address and size of the first target section stored in the header area, which improves the security of the target dynamic link library file.

[0110] In addition, during the decryption process, not only the second target section in the target dynamic link library file needs to be decrypted and restored, but also the encrypted anti-reverse function in the target dynamic link library file needs to be decrypted, that is, execute S403, to achieve data unpacking, and then obtain the decrypted dynamic link library file.

[0111] S403: The decryption device decrypts the encrypted anti-reverse function included in the target dynamic link library file to obtain the decrypted anti-reverse function.

[0112] It should be noted that the address and size of the encrypted anti-reverse function are also stored in the header area in the target format. Therefore, in this process, the address of the anti-reverse function can be obtained from the header area in the target format of the target dynamic link library file, and then the encrypted anti-reverse function is determined according to the address of the anti-reverse function; finally, the encrypted anti-reverse function is decrypted to obtain the decrypted anti-reverse function.

[0113] After obtaining the first target section and the decrypted anti-reverse function, the decrypted dynamic link library file can be generated, that is, execute S404.

[0114] S404: The decryption device generates a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function.

[0115] It should be noted that the target dynamic link library file also includes the address of the target interface, that is, the API address. When decrypting and running this target dynamic link library file, the API call needs to be implemented by the program headtable in the target dynamic link library file.

[0116] Therefore, in one embodiment, in order to timely clear the information of the program head table in the target dynamic link library file and prevent it from being obtained by other processes, after the decryption device obtains the API address of the target dynamic link library file, that is, after obtaining the address of the target interface, it will send the target interface loading completion information to the encryption device for the encryption device to clear the program head table in the target dynamic link library file, thereby preventing it from being obtained by other processes. In addition, even if the dynamic link library file is obtained by other processes, since the program head table in the dynamic link library file is missing at this time, even if the dynamic link library file is obtained, API calls cannot be realized. Therefore, this decryption process can improve the security of the target dynamic link library file.

[0117] In another embodiment, before replacing the target original function of the decryption device with a preset function through a preset replacement algorithm, the method can also send a loading feedback information to the encryption device based on the execution of a preset entry function, so that when the duration of the encryption device timing according to the loading feedback information exceeds a preset threshold, the program head table in the target dynamic link library file can be cleared, thereby preventing it from being obtained by other processes. Similarly, even if the dynamic link library file is obtained by other processes, since the program head table in the dynamic link library file is missing at this time, even if the dynamic link library file is obtained, API calls cannot be realized. Therefore, the security of the target dynamic link library file can be improved.

[0118] It can be seen from the above loading and decryption process that in this embodiment, a series of countermeasures against reverse engineering are implemented when the encrypted dynamic link library is loaded into the process space and restored to run, which can protect the code bytes from being extracted, making reverse engineering a dead-end proposition. Moreover, even if the dynamic link library file is reverse engineered, the extracted dynamic link library file is very likely to be incomplete without a program head table, and it takes a lot of time to crack and restore, so the security of the target dynamic link library file is improved.

[0119] It should be noted that for the dynamic link library file encryption method provided in the embodiments of the present application, the execution subject can be an encryption device, or a control module in the encryption device for executing the dynamic link library file encryption method. In the embodiments of the present application, the encryption device is used as an example to execute the dynamic link library file encryption method to illustrate the device for encrypting the dynamic link library file provided in the embodiments of the present application.

[0120] Figure 5 It is a schematic structural diagram of an encryption device provided in the embodiments of the present application, as Figure 5 shown, the encryption device 500 includes:

[0121] A receiving module 501, configured to receive a dynamic link library file to be processed;

[0122] An adding module 502, configured to add a first target section to the dynamic link library file;

[0123] An encrypting module 503, configured to encrypt the first target section using a first preset algorithm to obtain a second target section;

[0124] The encrypting module 503 is further configured to encrypt an anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain an encrypted anti-reverse function;

[0125] A generating module 504, configured to generate a target dynamic link library file, where the target dynamic link library file includes the second target section and the encrypted anti-reverse function.

