A software security protection system and method

CN115828193BActive Publication Date: 2026-09-25709TH RESEARCH INSTITUTE CHINA STATE SHIPBUILDING CORP LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211447707.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-18
Publication Date
2026-09-25
Estimated Expiration
2042-11-18

AI Technical Summary

Technical Problem

[0004]针对现有技术的缺陷,本发明的目的在于提供一种软件安全防护系统及方法,旨在解决现有的软件水印、代码混淆以及防纂改手段建立在计算机系统白盒环境中存在安全性较低且强度不足的问题

Benefits of technology

[0025]本发明提供了一种软件安全防护系统及方法,其中提出了软件安全防护系统提供了分离执行环境,嵌入式处理器作为一种处理器,SDRAM运行空间作为一种内存,可以通过调用计算机系统中应用程序中的关键代码,将应用程序的核心运算由软件安全防护系统进行操作(将计算机系统中的关键程序代码移植到安全防护系统中隔离运行),构建了基于硬件隔离的分离执行过程,实现了对计算机系统中关键软件代码的安全防护,相比传统的软件方式更具有安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115828193B_ABST
    Figure CN115828193B_ABST
Patent Text Reader

Abstract

The application provides a software security protection system and method, and belongs to the field of computer security and embedded hardware, and the system comprises an embedded processor, an SDRAM operation space, a high-speed communication interface, an encryption operation engine, a flash memory and a secure storage interface; the embedded processor is used for providing logical operation resources for the operation of key codes; the SDRAM operation space is used for providing operation cache for the separated operation codes; the high-speed communication interface is used for completing data communication and task calling with a computer system; the encryption operation engine is used for verifying the computer system environment and the user identity; the flash memory is used for storing sensitive data or core code images; and the secure storage interface is used for completing the reading and writing of the flash memory. A separated execution process based on hardware isolation is constructed, the security protection of key software codes in the computer system is realized, and the security is higher than that of the traditional software mode.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the fields of computer security and embedded hardware, and more specifically, relates to a software security protection system and method. Background Technology

[0002] With the development of software technology, reverse engineering techniques are also constantly advancing. Especially in network environments, many software programs run in uncertain or even malicious conditions, allowing hosts to arbitrarily analyze and trace them. Furthermore, the emergence of various reverse engineering techniques has made software analysis much easier. By using tools such as disassemblers, decompilers, debuggers, and a series of automated reverse analysis frameworks, attackers can easily view and modify data in memory. How to protect the core algorithms and execution logic of software has now become a focal point of attention.

[0003] The ever-evolving static and dynamic analysis of software, code deobfuscation, and malicious tampering techniques have created a demand for secure protection of computer software code. Traditional software watermarking, code obfuscation, and anti-tampering methods, which operate in a white-box environment, offer relatively low security and insufficient strength. Summary of the Invention

[0004] In view of the shortcomings of the prior art, the purpose of this invention is to provide a software security protection system and method, which aims to solve the problems that existing software watermarking, code obfuscation and anti-tampering measures are based in a white-box environment of computer system and have low security and insufficient strength.

[0005] To achieve the above objectives, in one aspect, the present invention provides a software security protection system, comprising: an embedded processor, an SDRAM operating space, a high-speed communication interface, an encryption operation engine, a Flash memory, and a secure storage interface;

[0006] The high-speed communication interface is bidirectionally connected to the embedded processor; the SDRAM operating space and the output of the encryption operation engine are connected to the embedded processor.

[0007] The embedded processor provides logical operation resources for the execution of critical code; the SDRAM runtime space provides runtime cache for separate running code; the high-speed communication interface is used to complete data communication and task invocation with the computer system; the encryption engine is used to verify the computer system environment and user identity; the Flash memory is used to store sensitive data or core code images; and the secure storage interface is used to complete reading and writing of the Flash memory.

[0008] More preferably, the software security protection system further includes a buffer, which is connected to a high-speed communication interface, an SDRAM operating space, an embedded processor, and a secure storage interface; the buffer is used to buffer data.

[0009] More preferably, the software security protection system also includes a random number generator, the output of which is connected to an embedded processor to generate a random number key between the computer system and the embedded processor, thereby strengthening the verification of the computer system environment and user identity.

[0010] More preferably, the software security protection system also includes a timer for continuously triggering the encryption engine and random number generator to periodically check the computer system environment and user identity.

[0011] On the other hand, the present invention provides a software security protection method, comprising the following steps:

[0012] S1: The embedded processor is connected to the computer system through a high-speed communication interface. An encryption engine is used to verify the computer system environment and user identity. After the verification is successful, proceed to S2.

