A code obfuscation method, device, electronic device and storage medium

By setting up encrypted replacement tables of multiple replacement solutions to be selected in the code, replacing constants in the code, solving the problem that the fixed code replacement method in the prior art cannot meet the security requirements, and achieving high security obfuscation of the code.

CN114357390BActive Publication Date: 2025-05-06BEIJING RUIHESOFT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210016432.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-07
Publication Date
2025-05-06
Estimated Expiration
2042-01-07

AI Technical Summary

Technical Problem

In the prior art, the code equivalent replacement method is fixed and cannot meet the code security requirements.

Method used

By setting up encrypted replacement tables for multiple replacement schemes to be selected, different constants in the original code are replaced by different replacement schemes to form obfuscated code.

Benefits of technology

Even after multiple replacements, the law of substitution is still difficult to obtain from it, which greatly improves the security of the original code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114357390B_ABST
    Figure CN114357390B_ABST
Patent Text Reader

Abstract

The present application provides a code obfuscation method, device, electronic device and storage medium, the method comprising: the present application obtains different numbers of candidate replacement methods from the encryption replacement table according to the content and order of encrypted cells in the preset encryption replacement table for the constants to be replaced in the original code; selects a target replacement method from the candidate replacement methods according to the preset selection method for the candidate replacement method; replaces the constants to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code; runs the replaced obfuscated code to hide the original code. The present application sets multiple candidate replacement schemes according to the encryption replacement table, and different candidate replacement schemes can be used to replace different constants in the original code. Even after running after multiple replacements, it is not easy to obtain the replacement rules, which greatly improves the security of the original code.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a code obfuscation method, device, electronic device and storage medium. Background Art

[0002] Obfuscated code, also known as junk instructions, is the act of converting the code of a computer program into a form that is functionally equivalent but difficult to read and understand. For example, it is rewritten into a single letter, or a short meaningless combination of letters, or even rewritten into symbols, so that readers cannot guess its purpose based on the name. Rewrite part of the logic in the code to make it functionally equivalent but more difficult to understand. Obfuscating the code generated by program compilation increases the difficulty of disassembling the code and interpreting the code logic. It improves the security of code algorithm cracking.

[0003] In the prior art, when performing equivalent replacement on the code, only a simple replacement is performed, and the replacement method is fixed, which can no longer meet the requirements for code security. Summary of the invention

[0004] In view of this, the purpose of the present application is to provide a code obfuscation method, device, electronic device and storage medium. Multiple candidate replacement schemes are set according to the encryption replacement table. Different candidate replacement schemes can be used to replace different constants in the original code. Even after running after multiple replacements, it is not easy to obtain the replacement rules, which greatly improves the security of the original code.

[0005] In a first aspect, an embodiment of the present application provides a code obfuscation method, the method comprising:

[0006] For the constant to be replaced in the original code, according to the content and order of the encrypted cells in a preset encrypted replacement table, different numbers of replacement methods to be selected are obtained from the encrypted replacement table;

[0007] Selecting a target replacement method from the candidate replacement methods according to a preset selection method for the candidate replacement methods;

[0008] According to the target replacement method, the constant to be replaced in the original code is replaced to obtain the replaced obfuscated code;

[0009] The replaced obfuscated code is run to hide the original code.

[0010] In some technical solutions of the present application, the above method obtains the encryption replacement table in the following manner:

[0011] Establishing an initial replacement table including a preset number of initial cells; wherein the initial cells are provided with at least one of the following: numbers, characters, functions, and operation symbols;

[0012] Selecting a target encryption algorithm from multiple encryption algorithms in the encryption algorithm library;

[0013] The initial replacement table is encrypted using the target candidate encryption algorithm to obtain the encrypted replacement table containing encrypted cells.