[0126] It should be further noted that the anti-reverse function can also be referred to as an anti-reverse core function and a function for combating reverse unpacking, so as to prevent reverse unpacking and cracking, thereby improving the security of the target dynamic link library file.

[0127] In the embodiment of the present application, after receiving the dynamic link library file to be processed, a first target section is added to the dynamic link library file, and the first target section is encrypted using a first preset algorithm to obtain a second target section. Since adding the second target section obtained through encryption processing will make the target dynamic link library file become a defective library file, the target dynamic link library file cannot be opened by IDA and will report an error when opened. Then, the anti-reverse function in the dynamic link library file is encrypted using a second preset encryption algorithm to obtain an encrypted anti-reverse function, and finally, a target dynamic link library file including the second target section and the encrypted anti-reverse function is generated. Since the data in the generated target dynamic link library file has been processed, it is difficult to perform reverse modification through static analysis, improving the security of the encrypted file.

[0128] In one embodiment, the encryption device 500 further includes:

[0129] An obtaining module, configured to obtain the address of the first target section and store the address in the header area of the target format of the dynamic link library file for decrypting the second target section;

[0130] The generating module is further configured to generate a target dynamic link library file according to the header area of the target format, the second target section, and the encrypted anti-reverse function.

[0131] In this embodiment, adding the second target section area obtained through encryption processing will make the target dynamic link library file become a mutilated library file, so that the target dynamic link library file cannot be opened by IDA and will report an error when opened. Then, the anti-reverse function in the dynamic link library file is encrypted using the second preset encryption algorithm to obtain the encrypted anti-reverse function. Finally, a target dynamic link library file including the second target section area and the encrypted anti-reverse function is generated. Since the data in the generated target dynamic link library file has been processed, it is difficult to analyze and modify it statically, which improves the security of the encrypted file.

[0132] In addition, it should be noted that for the dynamic link library file decryption method provided in the embodiments of the present application, the execution subject may be a decryption device, or a control module in the decryption device for executing the dynamic link library file decryption method. In the embodiments of the present application, the case where the decryption device executes the dynamic link library file decryption method is taken as an example to illustrate the device for decrypting the dynamic link library file provided in the embodiments of the present application.

[0133] Figure 6 It is a schematic structural diagram of a decryption device provided in the embodiments of the present application, as Figure 6 shown, the decryption device 600 includes:

[0134] An acquisition module 601, configured to acquire a target dynamic link library file;

[0135] A decryption module 602, configured to decrypt the second target section area included in the target dynamic link library file to obtain a first target section area;

[0136] The decryption module 602 is further configured to decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function;

[0137] A generation module 603, configured to generate a decrypted dynamic link library file according to the first target section area and the decrypted anti-reverse function.

[0138] In this embodiment, during the process of decrypting the acquired target dynamic link library file, a series of anti-reverse measures including decrypting the second target section area and decrypting the anti-reverse function are implemented when loading the encrypted dynamic link library, that is, the target dynamic link library file, into the process space for restoration and operation. Therefore, it is possible to protect the code bytes from being extracted, making reverse engineering a dead-end proposition, improving the security of the data during the decryption process, and further enhancing the security of the encrypted file.

[0139] In one embodiment, the decryption device 600 further includes:

[0140] A replacement module, configured to replace the target original function of the decryption device with a preset function through a preset replacement algorithm;

[0141] A calculation module, configured to calculate the hash value of the address of a preset function in the decryption device;

[0142] The decryption module is further configured to decrypt the second target section included in the target dynamic link library file to obtain the first target section when the hash value is the same as the preset hash value. If the hash value is inconsistent with the preset hash value at this time, the current decryption process is also exited and the process is ended to prevent reverse behavior. Therefore, in this process, by comparing the hash values, it is possible to monitor whether other processes enter the memory of this decryption process, and then it is possible to implement the decryption process without other processes entering, improving the security of the data during the decryption process.

[0143] It should be noted that the preset function includes a preset target interface function and a preset target system function.

