Protection Method, Device, Computer Equipment and Storage Medium for Sensitive Code

By embedding sensitive machine instructions in non-sensitive code with defined function pointers, the method simplifies sensitive code maintenance, avoiding compatibility issues and ensuring reliable executable files.

CN114417266BActive Publication Date: 2025-07-15KINCO AUTOMATION (SHANGHAI) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210064507.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-20
Publication Date
2025-07-15
Estimated Expiration
2042-01-20

AI Technical Summary

Technical Problem

The existing sensitive code compilation and linking methods are inconvenient for maintenance, resulting in the inability to modify the sensitive code directly and the generated executable files may not be able to run reliably.

Method used

Compile sensitive code into sensitive files and extract sensitive machine instructions, embed them into non-sensitive code, and define calling function pointers to call sensitive machine instructions, simplifying the steps of generating executable files.

Benefits of technology

It realizes direct maintenance of sensitive code and synchronous maintenance of non-sensitive code, avoiding the risk that the generated executable files cannot be reliably run due to compatibility issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114417266B_ABST
    Figure CN114417266B_ABST
Patent Text Reader

Abstract

Embodiments of the present invention disclose a method, apparatus, computer device, and storage medium for protecting sensitive code. The method for protecting sensitive code includes: compiling the obtained sensitive code into a sensitive file and extracting sensitive machine instructions in the sensitive file; embedding the sensitive machine instructions into non-sensitive code; defining a call function pointer of the sensitive machine instructions in the non-sensitive code to call the sensitive machine instructions in the non-sensitive code. During the process of maintaining sensitive code, non-public sensitive code can be directly added without modifying the link control file that links the sensitive file and the non-sensitive file, simplifying the steps of generating an executable file. In addition, while maintaining sensitive code, non-sensitive code can also be synchronously maintained, avoiding the risk that the generated executable file cannot run reliably due to incompatibility between the maintained sensitive file and non-sensitive file.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer devices, and in particular, to a method, device, computer device and storage medium for protecting sensitive code. Background Art

[0002] Programming code is a source file generated based on the writing rules supported by development tools, and is a rule system in which a group of characters, symbols or information code elements represent information in a discrete form. With the rapid development of Internet technology, the number of software programs developed based on programming code has gradually increased. Software programs usually contain sensitive code that cannot be directly disclosed. To prevent others from plagiarizing and tampering with software programs through decompilation, disassembly and other means, sensitive code is usually compiled into independent sensitive files. The compiled sensitive files are linked with non-sensitive files to generate an executable file of the software program to protect the sensitive code in the software program.

[0003] However, during the process of maintaining sensitive code, developers cannot directly modify the sensitive files in the executable file. It is necessary to recompile the maintained sensitive code to obtain new sensitive files and modify the link control file used to link sensitive files and non-sensitive files. At the same time, if the non-sensitive files are not compatible with the new sensitive files, it will also cause the generated executable file to not run reliably. Obviously, the existing compilation and linking method for sensitive code is not convenient for maintaining sensitive code. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to overcome the deficiencies in the prior art and provide a method, device, computer device and storage medium for protecting sensitive code to solve the problem that the sensitive code in software programs is not convenient to maintain.

[0005] In a first aspect, an embodiment of the present application provides a method for protecting sensitive code, the method including:

[0006] Compiling the obtained sensitive code into a sensitive file, and extracting sensitive machine instructions in the sensitive file;

[0007] Embedding the sensitive machine instructions into non-sensitive code;

[0008] Defining a call function pointer of the sensitive machine instructions in the non-sensitive code to call the sensitive machine instructions in the non-sensitive code.

[0009] In combination with the first aspect, in a first possible implementation manner, the embedding the sensitive machine instructions into non-sensitive code includes:

[0010] Creating an array for storing sensitive machine instructions;

[0011] Store the sensitive machine instructions in the storage array and embed the storage array into the non-sensitive code.

[0012] Combined with the first possible implementation manner of the first aspect, in the second possible manner, the defining the call function pointer of the sensitive machine instruction in the non-sensitive code includes:

[0013] Create a call function pointer in the non-sensitive code and point the call function pointer to the storage array.

[0014] Combined with the first aspect, in the third possible implementation manner, after the defining the call function pointer of the sensitive machine instruction in the non-sensitive code, it further includes:

[0015] Compile the non-sensitive code embedded with the sensitive machine instructions into an executable file.

[0016] Combined with the first aspect, in the fourth possible implementation manner, the extracting the sensitive machine instructions from the sensitive file includes:

[0017] Obtain the core code segment in the sensitive file and extract the core code segment as sensitive machine instructions in binary format.

