A method for encrypting files during compilation and related devices
By injecting and encrypting sensitive data through the merge process during application compilation, the problem of difficult security of sensitive data during compilation is solved, automatic encryption is realized, omissions are avoided, and security is improved.
Patent Information
- Application Number
- CN202010837990.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-08-19
AI Technical Summary
During application compilation, sensitive data is easily extracted, resulting in security issues. The existing manual encryption methods increase the burden on developers and easily miss data.
By obtaining the data resources of the target application, merging the project files into the target directory based on the merge process, and injecting the target file containing sensitive data into the target directory after the merge process is completed, encrypting the encrypted data using a preset encryption algorithm to instruct the encoding process to generate the executable file.
It realizes automatic encryption of sensitive data during the compilation process, avoids the omission of sensitive data, and improves the security of sensitive data during the compilation process.
Smart Images

Figure CN114077431B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a method for encrypting files during compilation and related devices. Background Art
[0002] With the rapid development of computer technology, various applications have emerged in people's lives. However, some applications involve writing sensitive data, and this sensitive data is easily extracted during the compilation of the application. Therefore, how to ensure the security of sensitive data during the application compilation process has become a difficult problem.
[0003] Generally, in the development stage, developers manually use encryption tools to encrypt sensitive data one by one and put the encrypted files into the code project. That is, in the code during the development stage, the sensitive data is already encrypted files.
[0004] However, using the manual processing method, every time a sensitive data file is added, developers need to use encryption tools for encryption operations, which increases the burden on developers. And relying on manual processing, there may be cases of data omission, resulting in unencrypted sensitive data, increasing the risk of sensitive data leakage and affecting the security of sensitive data encryption. Summary of the Invention
[0005] In view of this, this application provides a method for encrypting files, which can effectively improve the security of encrypting sensitive data during compilation.
[0006] The first aspect of this application provides a method for encrypting files, which can be applied to a system or program with a file encryption function in a terminal device, and specifically includes:
[0007] Obtain the data resources corresponding to the target application, where the data resources include multiple sub-projects, and the sub-projects are used to indicate the execution of the compilation process, and the compilation process includes a merging process and an encoding process;
[0008] Based on the merging process, merge the project files corresponding to the sub-projects into the target directory;
[0009] In response to the completion of the merging process, inject a target file containing sensitive data into the target directory to generate encrypted data, where the target file is obtained by encrypting based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application.
[0010] Optionally, in some possible implementation manners of this application, the injecting a target file containing sensitive data into the target directory in response to the completion of the merging process to generate encrypted data includes:
[0011] Monitor the execution interface corresponding to the merging process to obtain an execution instruction;
[0012] If the execution instruction indicates that the merging process is completed, inject the target file containing the sensitive data into the target directory to generate the encrypted data.
[0013] Optionally, in some possible implementation manners of the present application, the monitoring the execution interface corresponding to the merging process to obtain an execution instruction includes:
[0014] Monitor the execution interface corresponding to the merging process to obtain an execution operation for the target directory;
[0015] Obtain an execution instruction based on the execution operation for the target directory.
[0016] Optionally, in some possible implementation manners of the present application, the injecting the target file containing the sensitive data into the target directory to generate the encrypted data includes:
[0017] Encrypt the target file containing the sensitive data using the preset encryption algorithm to obtain a target encrypted file;
[0018] Inject the target encrypted file into the target directory to generate the encrypted data.
[0019] Optionally, in some possible implementation manners of the present application, the responding to the completion of the merging process and injecting the target file containing the sensitive data into the target directory to generate the encrypted data includes:
[0020] Responding to the completion of the merging process, determine the temporary files included in the target directory, where the temporary files correspond to the project files;
[0021] Encrypt the target code indicated in the temporary file using the preset encryption algorithm to generate the encrypted data.
[0022] Optionally, in some possible implementation manners of the present application, the encrypting the target code indicated in the temporary file using the preset encryption algorithm to generate the encrypted data includes:
[0023] Analyze the data structure of the temporary file to obtain the target file and the target code;
[0024] Encrypt the target code to generate the encrypted data.
[0025] Optionally, in some possible implementation manners of the present application, the method further includes:
[0026] In response to a decryption instruction, monitor the reading process of the executable file;
[0027] Capture the target file based on the reading process to inject a decryption process;
[0028] In the decryption process, use a preset decryption algorithm to decrypt the target file to obtain the sensitive data.
[0029] Optionally, in some possible implementation manners of the present application, the capturing the target file based on the reading process to inject a decryption process includes:
[0030] Determine the target suffix corresponding to the target file;
[0031] Identify the target suffix based on the reading process to capture the target file;
[0032] Inject the target file into the decryption process.
[0033] Optionally, in some possible implementation manners of the present application, the method further includes:
[0034] Call the target file in response to a suffix setting instruction;
[0035] Update the file format of the target file based on the target suffix corresponding to the suffix setting instruction.
[0036] Optionally, in some possible implementation manners of the present application, the obtaining the data resources corresponding to the target application includes:
[0037] Determine the application type of the target application;
[0038] If the application type conforms to a preset type, obtain the data resources corresponding to the target application.
[0039] Optionally, in some possible implementation manners of the present application, the determining the type information of the target application includes:
[0040] Traverse the sensitive data corresponding to the target application to determine the privacy level;
[0041] Determine the type information of the target application based on the privacy level.
[0042] Optionally, in some possible implementation manners of the present application, the target application is a payment application or a financial application, the sensitive data is used to indicate user privacy data, and the user privacy data is related to the payment process.