[0144] In one embodiment, the target dynamic link library file includes a header area in a target format, and the header area includes the address of the first target section; the decryption device 600 further includes a determination module;

[0145] An acquisition module is further configured to acquire the address of the first target section from the header area in the target format of the target dynamic link library file;

[0146] The determination module is configured to determine the second target section according to the address of the first target section;

[0147] The decryption module is further configured to decrypt the second target section to obtain the first target section.

[0148] In one embodiment, the target dynamic link library file includes a header area in a target format, and the header area includes the address of an anti-reverse function;

[0149] An acquisition module is further configured to acquire the address of the anti-reverse function from the header area in the target format of the target dynamic link library file;

[0150] The determination module is configured to determine the encrypted anti-reverse function according to the address of the anti-reverse function;

[0151] The decryption module is further configured to decrypt the encrypted anti-reverse function to obtain the decrypted anti-reverse function. In this embodiment, it is necessary to decrypt the anti-reverse function to obtain the decrypted anti-reverse function for unpacking, so the security of the data during the decryption process is improved.

[0152] In one embodiment, the target dynamic link library file includes the address of a target interface; the decryption device 600 further includes:

[0153] A sending module, configured to send a target interface loading completion message to an encryption device when the address of a target interface is obtained, so as to enable the encryption device to clear a target program header table in a target dynamic link library file. In this embodiment, by clearing the target program header table in the target dynamic link library file, it is possible to prevent it from being obtained by other processes. In addition, even if the dynamic link library file is obtained by other processes, since the program head table, i.e., the target program header table, is missing in the dynamic link library file at this time, even if the dynamic link library file is obtained, API calls cannot be realized. Therefore, this decryption process can improve the security of the target dynamic link library file.

[0154] In one embodiment, the sending module in the decryption device 600 is further configured to send a loading feedback message to the encryption device based on the execution of a preset entry function before replacing the target original function of the decryption device with a preset function by a preset replacement algorithm, so as to enable the encryption device to clear the target program header table in the target dynamic link library file when the duration of timing according to the loading feedback message exceeds a preset threshold. In this embodiment, by clearing the target program header table in the target dynamic link library file, it is possible to prevent it from being obtained by other processes. Similarly, even if the dynamic link library file is obtained by other processes, since the program head table is missing in the dynamic link library file at this time, even if the dynamic link library file is obtained, API calls cannot be realized. Therefore, the security of the target dynamic link library file can be improved.

[0155] As can be seen from the decryption process executed by the above decryption device 600, in this embodiment, a series of countermeasures against reverse engineering are implemented when the encrypted dynamic link library is loaded into the process space and restored to run, which can protect the code bytes from being extracted, thus making reverse engineering a dead-end proposition. Moreover, even if the dynamic link library file is reverse-engineered, the extracted dynamic link library file is very likely to be incomplete without a program head table, and it takes a lot of time to crack and restore, so the security of the target dynamic link library file is improved.

[0156] The encryption device and decryption device in the embodiments of the present application may be a device, or a component, integrated circuit, or chip in a terminal. The device may be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc. The non-mobile electronic device may be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0157] The encryption device and decryption device in the embodiments of the present application may be devices with an operating system. The operating system may be a Linux operating system, an Android operating system, or an iOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0158] The encryption device provided by the embodiments of the present application can implement Figure 1 the various processes implemented on the encryption device side and Figure 3 For the sake of avoiding repetition, they will not be elaborated here.

[0159] Similarly, the decryption device provided by the embodiments of the present application can implement Figure 1 the various processes implemented on the decryption device side and Figure 4 For the sake of avoiding repetition, they will not be elaborated here.

[0160] Optionally, as Figure 7 shown, the embodiments of the present application further provide an electronic device 700, including a processor 701, a memory 702, and a program or instruction stored on the memory 702 and executable on the processor 701. When the program or instruction is executed by the processor 701, it implements the various processes of the above-mentioned method embodiments for encrypting dynamic link library files, or implements the various processes of the above-mentioned method embodiments for decrypting dynamic link library files, and can achieve the same technical effects. For the sake of avoiding repetition, they will not be elaborated here.