[0013] S2: The computer system's application sends instructions to call critical code to the embedded processor, intercepts the Linux system call in kernel mode and packages the relevant parameters, sends a request to the software security protection system using the communication protocol, executes the critical program image in the separate execution environment, and sends the result to the computer system through the high-speed communication interface after execution, and then transfers to S3; where the separate execution environment is the operating environment of the software security protection system, isolated from the computer system;

[0014] S3: The open function, driven by the application in the computer system, completes the critical code opening function and initializes the session linked list;

[0015] S4: Open sessions based on session linked lists and create proxy communication services in a detached execution environment;

[0016] S5: Allocate or register a block of shared memory in the computer system to store and separate data and control commands transferred between execution environments;

[0017] S6: Call the ioctl function in shared memory to send commands from the computer system to the detached execution environment. The detached execution environment schedules the secure communication service process to perform related transmission functions until the computer system issues a session closure command to the detached execution environment.

[0018] More preferably, S1 specifically includes the following steps:

[0019] The embedded processor is connected to the computer system via a high-speed communication interface;

[0020] After the software security protection system is inserted into the computer system, a timer is set; the timer continuously triggers the random number generator to generate random number keys, and then triggers the encryption engine to periodically check the computer system environment and user identity;

[0021] If the verification is successful, the software security protection system will respond to the legitimate call request from the computer system and execute the critical algorithm code; otherwise, it will prompt an unauthorized system or user and exit the software security protection system.

[0022] More preferably, the remote call in kernel mode uses system call APIs and communication protocols for remote calls. The system call APIs and communication protocols include system call conventions, executable program formats, program dependency libraries, and data type specifications.

[0023] In summary, compared with the prior art, the above-described technical solutions conceived by this invention have the following advantages:

[0024] Beneficial effects:

[0025] This invention provides a software security protection system and method. The software security protection system provides a separate execution environment, with an embedded processor as a processor and SDRAM as a memory. By calling key code in the application of the computer system, the core operation of the application can be operated by the software security protection system (the key program code in the computer system is ported to the security protection system for isolated execution). This constructs a hardware-isolated separate execution process, realizing the security protection of key software code in the computer system, which is more secure than traditional software methods.

[0026] This invention employs an encryption computing engine to support the security verification function of a computer system based on cryptographic algorithms. It binds the computer system application with the software security protection system. If the verification is successful, the software security protection system can respond to the computer system's legitimate call request and execute the application's key algorithm code; otherwise, it prompts an unauthorized system or unauthorized user, strictly restricting the unauthorized operation of the computer system by unauthorized users.

[0027] In this invention, the embedded processor supports general Linux API interface calls, intercepts Linux system requests for critical software code in kernel mode, and sends requests to the software security protection system using communication protocols, thereby achieving secure access control.

[0028] The remote invocation method for a separate execution environment provided by this invention uses computer system call APIs and communication protocols, including various details such as system call conventions, executable program formats, program dependency libraries, and data type specifications, reducing the implementation complexity of the separate execution environment and providing a consistent remote invocation interface for computer systems.

[0029] This invention provides a method to set up a memory in a computer system, use the ioctl function to send commands from the computer system to a separate execution environment, and have the separate execution environment schedule a secure communication service process to perform related transmission functions. By using a secure communication proxy, hardware layer operations are shielded, making it easy to conduct secondary development and use. Attached Figure Description

[0030] Figure 1 This is a basic hardware construction diagram of the software security protection system provided in the embodiments of the present invention;

[0031] Figure 2 This is a flowchart of the system security detection process provided in an embodiment of the present invention;

[0032] Figure 3 This is a diagram illustrating the remote invocation method of the separated execution environment provided in this embodiment of the invention;

[0033] Figure 4 This is a flowchart of the secure communication proxy service provided in an embodiment of the present invention. Detailed Implementation

[0034] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0035] This invention provides a software security protection method and system, the overall concept of which involves the following four aspects: embedded runtime environment construction, secure storage, cryptographic algorithms, and communication interface establishment; when the software security protection system is connected to a Linux computer system, it can perform hardware and software binding with key programs in the Linux system to prevent unauthorized use and execution of unauthorized versions. Simultaneously, the core functional modules or key algorithms in the Linux system's software programs are ported to the secure environment of the software security protection system for separate execution, thereby preventing malicious reverse engineering and analysis; the specific technical solution is as follows:

[0036] S1: Build a software security protection system;

