A method for implementing application signature verification based on JavaScript
Through a JavaScript-based application signature verification method, the web application is signed and verified, which solves the problem of lack of the Web application signature verification mechanism in the existing technology, significantly improves the security of Web applications, and prevents various security risks.
Patent Information
- Application Number
- CN202211331375.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-28
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-10-28
AI Technical Summary
The existing technology lacks a signature verification mechanism for Web applications implemented based on JavaScript, resulting in insufficient security in mobile Web applications, and it is difficult to prevent security issues such as forgery, denied, impersonation and tampering.
A JavaScript-based application signature verification method is adopted to unpack and parse the web application package through the application signature service, traversing and searching JavaScript files, and performing basic protection and signature processing to generate code signature values. At the same time, create custom signature verification identifiers and signature magic values and merge them into the original JavaScript file. The client web container integrates the application verification component to perform data verification and signature attribute verification on the pulled JavaScript files.
It significantly reduces security risks such as illegal tampering, malicious utilization, and malicious attacks, and can effectively prevent the forgery, debunking, impersonation and tampering of Web applications, and meets the urgent needs of application security system construction.
Smart Images

Figure CN115659318B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly relates to a method for implementing application signature verification based on JavaScript. Background Art
[0002] The application signature verification function verifies the signature information of the application installation file to check its legality and compliance. If the signature verification passes, the installation is permitted; if the signature verification fails, the installation is prohibited. By signing and verifying the application, security issues such as forgery, repudiation, impersonation, and tampering of the application installation file can be prevented.
[0003] Currently, in mobile operating systems, the signature verification mechanism system for native applications is relatively perfect, but there is a lack of a signature verification mechanism for Web applications implemented based on JavaScript. In mobile Web applications, lightweight applications represented by H5 applications and mini-programs have the characteristics of short development cycle, low cost, strong compatibility, and fast iteration speed. They have rich application scenarios and high flexibility. The market is becoming more prosperous and the occupancy rate is gradually increasing, and the demand for application authentication is strong. There are many development toolchains for Web applications implemented based on JavaScript, and the program structure after packaging is complex and diverse. It is difficult to refer to the signature verification method of native applications. The native application APK format is fixed and has an installation verification process executed by the operating system. However, lightweight applications do not need to be installed and are loaded by the Web container. The program files are pulled from the server to the client as needed and are executed and loaded and rendered by the client engine. Therefore, it is impossible to perform a full-scale verification operation on the Web application program files at one time on the client side. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention aims to provide a method for implementing application signature verification based on JavaScript, to make up for the blank of the current Web application signature verification mechanism, and to meet the urgent needs of the application security system construction.
[0005] To achieve the above object, the present invention adopts the following technical solutions:
[0006] A method for implementing application signature verification based on JavaScript includes two parts: application signature and application verification;
[0007] 1) Application Signature
[0008] The application signature service is deployed on the signature service side to unpack and parse the Web application package and traverse to find all JavaScript files. For each JavaScript file, first, basic protection processing is performed on the code, which is compressed and obfuscated. Then, using a dedicated application signature certificate and based on national cryptography commercial certificates and algorithms, the JavaScript file is signed to generate a code signature value. A custom signature verification identifier is created, which includes a fixed identifier, signature algorithm and version information, signature attribute data, and the signature value of the signature verification identifier. A signature magic value for locating and finding relevant data is created. Then, in sequence, the signature verification identifier, code signature value, signature magic value, and the original code data after basic protection processing are incorporated into the original JavaScript file to replace the original data. After the above processing, the program is repackaged in the original format of the package.
[0009] 2) Application signature verification
[0010] The local client Web container integrates an application signature verification component, which performs data signature verification and signature attribute verification on each JavaScript file pulled into the local client Web container. The logic of the application signature verification component is implemented based on JavaScript code. If the signature verification fails or the signature attribute verification fails, loading of this JavaScript file is prohibited and an appropriate prompt is given to the user. If the signature verification passes and the signature attribute verification passes, loading and execution of the corresponding JavaScript file are allowed. The specific process of signature verification is as follows:
[0011] 2.1) When the local client Web container requests a JavaScript file, the application signature verification component intercepts and processes the JavaScript file.