[0161] It should be noted that the electronic device in the embodiments of the present application includes the above-mentioned mobile electronic devices and non-mobile electronic devices.

[0162] Figure 8 Schematic diagram of the hardware structure of an electronic device for implementing the embodiments of the present application.

[0163] The electronic device 800 includes, but is not limited to, components such as a radio frequency unit 801, a network module 802, an audio output unit 803, an input unit 804, a sensor 805, a display unit 806, a user input unit 807, an interface unit 808, a memory 809, and a processor 810.

[0164] Those skilled in the art can understand that the electronic device 800 may further include a power source (such as a battery) for supplying power to each component. The power source can be logically connected to the processor 810 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. Figure 8 The structure of the electronic device shown does not limit the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0165] Among them, the interface unit 808 is used to receive a dynamic link library file to be processed.

[0166] The processor 810 is used to add a first target section to the dynamic link library file.

[0167] The processor 810 is further used to encrypt the first target section using a first preset algorithm to obtain a second target section.

[0168] The processor 810 is further used to encrypt the anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain an encrypted anti-reverse function.

[0169] The processor 810 is further used to generate a target dynamic link library file, which includes the second target section and the encrypted anti-reverse function.

[0170] In the embodiment of the present application, after receiving the dynamic link library file to be processed, a first target section is added to the dynamic link library file, and the first target section is encrypted using a first preset algorithm to obtain a second target section. Since adding the second target section obtained through encryption processing will make the target dynamic link library file become a defective library file, the target dynamic link library file cannot be opened by IDA and will report an error when opened. Then, the anti-reverse function in the dynamic link library file is encrypted using a second preset encryption algorithm to obtain an encrypted anti-reverse function. Finally, a target dynamic link library file including the second target section and the encrypted anti-reverse function is generated. Since the data in the generated target dynamic link library file has been processed, it is difficult to perform static analysis for reverse modification, improving the security of the encrypted file.

[0171] Optionally, the processor 810 is further configured to obtain the address of the first target section and store the address in the header section of the target format of the dynamic link library file for decrypting the second target section;

[0172] The processor 810 is further configured to generate a target dynamic link library file according to the header section of the target format, the second target section, and the encrypted anti-reverse function.

[0173] In this embodiment, adding the second target section obtained through encryption processing makes the target dynamic link library file become a defective library file, so that the target dynamic link library file cannot be opened by IDA and an error will be reported when opened. Then, the anti-reverse function in the dynamic link library file is encrypted using the second preset encryption algorithm to obtain the encrypted anti-reverse function. Finally, a target dynamic link library file including the second target section and the encrypted anti-reverse function is generated. Because the data in the generated target dynamic link library file has been processed, it is difficult to statically analyze and reverse modify, which improves the security of the encrypted file.

[0174] In addition, the interface unit 808 is further configured to obtain the target dynamic link library file;

[0175] The processor 810 is configured to decrypt the second target section included in the target dynamic link library file to obtain the first target section;

[0176] The processor 810 is further configured to decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain the decrypted anti-reverse function;

[0177] The processor 810 is configured to generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function.

[0178] In this embodiment, during the process of decrypting the obtained target dynamic link library file, a series of anti-reverse measures including decrypting the second target section and decrypting the anti-reverse function are implemented when loading the encrypted dynamic link library into the process space for restoration operation. Therefore, it is possible to protect the code bytes from being extracted, making reverse engineering a dead-end proposition and improving the security of the data during the decryption process.

