A software deployment method, device, computer device, and storage medium
By obtaining encrypted code data and software initiator and modifying the initiator with security information during software operation, the problems of insufficient security and efficiency of software deployment in the prior art are solved, and more efficient and secure software deployment is achieved.
Patent Information
- Application Number
- CN202210161671.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-22
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-02-22
AI Technical Summary
The existing software deployment methods are not perfect in terms of code security protection, which leads to the need to improve the efficiency and security of software deployment.
By obtaining the encrypted code data of the software and the software launcher, the program security information of the software during operation is determined, and the code parameter information in the software launcher is modified based on this information, the software deployment data is generated, and the software is deployed on the target device.
It improves the security and efficiency of software deployment, and can adaptively modify the software initiator based on the security information of different programs to build a software deployment environment that meets various security needs.
Smart Images

Figure CN114579145B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to a software deployment method, apparatus, computer device, storage medium, and computer program product. Background Art
[0002] Software deployment can deploy a software project, such as a code program of the software, a configuration file, a user manual, a help document, etc., to a target device through steps such as collection, packaging, installation, configuration, and release. In the era of the rapid development of the information industry, software deployment work is becoming increasingly important.
[0003] In the process of researching and practicing related technologies, the inventors of this application found that there are problems related to code security protection in the process of software deployment. For this problem, the current software deployment methods are still not perfect enough, so the efficiency and security of software deployment need to be improved. Summary of the Invention
[0004] Embodiments of this application provide a software deployment method, apparatus, computer device, storage medium, and computer program product, which can improve the security and efficiency of software deployment.
[0005] Embodiments of this application provide a software deployment method, including:
[0006] Obtaining encrypted code data of the software and a software launcher, where the software launcher is used to assist in starting the software;
[0007] Determining program security information during the operation of the software;
[0008] Based on the program security information, modifying code parameter information corresponding to the program security information in the software launcher;
[0009] Generating software deployment data of the software according to the encrypted code data and the modified software launcher;
[0010] Deploying the software to the target device according to the software deployment data.
[0011] Correspondingly, embodiments of this application also provide a software deployment apparatus, including:
[0012] An obtaining unit, configured to obtain encrypted code data of the software and a software launcher, where the software launcher is used to assist in starting the software;
[0013] A determining unit, configured to determine program security information during the operation of the software;
[0014] A modification unit, configured to modify the code parameter information corresponding to the program security information in the software launcher based on the program security information;
[0015] A generation unit, configured to generate software deployment data of the software according to the encrypted code data and the modified software launcher;
[0016] A deployment unit, configured to deploy the software on a target device according to the software deployment data.
[0017] In one embodiment, the program security information includes program key security information of the software; the modification unit includes:
[0018] A parameter generation subunit, configured to generate key parameters required for deploying the software;
[0019] A first modification subunit, configured to modify the code parameter information corresponding to the program key security information in the software launcher according to the key parameters.
[0020] In one embodiment, the parameter generation subunit is configured to:
[0021] Obtain original password information required for deploying the software; determine encryption parameters of the original password information; encrypt the original password information according to the encryption parameters to obtain key parameters required for deploying the software.
[0022] In one embodiment, the program security information includes program detection security information of the software; the modification unit includes:
[0023] A parameter determination subunit, configured to determine program detection parameters to be disabled in the software launcher based on the program detection security information;
[0024] A second modification subunit, configured to modify the code parameter information corresponding to the program detection security information in the software launcher according to the program detection parameters.
[0025] In one embodiment, the program security information includes dependency data security information of the software; the modification unit includes:
[0026] A first determination subunit, configured to determine data encryption information of dependency resource data of the software, where the data encryption information is generated based on a data storage directory and a data mounting directory of the dependency resource data, the data storage directory is used to store the dependency resource data, and the data mounting directory is used to mount the data storage directory;
[0027] A third modification subunit, configured to modify the code parameter information corresponding to the dependent data security information in the software launcher according to the data encryption information.
[0028] In one embodiment, the program security information includes the program time limit security information of the software; the modification unit includes:
[0029] A second determination subunit, configured to determine the time limit inquiry cycle information of the software;
[0030] A fourth modification subunit, configured to modify the code parameters corresponding to the program time limit security information in the software launcher according to the time limit inquiry cycle information.
[0031] In one embodiment, the generation unit includes:
[0032] A second acquisition subunit, configured to acquire the dependent resource data of the software;
[0033] An image generation subunit, configured to generate a base image file of the software according to the dependent resource data;
[0034] A data generation subunit, configured to generate software deployment data of the software according to the base image file, the encrypted code data, and the modified software launcher.
[0035] In one embodiment, the image generation subunit is configured to:
[0036] Create a data storage directory and a data mounting directory for the dependent resource data, where the data storage directory is used to store the dependent resource data, and the data mounting directory is used to mount the data storage directory; mount the data storage directory to the data mounting directory; store the dependent resource data in the mounted data storage directory; and generate a base image file of the software based on the storage result.
[0037] In one embodiment, the image generation subunit is specifically configured to:
[0038] If the storage result is successful storage, unmount the data storage directory; and generate a base image file of the software based on the processing result.
[0039] In one embodiment, the acquisition unit includes:
[0040] A plugin configuration subunit, configured to configure a software encryption plugin of the software in a configuration file of the software, where the software encryption plugin has software encryption instructions;
[0041] A software encryption subunit, configured to encrypt the software through the software encryption instructions.
[0042] A first acquisition subunit, configured to acquire encrypted code data of the software and a software launcher based on a processing result.
[0043] Correspondingly, an embodiment of the present application further provides a storage medium, on which a computer program is stored, where when the computer program is executed by a processor, the steps of the software deployment method shown in the embodiment of the present application are implemented.
[0044] Correspondingly, an embodiment of the present application further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, the steps of the software deployment method shown in the embodiment of the present application are implemented.
[0045] Correspondingly, an embodiment of the present application further provides a computer program product, including a computer program / instructions, where when the computer program / instructions are executed by a processor, the steps of the software deployment method shown in the embodiment of the present application are implemented.
[0046] The embodiment of the present application can acquire encrypted code data of the software and a software launcher, where the software launcher is used to assist in starting the software; determine program security information during the operation of the software; modify code parameter information corresponding to the program security information in the software launcher based on the program security information; generate software deployment data of the software according to the encrypted code data and the modified software launcher; and deploy the software on a target device according to the software deployment data.
[0047] In this solution, when the software is deployed, the software is encrypted to obtain encrypted code data of the software, and in this solution, the software launcher of the software is used to assist in starting the software during software deployment, which enables the corresponding code parameter information in the software launcher to be modified based on the program security information during the operation of the software, thereby improving the security and efficiency during software deployment. For example, for different program security information of the software, the software launcher can be correspondingly modified so that the modified software launcher can prevent and process corresponding program security information. In this way, a software launcher that meets diverse security requirements during the software deployment process can be constructed, and a more secure and efficient software deployment environment can be constructed by using this software launcher. In addition, since the security and efficiency during software deployment are improved by modifying the software launcher in this solution, this solution ensures the security and efficiency during the software deployment process without intruding into the business code of the software and without the awareness of business developers. Description of the Drawings
[0048] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those skilled in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0049] Figure 1 It is a schematic diagram of the scenario of the software deployment method provided by the embodiment of the present application;
[0050] Figure 2 It is a flowchart of the software deployment method provided by the embodiment of the present application;
[0051] Figure 3 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0052] Figure 4 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0053] Figure 5 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0054] Figure 6 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0055] Figure 7 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0056] Figure 8 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0057] Figure 9 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0058] Figure 10 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0059] Figure 11 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0060] Figure 12 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0061] Figure 13 It is another schematic diagram of the process of the software deployment method provided by the embodiment of the present application;
[0062] Figure 14It is another schematic flowchart of the software deployment method provided by the embodiments of the present application;
[0063] Figure 15 It is another schematic flowchart of the software deployment method provided by the embodiments of the present application;
[0064] Figure 16 It is a schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0065] Figure 17 It is another schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0066] Figure 18 It is another schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0067] Figure 19 It is another schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0068] Figure 20 It is another schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0069] Figure 21 It is another schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0070] Figure 22 It is another schematic structural diagram of the software deployment device provided by the embodiments of the present application;
[0071] Figure 23 It is a schematic structural diagram of the computer device provided by the embodiments of the present application. Detailed implementation manners
[0072] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0073] The embodiments of the present application provide a software deployment method, apparatus, computer device, storage medium, and computer program product. Specifically, the embodiments of the present application provide a software deployment apparatus applicable to a computer device. Among them, the computer device can be a device such as a server or a terminal. Specifically, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and the present application does not make any restrictions in this regard. The embodiments of the present application can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, intelligent transportation, assisted driving, etc.
