Front-end code processing method and device

By generating a secondary key and combining version number checksum deep obfuscation technology, the problem of easy leakage of front-end code keys is solved, the balance of security and performance is improved, the risk of key exposure is reduced, and the user experience is improved.

CN114826556BActive Publication Date: 2025-07-22WIRELESS LIFE (HANGZHOU) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210238914.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-11
Publication Date
2025-07-22
Estimated Expiration
2042-03-11

AI Technical Summary

Technical Problem

In the prior art, the keys of the front-end code are easily leaked in the browser, and existing encryption methods are difficult to balance between security and performance, especially the security of AES keys and the risk issues during transmission.

Method used

The method of generating a secondary key is adopted, and the real key is converted into a secondary key through a preset algorithm, and version number verification is introduced in the front-end code, and the front-end code files available to the browser are generated in combination with deep obfuscation technology.

Benefits of technology

It effectively reduces the risk of key exposure, improves cracking difficulty, shortens the time-consuming of the encryption process, improves the page response speed, ensures that the key can be updated in time when it is broken, and reduces losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114826556B_ABST
    Figure CN114826556B_ABST
Patent Text Reader

Abstract

The present invention relates to a front-end code processing method and apparatus for reducing the risk of key exposure. The method includes: obtaining a secondary key, where the secondary key is generated according to a true key and a preset algorithm; introducing the secondary key into the front-end code, and decrypting the secondary key according to the preset algorithm to obtain the true key and a version number; if the version number verification passes, encrypting the information to be encrypted in the front-end code according to the true key; and deeply obfuscating the front-end code to generate a front-end code file for use by a browser.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of front-end technologies, and particularly to a front-end code processing method and apparatus. Background Art

[0002] Since front-end code is executed in the client's browser and is in a public state, anyone can obtain the front-end code through the browser's developer tools, resulting in the possible leakage of any private information contained in the front-end code. Therefore, in some scenarios, encryption needs to be adopted in the front-end to enhance data security. For the balance between security and performance, the industry usually adopts the AES (Advanced Encryption Standard) encryption algorithm. However, how to improve the security of the AES key is the key to ensuring front-end encryption security. The industry usually has the following methods:

[0003] Obtain the key from the server through an interface request. The essence of this method is to store the key on the server and obtain it from the server when needed. The advantage of this method is that it ensures the security of key storage. At the same time, each time the key is obtained, the server can generate a new key for distribution to ensure that the key is updated at any time. However, the disadvantages are also obvious. First, although server storage ensures the security of key storage, there is still a risk of leakage during the key transmission process. An attacker can easily obtain the key sent by the interface through the browser's developer debugging tools. Second, obtaining the key from the server will block the encryption process. The client must wait for the interface to be successfully sent before encrypting. In many scenarios with high timeliness requirements, it will reduce the page response speed and affect the user experience.

[0004] Store the key in the local client cache, such as cookie (data stored on the user's local terminal), localstorage (local storage), etc. The advantage of this method is that it does not block the encryption process and can be retrieved as needed. However, the disadvantages are also relatively obvious. An attacker can relatively easily obtain the key from the cache, and it is also more troublesome to update the key, which requires modifying the client code and republishing.

[0005] Store the key in the obfuscated and compressed code of the client. The usual approach is to directly write the key in the front-end code and then obfuscate and compress the front-end code. In this way, an attacker must debug or analyze the front-end code to find the key in the obfuscated and compressed code. However, this method only relatively increases the cost of cracking the key. An attacker familiar with the browser developer tools can still relatively easily obtain the key. Summary of the Invention

[0006] To overcome the problems existing in the related art, embodiments of the present disclosure provide a front-end code processing method and apparatus. The technical solutions are as follows:

[0007] According to the first aspect of the embodiments of the present disclosure, a front-end code processing method is provided, including:

[0008] Obtain a secondary key, where the secondary key is generated according to a real key and a preset algorithm;

[0009] Introduce the secondary key into the front-end code, and decrypt the secondary key according to the preset algorithm to obtain the real key and the version number;

[0010] If the version number verification passes, encrypt the information to be encrypted in the front-end code according to the real key;

[0011] Deeply obfuscate the front-end code to generate a front-end code file for use by the browser.