[0179] In one embodiment, the processor 810 is configured to replace the target original function of the decryption device with a preset function through a preset replacement algorithm;

[0180] The processor 810 is configured to calculate the hash value of the address of the preset function in the decryption device;

[0181] The processor 810 is further configured to decrypt the second target section included in the target dynamic link library file to obtain the first target section when the hash value is the same as the preset hash value. If the hash value at this time is inconsistent with the preset hash value, the current decryption process is also exited and the process is ended to prevent reverse behavior. Therefore, in this process, by comparing the hash values, it is possible to monitor whether other processes enter the memory of the decryption process, and then it is possible to execute the decryption process without other processes entering, improving the security of the data during the decryption process.

[0182] It should be noted that the preset function includes a preset target interface function and a preset target system function.

[0183] In one embodiment, the target dynamic link library file includes a header area in a target format, and the header area includes the address of the first target section; the processor 810 is configured to obtain the address of the first target section from the header area in the target format of the target dynamic link library file;

[0184] The processor 810 is configured to determine the second target section according to the address of the first target section;

[0185] The processor 810 is further configured to decrypt the second target section to obtain the first target section.

[0186] In one embodiment, the target dynamic link library file includes a header area in a target format, and the header area includes the address of the anti-reverse function;

[0187] The processor 810 is further configured to obtain the address of the anti-reverse function from the header area in the target format of the target dynamic link library file;

[0188] The processor 810 is configured to determine the encrypted anti-reverse function according to the address of the anti-reverse function;

[0189] The processor 810 is further configured to decrypt the encrypted anti-reverse function to obtain the decrypted anti-reverse function. In this embodiment, it is necessary to decrypt the anti-reverse function to obtain the decrypted anti-reverse function for unpacking, so the security of the data during the decryption process is improved.

[0190] In one embodiment, the target dynamic link library file includes the address of the target interface; the processor 810 is configured to send a target interface loading completion message to the encryption device when the address of the target interface is obtained, so that the encryption device clears the target program header table in the target dynamic link library file. In this embodiment, by clearing the target program header table in the target dynamic link library file, it can be prevented from being obtained by other processes. In addition, even if the dynamic link library file is obtained by other processes, since the program head table, that is, the target program header table, is missing in the dynamic link library file at this time, even if the dynamic link library file is obtained, API calls cannot be realized. Therefore, this decryption process can improve the security of the target dynamic link library file.

[0191] In one embodiment, the processor 810 is further configured to send a loading feedback message to the encryption device based on the execution of a preset entry function before replacing the target original function of the decryption device with a preset function by a preset replacement algorithm, so that the encryption device clears the target program header table in the target dynamic link library file when the duration of timing according to the loading feedback message exceeds a preset threshold. In this embodiment, by clearing the target program header table in the target dynamic link library file, it can be prevented from being obtained by other processes. Similarly, even if the dynamic link library file is obtained by other processes, since the program head table is missing in the dynamic link library file at this time, even if the dynamic link library file is obtained, API calls cannot be realized. Therefore, the security of the target dynamic link library file can be improved.

[0192] In this embodiment, a series of countermeasures against reverse engineering are implemented when the encrypted dynamic link library is loaded into the process space for restoration and operation, which can protect the code bytes from being extracted, thus making reverse engineering a dead-end proposition. Moreover, even if the dynamic link library file is reverse engineered, the extracted dynamic link library file is very likely to be incomplete without a program head table, and it takes a lot of time to crack and restore, so the security of the target dynamic link library file is improved.

[0193] It should be understood that in the embodiments of the present application, the input unit 804 may include a Graphics Processing Unit (GPU) and a microphone. The GPU processes the image data of static pictures or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 806 may include a display panel, and the display panel may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 807 includes a touch panel and other input devices. The touch panel is also called a touch screen. The touch panel may include two parts: a touch detection device and a touch controller. Other input devices may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here. The memory 809 may be used to store software programs and various data, including but not limited to application programs and operating systems. The processor 810 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communications. It can be understood that the above-mentioned modem processor may not be integrated into the processor 810.

[0194] The embodiments of the present application further provide a readable storage medium. A program or instruction is stored on the readable storage medium. When the program or instruction is executed by a processor, it implements each process of the above-mentioned embodiment of the dynamic link library file encryption method or each process of the above-mentioned embodiment of the dynamic link library file decryption method, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0195] Among them, the processor is the processor in the electronic device described in the above-mentioned embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, or an optical disc.