[0043] The second aspect of the present application provides a file encryption device, including: an acquisition unit, configured to acquire data resources corresponding to a target application, where the data resources include a plurality of sub-items, and the sub-items are used to indicate the execution of a compilation process, and the compilation process includes a merging process and an encoding process;
[0044] A merging unit, configured to merge project files corresponding to the sub-items into a target directory based on the merging process;
[0045] An encryption unit, configured to, in response to the completion of the merging process, inject a target file containing sensitive data into the target directory to generate encrypted data, where the target file is obtained by encrypting based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application.
[0046] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to monitor an execution interface corresponding to the merging process to obtain an execution instruction;
[0047] The encryption unit is specifically configured to, if the execution instruction indicates the completion of the merging process, inject the target file containing the sensitive data into the target directory to generate the encrypted data.
[0048] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to monitor an execution interface corresponding to the merging process to obtain an execution operation for the target directory;
[0049] The encryption unit is specifically configured to obtain an execution instruction based on the execution operation for the target directory.
[0050] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to encrypt the target file containing the sensitive data by using the preset encryption algorithm to obtain a target encrypted file;
[0051] The encryption unit is specifically configured to inject the target encrypted file into the target directory to generate the encrypted data.
[0052] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to, in response to the completion of the merging process, determine temporary files included in the target directory, where the temporary files correspond to the project files;
[0053] The encryption unit is specifically configured to encrypt target code indicated in the temporary files by using the preset encryption algorithm to generate the encrypted data.
[0054] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to parse the data structure of the temporary file to obtain the target file and the target code;
[0055] The encryption unit is specifically configured to encrypt the target code to generate the encrypted data.
[0056] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to monitor the reading process of the executable file in response to a decryption instruction;
[0057] The encryption unit is specifically configured to capture the target file based on the reading process to inject a decryption process;
[0058] The encryption unit is specifically configured to decrypt the target file by using a preset decryption algorithm in the decryption process to obtain the sensitive data.
[0059] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to determine a target suffix corresponding to the target file;
[0060] The encryption unit is specifically configured to identify the target suffix based on the reading process to capture the target file;
[0061] The encryption unit is specifically configured to inject the target file into the decryption process.
[0062] Optionally, in some possible implementation manners of the present application, the encryption unit is specifically configured to call the target file in response to a suffix setting instruction;
[0063] The encryption unit is specifically configured to update the file format of the target file based on the target suffix corresponding to the suffix setting instruction.
[0064] Optionally, in some possible implementation manners of the present application, the acquisition unit is specifically configured to determine an application type of the target application;
[0065] The acquisition unit is specifically configured to obtain the data resource corresponding to the target application if the application type conforms to a preset type.
[0066] Optionally, in some possible implementation manners of the present application, the acquisition unit is specifically configured to traverse the sensitive data corresponding to the target application to determine a privacy level;
[0067] The acquisition unit is specifically configured to determine type information of the target application based on the privacy level.
[0068] A third aspect of the present application provides a computer device, including: a memory, a processor, and a bus system; the memory is used to store program codes; the processor is used to execute the file encryption method described in the first aspect or any item of the first aspect according to the instructions in the program codes.
[0069] A fourth aspect of the present application provides a computer-readable storage medium, in which instructions are stored, and when it runs on a computer, it causes the computer to execute the file encryption method described in the first aspect or any item of the first aspect.
[0070] According to an aspect of the present application, there is provided a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the file encryption method provided in the first aspect or various optional implementation manners of the first aspect.
[0071] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0072] By obtaining the data resources corresponding to the target application, where the data resources include multiple sub-items, and the sub-items are used to indicate the execution of the compilation process, and the compilation process includes a merging process and an encoding process; then based on the merging process, the project files corresponding to the sub-items are merged into the target directory; and in response to the completion of the merging process, a target file containing sensitive data is injected into the target directory to generate encrypted data, the target file is obtained by encrypting based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application. Thus, the automatic encryption process of sensitive data during the compilation process is realized. Since the encryption process of sensitive data is carried out after the merging process, it is not necessary to scan and identify all sub-items, avoiding the omission of sensitive data and improving the security of sensitive data during the compilation process. Description of the Drawings
[0073] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0074] Figure 1 The network architecture diagram for the operation of the file encryption system;
[0075] Figure 2System architecture diagram for file encryption provided by an embodiment of the present application;
[0076] Figure 3 Flowchart of a file encryption method provided by an embodiment of the present application;
[0077] Figure 4 Scenario schematic diagram of a file encryption method provided by an embodiment of the present application;
[0078] Figure 5 Flowchart of another file encryption method provided by an embodiment of the present application;
[0079] Figure 6 Scenario schematic diagram of another file encryption method provided by an embodiment of the present application;
[0080] Figure 7 Structural schematic diagram of a file encryption device provided by an embodiment of the present application;
[0081] Figure 8 Structural schematic diagram of a terminal device provided by an embodiment of the present application;
[0082] Figure 9 Structural schematic diagram of a server provided by an embodiment of the present application. Detailed implementation manners
[0083] An embodiment of the present application provides a file encryption method and related devices, which can be applied to a system or program with a file encryption function in a terminal device. By obtaining data resources corresponding to a target application, where the data resources include multiple sub-items, and the sub-items are used to indicate the execution of a compilation process, and the compilation process includes a merging process and an encoding process; then based on the merging process, project files corresponding to the sub-items are merged into a target directory; and in response to the completion of the merging process, a target file containing sensitive data is injected into the target directory to generate encrypted data, the target file is obtained by encrypting based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application. Thus, an automatic encryption process for sensitive data during the compilation process is realized. Since the encryption process of sensitive data is performed after the merging process, it is not necessary to scan and identify all sub-items, avoiding the omission of sensitive data and improving the security of sensitive data during the compilation process.