[0012] In one embodiment, generating a secondary key according to a real key and a preset algorithm includes:

[0013] Generate multiple obfuscation keys according to the real key and form an obfuscation key array, where each obfuscation key is a string composed of the same character set as the real key and has the same length as the real key;

[0014] Randomly insert the real key into the obfuscation key array, and record the position of the real key in the obfuscation key array as the first insertion position;

[0015] Insert the preset key version number into the obfuscation key array, and record the position of the key version number in the obfuscation key array as the second insertion position;

[0016] Insert the first insertion position and the second insertion position into a preset position of the obfuscation key array;

[0017] Convert the obfuscation key array into a string in a preset manner;

[0018] Encrypt the string using a preset encryption algorithm to obtain the secondary key.

[0019] In one embodiment, inserting the first insertion position and the second insertion position into a preset position of the obfuscation key array includes inserting the first insertion position and the second insertion position at the end of the obfuscation key array.

[0020] In one embodiment, the module for generating the secondary key is independent of the front-end code, and the front-end code introduces the decryption module for decrypting the secondary key to obtain the real key as a dependency.

[0021] According to the second aspect of the embodiments of the present disclosure, a front-end code processing device is provided, including:

[0022] An acquisition module for acquiring a secondary key, where the secondary key is generated according to a real key and a preset algorithm;

[0023] A decryption module for introducing the secondary key into the front-end code and decrypting the secondary key according to the preset algorithm to obtain the real key and the version number;

[0024] An encryption module for encrypting the front-end code according to the real key if the version number verification passes;

[0025] A confusion module for deeply confusing the front-end code to generate a front-end code file for use by the browser.

[0026] In one embodiment, the apparatus further includes: a generation module for generating a secondary key according to a real key and a preset algorithm, including:

[0027] Generating a plurality of confusion keys based on the real key and forming a confusion key array, where each confusion key is a string composed of the same character set as the real key and has the same length as the real key;

[0028] Randomly inserting the real key into the confusion key array and recording the position of the real key in the confusion key array as the first insertion position;

[0029] Inserting a preset key version number into the confusion key array and recording the position of the key version number in the confusion key array as the second insertion position;

[0030] Inserting the first insertion position and the second insertion position into a preset position of the confusion key array;

[0031] Converting the confusion key array into a string in a preset manner;

[0032] Encrypting the string using a preset encryption algorithm to obtain the secondary key.

[0033] In one embodiment, inserting the first insertion position and the second insertion position into a preset position of the confusion key array includes inserting the first insertion position and the second insertion position at the end of the confusion key array.

[0034] In one embodiment, the module for generating the secondary key is independent of the front-end code, and the front-end code introduces the decryption module for decrypting the secondary key to obtain the real key as a dependency.

[0035] According to a third aspect of the embodiments of the present disclosure, there is provided a front-end code processing apparatus, characterized by including:

[0036] A processor;

[0037] A memory for storing processor-executable instructions;

[0038] Wherein, the processor is configured to:

[0039] Obtain a secondary key, wherein the secondary key is generated according to a real key and a preset algorithm;

[0040] Decrypt the secondary key according to the preset algorithm to obtain the real key and the version number;

[0041] If the version number verification passes, encrypt the front-end code according to the real key;

[0042] Deeply obfuscate the front-end code to generate a front-end code file for use by the browser.

[0043] According to a fourth aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium having computer instructions stored thereon, characterized in that when the instructions are executed by a processor, the steps of any one of the methods in the first aspect of the embodiments of the present disclosure are implemented.