[0018] In a second aspect, an embodiment of the present application provides a protection device for sensitive code, and the device includes:

[0019] An instruction extraction module, configured to compile the obtained sensitive code into a sensitive file and extract the sensitive machine instructions from the sensitive file;

[0020] An instruction embedding module, configured to embed the sensitive machine instructions into the non-sensitive code;

[0021] A pointer definition module, configured to define a call function pointer of the sensitive machine instruction in the non-sensitive code to call the sensitive machine instruction in the non-sensitive code.

[0022] Combined with the second aspect, in the first possible implementation manner, the instruction embedding module includes:

[0023] An array creation sub-module, which creates a storage array for sensitive machine instructions;

[0024] An instruction storage sub-module, configured to store the sensitive machine instructions in the storage array and embed the storage array into the non-sensitive code.

[0025] Combined with the first possible implementation manner of the second aspect, in the second possible manner, the pointer definition module is further configured to create a call function pointer in the non-sensitive code and point the call function pointer to the storage array.

[0026] In a third aspect, an embodiment of the present application provides a computer device, including a processor and a memory, where a program or instruction is stored on the memory, and the program or instruction is executed by the processor to enable the computer device to execute the steps of the above-mentioned protection method for sensitive code.

[0027] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, where a program or instruction is stored on the computer-readable storage medium, and when the program or instruction is executed by a processor, the steps of the above-mentioned protection method for sensitive code are implemented.

[0028] The present application provides a method for protecting sensitive code, including: compiling the obtained sensitive code into a sensitive file and extracting sensitive machine instructions in the sensitive file; embedding the sensitive machine instructions into non-sensitive code; defining a call function pointer for the sensitive machine instructions in the non-sensitive code to call the sensitive machine instructions in the non-sensitive code. During the process of maintaining sensitive code, non-public sensitive code can be directly added without modifying the link control file that links the sensitive file and the non-sensitive file, simplifying the steps of generating an executable file. In addition, while maintaining sensitive code, non-sensitive code can also be synchronously maintained, avoiding the risk that the generated executable file cannot run reliably due to incompatibility between the maintained sensitive file and non-sensitive file. Description of the Drawings

[0029] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the protection scope of the present invention. In each drawing, similar components are numbered similarly.

[0030] Figure 1 Shows a flowchart of the method for protecting sensitive code provided by an embodiment of the present invention;

[0031] Figure 2 Shows another flowchart of the method for protecting sensitive code provided by an embodiment of the present invention;

[0032] Figure 3 Shows a schematic structural diagram of the device for protecting sensitive code provided by an embodiment of the present invention. Detailed Embodiments

[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0034] Generally, the components of the embodiments of the present invention described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0035] In the following text, the terms "including", "having" and their cognates that can be used in various embodiments of the present invention are only intended to represent specific features, numbers, steps, operations, elements, components or combinations of the foregoing items, and should not be construed as first excluding the existence of one or more other features, numbers, steps, operations, elements, components or combinations of the foregoing items or increasing the possibility of one or more features, numbers, steps, operations, elements, components or combinations of the foregoing items.

[0036] In addition, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0037] Unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as commonly understood by those of ordinary skill in the art to which the various embodiments of the present invention belong. The terms (such as those defined in a commonly used dictionary) will be interpreted as having the same meaning as the contextual meaning in the relevant technical field and will not be interpreted as having an idealized meaning or an overly formal meaning unless clearly defined in the various embodiments of the present invention.

[0038] Embodiment 1

[0039] Please refer to Figure 1 , Figure 1 which shows a flowchart of a method for protecting sensitive code provided by an embodiment of the present invention. Figure 1 The method for protecting sensitive code in

[0040] Step 101: Compile the obtained sensitive code into a sensitive file and extract sensitive machine instructions from the sensitive file.

[0041] Program files, configuration files, log files, backup files, and databases of a computer device may contain sensitive data. Sensitive data includes, but is not limited to: passwords, keys, certificates, session identifiers, and privacy data, etc., which are not limited here. Before generating the executable file of the software program, sensitive code is pre-generated based on the writing rules supported by the development tool. Among them, the sensitive code is non-public code, that is, the sensitive code cannot be accessed by requests on the Internet.

[0042] The writing rules supported by the development tool are a high-level language, and the computer device cannot directly recognize the content contained in the high-level language. The sensitive code pre-written by the developer in the high-level language is converted into a sensitive file recognizable by the computer device through compilation, and the sensitive file cannot be accessed by requests on the Internet. Obtain all code segments in the sensitive file and extract the sensitive machine instructions in the code segments. Among them, the sensitive machine instructions are code segments for implementing functions.

[0043] As an example, the extracting of the sensitive machine instructions from the sensitive file includes:

[0044] Obtain the core code segment in the sensitive file and extract the core code segment into sensitive machine instructions in binary format.