[0074] In the embodiments of the present application, the software deployment method executed by the server will be taken as an example to introduce the software deployment method.
[0075] Reference Figure 1 , the server 10 can obtain the encrypted code data of the software and the software launcher. Among them, the software launcher of the software is used to assist in starting the software and determine the program security information during the operation of the software. Further, the server 10 can modify the code parameter information corresponding to the program security information in the software launcher based on the program security information, and generate the software deployment data of the software according to the encrypted code data and the modified software launcher. In this way, the server 10 can deploy the software on the target device according to the software deployment data. For example, taking the target device as the Figure 1 terminal 20 in it as an example, the server 10 can send the software deployment data to the terminal 20 so that the software can be deployed on the terminal 20 through the software deployment data.
[0076] The following will be described in detail respectively. It should be noted that the description order of the following embodiments does not limit the preferred order of the embodiments.
[0077] A software deployment method provided by the embodiments of the present application can be executed by a server or a terminal, or jointly executed by a server and a terminal. In the embodiments of the present application, the software deployment method executed by the server is taken as an example for explanation. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and the present application does not make any restrictions in this regard. In the embodiments of the present application, this method can be executed by a software deployment apparatus integrated in the server, as Figure 2 described, the specific process of this software deployment method can be as follows:
[0078] 110. Obtain the encrypted code data of the software and the software launcher, where the software launcher is used to assist in starting the software.
[0079] The encrypted code data of the software refers to the code data obtained after encrypting the software. For example, the software can be an application to be deployed, such as a Java application under the Spring Boot framework. The application can be encrypted to obtain the encrypted code data of the application, which can specifically be in the form of a Java Archive (JAR). Among them, Spring Boot is a framework used to simplify the initial setup and development process of new Spring applications, and Spring is an open-source J2EE (Java 2 Platform Enterprise Edition) application framework.
[0080] The software launcher of the software refers to an application used to assist in starting the software. For example, the software launcher can have decryption and startup functions. In this way, when the software is deployed to the target device, the encrypted code data of the software can be decrypted by the software launcher, so that the target device can obtain the decrypted software and start the software through the startup function of the software launcher.
[0081] In this application, there are various ways to obtain the encrypted code data of the software and the software launcher. For example, different processing mechanisms can be designed to obtain the encrypted code data of the software and the software launcher respectively; for example, an encryption mechanism can be designed to obtain the encrypted code data of the software, and a software launcher can be developed for the software so that the generated software launcher can be used to assist in starting the software. As an example, the encryption mechanism can include a symmetric encryption mechanism, an asymmetric encryption mechanism, etc. Another example is that for generating the encrypted code data of the software and the software launcher, an integrated system can be designed to obtain the encrypted code data of the software and the software launcher at the same time, such as designing a software encryption plug-in, which can specifically be used to encrypt the software to obtain the encrypted code data of the software and generate the software launcher of the software.
[0082] In an embodiment, the encrypted code data of the software and the software launcher can be obtained through a software encryption plug-in. In this way, by simply introducing the software encryption plug-in into the software deployment and development project corresponding to the software, the encrypted code data of the software and the software launcher can be obtained without invading the software source code. Specifically, the step "Obtain the encrypted code data of the software and the software launcher, where the software launcher is used to assist in starting the software" can include:
[0083] Configure the software encryption plugin of the software in the software configuration file, where the software encryption plugin has software encryption instructions;
[0084] Encrypt the software through the software encryption instructions;
[0085] Based on the processing result, obtain the encrypted code data and the software launcher of the software.
[0086] Among them, the software configuration file is a computer file that can configure parameters and initial settings for some computer programs of the software.
[0087] As an example, in the software deployment and development project of the software, a project management tool such as Maven can be used to manage the construction, reports, and documents of the project. Then, the software configuration file can specifically be the pom.xml file in the software deployment and development project of the software. Among them, Maven is a project management tool that can manage the construction, reports, and documents of the project through a short description information; the project object model (pom) is the description of a single project by Maven; the Extensible Markup Language (XML) is a markup language used to mark electronic files to make them structured.
[0088] Among them, the software encryption plugin of the software is a program written according to a certain specification of the application programming interface, which can be used to encrypt the software and create the software launcher of the software. For example, taking the software to be deployed as a software written in the Java language as an example, the original JAR package resources can be encrypted by using the Advanced Encryption Standard (AES), and a custom class loader can be extended and customized to design the software encryption plugin of the software, so that the created software encryption plugin can achieve dynamic decryption and operation, and ensure that the Java bytecode is not tampered with.
[0089] As an example, the open-source code xjar tool can be used as the software encryption plugin of the software. Among them, xjar provides a set of program encryption startup and dynamic decryption operation solutions based on the encryption of resources in the JAR package and the extended class loader, which can avoid source code leakage and decompilation.
[0090] Among them, the software encryption instruction refers to the instruction provided by the software encryption plug-in. By running this instruction, the software encryption plug-in can be triggered to encrypt the software, generating the encrypted code data of the software and the software launcher. For example, the software can be encrypted by setting relevant parameters in this instruction, so as to obtain the encrypted code data of the software and the software launcher. For instance, relevant parameters can be set to specify the JAR package file to be encrypted, the encryption password, the encryption algorithm, the output file of the encrypted JAR package, etc.
[0091] As an example, if the project management tool is not used in the software deployment and development project of the software, the software encryption instruction provided by the software encryption plug-in can be directly used to encrypt the software; if the project management tool is used in the software deployment and development project of the software, the software encryption instruction provided by the software encryption plug-in docking with the software management tool can be used to encrypt the software.
[0092] In one embodiment, the software to be deployed can be a Java application under the Spring Boot framework, and maven can be used to manage the project of the software deployment and development project of this software. Taking xjar as the software encryption plug-in of this software as an example, see Figure 3 , the maven plug-in of xjar can be introduced into the pom.xml of the software deployment and development project in a non-invasive manner in the form of a shell command, so as to realize the configuration of the software encryption plug-in of this software in the configuration file of the software. Among them, the software encryption plug-in has software encryption instructions. For example, the packaging instruction provided by the maven plug-in of xjar. Further, the software can be encrypted by using this packaging command to generate an encrypted xjar package, and the encrypted code data of the software and the software launcher can be specifically included in this xjar.
[0093] 120. Determine the program security information during the operation of the software.
[0094] Among them, the program security information is used to describe the influencing factors of program security. Then, the program security information during the operation of the software can be used to describe the influencing factors of program security when this software is running.
[0095] In practical applications, the software provider can develop or provide the software to be deployed, and this software can be deployed to the target device so that the target device can further run this software. Since the software running environment in the target device can be a private environment relative to the software provider, when the software is deployed to the private environment, the software provider needs to pay attention to code protection issues. For example, the software provider needs to avoid program security issues such as the software being decompiled or the code being tampered with in the private environment.
[0096] Therefore, considering the program security issues that the software may encounter in the privatized software, the program security information during the operation of the software can be determined before the software is deployed, so that the corresponding code parameter information in the software launcher can be modified based on the program security information subsequently.
[0097] As an example, the program security information may include program key security information, program detection security information, dependent data security information, program time limit security information, etc. Among them, the program key security information is a type of program security information, which describes the relevant information of program security from the perspective of key security; among them, the program detection security information is a type of program security information, which describes the relevant information of program security from the perspective of program detection; among them, the dependent data security information is a type of program security information, which describes the relevant information of program security from the perspective of the dependent resource data of the software; among them, the program time limit security information is a type of program security information, which describes the relevant information of program security from the perspective of program time limit.