[0044] In the technical solutions provided by the embodiments of the present disclosure, the time-consuming of asynchronous requests is avoided, which greatly shortens the time to obtain data from the backend in the scenario of interface request encryption, improves the overall response speed of the page and the user experience, and also avoids the risk of the key being cracked during transmission; the problems of easy key leakage and difficult update caused by local caching are avoided; by introducing the "secondary key", the risk of key exposure is further reduced and the cracking difficulty is improved. Even if an attacker finally obtains the key through debugging, the key is a processed "secondary key" and cannot be directly used. At the same time, through the version verification of the key, it can be ensured that once the key is compromised, the key can be updated in time, and the key version and key generation algorithm can be upgraded, making the exposed key completely invalid and reducing the losses caused by key exposure.

[0045] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure and used together with the specification to explain the principles of the present disclosure.

[0047] Figure 1 is a flowchart of a front-end code processing method shown according to an exemplary embodiment;

[0048] Figure 2 is a flowchart of a front-end code processing method shown according to an exemplary embodiment;

[0049] Figure 3It is a flowchart of a front - end code processing method shown according to an exemplary embodiment;

[0050] Figure 4 It is a block diagram of a front - end code processing device shown according to an exemplary embodiment;

[0051] Figure 5 It is a block diagram of a front - end code processing device shown according to an exemplary embodiment;

[0052] Figure 6 It is a block diagram of a front - end code processing device shown according to an exemplary embodiment. Detailed implementation

[0053] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0054] Regarding the encryption key of the front - end code, currently in the industry, generally: obtain the key from the server through an interface request; store the key in the local client cache; or store the key in the obfuscated and compressed code of the client. However, none of the above - mentioned methods for processing the encryption key can ensure the security of the key. Embodiments of the present invention provide a front - end code processing method to improve this situation.

[0055] Embodiments of the present invention provide a front - end code processing method, as Figure 1 shown, including the following steps 101 to 104:

[0056] In step 101, obtain a secondary key, where the secondary key is generated according to a real key and a preset algorithm.

[0057] In this embodiment, when developers process the front - end code, they need to obtain a key to encrypt the information to be encrypted in the front - end code. Here, the information to be encrypted is some key information during the code running process, such as the request parameters of an http request, the private information of users, etc. The secondary key can be generated by a generation module independent of the business code according to the real key and the preset algorithm, that is, it is not the real key. The input of this generation module is the real secret key, and then it encrypts the real secret key and outputs the secondary secret key for use. Here, making the module that generates the secondary key independent of the business makes it impossible for attackers to crack the encryption logic of the secondary secret key through the business code.

[0058] In step 102, the secondary key is introduced into the front-end code, and the real key and version number are obtained by decrypting the secondary key according to a preset algorithm.

[0059] Exemplarily, if the secondary key is generated according to the real key and a preset encryption algorithm, then to obtain the real key, the inverse operation of the preset encryption algorithm can be used. In this embodiment, a version number is also added to the secondary key. After decrypting to obtain the real key and version number, the version number can be verified first. The correct version number is built into the decryption module part in the front-end code, and the version number obtained after decrypting the secondary key should be the same as the version number built into the decryption module. Only when the verification passes and it is confirmed that the version number is legal, the secondary key is valid and can be used to encrypt the information to be encrypted in the front-end code. This can ensure that once the key is compromised, the key can be updated in time, and the key version and key generation algorithm can be upgraded, making the exposed key completely invalid and reducing the losses caused by key exposure.

[0060] In step 103, if the version number verification passes, the information to be encrypted in the front-end code is encrypted according to the real key.

[0061] Exemplarily, in this embodiment, the AES encryption algorithm is used to encrypt the front-end code.

[0062] In step 104, the front-end code is deeply obfuscated to generate a front-end code file for use by the browser.

[0063] At this time, the secondary key has been introduced into the front-end code, and the information to be encrypted in the front-end code has been encrypted. When the current front-end code file is deeply obfuscated, the secondary key is also obfuscated. In one embodiment, the tool javascript-obfuscator (a JavaScript code obfuscation tool) can be used for code obfuscation. The obfuscation of javascript-obfuscator is relatively complex and thorough, including slicing and storing strings separately, injecting useless code for logical obfuscation, flattening the code structure, injecting anti-debugging debugger, etc. It can greatly improve the unreadability and non-debuggability of the code, and at the same time make the reverse recovery of the obfuscated code more difficult.

