A method, device, equipment and storage medium for protecting program core code
The method of filling data with state machine tags and empty thread events solves the problem that the core code of Windows client programs is easily stolen, achieving higher security and concealment.
Patent Information
- Application Number
- CN202110156663.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-02-04
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-02-04
AI Technical Summary
Existing Windows client programs publish the program's core code to all end user devices, resulting in low program security and easy to be acquired and exploited by hackers.
The state data of the loading module is marked by a state machine, and by creating an empty thread event, state machine data filling is realized to form verification or encrypted data. The thread creation event is irreversible, thus protecting the program core code.
It realizes effective protection of program core code, ensuring that only by loading modules in a list of preset loading order can the program core code be compiled correctly, improving security and concealment.
Smart Images

Figure CN114861137B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to a method, apparatus, device and storage medium for protecting program core code. Background Art
[0002] In the existing technology, Windows client programs will publish the core code of the program, that is, the assembly code of the core function, to all terminal user devices, such as publishing the assembly code of the program's data decryption function or the core algorithm of the core function to all terminals. This makes the program less secure.
[0003] With regard to the above-mentioned problems of Windows client programs, some programmers, especially hackers, may obtain the assembly code of the core code of the calling program, which may bring adverse effects.
[0004] Therefore, we can see that a solution is needed to protect the core code and prevent it from being called. Summary of the invention
[0005] An embodiment of the present invention provides a method for protecting the core code of a program, which utilizes a state machine to mark the state data of a loading module, and implements state machine data filling by creating an empty thread event, thereby forming verification or encryption data. The thread creation event is irreversible, thereby implementing the protection of the core code of the program.
[0006] In a first aspect, an embodiment of the present invention provides a method for protecting a program core code, comprising:
[0007] Marking the loading state of any loading module by the state machine to obtain the state machine data matrix of the loading module;
[0008] By creating an empty thread event, the state machine data matrix is filled into the loading module according to the module loading order of the main program, and the state machine data matrix of any loading module is stored in the core module;
[0009] Transforming the state machine data matrix in the loading module into matrix result data, and converting the matrix result data into one-dimensional array result data;
[0010] The one-dimensional array result data is embedded into the program core code as key data and / or seed data of the random algorithm to perform data verification or encryption, thereby completing the protection of the program core code.
[0011] Preferably, the creation of the state machine data matrix of the loading module specifically includes:
[0012] Get any loaded module of the main program;
[0013] And establishing a loading order list according to the loading order of the loading modules;
[0014] Establish a state machine and use a two-dimensional array matrix to represent the data of the state machine;
[0015] The two-dimensional array matrix is a two-dimensional array of N rows and N columns, and N is the number of loaded modules.
[0016] Preferably, filling the state machine data matrix into the loading module specifically includes:
[0017] Initializing the two-dimensional array matrix to a zero matrix;
[0018] Add a function export interface in any load module to pass the state machine data matrix to other load modules;
[0019] Added an empty thread creation event;
[0020] Filling the data of the two-dimensional array matrix according to the loading order of the loading order list;
[0021] And the data of the two-dimensional array matrix is set into the core module through the function export interface.
[0022] Preferably, adding an empty thread creation event specifically includes:
[0023] The main program traverses any thread in the process and pauses the thread;
[0024] By modifying the dllmain function of the module, an empty thread is created, wherein the empty thread is an empty function logic, so that the assignment of state machine data and the formation of a transfer order between loaded modules are completed; wherein the transfer order is the module loading order;
[0025] Execute the empty thread, traverse the current loading modules, obtain the handles of the loading modules, and disable the thread creation event for each loading module by calling the system function;
[0026] The main program iterates over the threads and resumes the execution of the threads.