[0014] In some technical solutions of the present application, for the constant to be replaced in the original code, according to the content and order of the encrypted cells in the preset encrypted replacement table, different numbers of replacement methods to be selected are obtained from the encrypted replacement table, including:

[0015] For the constant to be replaced in the original code, at least one of the encrypted cells in the encrypted replacement table is arranged and combined to obtain a plurality of expressions to be selected, and a calculation result of each of the expressions to be selected is calculated;

[0016] According to the calculation result of each of the candidate expressions, a target candidate expression whose calculation result is equivalent to the candidate replacement constant is selected from the candidate expressions;

[0017] The candidate replacement method is set according to the target candidate expression.

[0018] In some technical solutions of the present application, the above-mentioned setting of the candidate replacement method according to the target candidate expression includes:

[0019] The constant to be replaced is replaced according to the content of the encrypted cell corresponding to the target expression to be selected.

[0020] In some technical solutions of the present application, the above-mentioned setting of the candidate replacement method according to the target candidate expression includes:

[0021] The constant to be replaced is replaced according to the position of the encrypted cell corresponding to the target expression to be selected in the encrypted replacement table.

[0022] In some technical solutions of the present application, the above-mentioned constant to be replaced is a constant to be replaced, and for the constant to be replaced in the original code, according to the content and order of the encrypted cells in a preset encrypted replacement table, different numbers of candidate replacement methods are obtained from the encrypted replacement table; including:

[0023] For the constant to be replaced in the original code, split the constant to be replaced according to the digit of each number in the constant to be replaced to obtain sub-constants to be replaced;

[0024] For each of the sub-constants to be replaced, different numbers of candidate replacement methods are obtained from the encrypted replacement table according to the content and order of the encrypted cells in the preset encrypted replacement table.

[0025] In some technical solutions of the present application, the above-mentioned target replacement method is used to replace the constant to be replaced in the original code to obtain the replaced obfuscated code, including:

[0026] performing a replacement process on the sub-constant to be replaced according to the target replacement method to obtain a sub-replacement result;

[0027] The sub-replacement results are combined according to the digits of each number in the constant to be replaced to obtain the replaced obfuscated code.

[0028] In a second aspect, an embodiment of the present application provides a code obfuscation device, the device comprising:

[0029] An acquisition module, for acquiring different numbers of candidate replacement methods from a preset encryption replacement table according to the contents and order of encrypted cells in the encryption replacement table for the constants to be replaced in the original code;

[0030] A screening module, configured to select a target replacement method from the candidate replacement methods according to a preset selection method for the candidate replacement methods;

[0031] A replacement module, used to replace the constant to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code;

[0032] The running module is used to run the replaced obfuscated code to hide the original code.

[0033] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned code obfuscation method when executing the computer program.

[0034] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned code obfuscation method are executed.

[0035] The technical solution provided by the embodiments of the present application may have the following beneficial effects:

[0036] The present application targets the constants to be replaced in the original code, and obtains different numbers of candidate replacement methods from the encrypted replacement table according to the content and order of the encrypted cells in the preset encrypted replacement table; then, according to the preset selection method for the candidate replacement method, a target replacement method is selected from the candidate replacement methods; then, according to the target replacement method, the constants to be replaced in the original code are replaced to obtain the replaced obfuscated code; then, the replaced obfuscated code is run to hide the original code. The present application sets multiple candidate replacement schemes according to the encrypted replacement table, and different candidate replacement schemes can be used to replace different constants in the original code. Even after running after multiple replacements, it is not easy to obtain the replacement rules, which greatly improves the security of the original code.

[0037] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0039] Figure 1 A schematic diagram of a code obfuscation method provided in an embodiment of the present application is shown;

[0040] Figure 2 A schematic diagram of a process for setting an encryption replacement table provided in an embodiment of the present application is shown;

[0041] Figure 3 A schematic diagram of a code obfuscation device provided in an embodiment of the present application is shown;

[0042] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0043] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of order, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the present application, or remove one or more operations from the flowchart.

[0044] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0045] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0046] Obfuscated code, also known as junk instructions, is the act of converting the code of a computer program into a form that is functionally equivalent but difficult to read and understand. For example, it is rewritten into a single letter, or a short meaningless combination of letters, or even rewritten into symbols, so that readers cannot guess its purpose based on the name. Rewrite part of the logic in the code to make it functionally equivalent but more difficult to understand. Obfuscating the code generated by program compilation increases the difficulty of disassembling the code and interpreting the code logic. It improves the security of code algorithm cracking.