[0098] In this application, there are various ways to determine the program security information during the operation of the software. For example, the program security information during the operation of the software can be determined according to the software type of the software. Specifically, since different types of software may have different program security issues during operation, the software type to which the software belongs can be determined, and then the program security information corresponding to the software type can be determined, so as to determine the program security information during the operation of the software. Another example is that the program security information during the operation of the software can be determined according to the device type of the target device. Specifically, after the software is deployed to the target device, the target device can further run the software, and for different types of target devices, the software may face different program security issues during operation. Therefore, the device type to which the target device belongs can be determined, and then the program security issues corresponding to the device type can be determined, so as to determine the program security issues during the operation of the software.
[0099] 130. Modify the code parameter information corresponding to the program security information in the software launcher based on the program security information.
[0100] Among them, the code parameter information corresponding to the program security information in the software launcher refers to the program data in the software launcher that corresponds to the program security information. The program data may specifically include relevant code segments, relevant parameter information, etc.
[0101] In this application, since the program security information is used to describe the influencing factors of program security, modifying the code parameter information corresponding to the program security information in the software launcher can implement modifying the software launcher based on the program security influencing factors corresponding to the program security information. When the software is assisted in starting through the modified software launcher, the corresponding program security influencing factors can be taken into account, thereby improving the security of program deployment.
[0102] There can be multiple ways to modify the code parameter information in the software launcher. For example, it can include modifying relevant code snippets; or it can include modifying relevant parameter information, etc. In this application, considering that there can be multiple categories of program security information, such as program key security information, program detection security information, dependent data security information, program time limit security information, etc., the following will take different categories of program security information as examples to illustrate the step of "modifying the code parameter information corresponding to the program security information in the software launcher based on the program security information".
[0103] In one embodiment, the program security information can include the program key security information of the software. Specifically, the step of "modifying the code parameter information corresponding to the program security information in the software launcher based on the program security information" can include:
[0104] Generate the key parameters required for software deployment;
[0105] Modify the code parameter information corresponding to the program key security information in the software launcher according to the key parameters.
[0106] Since the use of keys can be involved in the process of software deployment and development for the software to be deployed. For example, in the process of generating the encrypted code data of the software at the software supply end, a password can be used to encrypt the source code of the software to obtain the encrypted code data; or in the process of mounting the dependent resource data of the software at the software supply end, a password can be used to encrypt this process to improve the security of the dependent resource data; and so on. Therefore, the program security during software operation can be improved from the perspective of key security.
[0107] Among them, the program key security information is a type of program security information, which is the relevant information describing program security from the perspective of key security.
[0108] Among them, a key is the secret information used to complete cryptographic applications such as encryption, decryption, and integrity verification. In this application, the key parameter refers to the relevant parameters of the key. For example, the key parameter can include the password used for encryption or decryption, such as plaintext password, ciphertext password, etc.
[0109] In this application, there can be multiple ways to generate the key parameters required for deploying software. For example, the key parameters required for deploying software can include a plaintext password. Therefore, the key parameters can be obtained by acquiring this plaintext password. As an example, when the software provider generates the encrypted code data of the software, it can use the password to encrypt the source code of the software to obtain the encrypted code data. Since this process is carried out at the software provider, this password can be set in the form of a plaintext password.
[0110] Also, the key parameters required for deploying software can include a ciphertext password. As an example, during the process of the software provider mounting the dependent resource data of the software, it can use the password for encryption. And when the software is deployed to the target device, the target device needs to decrypt using this password in order to obtain the dependent resource data of the software. For this example, considering that this password not only functions at the software provider but also at the target device, in order to improve key security and data security, this password can be set in the form of a ciphertext password.
[0111] The generation of the ciphertext password can specifically be achieved by encrypting the original password. Specifically, the step of "generating the key parameters required for deploying software" can include:
[0112] Acquire the original password information required for deploying software;
[0113] Determine the encryption parameters for the original password information;
[0114] According to the encryption parameters, encrypt the original password information to obtain the key parameters required for deploying software.
[0115] Among them, the original password information refers to the password information to be encrypted. For example, the plaintext password to be encrypted, etc.
[0116] Among them, the encryption parameters are auxiliary parameters required for encrypting the original password information. As an example, in the white-box encryption mechanism, the original password information can be the plaintext password to be encrypted, and the encryption parameters can be the initialization vector (IV) parameter and the key parameter required for encrypting the original password information. As another example, the Data Encryption Standard (DES) can be used to generate the key parameters required for deploying software. Then the original password information can be the plaintext password to be encrypted, and the encryption parameters can be the key parameter and the mode parameter in DES.
[0117] After determining the original password information to be encrypted and the encryption parameters required for encrypting the original password information, the original password information can be encrypted according to the encryption parameters to obtain the encrypted ciphertext password, and then the key parameters required for deploying the software can be obtained. For example, the encrypted ciphertext password can be directly used as the key parameters required for deploying the software. Another example is that the ciphertext password can be further processed, such as adding a random number to the ciphertext password, to obtain the key parameters required for deploying the software.
[0118] As an example, based on the white-box encryption mechanism, the plaintext password can be encrypted according to iv and key to obtain the encrypted ciphertext password. Further, the ciphertext password can be added to a random number, and the added result can be used as the key parameters required for deploying the software. As another example, based on DES, the plaintext password can be encrypted according to key and mode, and the encryption result can be used as the key parameters required for deploying the software.
[0119] After generating the key parameters required for deploying the software, the code parameter information corresponding to the program key security information in the software launcher can be further modified according to the key parameters.
[0120] For example, the key parameters required for deploying the software, specifically the plaintext password, can be taken as an example. The code parameter information corresponding to the program key security information in the software launcher can specifically be the code segment storing the plaintext password. Therefore, the code segment can be updated according to the plaintext password so that the updated code segment stores the plaintext password.
[0121] As an example, take the software to be deployed as a Java application under the Spring Boot framework. Use maven to manage the software deployment development project of this software, use xjar as the software encryption plugin for this software, and the software launcher is specifically a program written in the Golang language (Golang is a statically strongly typed, compiled, concurrent, and garbage-collected programming language). See Figure 4 , then mvn build Dxjar.passwor is the call instruction in maven, launcher is the software launcher, and Golang launcher refers to the software launcher in the Golang language. The key parameters required for deploying the software can specifically include the plaintext password involved in encrypting this software by xjar based on the aes mechanism. In this example, the plaintext password encrypted by xjar aes can be written into the software launcher through this call instruction, so as to modify the code parameter information corresponding to the program key security information in the software launcher according to the key parameters, and then obtain the binary executable file of the software launcher.
[0122] For another example, the key parameters required for software deployment, specifically the ciphertext password, can be used as an example. The code parameter information corresponding to the program key security information in the software launcher can specifically be the code snippet storing the ciphertext password. Therefore, based on the plaintext password, the code snippet can be updated so that the updated code snippet stores the ciphertext password.
[0123] As an example, the software to be deployed can be a Java application under the Spring Boot framework, and maven can be used to manage the software deployment and development project of this software. And the software launcher is specifically a program written in the Golang language. Refer to Figure 5 , "mvn build Dxjar.passwor" is the call instruction in maven, "launcher" is the software launcher, and "Golang launcher" refers to the software launcher under the Golang language. The key parameters required for software deployment can specifically include the ciphertext password, such as the ciphertext password involved in mounting the dependent resource data of the software. In this example, the plaintext password can be encrypted based on the white-box encryption mechanism. Specifically, the iv and key required for white-box encryption can be generated first, and the plaintext password can be encrypted using the iv and key to obtain the encrypted ciphertext password. Further, the ciphertext password and a random number can be added, and the added result can be used as the key parameter required for software deployment to generate the key parameter required for software deployment. Further, through this call instruction, the key parameter can be written into the software launcher, so as to modify the code parameter information corresponding to the program key security information in the software launcher according to the key parameter, and then obtain the binary executable file of the software launcher.
[0124] In another embodiment, the program security information can include the program detection security information of the software. Specifically, the step of "modifying the code parameter information corresponding to the program security information in the software launcher based on the program security information" can include:
[0125] Based on the program detection security information, determine the program detection parameters to be disabled in the software launcher;
[0126] Modify the code parameter information corresponding to the program detection security information in the software launcher according to the program detection parameters.