[0084] The terms "first", "second", "third", "fourth", etc. (if any) in the description, claims and above-mentioned drawings of this application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of this application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "corresponding to" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0085] It should be understood that the file encryption method provided by this application can be applied to a system or program with file encryption function in a terminal device, such as a software manager. Specifically, the file encryption system can run in a network architecture as Figure 1 shown, such as Figure 1 shown, which is a network architecture diagram for the operation of the file encryption system. As can be seen from the figure, the file encryption system can provide the process of file encryption with multiple information sources, that is, through the installation package file called by the terminal, compile the corresponding application data, and encrypt sensitive data during the compilation process, thereby improving the security of the data; it can be understood that Figure 1 shows a variety of terminal devices, and in actual scenarios, more or fewer types of terminal devices may participate in the file encryption process. The specific quantity and types depend on the actual scenario and are not limited here. In addition, Figure 1 shows a server, but in actual scenarios, multiple servers may also participate, especially in scenarios of multi-application interaction. The specific number of servers depends on the actual scenario.
[0086] In this embodiment, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and this application does not limit this here.
[0087] It can be understood that the above file encryption system can run on a personal mobile terminal. For example, it can run as an application like a software steward, or on a server, or on a third-party device to provide file encryption to obtain the processing result of file encryption of the information source. Specifically, the file encryption system can run in the form of a program on the above devices, or run as a system component in the above devices, or be a type of cloud service program. The specific operation mode depends on the actual scenario and is not limited here.
[0088] With the rapid development of computer technology, various applications have emerged in people's lives. However, some applications involve writing sensitive data, and this sensitive data is easily extracted during the compilation of the application. Therefore, how to ensure the security of sensitive data during the application compilation process has become a difficult problem.
[0089] Generally, in the development stage, developers manually use encryption tools to encrypt sensitive data one by one and put the encrypted files into the code project. That is, in the code during the development stage, the sensitive data is already in the form of encrypted files.
[0090] However, using the manual processing method, every time a sensitive data file is added, developers need to use encryption tools for encryption operations, which increases the burden on developers. And relying on manual processing may result in data omission, causing sensitive data not to be encrypted, increasing the risk of sensitive data leakage and affecting the security of sensitive data encryption.
[0091] To solve the above problems, this application proposes a file encryption method, which is applied to Figure 2 the file encryption process framework shown below. As Figure 2 shown, it is a system architecture diagram of file encryption provided by an embodiment of this application. The figure shows that the compilation process of APP data includes resource packaging, code compilation, format conversion, and the generation of an installation package. Specifically, taking the compilation process in a Java environment as an example, the process of resource packaging (merging process) is to create a root directory (target directory) under the application program directory. After creation, the corresponding root structure and directory tree are generated under the root directory. For the process of code compilation (encoding process), the Java compiler is used to compile the source code to generate bytecode. And further, format conversion is performed, that is, the class file is converted into a recognizable dex file, and the dex file is the executable file of the SDK file. Thus, the generation of the installation package can be completed.
[0092] In this embodiment, an encryption operation is performed after resource packaging in the above compilation process to reduce the recognition amount of sub-projects during the encryption process, without the need to copy and save sensitive data, saving encryption time.
[0093] It can be understood that the method provided in this application can be a program writing to serve as a processing logic in a hardware system, or can also be a file encryption device, and the above-mentioned processing logic is implemented in an integrated or external connection manner. As an implementation method, the file encryption device obtains the data resources corresponding to the target application, where the data resources include multiple sub-items, and the sub-items are used to indicate the execution of the compilation process. The compilation process includes a merging process and an encoding process; then, based on the merging process, the project files corresponding to the sub-items are merged into the target directory; and in response to the completion of the merging process, a target file containing sensitive data is injected into the target directory to generate encrypted data. The target file is obtained by encrypting based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application. Thus, an automatic encryption process for sensitive data during the compilation process is realized. Since the encryption process of sensitive data is performed after the merging process, it is not necessary to scan and identify all sub-items, avoiding the omission of sensitive data and improving the security of sensitive data during the compilation process.
[0094] Combined with the above system architecture, the method for file encryption in this application will be introduced below. Please refer to Figure 3 , Figure 3 which is a flowchart of a method for file encryption provided by an embodiment of this application. The embodiment of this application includes at least the following steps:
[0095] 301. Obtain the data resources corresponding to the target application.
[0096] In this embodiment, the data resources corresponding to the target application include multiple sub-items, and the sub-items are used to indicate the execution of the compilation process; for example, for a payment application, the sub-items include an account resource item, an interface management item, etc. For the Figure 2 system architecture shown, the compilation process in this embodiment includes a merging process and an encoding process, that is, the encryption of sensitive data is performed after the merging process is completed.
[0097] Specifically, the merging process is the process of performing resource merging (mergeAsset), so as to merge the files in all sub-items into the same target directory for subsequent encoding operations in the compilation process.