[0047] In the prior art, when performing equivalent replacement on the code, only a simple replacement is performed, and the replacement method is fixed, which can no longer meet the requirements for code security.

[0048] Based on this, the embodiments of the present application provide a code obfuscation method, device, electronic device and storage medium, which are described below through embodiments.

[0049] Figure 1A schematic flow chart of a code obfuscation method provided in an embodiment of the present application is shown, wherein the method includes steps S101-S104; specifically:

[0050] S101, for the constant to be replaced in the original code, according to the content and order of the encrypted cells in the preset encryption replacement table, obtain different numbers of replacement methods to be selected from the encryption replacement table;

[0051] S102, selecting a target replacement method from the replacement methods to be selected according to a preset selection method for the replacement methods to be selected;

[0052] S103, replacing the constant to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code;

[0053] S104: Run the replaced obfuscated code to hide the original code.

[0054] The present application sets multiple candidate replacement schemes according to the encryption replacement table. Different candidate replacement schemes can be used to replace different constants in the original code. Even after running for multiple replacements, it is not easy to get the replacement rules, which greatly improves the security of the original code.

[0055] Some embodiments of the present application are described in detail below. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.

[0056] S101. For a constant to be replaced in the original code, according to the content and order of encrypted cells in a preset encryption replacement table, obtain different numbers of replacement methods to be selected from the encryption replacement table.

[0057] For the constants to be replaced in the original code, the present application sets a replacement method to be selected according to the encrypted replacement table. The constants to be replaced here are constant quantities and quantities that can be regarded as constant, including constant numbers, constant letters, or functions that can be regarded as constant.

[0058] Depending on the confidentiality requirements for the original code, different numbers of candidate replacement methods can be set. That is to say, for original codes with higher confidentiality requirements, the preset encryption replacement table in this application can be set to be more complex, and then the number of candidate replacement methods obtained based on the preset encryption replacement table is larger. The complexity of the encryption replacement table is mainly reflected in the number of encrypted cells set in the table, the amount of content set in each encrypted cell, and the complexity of the encryption algorithm. Secondly, the number of candidate replacement methods obtained based on the encryption replacement table also affects the confidentiality of the original code. The more the number of candidate replacement methods, the stronger the confidentiality of the original code.

[0059] The replacement method to be selected in the embodiment of the present application is determined by the content and order of the encrypted cells in the encrypted replacement table. That is to say, the replacement order of the method to be replaced in the present application is determined by the order in which the encrypted cells are obtained in the encrypted replacement table, and the content to be replaced in the method to be replaced in the present application is determined by the encrypted cells in the encrypted replacement table.

[0060] The encrypted replacement form in this application is pre-set, such as Figure 2 This application is shown in the following way to set up the encrypted replacement form:

[0061] S201, establishing an initial replacement table including a preset number of initial cells; the initial cells are provided with at least one of the following: numbers, characters, functions, and operation symbols;

[0062] S202, selecting a target encryption algorithm from a plurality of encryption algorithms in an encryption algorithm library;

[0063] S203: Use the target candidate encryption algorithm to encrypt the initial replacement table to obtain an encrypted replacement table containing encrypted cells.

[0064] In order to obtain an encryption replacement table, the present application needs to first establish an initial replacement table, which includes multiple initial cells, each of which is set with replacement content. The replacement content here can be numbers, characters, functions, operators, or a combination of one or more of numbers, characters, functions, and operators. The content in each initial cell can be set according to encryption needs or generated randomly. Each initial cell has its own position in the initial replacement table, and the position of each initial cell in the initial replacement table can be represented by coordinates, order, etc.

[0065] After obtaining the initial replacement table, the present application also encrypts the initial replacement table in order to further improve security. When encrypting the initial replacement table, the present application sets an encryption algorithm library including multiple encryption algorithms to be selected. Then, a target encryption algorithm to be selected is selected from the encryption algorithm library, and the initial replacement table is encrypted using the target encryption algorithm to be selected.