[0127] Among them, program detection security information is a type of program security information, which describes the relevant information of program security from the perspective of program detection. Taking Java as an example, when a Java program runs, users can use Java agent or Attach mechanism to detect and even crack the Java source code in the form of bytecode. Therefore, when deploying software, the program security can be concerned from the perspective of program detection. Among them, in practical applications, the agent is an agent program independent of the application program; the Attach mechanism is a capability of inter-process communication provided by the Java Development Kit (JDK) of the Java language for the Java Virtual Machine (JVM), which enables one process to send commands to another process and let it perform some internal operations.
[0128] Among them, program detection parameters refer to the parameters that can trigger relevant programs to detect the software. For example, taking the software to be deployed as a Java application program, the program detection parameters can include the relevant parameters for implementing program detection based on Java agent, including the relevant parameters for implementing program detection based on the Attach mechanism, and so on. In this application, since the program detection parameters refer to the parameters that can trigger relevant programs to detect the software, these program detection parameters can be set to be disabled in the software launcher to avoid the program detection security problems caused by the software being detected and even cracked after being deployed to the target device.
[0129] In this application, the program detection parameters to be disabled in the software launcher can be determined based on the program detection security information of the software, and then the code parameter information corresponding to the program detection security information in the software launcher can be modified. For example, these program detection parameters can be disabled in the corresponding code segment in the software launcher. In this way, even if the client passes in these program detection parameters, they will still not be read, thus effectively avoiding the program detection security problems after software deployment. As an example, taking the software to be deployed as a Java application program under the Spring Boot framework, and the software launcher is specifically a program written in the Golang language, the code parameter information corresponding to the program detection security information in the software launcher can be modified by disabling the program detection parameters in the software launcher.
[0130] In another embodiment, the program security information may include the dependent data security information of the software. Specifically, the step of "modifying the code parameter information corresponding to the program security information in the software launcher based on the program security information" may include:
[0131] Determine the data encryption information of the dependent resource data of the software, where the data encryption information is generated based on the data storage directory and the data mounting directory of the dependent resource data. The data storage directory is used to store the dependent resource data, and the data mounting directory is used to mount the data storage directory;
[0132] Modify the code parameter information corresponding to the dependent data security information in the software launcher according to the data encryption information.
[0133] Among them, the dependent data security information is a type of program security information, which is the relevant information describing program security from the perspective of the dependent resource data of the software. Taking Java as an example, a Java program can have dependent resource data. Since the dependent resource data can be used to support the operation of the Java program, it is necessary to pay attention to program security from the perspective of the dependent resource data of the software. In addition, when a Java application runs, it can use the dependent packages related to the skywalking (skywalking is an open-source tool for distributed detection, analysis, and alarm) agent call chain. Therefore, if the JDK or the JAR package of the skywalking agent is tampered with, it is also possible to crack the source code of the Java application. It can be seen that it is quite important to pay attention to program security from the perspective of the dependent resource data of the software.
[0134] Among them, the dependent resource data refers to the resource data on which the software depends. For example, taking the software as a Java application specifically, the dependent resource data of the software can include the Java Development Kit (JDK) on which the Java program depends; another example is that the dependent data source can include the Software Development Kit (SDK) on which the Java program depends; and so on.
[0135] Among them, the data encryption information of the dependent resource data refers to the secret information involved in the process of encrypting the dependent resource data. For example, the data encryption information can specifically be a password, such as a plaintext password, a ciphertext password, etc. Specifically, after the software is deployed to the target device, the target device can obtain the dependent resource data through this data encryption information. For example, the target device can obtain the access permission of the relevant directory through this data encryption information, and then obtain the dependent resource data from this directory.
[0136] In this application, the data encryption information of the dependent resource data is generated based on the data storage directory and the data mounting directory of the dependent resource data. Among them, the data storage directory is the directory used to store the dependent resource data, and the data mounting directory is the directory used to mount the data storage directory.
[0137] For example, a data storage directory can be created, and the dependent resource data of the software can be stored in this data storage directory. Further, this data storage directory can be mounted to a data mount directory, and during this process, data encryption information for the dependent resource data can be set to achieve encrypted mounting. In this way, when the software is deployed to the target device, the software launcher can be triggered to obtain the pre-stored dependent resource data according to the set data encryption information. Since this can prevent the dependent resource data during software operation from being tampered with, therefore, the security of software deployment can be improved by ensuring the security of the dependent resource data of the software, and the source code of the software can be better protected from being stolen or tampered with. In practical applications, the software provider can use open-source tools such as gocryptfs and zbox to achieve encrypted mounting of dependent resource data, or can also develop relevant programs by itself to achieve encrypted mounting of dependent resource data.
[0138] As an example, the software to be deployed can be a Java application under the Spring Boot framework, and the dependent resource data of the software includes the dependent SDK of the software. Taking the use of the open-source tool gocryptfs to achieve encrypted mounting of dependent resource data, with the plain directory as the data storage directory and the cipher directory as the data mount directory as an example. Refer to Figure 6 , the software provider can encrypt and mount the data storage directory to the data mount directory, that is, as shown in the figure, encrypt and mount the plain directory to the cipher directory. It should be noted that the process of encrypted mounting can include setting password information for the access permission of the data mount directory and determining this password information as the data encryption information of the dependent resource data of the software. Furthermore, the dependent resource data of the software can be stored in the data storage directory, that is, as shown in the figure, copying the dependent SDKs such as the jdk of the software to the plain directory through the cp command (the copy command in the Linux system); further, the data storage directory can be unmounted, that is, as shown in the figure, unmount the plain directory, to ensure that when the software is deployed to the target device, the target device can only obtain the pre-stored dependent resource data through the data mount directory cipher directory. Also, since data encryption information was set for the access to the data mount directory cipher directory beforehand, in this way, it can be ensured that the target device can only obtain the pre-stored dependent resource data through the data mount directory on the premise of knowing the data encryption information, thus improving data security.
[0139] After determining the data encryption information of the dependent resource data of the software, the code parameter information corresponding to the dependent data security information in the software launcher can be further modified according to the data encryption information. Specifically, in this application, since after the software is deployed to the target device, the target device can obtain the dependent resource data through this data encryption information, therefore, based on the setting method of the data encryption information, the corresponding code parameter information in the software launcher can be modified so that the target device can obtain the dependent resource data through the modified software launcher using this data encryption information.
[0140] As an example, the software to be deployed can be a Java application under the Spring Boot framework. The dependent resource data of the software includes the dependent SDK of the software. The software provider uses the open-source tool gocryptfs to implement the encrypted mounting of the dependent resource data, uses the plain directory as the data storage directory, uses the cipher directory as the data mounting directory, and sets the data encryption information for accessing the data mounting directory when encrypting and mounting the data storage directory to the data mounting directory, that is, the data encryption information of the dependent resource data of the software. In this example, the flowchart shown in Figure 7 can be referred to for modifying the code parameter information corresponding to the dependent data security information in the software launcher.
[0141] Specifically, it can be set that the software launcher first determines whether there are files in the plain directory. If so, the plain directory is unmounted. For this setting, referring to Figure 6 it can be known that after the software provider encrypts and mounts the dependent resource data to the cipher directory (the data mounting directory), the plain directory (the data storage directory) is unmounted. Therefore, after the software is deployed to the target device, when the target device determines whether there are files in the plain directory through the software launcher, the determination result should be none. If the determination result is yes, it means that the plain directory has been tampered with and the data in the plain directory is not trustworthy. Therefore, in the case where the determination result is yes, the software launcher should be set to perform the operation of unmounting the plain directory.
[0142] Furthermore, if it is determined that there are no files in the plain directory or after the plain directory is uninstalled, the software launcher can be set to further access the cipher directory in read-only mode and mount the cipher directory to the plain directory. It should be noted that at this time, on the target device, the plain directory serves as the data mount directory for the cipher directory. In addition, since data encryption information has been set for accessing the cipher directory previously, the software launcher can use this data encryption information to access the cipher directory, that is, access the cipher directory in read-only form, and then mount the cipher directory to the plain directory. Further, the software launcher can be set to obtain the dependent SDK of the software through the data mount directory plain directory of the cipher directory. If the acquisition is successful, the startup is successful; otherwise, the startup fails.