[0045] Usually, a storage unit of a computer device can only store one binary data. However, for the convenience of converting sensitive code into a binary executable file and improving the data processing performance of the computer device, the sensitive code is usually compiled into a sensitive file composed of hexadecimal code segments. The sensitive machine instructions in the sensitive file can be extracted through a file copy tool. The file copy tool includes, but is not limited to: TeraCopy Pro, Fastcopy, and ExtremeCopy, etc., which are not limited here.

[0046] Obtain the core code segment in the sensitive file for implementing functions, specify the sensitive file as the input file of the file copy tool, specify the core code segment as the code segment to be extracted by the file copy tool, and specify the output format of the file copy tool as binary. Extract the core code segment into sensitive machine instructions in binary format to obtain binary instructions for implementing functions that can be directly recognized by the computer device.

[0047] Step 102, embed the sensitive machine instructions into the non-sensitive code.

[0048] Embed the sensitive machine instructions into any position of the non-sensitive code, and then the sensitive machine instructions embedded in the non-sensitive code can be called. It should be understood that the sensitive code and the sensitive file cannot be accessed by requests on the Internet, and the sensitive machine instructions extracted from the sensitive file and embedded in the non-sensitive code also cannot be accessed by requests on the Internet.

[0049] Step 103: Define a function pointer for calling the sensitive machine instruction in the non-sensitive code to call the sensitive machine instruction in the non-sensitive code.

[0050] When compiling code, each function has an entry address, and a function pointer for calling is a pointer variable pointing to the entry address of the function. Define a function pointer for calling the sensitive machine instruction in the non-sensitive code to call the sensitive machine instruction in the non-sensitive code through the function pointer for calling. By defining the function pointer for calling the sensitive machine instruction in the non-sensitive code, developers can directly add non-public sensitive code without modifying the link control file that links the sensitive file and the non-sensitive file, simplifying the steps of generating an executable file and facilitating developers to more intuitively maintain the sensitive code.

[0051] Please refer to Figure 2 , Figure 2 , which shows another flowchart of the method for protecting sensitive code provided by the embodiments of the present invention. As an example, after step 103, the method further includes:

[0052] Step 104: Compile the non-sensitive code embedded with the sensitive machine instruction into an executable file.

[0053] Compile the non-sensitive code embedded with the sensitive machine instruction into an executable file. During the process of generating a binary executable file recognizable by a computer device through the non-sensitive code, the sensitive machine instruction embedded in the non-sensitive code is synchronously compiled into the executable file. When developers maintain the sensitive code, they can also synchronously maintain the non-sensitive code, avoiding the risk that the generated executable file cannot run reliably due to incompatibility between the maintained sensitive file and non-sensitive file.

[0054] As an example, embedding the sensitive machine instruction into the non-sensitive code includes:

[0055] Create an array for storing the sensitive machine instruction;

[0056] Store the sensitive machine instruction in the array for storage and embed the array for storage into the non-sensitive code.

[0057] Create an array for storing the sensitive machine instruction. The array for storage is a set for storing a limited number of sensitive machine instructions. Package and store the sensitive machine instruction in the array for storage and embed the array for storage into the non-sensitive code. By packaging and storing the sensitive machine instruction in the array for storage, the sensitive machine instruction is effectively distinguished from the non-sensitive code, preventing the computer device from misidentifying the sensitive machine instruction in the non-sensitive code as non-sensitive code.

[0058] In an optional example, defining the call function pointer of the sensitive machine instruction in the non-sensitive code includes:

[0059] Create a call function pointer in the non-sensitive code and point the call function pointer to the storage array.

[0060] Create a call function pointer in the non-sensitive code, point the call function pointer to the storage array, where the sensitive machine instructions are encapsulated and stored in the storage array, and the call function pointer is not stored in the storage array. By calling the array that encapsulates and stores the sensitive machine instructions, it is not necessary to define multiple function pointers for all sensitive machine instructions, reducing the number of defined call function pointers, facilitating developers to maintain sensitive code, and improving the data processing performance of the computer device.

[0061] This application provides a method for protecting sensitive code, including: compiling the obtained sensitive code into a sensitive file and extracting the sensitive machine instructions in the sensitive file; embedding the sensitive machine instructions into the non-sensitive code; defining the call function pointer of the sensitive machine instruction in the non-sensitive code to call the sensitive machine instruction in the non-sensitive code. During the process of maintaining sensitive code, non-public sensitive code can be directly added without modifying the link control file that links the sensitive file and the non-sensitive file, simplifying the steps of generating an executable file. In addition, while maintaining sensitive code, non-sensitive code can also be synchronized, avoiding the risk that the generated executable file cannot run reliably due to incompatibility between the maintained sensitive file and non-sensitive file.