[0066] The target encryption algorithm to be selected here can be one or more. When the target encryption algorithm to be selected is one, the target encryption algorithm to be selected is used to encrypt each initial cell in the initial replacement table. When the target encryption algorithm to be selected is multiple, each target encryption algorithm encrypts part of the initial cells. By encrypting each initial cell in the initial replacement table separately, an encrypted replacement table containing encrypted cells is obtained.

[0067] After obtaining the encrypted replacement table, the present application will obtain the candidate replacement method from the encrypted replacement table. When obtaining the candidate replacement method, the present application performs permutations and combinations on at least one encrypted cell in the encrypted replacement table. The encrypted cells to be permuted and combined here can be specifically selected according to the content of the constant to be replaced in the original code. If the content of the constant to be replaced is small or the confidentiality is low, a small number of encrypted cells can be selected for permutations and combinations. If the content of the constant to be replaced is large or the confidentiality is high, a large number of encrypted cells can be selected for permutations and combinations. After the encrypted cells are permuted and combined, the content in each encrypted cell is extracted and the candidate expression is formed in the order of permutations and combinations. Then the calculation result of each candidate expression is calculated. The present application believes that if the calculation result of the candidate expression is equivalent to the constant to be replaced, the candidate expression can be replaced by the constant to be replaced, and the target candidate expression whose calculation result is equivalent to the candidate replacement constant can be obtained. After obtaining the target candidate expression, the present application also needs to set the candidate replacement method according to the target candidate expression.

[0068] When setting the replacement method according to the target expression to be selected, the present application can set it according to the content of each corresponding encrypted cell in the target expression to be selected, or can set it according to the position of each corresponding encrypted cell in the target expression to be selected in the encryption replacement table. As an optional implementation, when setting according to the content of each corresponding encrypted cell in the target expression to be selected, the content of each corresponding encrypted cell in the target expression to be selected is used to replace it in the order of the content in the target expression to be selected. For example: the constant to be replaced is b+c, and then according to the specific content in the encrypted cell, there can be the following different replacement methods: if the contents of the three encrypted cells are b, -, and -c, respectively, then the replacement of b+c is b-(-c).

[0069] a=b+c=>

[0070] a=b-(-c);

[0071] a=-(-b+(-c));

[0072] r=rand(); a=b+r; a=a+c; a=ar;

[0073] r=rand(); a=br; a=a+b; a=a+r;

[0074] a=b–c=>

[0075] a=b+(-c);

[0076] r=rand(); a=b+r; a=ac; a=ar;

[0077] r=rand(); a=br; a=ac; a=a+r;

[0078] a=b&c=>a=(b^~c)&b;

[0079] a=b|c=>

[0080] a=(b&c)|(b^c);

[0081] a=a^b=>

[0082] a=(~a&b)|(a&~b).

[0083] As an optional implementation, when setting according to the position of each encrypted cell corresponding to the target candidate expression in the encrypted replacement table, the constant to be replaced is replaced in the order of the content in the target candidate expression in combination with the relevant operator pointing to the position.

[0084] In the embodiment of the present application, as an optional embodiment, the initial replacement table is: constants of 0x0000-0xffff, the order is random, and is randomly generated before compilation during the compilation process.

[0085] unsigned char raw_const_data[]={0x03,0xa2,0x5f,0x06…};

[0086] Encrypt raw_const_data to get the encrypted replacement table: encrypt_const_data. Replace the expressions in the program that have constants involved in the calculation (capital letters represent constants):

[0087] a=a+B=>

[0088] a=a+decode_func(encrypt_const_data)->data[position(B)], where position(B) is generated during the compilation phase.

[0089] Specifically: a=a+6=>

[0090] a=a+decode_func(encrypt_const_data)->data[3].

[0091] S102: Select a target replacement method from the candidate replacement methods according to a preset selection method for the candidate replacement methods.

[0092] After obtaining the candidate replacement methods, the present application also provides a selection method for the candidate replacement methods. The selection method here includes an encrypted algorithm, a random algorithm, etc. According to the selection method, a target replacement method is selected from the candidate replacement methods.