[0027] Preferably, the acquisition of the matrix result data specifically includes:
[0028] Get the state machine data matrix of each loaded module in the core module;
[0029] Sorting the state machine data matrix of the loading module according to the loading order to obtain the state machine data matrix of the N-bit loading modules arranged in sequence;
[0030] Multiplying the state machine data matrix of the Nth loading module with the N-1th product data to obtain the Nth product data;
[0031] Multiply N product data to obtain a product matrix as matrix result data;
[0032] Wherein, N is the number of loading modules, and the first product data is the state machine data matrix of the first loading module.
[0033] Preferably, converting the matrix result data into one-dimensional array result data specifically includes:
[0034] Obtaining each row of data of the product matrix;
[0035] And concatenate and arrange them in row order to obtain string data;
[0036] The string data is converted into a one-dimensional array result data.
[0037] Preferably, the string data is complicated by a hash algorithm.
[0038] In a second aspect, an embodiment of the present invention provides a device for protecting a program core code, comprising:
[0039] An acquisition unit, used for marking the loading state of any loading module through a state machine to obtain a state machine data matrix of the loading module;
[0040] A filling unit, used to fill the state machine data matrix into the loading module according to the module loading order of the main program by creating an empty thread event, and store the state machine data matrix of any loading module in the core module;
[0041] A conversion unit, which is used to convert the state machine data matrix into matrix result data in the core module; and convert the matrix result data into one-dimensional array result data;
[0042] The encryption unit is used to embed the one-dimensional array result data as key data and / or seed data of the random algorithm into the program core code to perform data verification or encryption to complete the protection of the program core code.
[0043] In a third aspect, an embodiment of the present invention provides an electronic device, comprising an application processor and a memory, wherein the processor is used to implement the steps of the method for protecting the core code of the program as described above when a computer management program is stored in the memory.
[0044] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium on which a computer management program is stored. When the computer management program is executed by a processor, the steps of the method for protecting the core code of the program as described above are implemented.
[0045] Beneficial Effects
[0046] The embodiment of the present invention provides a method for protecting the core code of a program, uses a state machine to mark the state data of a loading module, and creates an empty thread event to achieve state machine data filling, thereby forming verification or encryption data. The thread creation event is irreversible, and a unique result can be obtained under the order of the loading sequence list, so that when the loading sequence of the module is abnormal, or a certain module is used abnormally, it can be directly known. Thus, the method for protecting the core code of the program can be completed covertly.
[0047] The program core code protection method provided by the present invention can compile the program core code correctly only when the modules are loaded in the order of the loading sequence list. Compared with the existing protection method using hook or using obfuscated code to encrypt the code, the program core code protection method can better ensure the concealment and security of the program core code protection method process. By complicating the string data, the program core code protection method can be made more concealed. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] Figure 1 A flowchart of an embodiment of a method for protecting a program core code of the present invention;
[0049] Figure 2 Flowchart created for the state machine data matrix of the present invention.
[0050] Figure 3 This is a flow chart of module transfer and core module assignment of the state machine data matrix described in the present invention.
[0051] Figure 4 A flowchart of an empty thread creation event according to the present invention.
[0052] Figure 5 This is a calculation flow chart of the matrix result data described in the present invention.
[0053] Figure 6 A schematic diagram of the unit structure of an embodiment of a protection device for a program core code of the present invention;
[0054] Figure 7 A schematic diagram of the hardware structure of a device with a program core code protection function provided by an embodiment of the present invention;
[0055] Figure 8 A schematic diagram of a possible electronic device provided by an embodiment of the present invention;
[0056] Fig. 9 A schematic diagram of an embodiment of a possible computer-readable storage medium provided for an embodiment of the present invention. DETAILED DESCRIPTION
[0057] The following is a description of the implementation of the present invention by specific embodiments. People familiar with the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0058] It should be noted that in the description of the present invention, the terms "middle", "upper", "lower", "lateral", "inner", etc. indicating directions or positional relationships are based on the directions or positional relationships shown in the drawings, which are only for the convenience of description, and do not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as limiting the present invention. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0059] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "set", "install", "connect", and "connect" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0060] It should be noted that the method for protecting the program core code provided in the embodiment of the present invention is implemented based on the Windows client program. The Windows client program includes a main program exe and multiple module dlls.