[0012] 2.2) First, obtain a signature verification identifier with a length of 256 bytes, calculate and parse the signature value SJT of the signature verification identifier, verify whether the signature verification identifier has been tampered with. After verification passes, process the first 128 bytes of the signature verification identifier, parse to obtain 64 bytes of signature attribute data, and determine whether the included signature attribute value and / or certificate attribute value meet the expectations.
[0013] 2.3) After completing the verification in step 2.2), find the signature magic value, and calculate and parse the code signature value based on its first-byte offset and the last-byte offset of the signature verification identifier.
[0014] 2.4) Find the signature magic value, and calculate and parse the original JavaScript code data based on its last-byte offset.
[0015] 2.5) According to the obtained code signature value and the original code data, use the national cryptography certificate and signature verification algorithm to verify whether it passes. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0016] Furthermore, the specific process of applying the signature is as follows:
[0017] 1.1) Unpacking, traversing and analyzing: After the signature service obtains the program compressed package file, decompress the compressed file and traverse the files ending with js. For each JavaScript file, perform lexical analysis and syntax analysis.
[0018] 1.2) Code protection and refactoring: Obfuscate and rename the variable names in the JavaScript file, and compress the code to generate the first refactored JavaScript file.
[0019] 1.3) Calculate the signature value of the JavaScript file generated in step 1.2): Use the national cryptography algorithms SM3 / SM2 to perform a full-signature on the first refactored JavaScript file to generate the code signature value SDT.
[0020] 1.4) Calculate the signature verification identifier: The length of the signature verification identifier is defined as 256 bits, which is composed of the fixed identifier, signature algorithm and version information, signature attribute data, and the signature value SJT of the signature verification identifier in sequence; the fixed identifier is 16 bytes long, the signature algorithm and version information are 40 bytes long, the signature attribute data is 64 bytes long, the signature data is 8 bytes long, and the signature value SJT of the signature verification identifier is 128 bytes long.
[0021] 1.5) Incorporate to generate the signature file: Insert the signature verification identifier, the code signature value SDT in sequence, and then insert a 16-byte fixed-length signature magic value, which is custom extended data used to cooperate with the signature verification identifier to find and verify the signature data. Finally, insert the original JavaScript code after code protection processing; after the above four parts of data are incorporated, perform secondary compression to generate the second refactored JavaScript file.
[0022] Even further, in step 1.4), the signature attribute data includes multiple signature attribute values and certificate attribute values.
[0023] The beneficial effects of the present invention are as follows: Based on the national cryptographic algorithms SM3 / SM2, signature verification technology, and code protection processing, the present invention can sign and verify JavaScript code files, significantly reducing security risks such as illegal tampering, malicious exploitation, and malicious attacks. It can be applied to application scenarios such as anti-tampering, anti-theft, and anti-analysis, making up for the gap in the current Web application signature verification mechanism and meeting the urgent needs of the construction of the application security system. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is a schematic diagram of the application signature process in Embodiment 1 of the present invention;
[0025] Figure 2 It is a schematic diagram of the structure of signature attribute data in Embodiment 1 of the present invention;
[0026] Figure 3 It is a schematic diagram of the structure of the finally reconstructed JavaScript file in Embodiment 1 of the present invention;
[0027] Figure 4 It is a schematic diagram of the application verification signature process in Embodiment 1 of the present invention;
[0028] Figure 5 It is a schematic diagram of the application signature process in Embodiment 2 of the present invention;
[0029] Figure 6 It is a schematic diagram of the application verification signature process in Embodiment 2 of the present invention;
[0030] Figure 7 It is a schematic diagram of the application signature process in Embodiment 3 of the present invention;
[0031] Figure 8 It is a schematic diagram of the application verification signature process in Embodiment 3 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] The present invention will be further described below. It should be noted that this embodiment is based on the present technical solution and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to this embodiment. Embodiment 1
[0033] This embodiment provides a method for implementing application signature verification based on JavaScript, including two parts: application signature and application verification signature;
[0034] 1) Application signature
[0035] The application signature service is deployed on the signature service side, unpacks and parses the Web application package, and traverses to find all JavaScript files. For each JavaScript file, first perform basic protection processing on the code, compress and obfuscate it, and then use a special application signature certificate to sign the JavaScript file based on the national cryptography commercial certificate and algorithm to generate code signature data; create a custom signature verification identifier, and custom data can also be added according to requirements; create a signature magic value for locating and finding relevant data, and sequentially incorporate the signature verification identifier + code signature data + signature magic value + the original code data after basic protection processing into the original JavaScript file to replace the original data. The code data incorporated in the above operations is based on the principle of not affecting the execution logic of the original code data.