[0093] For example, a random algorithm is used to select a target replacement method from the candidate replacement methods. When replacing the same constant of the same original code, multiple candidate replacement methods are generated, and each time the target replacement method is randomly selected from multiple candidate replacement methods. The target replacement method used each time may be the same as the last time, or it may be different from the last time. In other words, when the present application confuses the same constant of the same original code, there are multiple different obfuscation results for different number of runs, which greatly reduces the risk of finding replacement rules through multiple runs.

[0094] S103: According to the target replacement method, the constant to be replaced in the original code is replaced to obtain the replaced obfuscated code.

[0095] After obtaining the target replacement method, the constant to be replaced in the original code can be replaced according to the target replacement method, and the constant will be hidden by the relevant content in the replacement method. The code after replacing the constant with the relevant content in the replacement method is the obfuscated code.

[0096] Here, using the target replacement method to replace the constant to be replaced means using the target replacement method to replace the constant to be replaced in the order in which the encrypted cell in the encryption replacement table appears in the target replacement method.

[0097] S104: Run the replaced obfuscated code to hide the original code.

[0098] During runtime, the obfuscated code obtained in the above manner is run, so that the original code can be hidden and the purpose of protecting the original code can be achieved.

[0099] In the embodiment of the present application, as an optional embodiment, if the constant to be replaced in the original code is a constant to be replaced, the present application can split the constant to be replaced according to the digits of each number in the constant to be replaced to obtain the sub-constants to be replaced. That is to say, these sub-constants to be replaced can be combined according to their respective digits to obtain the constant to be replaced. For example, 985 (nine hundred and eighty-five) can be split into 9, 8 and 5. Then replace each sub-constant to be replaced. The method of replacing each sub-constant to be replaced is the same as the above method, that is, for each sub-constant to be replaced, according to the content and order of the encrypted cells in the preset encryption replacement table, different numbers of replacement methods to be selected are obtained from the encryption replacement table, and according to the preset selection method for the replacement method to be selected, the target replacement method is selected from the replacement method to be selected; then, according to the target replacement method, each sub-constant to be replaced is replaced. At this time, after replacing each sub-constant to be replaced, a sub-replacement result is obtained. In order to ensure the normal operation of the obfuscated code after replacement, the sub-replacement result needs to be combined according to the digits of each number in the constant to be replaced. When combining, you can use the corresponding bit operations to put the sub-replacement result corresponding to each sub-constant to be replaced in the correct position.

[0100] For example:

[0101] unsigned char raw_const_data[]={0x03,0xa2,0x5f,0x06…};

[0102] Encrypt raw_const_data to obtain an encryption replacement table: encrypt_const_data table.

[0103] a=a+0x12345678=>

[0104] a=a+decode_func(encrypt_const_data)->data[postion(0x1234)]<<16+decode_func(encrypt_const_data)->data[postion(0x5678)];

[0105] Another example is as follows, when performing equivalent replacement on the addition expression, it can be replaced with:

[0106] r=rand(); a=b+r; a=a+c; a=a–r;

[0107] rand() can be generated during compilation and is considered an equivalent constant.

[0108] a=b+decode_func(encrypt_const_data)->data[postion(r)];

[0109] a=a+c;

[0110] a=a–decode_func(encrypt_const_data)->data[postion(r)];

[0111] Similarly, the addition, subtraction, multiplication, division and bitwise operations in the expression can be replaced to achieve the purpose of hiding the code algorithm.

[0112] Figure 3 A schematic diagram of the structure of a code obfuscation device provided in an embodiment of the present application is shown, and the device includes:

[0113] The acquisition module is used to obtain different numbers of candidate replacement methods from the encrypted replacement table according to the content and order of the encrypted cells in the preset encrypted replacement table for the constants to be replaced in the original code;

[0114] A screening module, used to select a target replacement method from the candidate replacement methods according to a preset selection method for the candidate replacement methods;

[0115] The replacement module is used to replace the constants to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code;

[0116] The run module is used to run the replaced obfuscated code to hide the original code.