[0061] like Figure 1 As shown, the present invention provides a method for protecting program core code, comprising:
[0062] Step S110, mark the loading state of any loading module through the state machine, and obtain the state machine data matrix of the loading module.
[0063] like Figure 2 Specifically, the establishment of the state machine data matrix in step S110 includes the following steps:
[0064] Step S111, obtaining any loading module of the main program;
[0065] Specifically, the embodiment of the present invention is implemented based on a Windows client program, including a main program and multiple modules. As a preferred embodiment, step S111 of this embodiment is to obtain all loaded modules by running the main program.
[0066] Step S112, establishing a loading order list according to the loading order of the loading modules;
[0067] Specifically, the present invention obtains the loading order of modules through the operation of the main program, wherein the loading order of modules is preset based on the core code of the program. The embodiment of the present invention sets a preset module order list based on the preset module loading order. In a specific embodiment, the module loading order list can be expressed as: dll1, dll2...dllN, wherein dll is the module name and N is the number of modules.
[0068] It should be noted that this embodiment obtains the loading sequence table through the loading sequence preset by the main program core code, and arranges the sequence according to the preset priority level. There is no need to adjust the loading sequence, thereby achieving the beneficial effect of effectively avoiding operation conflicts.
[0069] Step S113, establishing a state machine, and using a two-dimensional array matrix to represent the data of the state machine;
[0070] The embodiment of the present invention sets a state machine to mark the loading of each module, and the state machine of the embodiment of the present invention is marked according to the module loading order, so the state of this state machine will obtain all the data of a state according to the module loading order. Wherein, the two-dimensional array matrix is a two-dimensional array of N rows and N columns, and N is the number of loaded modules.
[0071] Specifically, the state machine in the embodiment of the present invention is a matrix, the rows of the matrix represent the modules corresponding to the currently acquired state machine data matrix, and the columns of the matrix represent the matrix of the currently loaded modules, that is, the rows and columns correspond to the modules, so the number of rows and columns of the matrix is equal to the number of modules, and the state machine is represented as an N*N matrix, where N is the number of loaded modules, and is described in computer language as int State[N*N].
[0072] It should be noted that: this embodiment achieves the beneficial effect of being more conducive to state transfer between modules by establishing a state machine and setting the state machine as a matrix corresponding to the loaded module, marking the module status in the form of data.
[0073] like Figure 3As shown, step S120, by creating an empty thread event, fill the state machine data matrix into the loading module according to the module loading order of the main program, and store the state machine data matrix of all loading modules in the core module, specifically, including the following steps:
[0074] Step S121, initializing the two-dimensional array matrix to a zero matrix;
[0075] Specifically, the two-dimensional array matrix dll1, dll2...dllN is arranged in the order of module loading, dll1 is loaded first, dll2 is loaded second, dll3 is loaded second, and so on. The rows represent the modules where the table of the current state machine is located, and the columns represent the modules currently loaded. The array data of the initialized state machine is a matrix of all 0s. The current initialized state is a two-dimensional array of intState[N*N], which is specifically expressed as:
[0076]
[0077] It should be noted that by initializing the state machine data to a zero matrix, the two-dimensional array can be reassigned according to the state of the module, thereby achieving the beneficial effect of facilitating subsequent assignment and transfer processing.
[0078] Step S122, adding a function export interface in any load module to transfer the state machine data matrix to other load modules; the transfer of the state machine data matrix between modules is completed through the export interface, specifically, including the following steps:
[0079] First, add a function interface in each module to receive the state machine data matrix of other modules. The added function interface can be implemented in the following computer language:
[0080] extern "C" __declspec(dllexport);
[0081] void_stdcall setState(int State[N*N]);
[0082] Among them, extern "C" __declspec (dllexport); means exporting the function to other modules for use, void_stdcall setState (int State [N * N]) means setting the interface about the two-dimensional array int State [N * N], and the parameter State is used to pass in the state machine data matrix.