[0143] In another embodiment, the program security information may include the program time limit security information of the software. Specifically, the step of "modifying the code parameter information corresponding to the program security information in the software launcher based on the program security information" may include:
[0144] Determine the time limit inquiry cycle information of the software;
[0145] Modify the code parameters corresponding to the program time limit security information in the software launcher according to the time limit inquiry cycle information.
[0146] Among them, the program time limit security information is a type of program security information, which is the relevant information describing program security from the perspective of the program time limit. The program time limit of the software refers to the time limit set for the normal operation and service provision of the software. Specifically, when the program time limit of the software has not expired, the software can run normally to provide services; after the program time limit of the software expires, the software terminates running to stop the service.
[0147] In practical applications, it is a common requirement to stop the service according to the service duration purchased by the customer. As the service provided by the software supplier to the target device, the software can also have a corresponding program time limit. Specifically, the software supplier can provide the software with a program time limit to the target device. Within the program time limit, the software can run normally and provide services to the target device. If the program time limit of the software expires, the software can terminate running to stop the service of the target device.
[0148] Among them, the time limit inquiry cycle of the software refers to the cycle for inquiring about the program time limit of the software. Specifically, after the software is deployed to the target device, the program time limit of the software can be inquired from the relevant service to determine whether the program time limit of the current software has expired. For example, the relevant service can be the storage service provided by the software supplier, and this storage service can be used to store the program time limit of the software.
[0149] After determining the time limit inquiry cycle of the software, the code parameters corresponding to the program time limit security information in the software launcher can be modified according to the time limit inquiry cycle information. So that after the software is deployed to the target device, through the modified software launcher, the program time limit of the software can be regularly inquired from the relevant service according to the time limit inquiry cycle of the software, and it can be determined whether the program time limit of the current software has expired.
[0150] As an example, reference can be made to Figure 8 , to modify the code parameters corresponding to the program time limit security information in the software launcher. Specifically, it can be set that after the software deployment is completed, the software launcher regularly inquires the time limit information of the software from the storage service provided by the software supplier according to the time limit inquiry cycle information of the software, so as to achieve Figure 8 the timed acquisition of the license of the software shown in, where the license contains the program time limit of the software on the target device. Furthermore, it can be set that the software launcher further determines whether the program time limit of the software has expired, that is, Figure 8 the judgment of whether the license has expired shown in. Further, it can be set that if the judgment result is that the program time limit of the software has expired, then the software launcher is set to terminate the operation of the software to stop providing services after the program time limit expires; if the judgment result is that the program time limit of the software has not expired, then the software launcher is set to continue to regularly inquire the time limit information of the software from the storage service provided by the software supplier according to the time limit inquiry cycle information of the software. Among them, the deployment container is the program used when deploying the software to the target device. In practical applications, software deployment can be achieved through the deployment container.
[0151] 140. Generate the software deployment data of the software according to the encrypted code data and the modified software launcher.
[0152] Among them, the software deployment data is the relevant data required when deploying the software to the target device. As an example, the software deployment data can include the encrypted code data and the modified software launcher of the software. In practical applications, there can be multiple ways to deploy the software, and correspondingly, there can also be multiple ways to generate the software deployment data.
[0153] For example, the encrypted code data of the software can be packaged with the modified software launcher, and the generated data packet can be used as the software deployment data of the software.
[0154] For another example, the software deployment data of the software can be generated based on the mechanism of Docker containerized deployment. Among them, Docker is an application container engine developed in the Golang language. Based on the containerized application deployment mechanism, it can be applied to scenarios such as packaging, continuous integration, and releasing applications. In one embodiment, the software deployment data of the software can be generated based on the encrypted code data and the modified software launcher according to the mechanism of containerized deployment. Specifically, the step "generate the software deployment data of the software according to the encrypted code data and the modified software launcher" can include:
[0155] Obtain the dependent resource data of the software;
[0156] Generate the base image file of the software according to the dependent resource data;
[0157] Generate the software deployment data of the software according to the base image file, the encrypted code data, and the modified software launcher.
[0158] Among them, the image file is a data packet constructed from the relevant data of the software. For example, the data packet constructed from the software can be called the project image file of the software. As an example, taking the Docker containerized deployment mechanism as an example, its main function is to implement software deployment by running containers. Specifically, the software and the dependent resource data of the software can be packaged into a project image file with startup instructions, and then a container can be created on the target device so that the project image can run in the container, thereby realizing the deployment of the software on the target device.
[0159] For another example, a data packet constructed from the dependent resource data of software can be referred to as the base image file of the software. As an example, taking the Docker containerization deployment mechanism as an example, when building an image file, it can rely on a parent image file as the underlying image file and package it together with the image file currently being built, thereby building a brand-new image file. And this parent image file used as a dependency is the base image file. For example, taking the software as a Node.js application specifically, this software cannot run everywhere. Its operation requires its dependent resource data, such as depending on the operating system and the Node.js runtime environment, etc. Therefore, a simple Node.js project image file cannot run. It needs to rely on a base image file, and this base image file is the Node.js image file, where the Node.js image file contains the operating system environment and the Node.js environment. In this way, the project image file built from the Node.js image file and the Node.js application can run completely.
[0160] Therefore, in the present application, in order to enable the project image file built from software to run smoothly, the dependent resource data of the software can be obtained, and based on the dependent resource data, the base image file of the software can be generated.
[0161] In one embodiment, in order to improve the data security of the dependent resource data and avoid data security problems that occur during software operation due to the tampering of the dependent resource data after the software is deployed to the target device, the base image file of the software can be built based on the dependent resource data of the software. Specifically, the step of "generating the base image file of the software according to the dependent resource data" can include:
[0162] Create a data storage directory and a data mounting directory for the dependent resource data, where the data storage directory is used to store the dependent resource data, and the data mounting directory is used to mount the data storage directory;
[0163] Mount the data storage directory to the data mounting directory;
[0164] Store the dependent resource data in the mounted data storage directory;
[0165] Generate the base image file of the software based on the storage result.
[0166] For example, a data storage directory and a data mounting directory that depend on resource data can be created, and the dependent resource data of the software can be stored in the data storage directory. Further, the data storage directory can be mounted to the data mounting directory, and data encryption information of the dependent resource data can be set during this process to achieve encrypted mounting. In this way, when the software is deployed to the target device, the software launcher can be triggered to obtain the previously set dependent resource data according to the set data encryption information. Since this can prevent the dependent resource data from being tampered with during software operation, the security of software deployment can be improved by ensuring the security of the dependent resource data of the software, and the source code of the software can be better protected from being stolen or tampered with. In practical applications, the software provider can use the open-source tool gocryptfs to achieve encrypted mounting of dependent resource data, or can also develop relevant programs by itself to achieve encrypted mounting of dependent resource data.
[0167] As an example, the software to be deployed can be a Java application under the Spring Boot framework, and the dependent resource data of the software includes the dependent SDK of the software. The open-source tool gocryptfs is used to achieve encrypted mounting of the dependent resource data, taking the plain directory as the data storage directory and the cipher directory as the data mounting directory as an example. Refer to Figure 6 , the software provider can encrypt and mount the data storage directory to the data mounting directory, that is, mount the plain directory to the cipher directory as shown in the figure. It should be noted that the process of encrypted mounting can include setting password information for the access permission of the data mounting directory and determining the password information as the data encryption information of the dependent resource data of the software. Further, the dependent resource data of the software can be stored in the data storage directory, that is, copying the dependent SDK such as the jdk of the software to the plain directory through the cp command (the copy command in the Linux system) as shown in the figure.
[0168] In this application, considering that after storing the dependent resources in the data storage directory, even if the data storage directory has been mounted under the data mounting directory, since the original data of the dependent resource data is stored in the data storage directory and the mounting process does not encrypt the access to the data storage directory, if other users tamper with the dependent resource data stored therein by accessing the data storage directory, it will still cause data security problems. To solve this problem, considering that the mounting process encrypts the access to the data mounting directory, a base image file of the software can be further generated based on the storage result of the dependent resource data. Specifically, the step of "generating the base image file of the software based on the storage result" can include:
[0169] If the storage result is successful storage, unmount the data storage directory;
[0170] Generate the base image file of the software based on the processing result.