[0117] The acquisition module is also used to obtain the encryption substitution table in the following way:

[0118] Establishing an initial replacement table including a preset number of initial cells; the initial cells are provided with at least one of the following: numbers, characters, functions, and operation symbols;

[0119] Selecting a target encryption algorithm from multiple encryption algorithms in the encryption algorithm library;

[0120] The initial replacement table is encrypted using the target candidate encryption algorithm to obtain an encrypted replacement table containing encrypted cells.

[0121] The acquisition module, when used for obtaining different numbers of candidate replacement methods from the encrypted replacement table according to the content and order of the encrypted cells in the preset encrypted replacement table for the constants to be replaced in the original code, includes:

[0122] For the constant to be replaced in the original code, at least one encrypted cell in the encrypted replacement table is arranged and combined to obtain multiple expressions to be selected, and the calculation result of each expression to be selected is calculated;

[0123] According to the calculation result of each candidate expression, a target candidate expression whose calculation result is equivalent to the candidate replacement constant is selected from the candidate expressions;

[0124] According to the target candidate expression, set the candidate replacement method. According to the target candidate expression, set the candidate replacement method, including:

[0125] Replace the constant to be replaced according to the content of the encrypted cell corresponding to the target expression to be selected;

[0126] Replace the constant to be replaced according to the position of the encrypted cell corresponding to the target candidate expression in the encryption replacement table.

[0127] The acquisition module is also used for obtaining the constant to be replaced as the constant to be replaced. For the constant to be replaced in the original code, according to the content and order of the encrypted cells in the preset encrypted replacement table, different numbers of candidate replacement methods are obtained from the encrypted replacement table; including:

[0128] For the constant to be replaced in the original code, split the constant to be replaced according to the digit of each number in the constant to be replaced to obtain the sub-constants to be replaced;

[0129] For each sub-constant to be replaced, different numbers of candidate replacement methods are obtained from the encrypted replacement table according to the content and order of the encrypted cells in the preset encrypted replacement table.

[0130] The replacement module, when used to replace the constant to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code, includes:

[0131] According to the target replacement method, the sub-constant to be replaced is replaced to obtain a sub-replacement result;

[0132] The sub-replacement results are combined according to the digits of each number in the constant to be replaced to obtain the replaced obfuscated code.

[0133] like Figure 4 As shown, an embodiment of the present application provides an electronic device for executing the code obfuscation method in the present application, the device includes a memory, a processor, a bus, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the code obfuscation method when executing the computer program.

[0134] Specifically, the above-mentioned memory and processor may be general-purpose memory and processor, which are not specifically limited here. When the processor runs the computer program stored in the memory, the above-mentioned code obfuscation method can be executed.

[0135] Corresponding to the code obfuscation method in the present application, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned code obfuscation method are executed.

[0136] Specifically, the storage medium can be a general storage medium, such as a mobile disk, a hard disk, etc. When the computer program on the storage medium is run, the above-mentioned code obfuscation method can be executed.

[0137] In the embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. The system embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of the system or unit can be electrical, mechanical or other forms.

[0138] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0139] In addition, each functional unit in the embodiments provided in the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0140] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0141] It should be noted that similar numbers and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first", "second", "third", etc. are only used to distinguish the description and are not to be understood as indicating or implying relative importance.