[0196] The embodiments of the present application further provide a chip. The chip includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run a program or instruction to implement each process of the above-mentioned embodiment of the dynamic link library file encryption method or each process of the above-mentioned embodiment of the dynamic link library file decryption method, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0197] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, a system chip, a chip system, or a system-on-chip.

[0198] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements not only includes those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or device comprising such element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0199] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0200] The embodiments of the present application have been described above with reference to the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A method for decrypting a target dynamic link library file, characterized in that, Applied to a decryption device, the method includes: Obtain a target dynamic link library file from an encryption device, where the target dynamic link library file is generated by the encryption device, and the target dynamic link library file includes the address of a target interface; Send loading feedback information to the encryption device based on the execution of a preset entry function, so that in the case where the duration of the encryption device timing according to the loading feedback information exceeds a preset threshold, clear the target program header table in the target dynamic link library file; Replace the target original functions of the decryption device with preset functions through a preset replacement algorithm, where the target original functions include interface functions and system call functions, and the preset functions include a preset target interface function and a preset target system function; Calculate the hash value of the address of the preset function in the decryption device; In the case where the hash value is the same as a preset hash value, decrypt a second target section included in the target dynamic link library file to obtain a first target section; Decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function; Generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function; In the case where the address of the target interface is obtained, send target interface loading completion information to the encryption device, so that the encryption device clears the target program header table in the target dynamic link library file.

2. The method according to claim 1, characterized in that, The target dynamic link library file includes a header area in a target format, and the header area includes the address of the first target section; the decrypting the second target section included in the target dynamic link library file to obtain a first target section includes: Obtain the address of the first target section from the header area in the target format of the target dynamic link library file; Determine the second target section according to the address of the first target section; Decrypt the second target section to obtain a first target section.

3. The method according to claim 1, characterized in that, The target dynamic link library file includes a header area in a target format, and the header area includes the address of the anti-reverse function; the decrypting the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function includes: Obtain the address of the anti-reverse function from the header area in the target format of the target dynamic link library file; Determine the encrypted anti-reverse function according to the address of the anti-reverse function; Decrypt the encrypted anti-reverse function to obtain a decrypted anti-reverse function.

4. A method for encrypting a dynamic link library file, characterized in that, Applied to an encryption device, the method includes: Receive a dynamic link library file to be processed; Add a first target section to the dynamic link library file; Encrypt the first target section using a first preset algorithm to obtain a second target section; Encrypt the anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain an encrypted anti-reverse function; Generate a target dynamic link library file, where the target dynamic link library file includes a second target section and an encrypted anti-reverse function, and the target dynamic link library file includes the address of a target interface, so that after obtaining the target dynamic link library file, a decryption device sends a loading feedback message to an encryption device based on the execution of a preset entry function, for the encryption device to clear the target program header table in the target dynamic link library file when the time counted according to the loading feedback message exceeds a preset threshold, replace the target original functions of the decryption device with preset functions through a preset replacement algorithm, the target original functions include interface functions and system call functions, and the preset functions include preset target interface functions and preset target system functions; calculate the hash value of the address of the preset function in the decryption device; when the hash value is the same as the preset hash value, decrypt the second target section included in the target dynamic link library file to obtain a first target section, decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function, generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function, and when obtaining the address of the target interface, send a target interface loading completion message to the encryption device for the encryption device to clear the target program header table in the target dynamic link library file.

5. The method according to claim 4, characterized in that, The generating of the target dynamic link library file includes: Obtain the address of the first target section and store the address in the header area of the target format of the dynamic link library file for decrypting the second target section; Generate a target dynamic link library file according to the header area of the target format, the second target section, and the encrypted anti-reverse function.