[0171] Specifically, if the storage result of the dependent resource data is successful storage, the data storage directory can be unmounted to unmount the data storage directory. As an example, see Figure 6 the unmounting of the plain directory shown in. To ensure that after the software is deployed to the target device, the target device can only obtain the pre-stored dependent resource data through the data mount directory. Also, since data encryption information is set for the access to the data mount directory beforehand, in this way, it can be ensured that the target device can obtain the pre-stored dependent resource data through the data mount directory only on the premise of knowing the data encryption information, thereby improving data security.
[0172] Further, after the unmounting process of the data storage directory, if the unmounting is successful, the base image file of the software can be further generated. For example, the base image file of the software can be generated based on the mechanism of Docker containerized deployment.
[0173] In one embodiment, reference can be made to Figure 9 to generate the software deployment data of the software. Specifically, the base image file of the software can be generated according to the dependent resource data of the software, which is Figure 9 the step of "making the mirror base package" shown in. And, based on the program security information of the software, the code parameter information corresponding to the program security information in the software launcher of the software can be modified to obtain the modified software launcher, which is Figure 9 the step of "modifying the software launcher of the software" shown in. Further, the project image file constructed by the encrypted code data of the software and the modified software launcher can be generated, which is Figure 9 the step of "making the project image" shown in.
[0174] 150. Deploy the software on the target device according to the software deployment data.
[0175] Among them, the target device refers to the device on which the software is to be deployed. In this application, after the software deployment data of the software is generated, the software can be deployed on the target device according to the software deployment data.
[0176] For example, the software deployment data can be sent to the target device so that the target device can implement software deployment according to the software deployment data.
[0177] In one embodiment, software deployment can be implemented based on the mechanism of Docker containerization deployment. Specifically, the software deployment data may include created image files, such as base image files and project image files. Among them, the project image file may have startup instructions for the software, and this startup command can be executed when the container starts. By creating a container on the target device, the image file can run within the container, thereby realizing the deployment of the software on the target device.
[0178] As can be seen from the above, in this embodiment, the encrypted code data of the software and the software launcher can be obtained, where the software launcher is used to assist in starting the software; determine the program security information during the operation of the software; modify the code parameter information corresponding to the program security information in the software launcher based on the program security information; generate the software deployment data of the software according to the encrypted code data and the modified software launcher; and deploy the software on the target device according to the software deployment data.
[0179] When deploying the software, this solution encrypts the software to obtain the encrypted code data of the software. Moreover, in this solution, the software launcher of the software is used to assist in starting the software during software deployment, which enables the modification of the corresponding code parameter information in the software launcher based on the program security information during the operation of the software, thereby improving the security and efficiency during software deployment. For example, for different program security information of the software, the software launcher can be correspondingly modified so that the modified software launcher can prevent and handle the corresponding program security information. In this way, a software launcher that meets the diverse security requirements during the software deployment process can be constructed, and a more secure and efficient software deployment environment can be built by using this software launcher. In addition, since this solution improves the security and efficiency during software deployment by modifying the software launcher, this solution ensures the security and efficiency during the software deployment process without intruding into the business code of the software and without the awareness of business developers.
[0180] In addition, this solution effectively solves the code security problem of Java code during the private deployment process for customers by using the xjar open-source project, the gocryptfs file encryption and mounting open-source project, and the storage service provided by the software provider, prevents the code from being decompiled and tampered with, avoids the problem that the SDK relied on by the Java application is tampered with, resulting in the Java code being detected or even cracked, ensures that the enterprise can automatically deactivate after the service purchase expires. Finally, this solution is completely non-invasive to the original Java program code and is not perceived by business developers.
[0181] According to the method described in the above embodiment, the following will give an example for further detailed description.
[0182] In this embodiment, the software deployment device is integrated in the server and the terminal as an example for illustration. As Figure 10 shown, a software deployment method has the following specific process:
[0183] 210. The server obtains the encrypted code data of the software and the software launcher, where the software launcher is used to assist in starting the software.
[0184] In this embodiment, the server can specifically be the device corresponding to the software supply side, the software to be deployed is a Java application under the Spring Boot framework, xjar is used as the software encryption plug-in for the software, and the software launcher of the software is specifically a program written in the Golang language. Based on the mechanism of Docker containerization deployment, the software deployment data of the software is generated, and the software is not used as an example based on the mechanism of Docker containerization deployment.
[0185] See Figure 11 , the server can transform the xjar encrypted source code. For example, see Figure 12 , so that the Java application can receive the service expiration signal, intercept the interface request entry, and check the service expiration. In this way, it can be ensured that the Java application can be deactivated after the service expires. See Figure 11 , the server can further use the transformed xjar to encrypt the source code of the Java application to obtain the encrypted code data of the Java application and the software launcher. For example, see Figure 13 , the server can obtain the source code of the Java application and use the transformed xjar plug-in to encrypt the source code, thereby generating the software launcher and the encrypted xjar package. Among them, the encrypted xjar package can include the encrypted code data of the Java application.
[0186] 220. The server determines the program security information during the operation of the software.
[0187] For example, the program security information can include program key security information, program detection security information, dependent data security information, program time limit security information, etc.
[0188] Among them, the program key security information is a type of program security information, which describes the relevant information of program security from the perspective of key security; the program detection security information is a type of program security information, which describes the relevant information of program security from the perspective of program detection; the dependent data security information is a type of program security information, which describes the relevant information of program security from the perspective of the dependent resource data of the software; the program time limit security information is a type of program security information, which describes the relevant information of program security from the perspective of program time limit.
[0189] 230. The server modifies the code parameter information corresponding to the program security information in the software launcher based on the program security information.
[0190] See Figure 11 , in practical applications, before modifying the software launcher, a mirror base protection can be made. For example, referring to Figure 6 the flowchart shown, a basic mirror file of the software can be generated according to the dependent resource data of the software, so as to realize the production of the mirror base package.
[0191] In one embodiment, the program security information may include the program key security information of the software, and the server may generate the key parameters required for deploying the software; according to the key parameters, the code parameter information corresponding to the program key security information in the software launcher is modified.
[0192] In another embodiment, the program security information may include the program detection security information of the software, and the server may determine the program detection parameters to be disabled in the software launcher based on the program detection security information; according to the program detection parameters, the code parameter information corresponding to the program detection security information in the software launcher is modified.
[0193] In another embodiment, the program security information may include the dependent data security information of the software, and the server may determine the data encryption information of the dependent resource data of the software, where the data encryption information is generated based on the data storage directory and data mount directory of the dependent resource data. The data storage directory is used to store the dependent resource data, and the data mount directory is used to mount the data storage directory; according to the data encryption information, the code parameter information corresponding to the dependent data security information in the software launcher is modified. For example,
[0194] In another embodiment, the program security information may include the program time limit security information of the software, and the server may determine the time limit inquiry cycle information of the software; according to the time limit inquiry cycle information, the code parameters corresponding to the program time limit security information in the software launcher are modified.
[0195] As an example, the program security information may include program key security information, program detection security information, dependent data security information, and program time limit security information, and the server may refer to Figure 14 the process shown to modify the software launcher so that the modified software launcher can prevent the SDK relied on by the Java application from being tampered with, can detect the expiration of the service of the Java application, and can disable the insecure parameters of Java.
[0196] 240. The server generates the software deployment data of the software according to the encrypted code data and the modified software launcher.
[0197] In one embodiment, the server may generate software deployment data of the software according to the Figure 15 process shown. Specifically, the server may use a base image file, i.e., the bottom image package, and through the build instructions of Docker, according to the encrypted code data and other key files for program operation, as well as the modified software launcher, to build a project image file, thereby generating the software deployment data of the software.
[0198] 250. The server sends the software deployment data to the terminal.
[0199] 260. The terminal deploys the software on the target device according to the software deployment data.
[0200] It should be noted that the terminal and the target device may be the same device or different devices. The terminal may trigger the creation of a container on the target device so that the image file in the software deployment data can run inside the container. Since the image file may carry the startup command of the Java application, and this startup command can be executed when the container starts, the terminal can thus implement the deployment of the Java application on the target device based on the mechanism of containerized deployment.