[0142] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present application, which are used to illustrate the technical solutions of the present application, rather than to limit them. The protection scope of the present application is not limited thereto. Although the present application is described in detail with reference to the above-mentioned embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-mentioned embodiments within the technical scope disclosed in the present application, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application. They should all be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A code obfuscation method, characterized in that: The method comprises: For the constants to be replaced in the original code, according to the contents and order of the encrypted cells in a preset encrypted replacement table, different numbers of replacement methods to be selected are obtained from the encrypted replacement table; Selecting a target replacement method from the candidate replacement methods according to a preset selection method for the candidate replacement methods; According to the target replacement method, the constant to be replaced in the original code is replaced to obtain the replaced obfuscated code; Running the replaced obfuscated code to hide the original code; The encryption substitution table is obtained by: Establishing an initial replacement table including a preset number of initial cells; wherein the initial cells are provided with at least one of the following: numbers, characters, functions, and operation symbols; Selecting a target encryption algorithm from multiple encryption algorithms in the encryption algorithm library; Using the target candidate encryption algorithm to encrypt the initial replacement table to obtain the encrypted replacement table containing encrypted cells; The method of obtaining different numbers of candidate replacement methods from a preset encrypted replacement table according to the content and order of encrypted cells in the encrypted replacement table for the constant to be replaced in the original code includes: For the constant to be replaced in the original code, at least one of the encrypted cells in the encrypted replacement table is arranged and combined to obtain a plurality of expressions to be selected, and a calculation result of each of the expressions to be selected is calculated; According to the calculation result of each of the candidate expressions, a target candidate expression whose calculation result is equivalent to the candidate replacement constant is selected from the candidate expressions; The candidate replacement method is set according to the target candidate expression.

2. The method according to claim 1, characterized in that The step of setting the candidate replacement method according to the target candidate expression comprises: The constant to be replaced is replaced according to the content of the encrypted cell corresponding to the target expression to be selected.

3. The method according to claim 1, characterized in that The step of setting the candidate replacement method according to the target candidate expression comprises: The constant to be replaced is replaced according to the position of the encrypted cell corresponding to the target expression to be selected in the encrypted replacement table.

4. The method according to claim 1, characterized in that The to-be-replaced constant is a constant to be replaced, and for the to-be-replaced constant in the original code, according to the content and order of encrypted cells in a preset encrypted replacement table, different numbers of to-be-selected replacement methods are obtained from the encrypted replacement table; including: For the constant to be replaced in the original code, split the constant to be replaced according to the digit of each number in the constant to be replaced to obtain sub-constants to be replaced; For each of the sub-constants to be replaced, different numbers of candidate replacement methods are obtained from the encrypted replacement table according to the content and order of the encrypted cells in the preset encrypted replacement table.

5. The method according to claim 4, characterized in that The step of replacing the constant to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code includes: performing a replacement process on the sub-constant to be replaced according to the target replacement method to obtain a sub-replacement result; The sub-replacement results are combined according to the digits of each number in the constant to be replaced to obtain the replaced obfuscated code.

6. A code obfuscation device, characterized in that: The device comprises: An acquisition module, for acquiring different numbers of candidate replacement methods from a preset encryption replacement table according to the contents and order of encrypted cells in the encryption replacement table for the constants to be replaced in the original code; A screening module, configured to select a target replacement method from the candidate replacement methods according to a preset selection method for the candidate replacement methods; A replacement module, used to replace the constant to be replaced in the original code according to the target replacement method to obtain the replaced obfuscated code; A running module, used for running the replaced obfuscated code to hide the original code; The encryption substitution table is obtained by: Establishing an initial replacement table including a preset number of initial cells; wherein the initial cells are provided with at least one of the following: numbers, characters, functions, and operation symbols; Selecting a target encryption algorithm from multiple encryption algorithms in the encryption algorithm library; Using the target candidate encryption algorithm to encrypt the initial replacement table to obtain the encrypted replacement table containing encrypted cells; The method of obtaining different numbers of candidate replacement methods from a preset encrypted replacement table according to the content and order of encrypted cells in the encrypted replacement table for the constant to be replaced in the original code includes: For the constant to be replaced in the original code, at least one of the encrypted cells in the encrypted replacement table is arranged and combined to obtain a plurality of expressions to be selected, and a calculation result of each of the expressions to be selected is calculated; According to the calculation result of each of the candidate expressions, a target candidate expression whose calculation result is equivalent to the candidate replacement constant is selected from the candidate expressions; The candidate replacement method is set according to the target candidate expression.

7. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the code obfuscation method according to any one of claims 1 to 5 are performed.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the code obfuscation method according to any one of claims 1 to 5 are executed.

Citation Information

Patent Citations

  • Code obfuscation method and device, computer equipment and storage medium

    CN113282892A