[0064] In the technical solution provided by the embodiments of the present disclosure, compared with the solution of obtaining the key in real time through a network request, the solution proposed in this application first avoids the time-consuming of asynchronous requests, which greatly shortens the time to obtain data from the backend in the scenario of interface request encryption, improves the overall response speed of the page and the user experience. Secondly, it also avoids the risk of the key being cracked during the transmission process. Compared with the solution of storing the key in the local client cache, the solution proposed in this application avoids the problems of easy key leakage and difficult update in the local cache. Compared with the solution of directly storing the real key in the front-end code, the solution proposed in this application further reduces the risk of key exposure and improves the difficulty of cracking by introducing a "secondary key". Even if the attacker finally obtains the key through debugging, the key is a processed "secondary key" and cannot be used directly. At the same time, through the version verification of the key, it can be ensured that once the key is broken, the key can be updated in time, and the key version and key generation algorithm can be upgraded, so that the exposed key becomes completely invalid and the loss caused by key exposure is reduced. In addition, through deep code obfuscation, compared with the traditional obfuscation methods in the industry, the obfuscated code of this solution is more reliable and secure, greatly increasing the attack cost, so that most attackers can retreat in the face of difficulties. The solution proposed in this application greatly improves the security of the front-end AES key storage and takes into account the page performance, achieving a good balance between security and performance.

[0065] The implementation process is introduced in detail below through embodiments.

[0066] The generation of the secondary key in step 101 can be performed in the generation module, independent of the business code. The method for generating the secondary key may include the following steps A1-A6:

[0067] Step A1, generate multiple obfuscated keys according to the real key and form an obfuscated key array, where each obfuscated key is a string composed of the same character set as the real key and has the same length as the real key.

[0068] As Figure 2 shown is a schematic diagram of generating the secondary key. First, generate obfuscated keys according to the real key. The so-called "obfuscated key" is a string with the same length and the same character set as the real key, and this string is randomly generated. From the appearance characteristics, it has no difference from the real key. Multiple obfuscated keys can be generated at one time: obfuscated key 1, obfuscated key 2,..., obfuscated key n, and multiple obfuscated keys form an obfuscated array A.

[0069] Step A2, randomly insert the real key into the obfuscated key array, and record the position of the real key in the obfuscated key array as the first insertion position.

[0070] As Figure 2As shown, the real key is randomly inserted into the obfuscated key array A, and the insertion position P1 is remembered.

[0071] Step A3, insert the preset key version number into the obfuscated key array, and record the position of the key version number in the obfuscated key array as the second insertion position.

[0072] As Figure 2 shown, a version concept is added to the key obfuscation algorithm, the version number at this time is inserted into the obfuscated key array A, and the insertion position P2 is remembered.

[0073] Step A4, insert the first insertion position and the second insertion position into the preset position of the obfuscated key array.

[0074] As Figure 2 shown, insert the positions P1 and P2 to the end of the obfuscated key group array A.

[0075] Step A5, convert the obfuscated key array into a string in a preset manner.

[0076] As Figure 2 shown, the preset manner is, for example, a specific conversion rule. According to the conversion rule, convert the obfuscated key array A into a string B. An appropriate conversion rule can be selected according to needs, as long as the conversion rule can splice the key array into a string in a specific way (algorithm) and can restore each component of the original array from the string.

[0077] Step A6, encrypt the string using a preset encryption algorithm to obtain a secondary key.

[0078] As Figure 2 shown, use the ABS encryption algorithm to encrypt the string B to generate a secondary key.

[0079] So far, the generation module has generated a secondary key with a version number. When processing the front-end code, the secondary key can be applied for from the generation module.

[0080] In one embodiment, as Figure 3 shown, the processing method for encrypting the front-end code may include the following steps 301-305:

[0081] Step 301, apply for a secondary key from the generation module. Among them, the generation module generates a secondary key according to a preset algorithm.

[0082] Step 302, perform reverse decryption on the secondary key according to the above preset algorithm to obtain the real key and the version number respectively.