[0083] Then, the name data of the next loaded module is added to each module, that is, the name of the next module to be loaded is informed through the preset module sequence list. The specific computer language description is as follows:
[0084] extern "C" __declspec(dllexport);
[0085] void_stdcall setNextLoadDllName(string name)
[0086] Among them, extern "C" __declspec (dllexport) indicates that the function is exported to other modules for use;
[0087] void_stdcall setNext Load DllName(string name); indicates that the function is used by the main program to inform the current module of the name of the next loaded module. setNext Load DllName indicates the name of the next loaded module, and string name is used to pass in the loaded module name.
[0088] It should be noted that: this embodiment realizes data transfer between modules by setting an export interface in the module, which facilitates subsequent thread transfer to transfer data according to rules, thereby achieving the beneficial effect of facilitating data transfer.
[0089] Step S123, adding an empty thread creation event;
[0090] Specifically, the creation of a thread will generate a thread event. Both the thread that implements the function and the empty thread will generate corresponding thread events. All modules corresponding to the main program will respond to the event, so that the main program can obtain the response of all modules based on the created thread event, thereby loading the module. The embodiment of the present invention creates an empty thread event. The main program loads the modules in the order of the loading order list. When each module is loaded, the corresponding state machine data will be generated, and the state machine data matrix will be filled into the corresponding loading module. In this way, as the modules are continuously loaded, the state machine data matrix of each loading module will eventually be obtained. The embodiment of the present invention stores the state machine data matrix of each loading module in the core module. In a specific embodiment, the specific computer language description is as follows:
[0091] By modifying the module's dllmain function, an empty thread creation event is added. The module's dllmain function is the default entry point of the dll module, which is used to handle module loading, module unloading and other related events.
[0092] The embodiment of the present invention adds a thread creation event in the dllmain function of each module to sense the creation of a thread. The dllmain function is as follows:
[0093] BOOL DllMain(HMODULE hModule,DWORDreason,LPVOID lpReserved)switch(reason){reason is used to sense the thread event type.
[0094] case DLL_PROCESS_ATTACH: indicates that the empty thread event in the embodiment of the present invention is received when the module is initialized and loaded.
[0095] break;
[0096] case DLL_THREAD_ATTACH: Add an empty thread creation event.
[0097] It should be noted that: in this embodiment, by creating an empty thread, the assignment transfer between modules can be completed, and the status data of all loaded modules can be transferred to the core module, thereby realizing the data transfer between the core module and the loaded module under the thread event.
[0098] Furthermore, in step S123, an empty thread creation event is added, which can fill the data of the two-dimensional array matrix according to the loading order of the loading order list, and set the data of the two-dimensional array matrix to the core module through the function export interface.
[0099] like Figure 4 As shown, further, in step S123, an empty thread creation event is added, which specifically includes the following steps:
[0100] Step S1231, the main program traverses all threads in the process and pauses all threads;
[0101] Start the main program, which traverses all threads in the process and pauses to prevent other modules from creating threads, which would cause the state machine data matrix of each module to be assigned multiple times or disordered.
[0102] Step S1232, by modifying the dllmain function of the module, create an empty thread, the empty thread is an empty function logic, so that the state machine data assignment and the transfer order are completed between the loaded modules; wherein the transfer order is the module loading order; for specific steps, see step S123.
[0103] It should be noted that an empty thread is created through the system function so that all modules can achieve the beneficial effects of assigning state machine data and forming a transfer order;
[0104] Step S1233, execute an empty thread, traverse the current load module, obtain the handle of the load module, and disable the thread creation event for each load module by calling the system function; further, adding an empty thread creation event in this step also specifically includes: executing the empty thread, traversing all current load modules, obtaining the handle of the load module, and calling the system function to disable the thread creation event for each load module. The specific computer language description is as follows:
[0105] HANDLE h=GetModuleHandle("module name.dll");
[0106] Call the system function DisableThreadLibraryCalls(h); disable the module's thread events.