[0037] The software security protection system includes: an embedded processor, SDRAM operating space, a high-speed communication interface, an encryption engine, Flash memory, a buffer, a random number generator, and a secure storage interface. The embedded processor provides logical operation resources for the execution of critical code. The embedded processor achieves bidirectional communication with the computer system environment through the high-speed communication interface. The SDRAM operating space provides sufficient runtime cache for separately running code. The high-speed communication interface completes data communication and task invocation with the computer system. The encryption engine provides hardware algorithm support, operates quickly, consumes low power, and does not consume system resources. The Flash memory ensures the security of sensitive data or core code images. The buffer buffers data. The random number generator generates random number keys between the computer system and the embedded processor, strengthening the verification of the computer system environment and user identity. The secure storage interface completes reading and writing to the Flash memory.

[0038] S2: System security detection;

[0039] After the software security protection system is connected to the computer system and started, the system uses its integrated encryption engine to continuously verify the host system environment and user identity. If the verification passes, the computer system is marked as legitimate and communication is allowed; otherwise, the communication request from the corresponding host system is rejected. More specifically:

[0040] To prevent unauthorized use of software, the software security protection system designed in this invention uses cryptographic algorithms to bind legitimate user identities and system environments, and can continuously and periodically check, stopping operation if a correct response is not received.

[0041] The operation process after software protection is as follows Figure 2 As shown; after the software security protection system is inserted into the computer system, a timer is set to verify the identity of the computer system and the current user; after verification, it can respond to the legitimate call requests of the computer system and execute key algorithm code; during use, the timer is continuously triggered to periodically check the identity of the computer system and the current user. If it passes the verification, it continues to run; otherwise, it prompts an illegal system or illegal user and exits the software.

[0042] S3: Remote Procedure Call;

[0043] This system implements a remote system call mechanism for software security protection based on the Linux system's API (Application Binary Interface). It intercepts Linux system calls in the computer system's kernel mode, packages the relevant parameters, and sends a request to the software security protection device using a communication protocol. The critical program image is then executed in a separate execution environment. After execution, the result is sent back to the computer environment via the communication interface, thus completing the entire system call process. The separate execution environment is a secure operating environment isolated from the computer system, jointly constructed by the embedded processor and other related resources. More specifically:

[0044] like Figure 3 As shown, a separate execution environment needs to meet two conditions to execute critical program code of a computer system: providing Linux system call APIs using the remote system call mechanism and implementing an ELF program loader that conforms to the Linux ABI (Application Binary Interface). The basic idea of ​​the remote system call mechanism is to use the computer system function server to implement system calls not provided by the separate execution environment, thereby providing a consistent system call interface for the upper layer and reducing the implementation complexity of the separate execution environment. The Linux ABI describes the low-level interface between an application and the operating system, or between an application and its dependent libraries, or between components of an application. The application binary interface contains various details, such as system call conventions, executable program format, program dependent libraries, and data type specifications.

[0045] S4: communication agent;

[0046] Communication between the separate execution environment and the computer system is implemented using Linux drivers, abstracting the separate execution environment as a character device; ioctl is used to send commands to the software security protection system and package parameters; mmap is used to create shared memory; the communication agent within the computer system is a daemon process used to receive commands from ordinary processes of the computer system; and high-security service processes are created to perform communication.

[0047] like Figure 4 As shown, the secure communication proxy service specifically includes the following steps:

[0048] The device is opened by the application-driven open function in the secure operating environment. This function creates a service list and initializes the session list for each service. The service list is stored in a private data field of the file descriptor.

[0049] Open a session, create a proxy communication service in the separate execution environment, and establish a communication connection between the computer system environment and the separate execution environment;

[0050] Allocate or register a block of shared memory to store the transmission data and control commands of the host system's decoupled execution environment and to receive data returned from the server;

[0051] Sending commands is accomplished by the ioctl function driven by the host system security agent, which separates the execution environment from the specific secure communication service process that performs the relevant transmission functions.

[0052] Close the session, and shut down the communication connection between the general computer system process and the detached execution environment;

[0053] Release shared memory and shut down the device.

[0054] In summary, compared with the prior art, the present invention has the following advantages:

[0055] This invention provides a software security protection system and method. The software security protection system provides a separate execution environment, with an embedded processor as a processor and SDRAM as a memory. By calling key code in the application of the computer system, the core operation of the application can be operated by the software security protection system (the key program code in the computer system is ported to the security protection system for isolated execution). This constructs a hardware-isolated separate execution process, realizing the security protection of key software code in the computer system, which is more secure than traditional software methods.