[0036] After the above processing is completed, repackage the program in the original format of the package. This process should not change the architecture of the original package and should not affect the code execution of the original program. The process of application signature is as Figure 1 shown.
[0037] The process of application signature includes unpacking traversal and analysis, code protection and reconstruction, calculating the file signature value, calculating the verification identifier, and incorporating to generate the signature file; specifically:
[0038] 1.1) Unpacking traversal and analysis. After the signature service obtains the program compressed package file, decompresses the compressed file, and traverses the files ending with js. For each JavaScript file, perform lexical analysis and syntactic analysis.
[0039] It should be noted that JavaScript is a lightweight, interpreted or just-in-time compiled high-level programming language with function priority. In Web applications, JS undertakes many important functions such as communication and interaction with the server side and logical processing on the client side. Therefore, the core requirement for parsing and reconstructing JS files is not to damage the logical functions of the original program code. Among them, the technical principles involved include the parsing and reconstruction of JS code and code protection technology.
[0040] In the logical processing process of signature verification, the functional integrity of the code needs to be ensured. JS is not only an "interpreted" language but also a compiled language using a special precompilation mechanism. The execution of the source code in a JS program is divided into three steps: lexical analysis, syntactic analysis, and code generation. Lexical analysis includes analyzing parameters, variable declarations, and function declarations. Syntactic analysis constructs an abstract syntax tree (AST) to abstractly represent the syntax structure of the source code, presenting the syntax structure of the programming language in a tree-like form. The AST is converted into executable code in the code generation stage. By code parsing, the content of the JS code can be reconstructed without damaging the original code logic.
[0041] 1.2) Code protection and refactoring. Obfuscate and rename the variable names in the JavaScript file, and compress the code to generate the first refactored JavaScript file.
[0042] 1.3) Calculate the signature value of the first refactored JavaScript file. Use the national cryptography algorithm SM3 / SM2 to perform a full-signature on the first refactored JavaScript file, with a length of 1334 - 1380 bytes (depending on the padding length), to generate the code signature value SDT.
[0043] 1.4) Calculate the signature verification identifier. The length of the signature verification identifier is defined as 256 bits, arranged in order. Among them, the fixed identifier length is 16 bytes, the signature algorithm and version information length is 40 bytes, the signature attribute data length is 64 bytes, and the signature data length is 8 bytes. To prevent the signature verification identifier from being tampered with and forged, add the signature value SJT of the 128-byte signature verification identifier. Among them, the signature attribute data includes multiple signature attribute values and certificate attribute values such as source and validity period, Figure 2 which is a structural example diagram of the signature attribute data.
[0044] 1.5) Incorporate and generate the signature file. Insert the signature verification identifier and the code signature value SDT in order, and then insert the 16-byte fixed-length signature magic value, which is custom extension data used to cooperate with the verification identifier to find and verify the signature data. Finally, insert the original JavaScript code data after code protection processing. After the above four parts of data are incorporated, perform secondary compression to generate the second refactored JavaScript file, and the overall code structure is as Figure 3 shown.
[0045] 2) Apply signature verification
[0046] The signature verification component needs to be integrated and installed on the client container side. The client can be a base or a browser, collectively referred to as a Web container. In the application operation and use of the Web architecture, JavaScript program files are pulled from the Web server to the local client Web container one by one as needed, and are loaded and executed through the JavaScript engine.