[0107] It should be noted that by traversing all currently loaded modules and calling the system function to disable thread creation events for each loaded module, the empty thread event can only occur once, so as to avoid deciphering the state machine data by repeatedly creating empty thread events, and the empty thread event clarifies the transmission order of the state machine data, thereby achieving the beneficial effect of avoiding multiple or chaotic assignments.
[0108] Step S1234: The main program traverses the thread and resumes the execution of the thread.
[0109] It should be noted that by calling the system function to disable the thread events of each loaded module, no thread creation event will be generated when any module or main program in the entire program creates a thread again. This ensures that the state machine data matrix will only be initialized and transferred once, so that some programmers cannot obtain the module state machine data matrix results even if they create a thread.
[0110] In a specific embodiment, the method specifically includes: filling the data of the two-dimensional array matrix according to the loading order of the loading order list, and the specific implementation process includes the following steps:
[0111] After the state machine is initialized, when the foremost module dll1 is loaded, the module corresponding to the state machine data matrix currently obtained is the foremost module, and the foremost module is currently loaded, that is, the element value of the first row and first column of the state machine data matrix of the foremost module is set to 1, which is specifically expressed as:
[0112]
[0113] The state machine data matrix of the first module is transferred to the second module, and the preset matrix of the second module is assigned to obtain the state machine data matrix of the second module, that is, the state machine data matrix of the first module is transferred to the second module, and on the basis of the state machine data matrix of the first module, the element value of the second row and the second column is set to 2 to obtain the state machine data matrix of the second module. This is the preferred filling rule to fill the data of the two-dimensional array matrix.
[0114] Specifically, the state machine data matrix is transmitted through the following computer language:
[0115] The module's system function LoadLibrary loads the frontmost module HMODULE hModule = LoadLibrary ("frontmost module name.dll"); the module's system function GetProcAddress obtains the module's receiving interface function Func = GetProcAddress (hModule, "setState"); then calls Func (state); and inserts the state machine data matrix to store the module's state machine data matrix to the frontmost module.
[0116] The previous module will pass the state machine data matrix to this module, which will receive the state machine data matrix passed by the previous module in the preset receiving interface function setState, set the state machine data matrix of the loading module on the state machine data matrix, and then store the state machine data matrix of the loading module in the core module.
[0117] The loading module then informs the loading name of the next module through the loading interface setNextLoadDllName, thereby sending the state machine data matrix of the current module to the receiving interface function setState of the next module.
[0118] After the empty thread is created, all modules will receive the DLL_THREAD_ATTACH event.
[0119] It should be noted that: the data of the two-dimensional array matrix is set to the core module through the function export interface, and the state machine matrix is assigned to each module so that the state machine matrix of each module is not a symmetric matrix, which can facilitate the subsequent acquisition of the module state machine data matrix results.
[0120] It should be noted that the core module in the embodiment of the present invention is preferably the frontmost module.
[0121] Step S130, transforming the state machine data matrix in the loading module into matrix result data, and converting the matrix result data into one-dimensional array result data;
[0122] From the above embodiment, it can be seen that the state machine data matrix of all loaded modules is stored in the core module, and the state machine data matrix in the core module is operated to obtain the matrix result data to complete the subsequent protection of the program core code.
[0123] like Figure 5 As shown, in a specific embodiment, the acquisition of the matrix result data in step S130 specifically includes the following steps:
[0124] Step S131: Obtain the state machine data matrix of each loading module in the core module.
[0125] Step S132: Use the principle of matrix multiplication to multiply the state machine data of each module to obtain a product matrix. This step specifically includes: sorting the state machine data matrix of the loading module according to the loading order to obtain the state machine data matrix of the N-bit loading modules arranged in sequence.
[0126] It should be noted that the loading order in step S132 refers to the module loading order stored in the loading order list in the above embodiment.
[0127] Step S133: multiply the state machine data matrix of the Nth loading module by the N-1th product data to obtain the Nth product data.