[0098] Optionally, considering the emergence of sensitive data generally in applications involving currency such as payment applications and financial applications, such as ID numbers, addresses, phone numbers, bank accounts, email addresses, passwords, etc., the type of the target application can be detected to determine whether an encryption process is required. Specifically, first determine the application type of the target application; if the application type meets the preset categories, obtain the data resources corresponding to the target application. For example, if the application type is financial, obtain the data resources corresponding to the target application. The specific application type depends on the actual scenario and is not limited here. By identifying the target application type, the accuracy of processing applications in a high-risk state of sensitive data leakage is improved.
[0099] Furthermore, different applications containing sensitive data may have different levels of protection for sensitive data. For example, the data protection requirements of bank applications are much higher than those of social software. Therefore, the sensitive data corresponding to the target application can be traversed to determine the privacy level; and the type information of the target application can be determined based on the privacy level. Thus, the security of applications in a high-risk state of sensitive data leakage is improved.
[0100] 302. Merge the project files corresponding to the sub-projects into the target directory based on the merge process.
[0101] In this embodiment, merging the project files corresponding to the sub-projects into the target directory is the link corresponding to mergeAsset. Specifically, the target directory is a temporary file generated during the compilation process. For the temporary file, the code in it can be conveniently extracted, and there is no need to perform an extra file-level parsing process during the processing.
[0102] 303. In response to the completion of the merge process, inject the target file containing sensitive data into the target directory to generate encrypted data.
[0103] In this embodiment, the target file is encrypted based on a preset encryption algorithm, and the encrypted data is used to instruct the encoding process to generate an executable file corresponding to the target application. Among them, the preset encryption algorithm can adopt the Advanced Encryption Standard (AES). Specifically, AES encryption is a symmetric encryption algorithm. The AES encryption process is a process that operates cyclically on a 4×4 byte matrix. Its input initial value is a plaintext block. During encryption, each round of AES performs an encryption cycle, thereby outputting the encrypted result. The specific preset encryption algorithm depends on the actual scenario and is not limited here.
[0104] Specifically, the determination of the completion of the merging process can be based on monitoring the execution interface corresponding to the merging process, that is, obtaining execution instructions by monitoring the execution interface; when the execution instructions indicate the completion of the merging process, a target file containing sensitive data is injected into the target directory to generate encrypted data. This ensures the accuracy of the judgment of the merging process.
[0105] In addition, since the object of the merging process is the target directory, the update situation of the target directory can also be monitored. Specifically, the execution interface corresponding to the merging process is monitored to obtain the execution operation for the target directory; then the execution instruction is obtained based on the execution operation for the target directory. For example, when the target directory stops updating, it indicates that the merging process is completed, so as to judge the merging process from different dimensions and ensure the accuracy of the judgment result.
[0106] Optionally, during the process of injecting the target file, it is necessary to identify the sensitive data or the target file. At this time, a special file suffix format (target suffix) can be set for the sensitive data or the target file, such as.love,.OHMYGOD, etc. During the process of injecting the encryption algorithm, the target suffix is identified and the encryption process is automatically performed; that is, the target file containing the target suffix is encrypted using a preset encryption algorithm to obtain a target encrypted file, and the target file contains sensitive data; then the target encrypted file is injected into the target directory to generate encrypted data. This ensures the accuracy of the encryption of sensitive data and does not cause the omission of sensitive data.
[0107] By monitoring the execution status of each link in the packaging and compilation, and injecting the step of encrypting sensitive data after the mergeAssets is executed, the purpose of automatic invisibility is achieved. It reduces the burden of manually encrypting files and eliminates the risk of omission.
[0108] In a possible scenario, in the code during the development stage, sensitive data is not encrypted. At the beginning of the packaging and compilation stage (merging process), all sensitive data in all sub-projects is scanned, then copied and saved in other directories; then the sensitive data is encrypted and the original file is replaced, and the subsequent packaging and compilation process uses the encrypted file, so as to realize that the sensitive data in the installation package is encrypted. For the viewing of sensitive data, after the packaging and compilation is completed, the above-mentioned copied unencrypted sensitive data needs to be restored to the sub-projects.
[0109] In the above scenario, the encryption injection is performed at the beginning of the merging process, but it is necessary to scan the sub-projects to ensure that sensitive data will not be omitted. On the one hand, there is a hidden danger of omission, and on the other hand, it is necessary to copy and save the sensitive data, occupying system resources.
[0110] In this embodiment, upon completion of the merging process, the temporary files included in the target directory can be determined; then, the target code indicated in the temporary files can be encrypted using a preset encryption algorithm to generate encrypted data. For the parsing of the temporary files, only the data structure of the temporary files needs to be parsed to obtain the target files and the target code; that is, the encryption of the target code can be completed to generate encrypted data. Thus, the encryption of the data can be completed quickly and conveniently.
[0111] It can be understood that the encryption process for sensitive data can be carried out after identifying the target suffix in the target directory, or can be carried out after identifying the target suffix and then injecting it into the target directory. The specific order depends on the actual scenario.
[0112] By analyzing the compilation process and parsing the mergeAssets process, the resources of all sub-projects can be integrated and transferred to the same target directory without scanning each sub-project one by one. This reduces the processing time. And by monitoring the changes in the file directory during the entire packaging and compilation process, all files in the installation package (executable file) directly originate from the temporary files generated during the compilation process, and this temporary file is easy to parse the code. Therefore, for the temporary files, only encryption processing is required, and no additional processing is required for the files in the code, reducing the processing time.