[0062] Embodiment 2

[0063] Please refer to Figure 3 , Figure 3 which shows the structural schematic diagram of the sensitive code protection device provided by the embodiment of the present invention. Figure 3 The sensitive code protection device 200 in

[0064] An instruction extraction module 210, configured to compile the obtained sensitive code into a sensitive file and extract the sensitive machine instructions in the sensitive file;

[0065] An instruction embedding module 220, configured to embed the sensitive machine instructions into the non-sensitive code;

[0066] A pointer definition module 230, configured to define the call function pointer of the sensitive machine instruction in the non-sensitive code to call the sensitive machine instruction in the non-sensitive code.

[0067] As an example, the instruction embedding module 220 includes:

[0068] An array creation sub-module creates an array for storing sensitive machine instructions;

[0069] An instruction storage sub-module is used to store the sensitive machine instructions in the storage array and embed the storage array into non-sensitive code.

[0070] In an optional example, the pointer definition module 230 is further used to create a call function pointer in the non-sensitive code and point the call function pointer to the storage array.

[0071] As an example, the protection device 200 for sensitive code further includes:

[0072] A code compilation module is used to compile the non-sensitive code embedded with the sensitive machine instructions into an executable file.

[0073] As an example, the instruction extraction module 210 is further used to obtain the core code segment in the sensitive file and extract the core code segment into sensitive machine instructions in binary format.

[0074] The protection device 200 for sensitive code is used to execute the corresponding steps in the above-mentioned protection method for sensitive code. The specific implementation of each function will not be described one by one here. In addition, the optional examples in Embodiment 1 are also applicable to the protection device 200 for sensitive code in Embodiment 2.

[0075] An embodiment of the present application further provides a computer device, including a processor and a memory. A program or instruction is stored on the memory, and the program or instruction is executed by the processor so that the computer device executes the above-mentioned protection method for sensitive code.

[0076] An embodiment of the present application further provides a computer-readable storage medium. A program or instruction is stored on the computer-readable storage medium, and when the program or instruction is executed by a processor, the above-mentioned protection method for sensitive code is implemented.

[0077] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and structure diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in an alternative implementation, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the structure diagram and / or flowchart, as well as the combination of blocks in the structure diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0078] In addition, in each embodiment of the present invention, the various functional modules or units may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0079] If the above functions are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a smart phone, a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0080] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, and all should be covered by the protection scope of the present invention.

Claims

1. A method for protecting sensitive code, characterized in that, The method includes: Compiling the obtained sensitive code into a sensitive file, and extracting sensitive machine instructions from the sensitive file; Embedding the sensitive machine instructions into non-sensitive code; Defining a call function pointer of the sensitive machine instructions in the non-sensitive code to call the sensitive machine instructions in the non-sensitive code; The embedding of the sensitive machine instructions into the non-sensitive code includes: Creating an array for storing the sensitive machine instructions; Storing the sensitive machine instructions into the storage array and embedding the storage array into the non-sensitive code; The defining of the call function pointer of the sensitive machine instructions in the non-sensitive code includes: Creating a call function pointer in the non-sensitive code and pointing the call function pointer to the storage array; After the defining of the call function pointer of the sensitive machine instructions in the non-sensitive code, it further includes: Compiling the non-sensitive code embedded with the sensitive machine instructions into an executable file.

2. The protection method of sensitive code according to claim 1, characterized in that, The extracting of the sensitive machine instructions from the sensitive file includes: Obtaining a core code segment in the sensitive file and extracting the core code segment as sensitive machine instructions in binary format.

3. A protection device for sensitive codes, characterized in that, The device includes: An instruction extraction module for compiling the obtained sensitive code into a sensitive file and extracting sensitive machine instructions from the sensitive file; An instruction embedding module for embedding the sensitive machine instructions into non-sensitive code; A pointer definition module for defining a call function pointer of the sensitive machine instructions in the non-sensitive code to call the sensitive machine instructions in the non-sensitive code; The instruction embedding module includes: An array creation sub-module for creating an array for storing the sensitive machine instructions; An instruction storage sub-module for storing the sensitive machine instructions into the storage array and embedding the storage array into the non-sensitive code; The pointer definition module is further configured to create a call function pointer in the non-sensitive code and point the call function pointer to the storage array; The pointer definition module is further configured to compile the non-sensitive code embedded with the sensitive machine instructions into an executable file.

4. A computer device, characterized in that, It includes a processor and a memory, and a program or instruction is stored on the memory. When the program or instruction is executed by the processor, the steps of the method for protecting sensitive code according to any one of claims 1 or 2 are implemented.

5. A computer-readable storage medium, characterized in that, A program or instruction is stored on the computer-readable storage medium. When the program or instruction is executed by a processor, the steps of the method for protecting sensitive code according to any one of claims 1 or 2 are implemented.

Citation Information

Patent Citations

  • Method and apparatus for protecting sensitive data in software product

    CN104881611A