[0056] This invention employs an encryption computing engine to support the security verification function of a computer system based on cryptographic algorithms. It binds the computer system application with the software security protection system. If the verification is successful, the software security protection system can respond to the computer system's legitimate call request and execute the application's key algorithm code; otherwise, it prompts an unauthorized system or unauthorized user, strictly restricting the unauthorized operation of the computer system by unauthorized users.

[0057] In this invention, the embedded processor supports general Linux API interface calls, intercepts Linux system requests for critical software code in kernel mode, and sends requests to the software security protection system using communication protocols, thereby achieving secure access control.

[0058] The remote invocation method for a separate execution environment provided by this invention, through computer system calls APIs and communication protocols, includes various details such as system call conventions, executable program formats, program dependency libraries, and data type specifications, reducing the implementation complexity of the separate execution environment and providing a consistent remote invocation interface for the computer system.

[0059] This invention provides a method to set up a memory in a computer system, use the ioctl function to send commands from the computer system to a separate execution environment, and have the separate execution environment schedule a secure communication service process to perform related transmission functions. By using a secure communication proxy, hardware layer operations are shielded, making it easy to conduct secondary development and use.

[0060] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A software security protection system, characterized in that, include: Embedded processor, SDRAM operating space, high-speed communication interface, encryption engine, Flash memory, secure storage interface, random number generator and timer; The high-speed communication interface is bidirectionally connected to the embedded processor; the SDRAM operating space and the output of the encryption operation engine are connected to the embedded processor. The embedded processor, as a type of processor, is used to provide logical operation resources for the execution of critical code; The SDRAM operating space, as a type of memory, is used to provide a runtime cache for separate running code; the high-speed communication interface is used to complete data communication and task invocation with the computer system; the encryption engine is used to verify the computer system environment and user identity; the Flash memory is used to store sensitive data or core code images; The secure storage interface is used to read and write to the Flash memory; The output of the random number generator is connected to the embedded processor to generate random number keys between the computer system and the embedded processor, thereby strengthening the verification of the computer system environment and user identity. A timer is used to continuously trigger the encryption engine and random number generator to periodically check the computer system environment and user identity.

2. The software security protection system according to claim 1, characterized in that, It also includes a buffer, which is connected to a high-speed communication interface, an SDRAM operating space, an embedded processor, and a secure storage interface; the buffer is used to buffer data.

3. A software security protection method based on the software security protection system of claim 1, characterized in that, Includes the following steps: S1: The embedded processor is connected to the computer system through a high-speed communication interface. An encryption engine is used to verify the computer system environment and user identity. After the verification is successful, proceed to S2. S2: The computer system's application sends instructions to the embedded processor to call critical code. The kernel mode of the computer system intercepts the Linux system call and packages the relevant parameters. It then sends a request to the software security protection system using a communication protocol. The critical program image is executed in the separate execution environment. After execution, the result is sent back to the computer system through a high-speed communication interface, and the process is transferred to S3. The separate execution environment is the operating environment of the software security protection system, which is isolated from the computer system. S3: The open function, driven by the application in the computer system, completes the critical code opening function and initializes the session linked list; S4: Open a session based on the session list, create a proxy communication service in the detached execution environment, and allocate or register a shared memory in the computer system to store the data transmitted between the detached execution environment and the control instructions. S5: Call the ioctl function in shared memory to send commands from the computer system to the detached execution environment. The detached execution environment schedules the secure communication service process to perform related transmission functions until the computer system issues a session closure command to the detached execution environment.

4. The software security protection method according to claim 3, characterized in that, S1 specifically includes the following steps: The embedded processor is connected to the computer system via a high-speed communication interface; After the software security protection system is inserted into the computer system, a timer is set; the timer continuously triggers the random number generator to generate random number keys, and then triggers the encryption engine to periodically check the computer system environment and user identity; If the verification is successful, the software security protection system will respond to the legitimate call request from the computer system and execute the critical algorithm code; otherwise, it will prompt an unauthorized system or user and exit the software security protection system.

5. The software security protection method according to claim 3 or 4, characterized in that, Kernel-mode remote calls use system call APIs and communication protocols. These include system call conventions, executable program formats, program dependency libraries, and data type specifications.

Citation Information

Patent Citations

  • Software protection method, hardware encryption equipment and software protection system comprising hardware encryption equipment

    CN104462882A

  • Method for realizing application program safety certification based on CPU space-time isolating mechanism

    CN106815494A

  • Internet-of-Things equipment safety protection system and method

    CN113014539A