[0113] In a possible scenario, the encryption process for sensitive data is as Figure 4 shown. Figure 4 This is a schematic diagram of the scenario of a file encryption method provided by an embodiment of the present application. The plaintext 1-3 in the figure is sensitive data. First, different sub-projects corresponding to the APP are merged to obtain a set of plaintexts under the same target directory, and then the AES symmetric algorithm is used for encryption. The determination of the plaintext 1-3 can be based on its special suffix; thus, the corresponding ciphertext 1-3 is obtained, and then the compilation process is continued, so as to obtain an installation package containing the ciphertext 1-3.
[0114] By utilizing the characteristics of each link during the APP packaging and compilation process, after the resource packaging is executed, files containing sensitive data inside the APP are injected and encrypted; thus, automatic file encryption is realized to prevent the leakage of sensitive information; on the one hand, it reduces the manual operations during the development process and is more friendly to developers; on the other hand, it avoids the problem of encryption omission for newly added sensitive files and improves the accuracy of the encryption process.
[0115] As can be seen from the above embodiments, by obtaining the data resources corresponding to the target application, where the data resources include multiple sub-items, and the sub-items are used to indicate the execution of the compilation process, and the compilation process includes a merging process and an encoding process; then based on the merging process, the project files corresponding to the sub-items are merged into the target directory; and in response to the completion of the merging process, a target file containing sensitive data is injected into the target directory to generate encrypted data, where the target file is encrypted based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application. Thus, an automatic encryption process for sensitive data during the compilation process is realized. Since the encryption process of sensitive data is performed after the merging process, there is no need to scan and identify all sub-items, avoiding the omission of sensitive data and improving the security of sensitive data during the compilation process.
[0116] The above embodiments introduce the encryption process during the application data compilation process. The corresponding decryption process will be described below. Please refer to Figure 5 , Figure 5 FIG. is a flowchart of another file encryption method provided by an embodiment of the present application. The embodiment of the present application at least includes the following steps:
[0117] 501. Respond to the decryption instruction to monitor the reading process of the executable file.
[0118] In this embodiment, the decryption instruction may be an operation corresponding to the user installing the target application. For example, an instruction to install a payment software, thereby invoking the corresponding installation package and the executable file contained therein, and monitoring the reading process of the executable file.
[0119] 502. Capture the target file based on the reading process to inject the decryption process.
[0120] In this embodiment, the specific process of monitoring the reading process to capture the target file may be based on the target suffix of the target file, that is, the special suffix format corresponding to the sensitive data. First, determine the target suffix corresponding to the target file; then identify the target suffix based on the reading process to capture the target file; and then inject the target file into the decryption process.
[0121] In a possible scenario, the target suffix corresponding to the target file can be set, that is, the target file is invoked in response to the suffix setting instruction; then the file format of the target file is updated based on the target suffix corresponding to the suffix setting instruction, thereby avoiding data reading failure caused by the loss of the target suffix.
[0122] 503. Decrypt the target file using a preset decryption algorithm in the decryption process to obtain sensitive data.
[0123] In this embodiment, the preset decryption algorithm may be the AES algorithm in the symmetric decryption algorithm, that is, corresponding to the preset encryption algorithm, so as to ensure the normal progress of the decryption process.
[0124] 504. Perform data call.
[0125] In this embodiment, after the sensitive data is decrypted, the corresponding data can be called and used, so as to complete the installation of the target application.
[0126] In a possible scenario, the encryption process of sensitive data is as Figure 6 shown. Figure 6 This is a schematic diagram of another file encryption method provided by the embodiment of the present application. The figure shows that the installation package contains ciphertexts 1-3 (sensitive data). During the reading process of ciphertexts 1-3, real-time monitoring of sensitive data is performed. Once sensitive data is captured, the corresponding AES decryption algorithm is injected to complete decryption, so as to call and obtain the corresponding plaintext data (plaintexts 1-3), and page display is performed based on the display interface of the corresponding sub-project.
[0127] Combined with the above embodiments, it can be seen that when sensitive data is used, AES decryption is automatically adopted, that is, no additional operations are required during the installation process of the target application, and a safe and convenient application installation process can be realized.
[0128] To better implement the above solutions of the embodiments of the present application, the following also provides related devices for implementing the above solutions. Please refer to Figure 7 , Figure 7 This is a schematic structural diagram of a file encryption device provided by the embodiment of the present application. The file encryption device 700 includes:
[0129] An acquisition unit 701, configured to acquire data resources corresponding to a target application, where the data resources include a plurality of sub-projects, and the sub-projects are used to indicate the execution of a compilation process, and the compilation process includes a merging process and an encoding process;
[0130] A merging unit 702, configured to merge the project files corresponding to the sub-projects into a target directory based on the merging process;
[0131] An encryption unit 703, configured to, in response to the completion of the merging process, inject a target file containing sensitive data into the target directory to generate encrypted data, where the target file is encrypted based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application.
[0132] Optionally, in some possible implementation manners of the present application, the encryption unit 703 is specifically configured to monitor an execution interface corresponding to the merging process to obtain an execution instruction;
[0133] The encryption unit 703 is specifically configured to inject the target file containing the sensitive data into the target directory to generate the encrypted data if the execution instruction indicates that the merging process is completed.
[0134] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to monitor an execution interface corresponding to the merging process to obtain an execution operation for the target directory.
[0135] The encryption unit 703 is specifically configured to obtain an execution instruction based on the execution operation for the target directory.
[0136] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to encrypt the target file containing the sensitive data by using the preset encryption algorithm to obtain a target encrypted file.
[0137] The encryption unit 703 is specifically configured to inject the target encrypted file into the target directory to generate the encrypted data.
[0138] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to, in response to the completion of the merging process, determine a temporary file included in the target directory, where the temporary file corresponds to the project file.