[0083] In one embodiment, the front-end code can also introduce the decryption module for decrypting the secondary key as a dependency.

[0084] Step 303: Verify the version number.

[0085] Step 304: Determine whether the version number is legal. If not, end the process. If so, execute step 305.

[0086] Step 305: Use the real key to encrypt the data that needs to be encrypted in the front-end code.

[0087] So far, the encryption process of the front-end code is completed. At this time, the secondary key is introduced into the front-end code, and the key data has been encrypted. Subsequently, the front-end code can be deeply obfuscated to generate a front-end code file for use by the browser. In this way, only the secondary key is stored in the business, and for example, the "secondary key" is sliced and stored. When in use, first assemble the slices, and then perform reverse decryption according to the corresponding encryption process to obtain the real key and then perform business encryption. The decryption code is hidden through deep obfuscation, greatly increasing the difficulty of cracking. In addition, the secondary encryption process for the key is independent of the business code, and the business code introduces the decryption module as a dependency, which can upgrade and update the key encryption algorithm at any time. For example, the key can be upgraded every fixed period to further ensure the security of key storage.

[0088] The following is an embodiment of the apparatus of the present disclosure, which can be used to execute the method embodiment of the present disclosure.

[0089] Figure 4 It is a block diagram of a front-end code processing apparatus shown according to an exemplary embodiment. The front-end construction apparatus can be a server or a part of a server, or can be a terminal or a part of a terminal. The front-end construction apparatus can be implemented as part or all of an electronic device through software, hardware, or a combination of both. As Figure 4 shown, the front-end code processing apparatus includes:

[0090] An acquisition module 401, configured to acquire a secondary key, where the secondary key is generated according to a real key and a preset algorithm;

[0091] A decryption module 402, configured to introduce the secondary key into the front-end code and decrypt the secondary key according to the preset algorithm to obtain a real key and a version number;

[0092] An encryption module 403, configured to encrypt the front-end code according to the real key if the version number verification passes;

[0093] An obfuscation module 404, configured to deeply obfuscate the front-end code to generate a front-end code file for use by the browser.

[0094] In one embodiment, the device further includes: a generation module, configured to generate a secondary key according to a real key and a preset algorithm, including:

[0095] Generating a plurality of obfuscated keys based on the real key and forming an obfuscated key array, wherein each obfuscated key is a string composed of the same character set as the real key and has the same length as the real key;

[0096] Randomly inserting the real key into the obfuscated key array, and recording the position of the real key in the obfuscated key array as the first insertion position;

[0097] Inserting a preset key version number into the obfuscated key array, and recording the position of the key version number in the obfuscated key array as the second insertion position;

[0098] Inserting the first insertion position and the second insertion position into a preset position of the obfuscated key array;

[0099] Converting the obfuscated key array into a string in a preset manner;

[0100] Encrypting the string using a preset encryption algorithm to obtain a secondary key.

[0101] In one embodiment, inserting the first insertion position and the second insertion position into a preset position of the obfuscated key array includes inserting the first insertion position and the second insertion position at the end of the obfuscated key array.

[0102] In one embodiment, the module for generating the secondary key is independent of the front-end code, and the front-end code introduces as a dependency the decryption module that decrypts the secondary key to obtain the real key.

[0103] Figure 5 FIG. 50 is a block diagram of a front-end code processing device according to an exemplary embodiment. The front-end construction device may be a server or a part of a server, or may be a terminal or a part of a terminal. The front-end code processing device includes:

[0104] A processor 501;

[0105] A memory 502 for storing executable instructions of the processor 501;

[0106] Wherein, the processor 501 is configured to:

[0107] Obtain a secondary key, wherein the secondary key is generated according to a real key and a preset algorithm;

[0108] Introduce the secondary key into the front-end code, and decrypt the secondary key according to the preset algorithm to obtain the real key and the version number;

[0109] If the version number verification passes, encrypt the information to be encrypted in the front-end code using the real key;

[0110] Deeply obfuscate the front-end code to generate a front-end code file for use by the browser.