[0201] As can be seen from the above, in the embodiment of the present application during software deployment, the software is encrypted to obtain the encrypted code data of the software, and in this solution, the software launcher of the software is used to assist in starting the software during software deployment, which enables the corresponding code parameter information in the software launcher to be modified based on the program security information during the operation of the software, thereby improving the security and efficiency during software deployment. For example, for different program security information of the software, the software launcher can be correspondingly modified so that the modified software launcher can prevent and process the corresponding program security information. In this way, a software launcher that meets the diverse security requirements during the software deployment process can be constructed, and a more secure and efficient software deployment environment can be built by using this software launcher.
[0202] In addition, since the security and efficiency during software deployment are improved by modifying the software launcher in this solution, this solution ensures the security and efficiency during the software deployment process without intruding on the business code of the software and without the awareness of business developers.
[0203] To better implement the above method, correspondingly, the embodiment of the present application also provides a software deployment device, where the software deployment device may be integrated in the server or the terminal.
[0204] For example, as Figure 16As shown, the software deployment device may include an acquisition unit 301, a determination unit 302, a modification unit 303, a generation unit 304, and a deployment unit 305, as follows:
[0205] The acquisition unit 301 may be configured to acquire the encrypted code data of the software and a software launcher, where the software launcher is used to assist in starting the software;
[0206] The determination unit 302 may be configured to determine the program security information during the operation of the software;
[0207] The modification unit 303 may be configured to modify the code parameter information corresponding to the program security information in the software launcher based on the program security information;
[0208] The generation unit 304 may be configured to generate software deployment data of the software according to the encrypted code data and the modified software launcher;
[0209] The deployment unit 305 may be configured to deploy the software on a target device according to the software deployment data.
[0210] In one embodiment, referring to Figure 17 , the program security information includes the program key security information of the software; the modification unit 303 may include:
[0211] The parameter generation subunit 3031 may be configured to generate key parameters required for deploying the software;
[0212] The first modification subunit 3032 may be configured to modify the code parameter information corresponding to the program key security information in the software launcher according to the key parameters.
[0213] In one embodiment, the parameter generation subunit 3031 may be configured to:
[0214] Acquire the original password information required for deploying the software; determine the encryption parameters of the original password information; encrypt the original password information according to the encryption parameters to obtain the key parameters required for deploying the software.
[0215] In one embodiment, referring to Figure 18 , the program security information includes the program detection security information of the software; the modification unit 303 may include:
[0216] The parameter determination subunit 3033 may be configured to determine the program detection parameters to be disabled in the software launcher based on the program detection security information;
[0217] The second modification subunit 3034 can be used to modify the code parameter information corresponding to the program detection security information in the software launcher according to the program detection parameters.
[0218] In one embodiment, referring to Figure 19 , the program security information includes the dependent data security information of the software; the modification unit 303 may include:
[0219] The first determination subunit 3035 can be used to determine the data encryption information of the dependent resource data of the software, where the data encryption information is generated based on the data storage directory and the data mounting directory of the dependent resource data, the data storage directory is used to store the dependent resource data, and the data mounting directory is used to mount the data storage directory;
[0220] The third modification subunit 3036 can be used to modify the code parameter information corresponding to the dependent data security information in the software launcher according to the data encryption information.
[0221] In one embodiment, referring to Figure 20 , the program security information includes the program time limit security information of the software; the modification unit 303 may include:
[0222] The second determination subunit 3037 can be used to determine the time limit inquiry cycle information of the software;
[0223] The fourth modification subunit 3038 can be used to modify the code parameters corresponding to the program time limit security information in the software launcher according to the time limit inquiry cycle information.
[0224] In one embodiment, referring to Figure 21 , the generation unit 304 may include:
[0225] The second acquisition subunit 3041 can be used to acquire the dependent resource data of the software;
[0226] The mirror generation subunit 3042 can be used to generate the basic mirror file of the software according to the dependent resource data;
[0227] The data generation subunit 3043 can be used to generate the software deployment data of the software according to the basic mirror file, the encrypted code data, and the modified software launcher.
[0228] In one embodiment, the mirror generation subunit 3042 can be used to:
[0229] Create a data storage directory and a data mounting directory for the dependent resource data, where the data storage directory is used to store the dependent resource data, and the data mounting directory is used to mount the data storage directory; mount the data storage directory to the data mounting directory; store the dependent resource data in the mounted data storage directory; generate a base image file of the software based on the storage result.
[0230] In one embodiment, the image generation subunit 3042 may specifically be used for:
[0231] If the storage result is successful storage, unmount the data storage directory; generate a base image file of the software based on the processing result.
[0232] In one embodiment, referring to Figure 22 , the obtaining unit 301 may include:
[0233] The plugin configuration subunit 3011 may be used to configure a software encryption plugin of the software in the configuration file of the software, where the software encryption plugin has software encryption instructions;
[0234] The software encryption subunit 3012 may be used to encrypt the software through the software encryption instructions;
[0235] The first obtaining subunit 3013 may be used to obtain the encrypted code data and the software launcher of the software based on the processing result.
[0236] In specific implementation, each of the above units may be implemented as an independent entity, or may be combined arbitrarily to be implemented as the same or several entities. For the specific implementation of each of the above units, reference may be made to the foregoing method embodiments, which will not be elaborated herein.
[0237] As can be seen from the above, in the software deployment device of this embodiment, the obtaining unit 301 obtains the encrypted code data and the software launcher of the software, where the software launcher is used to assist in starting the software; the determining unit 302 determines the program security information during the operation of the software; the modifying unit 303 modifies the code parameter information corresponding to the program security information in the software launcher based on the program security information; the generating unit 304 generates the software deployment data of the software according to the encrypted code data and the modified software launcher; the deploying unit 305 deploys the software on the target device according to the software deployment data.
[0238] When the software is deployed, the solution encrypts the software to obtain the encrypted code data of the software. Moreover, in this solution, through the software launcher of the software, the software is assisted to start during software deployment, which enables the modification of the corresponding code parameter information in the software launcher based on the program security information during the operation of the software, thereby improving the security and efficiency during software deployment. For example, for different program security information of the software, the software launcher can be correspondingly modified so that the modified software launcher can prevent and process the corresponding program security information. In this way, a software launcher that meets the diverse security requirements during software deployment can be constructed, and a more secure and efficient software deployment environment can be built by using this software launcher. In addition, since the security and efficiency during software deployment are improved by modifying the software launcher in this solution, this solution ensures the security and efficiency during software deployment without invading the business code of the software and without the awareness of business developers.
[0239] In addition, the embodiment of the present application further provides a computer device, which can be a device such as a server or a terminal. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. As Figure 23 shown, it shows a schematic structural diagram of the computer device involved in the embodiment of the present application. Specifically:
[0240] The computer device may include a memory 401 having one or more computer-readable storage media, an input unit 402, a processor 403 including one or more processing cores, and a power supply 404 and other components. Those skilled in the art can understand that Figure 23 the computer device structure shown in Figure 23 does not constitute a limitation on the computer device and may include more or fewer components than shown, or combine some components, or arrange different components. Among them:
[0241] The memory 401 can be used to store software programs and modules. The processor 403 executes various functional applications and data processing by running the software programs and modules stored in the memory 401. The memory 401 mainly includes a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, the image playback function, etc.); the data storage area can store the data created according to the use of the computer device (such as audio data, phone book, etc.). In addition, the memory 401 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory 401 can also include a memory controller to provide access to the memory 401 for the processor 403 and the input unit 402.
[0242] The input unit 402 can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function controls. Specifically, in a specific embodiment, the input unit 402 can include a touch-sensitive surface and other input devices. The touch-sensitive surface, also known as a touch display screen or a touchpad, can collect touch operations of the user on or near it (such as operations of the user using a finger, a stylus, or any suitable object or accessory on or near the touch-sensitive surface), and drive the corresponding connection device according to a pre-set program. Optionally, the touch-sensitive surface can include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the touch position of the user and detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into contact coordinates, and then sends it to the processor 403, and can receive and execute the commands sent by the processor 403. In addition, various types such as resistive, capacitive, infrared, and surface acoustic wave can be used to implement the touch-sensitive surface. In addition to the touch-sensitive surface, the input unit 402 can also include other input devices. Specifically, the other input devices can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, switch keys, etc.), trackballs, mice, joysticks, etc.