[0128] Specifically, the N-1th product data is the product of the state machine data matrix from the first loading module, that is, the front loading module to the N-1th loading module in the loading order. Therefore, the Nth product data is the product of the state machine data matrix from the first loading module to the Nth loading module in the loading order.
[0129] Step S134: Use the Nth product data as the product matrix and as the matrix result data; wherein N is the number of loading modules, the first product data is the state machine data matrix of the first loading module, and the Nth loading module is the last loading module.
[0130] Step S135, converting the product matrix into a one-dimensional array to obtain string data, specifically including: obtaining each row of data in the product matrix; and concatenating and arranging them in row order to obtain string data.
[0131] It should be noted that the state machine data matrices of all modules are asymmetric matrices. When the state machine data matrices of all modules are multiplied, different matrices will be obtained based on different orders. In the embodiment of the present invention, the order of the loading sequence list is multiplied. Only the order of the loading sequence list can be multiplied to obtain the product matrix, and based on other orders, the product matrix cannot be obtained. The beneficial effect of data encryption is achieved.
[0132] In another embodiment, it also includes: converting the string data into one-dimensional array result data.
[0133] The string data is complicated according to a preset algorithm and stored in a core module. The preset algorithm is preferably a hash algorithm. The hash value of the string data is obtained through the hash algorithm. In a preferred embodiment, the hash value can be used as key data or seed data of a random algorithm.
[0134] It should be noted that by complicating the string data through the hash algorithm, the data can be further encrypted and the number of bits of key data in the core program code can be generated, achieving the beneficial effect of facilitating the embedding of the core code.
[0135] Step S140: embed the one-dimensional array result data into the program core code as key data and / or seed data of the random algorithm to perform data verification or encryption, thereby completing the protection of the program core code.
[0136] The one-dimensional array result data can be used as part of the secret key data for data encryption and decryption codes; for calculation logic or table lookup algorithms, it can be used as the seed data of the algorithm, that is, the calculation factor participates in the algorithm.
[0137] It should be noted that only when the modules are loaded in the order of the loading sequence list can the core code of the program be compiled correctly. Compared with the existing protection methods of using hooks or obfuscating codes to encrypt codes, the protection method process of the core code of the program can better ensure the concealment and security of the process.
[0138] It should be noted that: since the loading sequence list is preset, the comparison matrix result data is stored in advance in the frontmost module. The loading sequence list in the embodiment of the present invention can be rewritten by the main program, so as to realize the transformation of the verification algorithm.
[0139] The above describes the method for setting the protection of the program core code in the embodiment of the present application. The following describes the device with the protection function of the program core code in the embodiment of the present application.
[0140] Figure 6 FIG. 1 is a schematic diagram of a unit structure of an embodiment of a protection device for a program core code of the present invention, as shown in FIG. Figure 6As shown, an embodiment of the present invention also provides an embodiment of a device with a program core code protection function, the device comprising: an acquisition unit 210, used to mark the loading state of any loading module through a state machine, and obtain the state machine data matrix of the loading module; a filling unit 220, used to fill the state machine data matrix into the loading module according to the module loading order of the main program by creating an empty thread event, and store the state machine data matrix of any loading module in the core module; a conversion unit 230, which is used to convert the state machine data matrix into matrix result data in the core module; and convert the matrix result data into one-dimensional array result data; an encryption unit 240, which is used to embed the one-dimensional array result data into the program core code as key data and / or seed data of a random algorithm to perform data verification or encryption to complete the protection of the program core code.
[0141] Figure 6 The device with the program core code protection function in the embodiment of the present application is described from the perspective of modular functional entity. The device with the program core code protection function in the embodiment of the present application is described in detail from the perspective of hardware processing. Figure 7 A schematic diagram of the hardware structure of a device with a program core code protection function provided by an embodiment of the present invention; see Figure 7 In the embodiment of the present invention, a device 300 having a program core code protection function is recommended as an embodiment, comprising:
[0142] An input device 301, an output device 302, a processor 303 and a memory 304 (the number of the processor 303 can be one or more, Figure 7 In some embodiments of the present invention, the input device 301, the output device 302, the processor 303 and the memory 304 may be connected via a bus or other means, wherein: Figure 7 The example of connecting through bus is taken in the following.