6. A decryption device, characterized in that, The decryption device includes: An obtaining module, configured to obtain a target dynamic link library file, where the target dynamic link library file is generated by an encryption device and includes the address of a target interface; A sending module, configured to send a loading feedback message to the encryption device based on the execution of a preset entry function, for the encryption device to clear the target program header table in the target dynamic link library file when the time counted according to the loading feedback message exceeds a preset threshold; A replacement module, configured to replace the target original functions of the decryption device with preset functions through a preset replacement algorithm, the target original functions include interface functions and system call functions, and the preset functions include preset target interface functions and preset target system functions; A calculating module, configured to calculate the hash value of the address of the preset function in the decryption device; A decryption module, configured to decrypt the second target section included in the target dynamic link library file to obtain a first target section when the hash value is the same as the preset hash value; The decryption module is further configured to decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function; A generation module, configured to generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function; A sending module, configured to send a target interface loading completion message to an encryption device when the address of the target interface is obtained, so that the encryption device clears a target program header table in the target dynamic link library file.

7. The decryption device according to claim 6, wherein, The target dynamic link library file includes a header area in a target format, and the header area includes the address of the first target section; the decryption device further includes a determination module; The obtaining module is further configured to obtain the address of the first target section from the header area in the target format of the target dynamic link library file; The determination module is configured to determine the second target section according to the address of the first target section; The decryption module is further configured to decrypt the second target section to obtain the first target section.

8. The decryption device according to claim 6, wherein, The target dynamic link library file includes a header area in a target format, and the header area includes the address of the anti-reverse function; the decryption device further includes a determination module; The obtaining module is further configured to obtain the address of the anti-reverse function from the header area in the target format of the target dynamic link library file; The determination module is configured to determine the encrypted anti-reverse function according to the address of the anti-reverse function; The decryption module is further configured to decrypt the encrypted anti-reverse function to obtain the decrypted anti-reverse function.

9. An encryption device, wherein, The encryption device includes: A receiving module, configured to receive a dynamic link library file to be processed; An adding module, configured to add a first target section to the dynamic link library file; An encryption module, configured to encrypt the first target section using a first preset algorithm to obtain a second target section; The encryption module is further configured to encrypt the anti-reverse function in the dynamic link library file using a second preset encryption algorithm to obtain an encrypted anti-reverse function; A generation module for generating a target dynamic link library file, the target dynamic link library file including a second target section and an encrypted anti-reverse function, the target dynamic link library file including the address of a target interface, so that after obtaining the target dynamic link library file, a decryption device sends a loading feedback message to an encryption device based on the execution of a preset entry function, for the encryption device to clear the target program header table in the target dynamic link library file when the elapsed time according to the loading feedback message exceeds a preset threshold, replace the target original functions of the decryption device with preset functions through a preset replacement algorithm, the target original functions including interface functions and system call functions, the preset functions including a preset target interface function and a preset target system function; calculate the hash value of the address of the preset function in the decryption device; in the case where the hash value is the same as a preset hash value, decrypt the second target section included in the target dynamic link library file to obtain a first target section, decrypt the encrypted anti-reverse function included in the target dynamic link library file to obtain a decrypted anti-reverse function, generate a decrypted dynamic link library file according to the first target section and the decrypted anti-reverse function, and send a target interface loading completion message to the encryption device in the case of obtaining the address of the target interface, for the encryption device to clear the target program header table in the target dynamic link library file.

10. The encryption device according to claim 9, wherein, The encryption device further includes: An acquisition module for acquiring the address of the first target section and storing the address in the header area of the target format of the dynamic link library file for decrypting the second target section; The generation module is further used for generating a target dynamic link library file according to the header area of the target format, the second target section and the encrypted anti-reverse function.

11. An electronic device, wherein, It includes a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, it implements the steps of the dynamic link library file decryption method according to any one of claims 1-3, or implements the steps of the dynamic link library file encryption method according to any one of claims 4 and 5.

Citation Information

Patent Citations

  • SO (Shared Object) file protection method and device

    CN107577715A

  • Executable code protecting method and device and readable storage medium

    CN108133147A