[0111] Figure 6 FIG. 7 is a block diagram of a front-end code processing apparatus 600 according to an exemplary embodiment. The apparatus can be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0112] The apparatus may include one or more of the following components: a processing component 602, a memory 604, a power supply component 606, a multimedia component 608, an audio component 610, an input / output (I / O) interface 612, a sensor component 614, and a communication component 616.

[0113] The processing component 602 generally controls the overall operation of the apparatus 600, such as operations associated with display, telephone calls, data communication, camera operations, and recording operations. The processing element 502 may include one or more processors 620 to execute instructions to complete all or part of the steps of the above-described method. In addition, the processing component 602 may include one or more modules to facilitate interaction between the processing component 602 and other components. For example, the processing component 602 may include a multimedia module to facilitate interaction between the multimedia component 508 and the processing component 602.

[0114] The memory 604 is configured to store various types of data to support the operation of the apparatus 600. Examples of such data include instructions for any application or method operating on the apparatus 600, contact data, phone book data, messages, pictures, videos, etc. The memory 604 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0115] The power supply component 606 provides power to various components of the apparatus 600. The power supply component 606 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the apparatus 600.

[0116] The multimedia component 608 includes a screen that provides an output interface between the device 600 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of the touch or swipe actions but also detect the duration and pressure associated with the touch or swipe operation. In some embodiments, the multimedia component 608 includes a front camera and / or a rear camera. When the device 600 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0117] The audio component 610 is configured to output and / or input audio signals. For example, the audio component 610 includes a microphone (MIC) that is configured to receive external audio signals when the device 600 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 604 or transmitted via the communication component 616. In some embodiments, the audio component 610 further includes a speaker for outputting audio signals.

[0118] The I / O interface 612 provides an interface between the processing component 602 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, etc. These buttons can include, but are not limited to: a home button, a volume button, a power button, and a lock button.

[0119] The sensor component 614 includes one or more sensors for providing an assessment of the state of the device 600 in various aspects. For example, the sensor component 614 can detect the on / off state of the device 600, the relative positioning of components, such as the display and the keypad of the device 600. The sensor component 614 can also detect a change in the position of the device 600 or a component of the device 600, the presence or absence of user contact with the device 600, the orientation or acceleration / deceleration of the device 600, and the temperature change of the device 600. The sensor component 614 can include a proximity sensor that is configured to detect the presence of nearby objects without any physical contact. The sensor component 614 can also include a light sensor, such as a CMOS or a CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 514 can also include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0120] The communication component 616 is configured to facilitate communication between the device 600 and other devices in a wired or wireless manner. The device 600 can access a communication standard-based wireless network, such as a walkie-talkie private network, WiFi, 2G, 3G, 4G, or 5G, or a combination thereof. In an exemplary embodiment, the communication component 616 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 616 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0121] In an exemplary embodiment, the device 600 can be implemented by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above method.

[0122] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 604 including instructions, and the above instructions can be executed by a processor 620 of the device 600 to complete the above method. For example, the non-transitory computer-readable storage medium can be a ROM, Random Access Memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0123] A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of the device 600, enables the device 600 to execute the above front-end code processing method, and the method includes:

[0124] Obtain a secondary key, where the secondary key is generated according to a real key and a preset algorithm;

[0125] Introduce the secondary key into the front-end code, and decrypt the secondary key according to the preset algorithm to obtain the real key and the version number;

[0126] If the version number verification passes, encrypt the information to be encrypted in the front-end code according to the real key;

[0127] Perform deep obfuscation on the front-end code to generate a front-end code file for use by the browser.

[0128] Other embodiments of the present disclosure will be readily apparent to those skilled in the art in view of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common general knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are only to be considered exemplary, and the true scope and spirit of the present disclosure are indicated by the following claims.