[0139] The encryption unit 703 is specifically configured to encrypt target code indicated in the temporary file by using the preset encryption algorithm to generate the encrypted data.
[0140] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to parse a data structure of the temporary file to obtain a target file and the target code.
[0141] The encryption unit 703 is specifically configured to encrypt the target code to generate the encrypted data.
[0142] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to monitor a reading process of the executable file in response to a decryption instruction.
[0143] The encryption unit 703 is specifically configured to capture the target file based on the reading process to inject a decryption process.
[0144] The encryption unit 703 is specifically configured to decrypt the target file by using a preset decryption algorithm in the decryption process to obtain the sensitive data.
[0145] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to determine a target suffix corresponding to the target file;
[0146] The encryption unit 703 is specifically configured to identify the target suffix based on the reading process to capture the target file;
[0147] The encryption unit 703 is specifically configured to inject the target file into the decryption process.
[0148] Optionally, in some possible implementation manners of this application, the encryption unit 703 is specifically configured to call the target file in response to a suffix setting instruction;
[0149] The encryption unit 703 is specifically configured to update a file format of the target file based on the target suffix corresponding to the suffix setting instruction.
[0150] Optionally, in some possible implementation manners of this application, the obtaining unit 701 is specifically configured to determine an application type of the target application;
[0151] The obtaining unit 701 is specifically configured to obtain the data resource corresponding to the target application if the application type conforms to a preset type.
[0152] Optionally, in some possible implementation manners of this application, the obtaining unit 701 is specifically configured to traverse sensitive data corresponding to the target application to determine a privacy level;
[0153] The obtaining unit 701 is specifically configured to determine type information of the target application based on the privacy level.
[0154] By obtaining a data resource corresponding to a target application, where the data resource includes multiple sub-items, and the sub-items are used to indicate the execution of a compilation process, and the compilation process includes a merging process and an encoding process; then based on the merging process, project files corresponding to the sub-items are merged into a target directory; and in response to the completion of the merging process, a target file containing sensitive data is injected into the target directory to generate encrypted data, where the target file is obtained by encrypting based on a preset encryption algorithm, and the encrypted data is used to indicate the encoding process to generate an executable file corresponding to the target application. Thus, an automatic encryption process for sensitive data during the compilation process is realized. Since the encryption process of the sensitive data is performed after the merging process, it is not necessary to scan and identify all sub-items, avoiding omission of sensitive data and improving the security of sensitive data during the compilation process.
[0155] The embodiment of this application further provides a terminal device, such as Figure 8As shown in the figure, it is a schematic structural diagram of another terminal device provided by an embodiment of the present application. For the convenience of description, only the parts related to the embodiment of the present application are shown. For the specific technical details not disclosed, please refer to the method part of the embodiment of the present application. The terminal can be any terminal device including a mobile phone, a tablet computer, a personal digital assistant (PDA), a point of sales (POS), an in-vehicle computer, etc. Taking the terminal as a mobile phone as an example:
[0156] Figure 8 Shown is a block diagram of a part of the structure of a mobile phone related to the terminal provided by an embodiment of the present application. Refer to Figure 8 , the mobile phone includes: a radio frequency (RF) circuit 810, a memory 820, an input unit 830, a display unit 840, a sensor 850, an audio circuit 860, a wireless fidelity (WiFi) module 870, a processor 880, and a power supply 890 and other components. Those skilled in the art can understand that Figure 8 the structure of the mobile phone shown in
[0157] does not limit the mobile phone, and it may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements. Figure 8 The following specifically introduces each component of the mobile phone in combination with
[0158] The RF circuit 810 can be used for receiving and transmitting information or signals during calls. Specifically, after receiving the downlink information from the base station, it is sent to the processor 880 for processing. Additionally, the uplink data designed is transmitted to the base station. Generally, the RF circuit 810 includes but is not limited to antennas, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 810 can also communicate with the network and other devices through wireless communication. The above wireless communication can use any communication standard or protocol, including but not limited to the Global System of Mobile Communication (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, Short Messaging Service (SMS), etc.
[0159] The memory 820 can be used to store software programs and modules. The processor 880 executes various functional applications and data processing of the mobile phone by running the software programs and modules stored in the memory 820. The memory 820 mainly includes a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, the image playback function, etc.); the data storage area can store the data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory 820 can include high-speed random access memory and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices.
[0160] The input unit 830 can be used to receive input numeric or character information and generate key signal inputs related to the user settings and function controls of the mobile phone. Specifically, the input unit 830 can include a touch panel 831 and other input devices 832. The touch panel 831, also known as a touch screen, can collect touch operations of the user thereon or nearby (such as operations of the user using any suitable object or accessory such as a finger, a stylus, etc. on or near the touch panel 831, and air-touch operations within a certain range on the touch panel 831), and drive corresponding connection devices according to a preset program. Optionally, the touch panel 831 can include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the touch position of the user, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into contact coordinates, and then sends it to the processor 880, and can receive and execute the commands sent by the processor 880. In addition, various types such as resistive, capacitive, infrared, and surface acoustic wave can be used to implement the touch panel 831. In addition to the touch panel 831, the input unit 830 can also include other input devices 832. Specifically, the other input devices 832 can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power-on keys, etc.), a trackball, a mouse, a joystick, etc.