[0047] Web container integrated application signature verification component. The application signature verification component performs data signature verification and signature attribute verification on each JavaScript file pulled to the local client Web container; the logic of the application signature verification component is implemented based on JavaScript code; if the signature verification fails or the signature attribute verification fails, loading of this JavaScript file is prohibited and corresponding prompts are given to the user; if the signature verification passes and the signature attribute verification passes, loading and execution of the corresponding JavaScript file are allowed. The process of application signature verification is as Figure 4 shown.
[0048] The specific signature verification process is as follows:
[0049] 2.1) When the local client Web container requests a JavaScript file, the application signature verification component intercepts and processes the JavaScript file.
[0050] 2.2) First, obtain a 256-byte signature verification identifier, calculate and parse the signature value SJT of the signature verification identifier, verify whether the signature verification identifier has been tampered with. After verification passes, process the first 128 bytes of the signature verification identifier, parse to obtain 64-byte signature attribute data, and determine whether the included signature attribute value and certificate attribute value meet the expectations.
[0051] 2.3) After completing the verification in step 2.2), search for a 16-byte signature magic value, and calculate and parse the code signature value SDT according to its first byte offset and the last byte offset of the signature verification identifier;
[0052] 2.4) Search for the signature magic value, and calculate and parse the original JavaScript code data according to its last byte offset;
[0053] 2.5) According to the obtained code signature value and the original code data, use the national secret certificate and the signature verification algorithm to verify whether it passes. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next operation. Embodiment 2
[0054] In this embodiment, taking an H5 application as an example, the client program is developed using the mainstream front-end framework VueJS, and the packaging tool is Webpack. After the H5 application program is packaged, it is a dist package. In the signature operation, the dist package needs to be compressed and submitted to the signature service side for processing. In the signature verification operation, the client Web container integrates the signature verification component to perform signature verification processing on each requested JavaScript file.
[0055] The application signature process is as Figure 5 shown, including the following steps:
[0056] Step 1: Start signing. Obtain the code dist package, perform the decompression operation. The packaged H5 program code files written using VueJS and Webpack generally include: index.html, favicon.ico, JavaScript files, CSS style files, and resource files such as images and fonts.
[0057] Step 2: Unpack and analyze the decompressed application package. Traverse the JavaScript files and find all files ending with js.
[0058] Step 3: For each found JavaScript file, sequentially perform code analysis, operations such as compression and obfuscation, and perform code protection processing.
[0059] Step 4: Use the national cryptography certificate and signature algorithm to perform a signature operation on the processed code data, generate a code signature value SDT, with a length of 1334 bytes.
[0060] Step 5: Create verification identification data with a length of 128 bytes, including a 16-byte fixed identification, 40 bytes of signature algorithm and version information, 64 bytes of signature attribute data, and 8 bytes of the length of the signature value SDT; customize the signature source attribute of the H5 application in the signature attribute data as "FRIYDJWH5APP".
[0061] Step 6: Use the national cryptography certificate and signature algorithm to sign the 128-byte verification identification data, generate a 128-byte verification identification signature value, and after merging, it is a 256-byte complete signature verification identification.
[0062] Step 7: Create a 16-byte fixed-length signature magic value for locating and searching relevant data in the signature verification stage.
[0063] Step 8: Sequentially incorporate the 256-byte signature verification identification (verification identification data + verification identification signature), the 1334-byte code signature value, the 16-byte signature magic value, and append the protected code data to generate a signed JavaScript code file.
[0064] Step 9: Replace the corresponding file in the original package with the signed JavaScript code file, and on the basis of the original structure, repackage the program to generate a signed package for downloading and use.
[0065] Step 10: End this signature.
[0066] The signature verification process is as Figure 6 shown and includes the following steps:
[0067] Step 1: Start signature verification. The signed H5 application package is deployed on the server side. The client Web container integrates the signature verification component and loads the specified signed JavaScript file according to the request.
[0068] Step 2: After the signature verification component intercepts the signed JavaScript file, it first parses the verification identification data in the file to obtain the verification identification signature SJT.
[0069] Step 3: Use the national cryptography certificate and signature verification algorithm to verify whether the signature value SJT data of the verification identification has been tampered with. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0070] Step 4: Parse the signature source attribute in the verification identification to determine whether it is the custom "FRIYDJWH5APP". If the judgment fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0071] Step 5: Search for the signature magic value, and calculate and parse the code signature value SDT according to its first byte offset and the last byte offset of the verification identification.