[0143] Wherein, by calling the operation instruction stored in the memory 304, the processor 303 is used to perform the following steps:
[0144] Marking the loading state of any loading module by the state machine to obtain the state machine data matrix of the loading module;
[0145] By creating an empty thread event, the state machine data matrix is filled into the loading module according to the module loading order of the main program, and the state machine data matrix of any loading module is stored in the core module;
[0146] Transforming the state machine data matrix in the loading module into matrix result data, and converting the matrix result data into one-dimensional array result data;
[0147] The one-dimensional array result data is embedded into the program core code as key data and / or seed data of the random algorithm to perform data verification or encryption, thereby completing the protection of the program core code.
[0148] By calling the operation instructions stored in the memory 304, the processor 303 is also used to execute Figure 1-5 Any method in the corresponding embodiment.
[0149] Figure 8 A schematic diagram of a possible electronic device provided by an embodiment of the present invention is shown in FIG. Figure 8 shown.
[0150] In another embodiment, the present invention further provides an electronic device, including a memory 410, a processor 420, and a computer program 411 stored in the memory 420 and executable on the processor 420. When the processor 420 executes the computer program 411, the following steps are implemented:
[0151] Marking the loading state of any loading module by the state machine to obtain the state machine data matrix of the loading module;
[0152] By creating an empty thread event, the state machine data matrix is filled into the loading module according to the module loading order of the main program, and the state machine data matrix of any loading module is stored in the core module;
[0153] Transforming the state machine data matrix in the loading module into matrix result data, and converting the matrix result data into one-dimensional array result data;
[0154] The one-dimensional array result data is embedded into the program core code as key data and / or seed data of the random algorithm to perform data verification or encryption, thereby completing the protection of the program core code.
[0155] In the specific implementation process, when the processor 420 executes the computer program 411, it can achieve Figure 1-5 Any implementation manner in the corresponding embodiments.
[0156] Since the electronic device introduced in this embodiment is a device used to implement a device with a program core code protection function in the embodiment of the present invention, based on the method introduced in the embodiment of the present invention, technical personnel in this field can understand the specific implementation method of the electronic device of this embodiment and its various variations. Therefore, how the electronic device implements the method in the embodiment of the present invention is not introduced in detail here. As long as the equipment used by technical personnel in this field to implement the method in the embodiment of the present invention is within the scope of protection of this application.
[0157] Fig. 9 For a possible computer-readable storage medium embodiment provided by the present invention, please refer to Fig. 9 .
[0158] like Fig. 9 As shown, this embodiment provides a computer-readable storage medium 500, on which a computer program 511 is stored. When the computer program 511 is executed by a processor, the following steps are implemented:
[0159] Marking the loading state of any loading module by the state machine to obtain the state machine data matrix of the loading module;
[0160] By creating an empty thread event, the state machine data matrix is filled into the loading module according to the module loading order of the main program, and the state machine data matrix of any loading module is stored in the core module;
[0161] Transforming the state machine data matrix in the loading module into matrix result data, and converting the matrix result data into one-dimensional array result data;
[0162] The one-dimensional array result data is embedded into the program core code as key data and / or seed data of the random algorithm to perform data verification or encryption, thereby completing the protection of the program core code.
[0163] In the specific implementation process, when the computer program 511 is executed by the processor, it can achieve Figure 1-5 Any implementation manner in the corresponding embodiments.
[0164] It should be noted that in the above embodiments, the description of each embodiment has its own emphasis, and for parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0165] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0166] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded computer, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0167] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0168] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0169] The embodiment of the present invention also provides a computer program product, which includes computer software instructions. When the computer software instructions are executed on a processing device, the processing device executes the following Figure 1 The process in the method for protecting the program core code in the corresponding embodiment.