[0161] The display unit 840 can be used to display information input by the user or information provided to the user and various menus of the mobile phone. The display unit 840 can include a display panel 841. Optionally, the display panel 841 can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 831 can cover the display panel 841. After the touch panel 831 detects a touch operation thereon or nearby, it transmits it to the processor 880 to determine the type of touch event. Subsequently, the processor 880 provides corresponding visual output on the display panel 841 according to the type of touch event. Although in Figure 8 the touch panel 831 and the display panel 841 are implemented as two independent components to realize the input and input functions of the mobile phone, in some embodiments, the touch panel 831 and the display panel 841 can be integrated to realize the input and output functions of the mobile phone.
[0162] The mobile phone may further include at least one sensor 850, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. Among them, the ambient light sensor can adjust the brightness of the display panel 841 according to the brightness of the ambient light, and the proximity sensor can turn off the display panel 841 and / or the backlight when the mobile phone is moved to the ear. As a kind of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary, and can be used for applications that identify the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer attitude calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors that the mobile phone can also be configured with, they will not be elaborated here.
[0163] The audio circuit 860, the speaker 861, and the microphone 862 can provide an audio interface between the user and the mobile phone. The audio circuit 860 can transmit the electrical signal converted from the received audio data to the speaker 861, and the speaker 861 converts it into a sound signal for output; on the other hand, the microphone 862 converts the collected sound signal into an electrical signal, which is received by the audio circuit 860 and then converted into audio data. After the audio data is output to the processor 880 for processing, it is sent through the RF circuit 810 to, for example, another mobile phone, or the audio data is output to the memory 820 for further processing.
[0164] WiFi belongs to short - range wireless transmission technology. The mobile phone can help users send and receive emails, browse the web, and access streaming media through the WiFi module 870, which provides users with wireless broadband Internet access. Although Figure 8 the WiFi module 870 is shown, it can be understood that it does not belong to an essential component of the mobile phone and can be omitted completely within the scope of not changing the essence of the invention according to needs.
[0165] The processor 880 is the control center of the mobile phone, connecting various parts of the entire mobile phone through various interfaces and lines. By running or executing software programs and / or modules stored in the memory 820, and by calling data stored in the memory 820, it executes various functions of the mobile phone and processes data. Optionally, the processor 880 may include one or more processing units; optionally, the processor 880 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above - mentioned modem processor may not be integrated into the processor 880 either.
[0166] The mobile phone further includes a power source 890 (such as a battery) for supplying power to each component. Optionally, the power source can be logically connected to the processor 880 through a power management system, so as to manage functions such as charging, discharging, and power consumption management through the power management system.
[0167] Although not shown, the mobile phone may further include a camera, a Bluetooth module, etc., which will not be elaborated here.
[0168] In the embodiment of the present application, the processor 880 included in the terminal further has the function of executing each step of the above-mentioned page processing method.
[0169] The embodiment of the present application also provides a server. Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of a server provided by the embodiment of the present application. The server 900 may vary greatly due to configuration or performance differences, and may include one or more central processing units (CPUs) 922 (for example, one or more processors) and a memory 932, and one or more storage media 930 (for example, one or more mass storage devices) for storing application programs 942 or data 944. Among them, the memory 932 and the storage media 930 can be transient storage or persistent storage. The program stored in the storage media 930 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Further, the central processor 922 may be configured to communicate with the storage media 930 and execute a series of instruction operations in the storage media 930 on the server 900.
[0170] The server 900 may further include one or more power sources 926, one or more wired or wireless network interfaces 950, one or more input / output interfaces 958, and / or one or more operating systems 941, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.
[0171] The steps executed by the management device in the above embodiment may be based on the Figure 9 server structure shown.
[0172] The embodiment of the present application also provides a computer-readable storage medium, in which instructions for file encryption are stored. When it runs on a computer, it causes the computer to execute the steps executed by the file encryption device in the method described in the foregoing Figures 2 to 6 embodiment shown.
[0173] An embodiment of the present application also provides a computer program product including an instruction for file encryption. When it runs on a computer, it causes the computer to execute the steps performed by the file encryption device in the method described in the foregoing Figures 2 to 6 embodiment shown.
[0174] An embodiment of the present application also provides a file encryption system, which may include Figure 7 the file encryption device in the described embodiment, or Figure 8 the terminal device in the described embodiment, or Figure 9 the described server.
[0175] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described system, device, and unit can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0176] In several embodiments provided by the present application, it should be understood that the disclosed system, device, and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be in an electrical, mechanical, or other form.
[0177] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0178] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0179] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a file encryption device, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0180] As described above, the above embodiments are only used to illustrate the technical solutions of this application, rather than to limit it; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of this application.
Claims
1. A method for encrypting files during compilation, characterized in that, it includes: Obtain the data resources corresponding to the target application, where the data resources include multiple sub-items, and the sub-items are used to indicate the execution of the compilation process, and the compilation process includes a merging process and an encoding process; Based on the merging process, merge the project files corresponding to the sub-items into the target directory; In response to the completion of the merging process, encrypt the target files containing the target suffix in the target directory using a preset encryption algorithm to obtain target encrypted files, where the target files contain sensitive data; Inject the target encrypted files into the target directory to generate encrypted data, and the encrypted data is used to indicate the encoding process to compile the source code to generate the executable file corresponding to the target application.
2. The method according to claim 1, characterized in that, the encrypting the target files containing the target suffix using a preset encryption algorithm in response to the completion of the merging process includes: Monitor the execution interface corresponding to the merging process to obtain an execution instruction; If the execution instruction indicates the completion of the merging process, encrypt the target files containing the target suffix using a preset encryption algorithm.