[0072] Step 6: Search for the signature magic value, and calculate and parse the original JavaScript code data according to its last byte offset.
[0073] Step 7: According to the obtained code signature value SDT and the original code data, use the national cryptography certificate and signature verification algorithm to verify whether it passes. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0074] Step 8: The Web container executes this JavaScript code.
[0075] Step 9: End this signature verification. Example 3
[0076] This embodiment takes a mini-program as an example. Mini-programs have significant differences from H5 applications in terms of architecture. They adopt a dual-process architecture with separate view layers and logic layers, and communicate through the system-level JSBridge. Various native interfaces can be called through the base client. However, mini-programs are essentially also implemented based on Web technologies, and their code composition structure is very similar to that of H5 applications. The core business logic processing is all handled by JavaScript code. Component code files depend on Html tags, and style files are basically variants of CSS files. Therefore, the signature verification process of mini-programs is basically the same as that of H5 applications. The program package is compressed and submitted to the signature service side for processing. During the signature verification operation, the client mini-program container (base) integrates a signature verification component to perform signature verification on each requested JavaScript file.
[0077] The signature process is as Figure 7 shown and includes the following steps:
[0078] Step 1: Start signing, obtain the program compressed package, and perform decompression processing. Mini-program code files generally include: an entry xml file, a JSON configuration file, JavaScript files, style files, and resource files such as pictures and fonts.
[0079] Step 2: Unpack and analyze the decompressed application package, traverse the JavaScript files, and find all files ending with js.
[0080] Step 3: For each found JavaScript file, sequentially perform code analysis, perform operations such as compression and obfuscation, and perform code protection processing.
[0081] Step 4: Use a national cryptography certificate and a signature algorithm to perform a signature operation on the processed code data to generate a code signature value SDT with a length of 1334 bytes.
[0082] Step 5: Create verification identification data with a length of 128 bytes, including a 16-byte fixed identification, 40 bytes of signature algorithm and version information, 64 bytes of signature attribute data, and 8 bytes of the signature value SDT length; customize the signature source attribute value of the mini-program as "FRIYDJWLITEAPP" in the signature attribute data.
[0083] Step 6: Use a national cryptography certificate and a signature algorithm to sign the 128-byte verification identification data to generate a signature value of the 128-byte verification identification, and after merging, it is a 256-byte complete signature verification identification.
[0084] Step 7: Create a 16-byte fixed-length signature magic value for locating and searching relevant data during the signature verification phase.
[0085] Step 8: Incorporate the 256-byte verification identifier (verification identifier data + verification identifier signature), 1334-byte code signature value, and 16-byte signature magic value in sequence, and append the protected code data to generate a signed JavaScript code file.
[0086] Step 9: Replace the corresponding file in the original package with the signed JavaScript code file, and repackage the program on the basis of the original structure to generate a signed package for download and use.
[0087] Step 10: End this signature.
[0088] The signature verification process is as Figure 8 shown and includes the following steps:
[0089] Step 1: Start signature verification. The signed package needs to be uploaded to the applet server. The applet container on the client integrates a signature verification component and loads the specified signed JavaScript file according to the request.
[0090] Step 2: After the signature verification component intercepts the signed JavaScript file, first parse the verification identifier data in the file to obtain the verification identifier signature SJT.
[0091] Step 3: Use the national cryptographic certificate and signature verification algorithm to verify whether the verification identifier signature SJT data has been tampered with. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0092] Step 4: Parse the signature source attribute in the signature verification identifier to determine whether it is the custom "FRIYDJWLITEAPP". If the determination fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0093] Step 5: Locate the signature magic value, and calculate and parse the code signature value SDT based on its first-byte offset and the last-byte offset of the verification identifier.
[0094] Step 6: Locate the signature magic value, and calculate and parse the original JavaScript code data based on its last-byte offset.
[0095] Step 7: Based on the obtained code signature value SDT and the original code data, use the national cryptographic certificate and signature verification algorithm to verify whether it passes. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next step.