[0170] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website site, a computer, a server, or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server, or data center. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or a data center that includes one or more available media integrated. The available medium may be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.
[0171] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0172] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0173] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0174] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0175] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (RandomAccess Memory, RAM), disk or optical disk and other media that can store program codes.
[0176] The embodiment of the present invention provides a method, device, equipment and storage medium for protecting the core code of a program, which has the following beneficial effects: by setting the state machine data matrices of all modules to be multiplied in the order of the loading sequence list, the matrix result data can be obtained, and a unique result under the order of the loading sequence list can be obtained, so that when the loading sequence of the modules is abnormal, or a certain module is used abnormally, it can be directly known. The embodiment of the present invention can covertly complete the method for protecting the core code of the program.
[0177] So far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
Claims
1. A method for protecting program core code, characterized in that: include: Marking the loading state of any loading module by the state machine to obtain the state machine data matrix of the loading module; By creating an empty thread event, the state machine data matrix is filled into the loading module according to the module loading order of the main program, and the state machine data matrix of any loading module is stored in the core module; Transforming the state machine data matrix in the loading module into matrix result data, and converting the matrix result data into one-dimensional array result data; The one-dimensional array result data is embedded into the program core code as key data and / or seed data of the random algorithm to perform data verification or encryption to complete the protection of the program core code; The creation of the state machine data matrix of the loading module specifically includes: Get any loaded module of the main program; And establishing a loading order list according to the loading order of the loading modules; Establish a state machine and use a two-dimensional array matrix to represent the data of the state machine; Wherein, the two-dimensional array matrix is a two-dimensional array of N rows and N columns, and N is the number of loaded modules; Filling the state machine data matrix into the loading module specifically includes: Initializing the two-dimensional array matrix to a zero matrix; Add a function export interface in any load module to pass the state machine data matrix to other load modules; Add an empty thread creation event; Filling the data of the two-dimensional array matrix according to the loading order of the loading order list; And setting the data of the two-dimensional array matrix into the core module through the function export interface; The adding of an empty thread creation event specifically includes: The main program traverses any thread in the process and pauses the thread; By modifying the dllmain function of the module, an empty thread is created, wherein the empty thread is an empty function logic, so that the assignment of state machine data and the formation of a transfer order between loaded modules are completed; wherein the transfer order is the module loading order; Execute the empty thread, traverse the current loading modules, obtain the handles of the loading modules, and disable the thread creation event for each loading module by calling the system function; The main program traverses the threads and resumes the execution of the threads; The acquisition of the matrix result data specifically includes: Get the state machine data matrix of each loaded module in the core module; Sorting the state machine data matrix of the loading module according to the loading order to obtain the state machine data matrix of the N-bit loading modules arranged in sequence; Multiplying the state machine data matrix of the Nth loading module with the N-1th product data to obtain the Nth product data; Multiply N product data to obtain a product matrix as matrix result data; Where N is the number of loading modules, and the first product data is the state machine data matrix of the first loading module; Converting the matrix result data into one-dimensional array result data specifically includes: Obtaining each row of data of the product matrix; And concatenate and arrange them in row order to obtain string data; The string data is converted into a one-dimensional array result data.
2. The method for protecting program core code according to claim 1, characterized in that: The string data is complicated by a hash algorithm.
3. An electronic device, comprising an application processor and a memory, characterized in that: The processor is used to implement the steps of the program core code protection method according to any one of claims 1 to 2 when executing the computer management program stored in the memory.
4. A computer-readable storage medium having a computer management program stored thereon, characterized in that: When the computer management program is executed by the processor, the steps of the program core code protection method as described in any one of claims 1-2 are implemented.
Citation Information
Patent Citations
Finite state machine and symbol execution-based source code enhancement method and apparatus
CN108446541A
Method of program exit and related equipment
CN109117201A