[0243] The processor 403 is the control center of the computer device, connecting various parts of the entire mobile phone through various interfaces and circuits. By running or executing software programs and / or modules stored in the memory 401, and by invoking the data stored in the memory 401, it executes various functions of the computer device and processes data. Optionally, the processor 403 may include one or more processing cores; preferably, the processor 403 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 403 either.
[0244] The computer device also includes a power supply 404 (such as a battery) for supplying power to each component. Preferably, the power supply can be logically connected to the processor 403 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The power supply 404 may also include any components such as one or more DC or AC power supplies, a recharge system, a power failure detection circuit, a power converter or inverter, and a power status indicator.
[0245] Although not shown, the computer device may also include a camera, a Bluetooth module, etc., which will not be elaborated here. Specifically, in this embodiment, the processor 403 in the computer device will load the executable files corresponding to the processes of one or more application programs into the memory 401 according to the following instructions, and the processor 403 will run the application programs stored in the memory 401 to realize various functions as follows:
[0246] Obtain the encrypted code data of the software and the software launcher, where the software launcher is used to assist in starting the software; determine the program security information during the operation of the software; based on the program security information, modify the code parameter information corresponding to the program security information in the software launcher; generate the software deployment data of the software according to the encrypted code data and the modified software launcher; deploy the software on the target device according to the software deployment data.
[0247] For the specific implementation of each of the above operations, reference can be made to the previous embodiments, which will not be elaborated here.
[0248] As can be seen from the above, when the computer device of this embodiment deploys software, it encrypts the software to obtain the encrypted code data of the software. Moreover, the computer device uses the software launcher of the software to assist in starting the software during software deployment, which enables the modification of the corresponding code parameter information in the software launcher based on the program security information during the operation of the software, thereby improving the security and efficiency during software deployment. For example, for different program security information of the software, the software launcher can be correspondingly modified so that the modified software launcher can prevent and process the corresponding program security information. In this way, a software launcher that meets the diverse security requirements during software deployment can be constructed, and a more secure and efficient software deployment environment can be built by using this software launcher. In addition, since the computer device improves the security and efficiency during software deployment by modifying the software launcher, the computer device ensures the security and efficiency during software deployment without intruding on the business code of the software and without the awareness of business developers.
[0249] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions or by controlling relevant hardware through instructions. These instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.
[0250] Therefore, an embodiment of the present application provides a storage medium that stores multiple instructions that can be loaded by a processor to execute the steps in any of the software deployment methods provided by the embodiments of the present application. For example, the instructions can perform the following steps:
[0251] Obtain the encrypted code data of the software and the software launcher, where the software launcher is used to assist in starting the software; determine the program security information of the software during operation; based on the program security information, modify the code parameter information corresponding to the program security information in the software launcher; generate the software deployment data of the software according to the encrypted code data and the modified software launcher; deploy the software on the target device according to the software deployment data.
[0252] For the specific implementation of each of the above operations, reference can be made to the previous embodiments and will not be elaborated here.
[0253] Among them, the storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.
[0254] Since the instructions stored in the storage medium can execute the steps in any of the software deployment methods provided in the embodiments of the present application, the beneficial effects achievable by any of the software deployment methods provided in the embodiments of the present application can be realized. For details, refer to the previous embodiments and will not be elaborated herein.
[0255] According to one aspect of the present application, there is provided a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in various alternative implementations of the above software deployment aspect.
[0256] The above has introduced in detail a software deployment method, apparatus, computer device, storage medium and computer program product provided in the embodiments of the present application. Specific examples are used herein to elaborate the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A software deployment method, comprising: Obtaining the encrypted code data of the software and a software launcher, wherein the software launcher is used to assist in starting the software; Determining the program security information during the operation of the software; Based on the program security information, modifying the code parameter information corresponding to the program security information in the software launcher; Generating software deployment data of the software according to the encrypted code data and the modified software launcher; Deploying the software on a target device according to the software deployment data; The program security information includes the dependent data security information of the software; based on the program security information, modifying the code parameter information corresponding to the program security information in the software launcher includes: Determining the data encryption information of the dependent resource data of the software, wherein the data encryption information is generated based on the data storage directory and the data mounting directory of the dependent resource data, the data storage directory is used to store the dependent resource data, and the data mounting directory is used to mount the data storage directory; According to the data encryption information, modifying the code parameter information corresponding to the dependent data security information in the software launcher.
2. The software deployment method according to claim 1, wherein The program security information includes the program key security information of the software; Based on the program security information, modifying the code parameter information corresponding to the program security information in the software launcher includes: Generating key parameters required for deploying the software; According to the key parameters, modifying the code parameter information corresponding to the program key security information in the software launcher.
3. The software deployment method according to claim 2, characterized in that, Generating key parameters required for deploying the software includes: Obtaining the original password information required for deploying the software; Determining the encryption parameters of the original password information; According to the encryption parameters, encrypting the original password information to obtain the key parameters required for deploying the software.
4. The software deployment method according to claim 1, characterized in that, The program security information includes the program detection security information of the software; Based on the program security information, modifying the code parameter information corresponding to the program security information in the software launcher includes: Based on the program detection security information, determining the program detection parameters to be disabled in the software launcher; According to the program detection parameters, modifying the code parameter information corresponding to the program detection security information in the software launcher.
5. The software deployment method according to claim 1, wherein The program security information includes the program time limit security information of the software; Based on the program security information, modifying the code parameter information corresponding to the program security information in the software launcher includes: Determining the time limit inquiry cycle information of the software; According to the time limit inquiry cycle information, modifying the code parameters corresponding to the program time limit security information in the software launcher.
6. The software deployment method according to claim 1, wherein Generating software deployment data of the software according to the encrypted code data and the modified software launcher includes: Obtaining the dependent resource data of the software; Generating a base image file of the software according to the dependent resource data; Generate the software deployment data of the software according to the base image file, the encrypted code data, and the modified software launcher.
7. The software deployment method according to claim 6, wherein Generate the base image file of the software according to the dependency resource data, including: Create a data storage directory and a data mounting directory for the dependency resource data, where the data storage directory is used to store the dependency resource data, and the data mounting directory is used to mount the data storage directory; Mount the data storage directory to the data mounting directory; Store the dependency resource data in the mounted data storage directory; Generate the base image file of the software based on the storage result.
8. The software deployment method according to claim 7, wherein Generate the base image file of the software based on the storage result, including: If the storage result is successful storage, unmount the data storage directory; Generate the base image file of the software based on the processing result.
9. The software deployment method according to claim 1, wherein Obtain the encrypted code data and the software launcher of the software, including: Configure a software encryption plugin for the software in the configuration file of the software, where the software encryption plugin has software encryption instructions; Perform an encryption process on the software through the software encryption instructions; Obtain the encrypted code data and the software launcher of the software based on the processing result.
10. A software deployment device, characterized in that, Including: An obtaining unit, configured to obtain the encrypted code data and the software launcher of the software, where the software launcher is used to assist in starting the software; A determining unit, configured to determine the program security information during the operation of the software; A modifying unit, configured to modify the code parameter information corresponding to the program security information in the software launcher based on the program security information; A generating unit, configured to generate the software deployment data of the software according to the encrypted code data and the modified software launcher; A deploying unit, configured to deploy the software on a target device according to the software deployment data; The program security information includes the dependency data security information of the software; the modifying unit includes: A first determining subunit, configured to determine the data encryption information of the dependency resource data of the software, where the data encryption information is generated based on the data storage directory and the data mounting directory of the dependency resource data, the data storage directory is used to store the dependency resource data, and the data mounting directory is used to mount the data storage directory; A third modifying subunit, configured to modify the code parameter information corresponding to the dependency data security information in the software launcher according to the data encryption information.
11. An electronic device, characterized in that, Including a memory and a processor; the memory stores an application program, and the processor is configured to run the application program in the memory to execute the operations in the software deployment method according to any one of claims 1 to 9.
12. A storage medium, characterized in that, The storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the software deployment method according to any one of claims 1 to 9.
13. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, the steps in the software deployment method according to any one of claims 1 to 9 are implemented.