[0129] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A front-end code processing method, characterized in that, including: Obtain a secondary key, where the secondary key is generated according to a real key and a preset algorithm; Introduce the secondary key into the front-end code, and decrypt the secondary key according to the preset algorithm to obtain the real key and the version number; If the version number verification passes, encrypt the information to be encrypted in the front-end code according to the real key; Deeply obfuscate the front-end code to generate a front-end code file for use by the browser; Generate a secondary key according to the real key and the preset algorithm, including: Generate multiple obfuscation keys according to the real key and form an obfuscation key array, where each obfuscation key is a string composed of the same character set as the real key and has the same length as the real key; Randomly insert the real key into the obfuscation key array, and record the position of the real key in the obfuscation key array as the first insertion position; Insert the preset key version number into the obfuscation key array, and record the position of the key version number in the obfuscation key array as the second insertion position; Insert the first insertion position and the second insertion position into a preset position in the obfuscation key array; Convert the obfuscation key array into a string in a preset manner; Encrypt the string using a preset encryption algorithm to obtain the secondary key.

2. The method according to claim 1, wherein Insert the first insertion position and the second insertion position into a preset position in the obfuscation key array, including inserting the first insertion position and the second insertion position at the end of the obfuscation key array.

3. The method according to claim 1, wherein where The module for generating the secondary key is independent of the front-end code, and the front-end code introduces the decryption module for decrypting the secondary key to obtain the real key as a dependency.

4. A front-end code processing device, characterized in that, including: An acquisition module for obtaining a secondary key, where the secondary key is generated according to a real key and a preset algorithm; A decryption module for introducing the secondary key into the front-end code and decrypting the secondary key according to the preset algorithm to obtain the real key and the version number; An encryption module for encrypting the front-end code according to the real key if the version number verification passes; An obfuscation module for deeply obfuscating the front-end code to generate a front-end code file for use by the browser; The device further includes: a generation module for generating a secondary key according to the real key and the preset algorithm: Generate multiple obfuscation keys according to the real key and form an obfuscation key array, where each obfuscation key is a string composed of the same character set as the real key and has the same length as the real key; Randomly insert the real key into the obfuscation key array, and record the position of the real key in the obfuscation key array as the first insertion position; Insert the preset key version number into the obfuscation key array, and record the position of the key version number in the obfuscation key array as the second insertion position; Insert the first insertion position and the second insertion position into a preset position in the obfuscation key array; Convert the obfuscation key array into a string in a preset manner; Encrypt the string using a preset encryption algorithm to obtain the secondary key.

5. The device according to claim 4, characterized in that, Insert the first insertion position and the second insertion position into a preset position in the obfuscation key array, including inserting the first insertion position and the second insertion position at the end of the obfuscation key array.

6. The device according to claim 4, characterized in that, where The module for generating the secondary key is independent of the front-end code, and the front-end code introduces as a dependency the decryption module that decrypts the secondary key to obtain the real key.

7. A front-end code processing device, characterized in that, It includes: A processor; A memory for storing the executable instructions of the processor; Wherein, the processor is configured to: Obtain a secondary key, wherein the secondary key is generated according to a real key and a preset algorithm; Decrypt the secondary key according to the preset algorithm to obtain the real key and the version number; If the version number verification passes, encrypt the front-end code according to the real key; Deeply obfuscate the front-end code to generate a front-end code file for use by the browser; The device further includes: a generation module for generating a secondary key according to a real key and a preset algorithm: Generate multiple obfuscation keys based on the real key and form an obfuscation key array, wherein each obfuscation key is a string composed of the same character set as the real key and has the same length as the real key; Randomly insert the real key into the obfuscation key array, and record the position of the real key in the obfuscation key array as the first insertion position; Insert the preset key version number into the obfuscation key array, and record the position of the key version number in the obfuscation key array as the second insertion position; Insert the first insertion position and the second insertion position into a preset position of the obfuscation key array; Convert the obfuscation key array into a string in a preset manner; Encrypt the string using a preset encryption algorithm to obtain the secondary key.

8. A computer-readable storage medium having computer instructions stored thereon, characterized in that, When the instruction is executed by the processor, the steps of the method according to any one of claims 1-3 are implemented.

Citation Information

Patent Citations

  • Methods and systems for migrating content licenses

    CN102457522A

  • File protection method and device

    CN112532379A