[0096] Step 8: The mini-program container executes this JavaScript code.
[0097] Step 9: End this signature verification.
[0098] For those skilled in the art, various corresponding changes and modifications can be made according to the above technical solutions and concepts, and all such changes and modifications should be included within the protection scope of the claims of the present invention.
Claims
1. A method for implementing application signature verification based on JavaScript, characterized in that, It includes two parts: application signature and application signature verification; 1) Application signature The application signature service is deployed on the signature service side, unpacks and parses the Web application package, and traverses to find all JavaScript files; For each JavaScript file, first perform basic protection processing on the code, compress and obfuscate it, and then use a special application signature certificate to sign the JavaScript file based on the national cryptographic commercial certificate and algorithm to generate a code signature value; Create a custom signature verification identifier, which includes a fixed identifier, signature algorithm and version information, signature attribute data, and the signature value of the signature verification identifier; Create a signature magic value for locating and finding relevant data; then sequentially incorporate the signature verification identifier, code signature value, signature magic value, and the original code data after basic protection processing into the original JavaScript file; after the above processing, repackage the program in the original format of the package; 2) Application signature verification The local client Web container integrates an application signature verification component, which performs data signature verification and signature attribute verification on each JavaScript file pulled to the local client Web container; the logic of the application signature verification component is implemented based on JavaScript code; if the signature verification fails or the signature attribute verification fails, this JavaScript file is prohibited from being loaded and a corresponding prompt is given to the user; if the signature verification passes and the signature attribute verification passes, the corresponding JavaScript file is allowed to be loaded and executed; the specific process of signature verification is as follows: 2.1) When the local client Web container requests a JavaScript file, the application signature verification component intercepts and processes the JavaScript file; 2.2) First, obtain a signature verification identifier with a length of 256 bytes, calculate and parse the signature value SJT of the signature verification identifier, verify whether the signature verification identifier has been tampered with, and after passing the verification, process the first 128 bytes of the signature verification identifier, parse to obtain 64 bytes of signature attribute data, and determine whether the signature attribute value and / or certificate attribute value it contains meet the expectations; 2.3) After completing the verification in step 2.2), find the signature magic value, and calculate and parse the code signature value according to its first byte offset and the last byte offset of the signature verification identifier; 2.4) Find the signature magic value, and calculate and parse the original JavaScript code data according to its last byte offset; 2.5) According to the obtained code signature value and original code data, use the national cryptographic certificate and signature verification algorithm to verify whether it passes. If the verification fails, reject the execution of this JavaScript file and give a user prompt; if the verification passes, continue with the next operation; The specific process of application signature is as follows: 1.1) Unpacking, traversing and analyzing: After the signature service obtains the program compressed package file, decompresses the compressed file, and traverses the files ending with js. For each JavaScript file, perform lexical analysis and syntax analysis; 1.2) Code protection and refactoring: Obfuscate and rename variable names in JavaScript files, and compress the code to generate the first refactored JavaScript file; 1.3) Calculate the signature value of the first refactored JavaScript file: Use the national cryptographic algorithm SM3 / SM2 to perform a full-signature on the first refactored JavaScript file to generate the code signature value SDT; 1.4) Calculate the signature verification identifier: The length of the signature verification identifier is defined as 256 bits, which are arranged in order and consist of a fixed identifier, signature algorithm and version information, signature attribute data, and the signature value SJT of the signature verification identifier; The fixed identifier is 16 bytes long, the signature algorithm and version information are 40 bytes long, the signature attribute data is 64 bytes long, the signature data is 8 bytes long, and the signature value SJT of the signature verification identifier is 128 bytes long; 1.5) Incorporate and generate the signature file: Insert the signature verification identifier and the code signature value SDT in order, then insert a 16-byte fixed-length signature magic value, which is custom extension data used to cooperate with the signature verification identifier to find and verify the signature data, and finally insert the original JavaScript code data after code protection processing; After the above four parts of data are incorporated, perform secondary compression to generate the second refactored JavaScript file.
2. The method according to claim 1, wherein In step 1.4), the signature attribute data includes multiple signature attribute values and certificate attribute values.