3. The method according to claim 2, characterized in that, the monitoring the execution interface corresponding to the merging process to obtain an execution instruction includes: Monitor the execution interface corresponding to the merging process to obtain the execution operation for the target directory; Obtain the execution instruction based on the execution operation for the target directory.
4. The method according to claim 1, characterized in that, the method further includes: In response to the completion of the merging process, determine the temporary files contained in the target directory, where the temporary files correspond to the project files; Encrypt the target code indicated in the temporary files using the preset encryption algorithm to generate the encrypted data.
5. The method according to claim 4, characterized in that, the encrypting the target code indicated in the temporary files using the preset encryption algorithm to generate the encrypted data includes: Analyze the data structure of the temporary files to obtain the target files and the target code; Encrypt the target code to generate the encrypted data.
6. The method according to any one of claims 1-5, characterized in that, the method further includes: Monitor the reading process of the executable file in response to a decryption instruction; Capture the target files based on the reading process to inject a decryption process; In the decryption process, decrypt the target files using a preset decryption algorithm to obtain the sensitive data.
7. The method according to claim 6, characterized in that, the capturing the target files based on the reading process to inject a decryption process includes: Determine the target suffix corresponding to the target files; Identify the target suffix based on the reading process to capture the target files; Inject the target files into the decryption process.
8. The method according to claim 7, characterized in that, the method further includes: Invoke the target file in response to a suffix setting instruction; Update the file format of the target file based on the target suffix corresponding to the suffix setting instruction.
9. The method according to claim 1, wherein, the obtaining of the data resources corresponding to the target application includes: determining the application type of the target application; if the application type conforms to a preset category, obtaining the data resources corresponding to the target application.
10. The method according to claim 9, wherein, the determining of the type information of the target application includes: traversing the sensitive data corresponding to the target application to determine the privacy level; determining the type information of the target application based on the privacy level.
11. The method according to claim 1, wherein, the target application is a payment application or a financial application, the sensitive data is used to indicate user privacy data, and the user privacy data is related to the payment process.
12. A file encryption device, wherein, it includes: an obtaining unit, configured to obtain data resources corresponding to a target application, the data resources including a plurality of sub-items, the sub-items being used to indicate the execution of a compilation process, the compilation process including a merging process and an encoding process; a merging unit, configured to merge the project files corresponding to the sub-items into a target directory based on the merging process; an encryption unit, configured to, in response to the completion of the merging process, encrypt a target file containing a target suffix in the target directory by using a preset encryption algorithm to obtain a target encrypted file, the target file containing sensitive data; inject the target encrypted file into the target directory to generate encrypted data, the encrypted data being used to indicate that the encoding process compiles source code to generate an executable file corresponding to the target application.
13. The device according to claim 12, wherein, the encryption unit is specifically configured to: monitor an execution interface corresponding to the merging process to obtain an execution instruction; if the execution instruction indicates the completion of the merging process, encrypt the target file containing the target suffix by using a preset encryption algorithm.
14. The device according to claim 13, wherein, the encryption unit is specifically configured to: monitor an execution interface corresponding to the merging process to obtain an execution operation for the target directory; obtain an execution instruction based on the execution operation for the target directory.
15. The device according to claim 12, wherein, the encryption unit is specifically configured to: in response to the completion of the merging process, determine a temporary file included in the target directory, the temporary file corresponding to the project file; encrypt the target code indicated in the temporary file by using the preset encryption algorithm to generate the encrypted data.
16. The device according to claim 15, wherein, the encryption unit is specifically configured to: parse the data structure of the temporary file to obtain a target file and the target code; encrypt the target code to generate the encrypted data.
17. The device according to any one of claims 12 - 16, wherein, the encryption unit is specifically configured to: monitor the reading process of the executable file in response to a decryption instruction; capture the target file based on the reading process to inject a decryption process; decrypt the target file using a preset decryption algorithm in the decryption process to obtain the sensitive data.
18. The device according to claim 17, wherein, the encryption unit is specifically configured to: determine the target suffix corresponding to the target file; identify the target suffix based on the reading process to capture the target file; inject the target file into the decryption process.
19. The device according to claim 18, wherein, the encryption unit is specifically configured to: invoke the target file in response to a suffix setting instruction; update the file format of the target file based on the target suffix corresponding to the suffix setting instruction.
20. The device according to claim 12, wherein, the acquisition unit is specifically configured to: determine the application type of the target application; if the application type conforms to a preset category, acquire the data resource corresponding to the target application.
21. The device according to claim 20, wherein, the acquisition unit is specifically configured to: traverse the sensitive data corresponding to the target application to determine a privacy level; determine the type information of the target application based on the privacy level.
22. The device according to claim 12, wherein, the target application is a payment application or a financial application, the sensitive data is used to indicate user privacy data, and the user privacy data is related to the payment process.
23. A computer device, wherein, the computer device includes a processor and a memory: the memory is used to store program code; the processor is used to execute the file encryption method according to any one of claims 1 to 11 based on the instructions in the program code.
24. A computer-readable storage medium, in which instructions are stored, and when the instructions run on a computer, the computer is caused to execute the file encryption method according to any one of claims 1 to 11 above.
25. A computer program product, wherein, the computer program product includes computer instructions, and the computer instructions are stored in a computer-readable storage medium; a processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the file encryption method according to any one of claims 1 to 11 above.
Citation Information
Patent Citations
Resource file processing method, apparatus and system
CN106598584A
Assets file encryption method based on Android compiling and related equipment thereof
CN111597576A
Method for combining and executing an application program and an additional application program
WO2012023786A2