A method, apparatus, device, and storage medium for encrypting and deploying bytecode files
By generating encryption keys in the Java running environment directory and encrypting Java bytecode files using DES algorithm, combined with custom class loader decryption and loading, the problem of Java bytecode files being easily decompiled is solved, and the secure deployment and core logic protection of Java applications are realized.
Patent Information
- Application Number
- CN202411098300.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-12
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-08-12
AI Technical Summary
Java bytecode files are easily decompiled, resulting in the leakage and illegal use of the company's core business logic.
Generate a key file in the Java running environment directory of the target server, generate an encryption key using the creation time and physical address of the key file, encrypt the encrypted archive file through the DES data encryption algorithm, and decrypt and load the file in JVM memory using a customized class loader.
Ensure that the encryption keys on each server are unique, prevent unauthorized access and use, protect the enterprise's core business logic and sensitive information, and enhance the security and deployment integrity of Java bytecode files.
Smart Images

Figure CN119026093B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and software encryption, and particularly relates to a method, device, equipment and storage medium for encrypting and deploying bytecode files. Background Art
[0002] As a widely used programming language, the Java language is favored by global developers due to its high development efficiency, cross-platform nature, stability, and strong scalability. Its feature of "write once, run anywhere" makes Java a common solution for large Internet platforms. The cross-platform nature of Java is mainly reflected in its compilation process: Java source code is not directly compiled into binary executable files for specific operating systems, but into bytecode files (i.e., .class files). These bytecode files are executed by the Java Virtual Machine (JVM for short). Oracle Corporation, as the main provider of the Java language, provides corresponding JVMs for almost all operating systems, which enables the compiled bytecode files to run in multiple operating system environments, further strengthening the cross-platform advantage of the Java language.
[0003] Although the Java language has its unique advantages in the development, deployment, and operation stages, the defect that Java bytecode files are easily decompiled brings significant security risks. In the development stage of a Java project, developers write Java source code according to business logic and compile it into bytecode files. Usually, multiple bytecode files are packaged into an archive file (such as a JAR package) for easy management and deployment. In the deployment stage, enterprises copy these compiled bytecode files to the server. Due to the widespread existence of the JVM, there are almost no restrictions on the types of server operating systems. However, these bytecode files deployed on the server are easily decompiled into the original Java source code, thereby leaking the core business logic of the enterprise. Therefore, how to effectively encrypt and protect Java bytecode files to prevent unauthorized access and use has become an urgent problem to be solved. Summary of the Invention
[0004] The present application provides a method, device, equipment and storage medium for encrypting and deploying bytecode files, aiming to solve the technical problem in the prior art that Java bytecode files are easily decompiled, resulting in the possible leakage and illegal use of the core business logic of enterprises.
[0005] In view of the above problems, the present application provides a method, device, equipment and storage medium for encrypting and deploying bytecode files.
[0006] The first aspect disclosed in this application provides a method for encrypting and deploying bytecode files. The method includes generating a secret key file in the Java runtime environment directory of the target server, obtaining the creation time of the secret key file and the physical address of the target server, generating an encryption key based on the creation time and the physical address, and storing it in the secret key file. The secret key file consists of 32 random characters; obtaining the Java source file, compiling and packaging the Java source file to obtain a set of target archive files, where the target archive files include multiple bytecode files; identifying the set of target archive files, determining the set of archive files to be encrypted and the set of non-encrypted archive files, where the archive files to be encrypted are the archive files related to predetermined business metrics; based on the encryption key in the secret key file, symmetrically encrypting the archive files to be encrypted using the DES data encryption algorithm to obtain a set of encrypted archive files; copying the set of non-encrypted archive files and the set of encrypted archive files to a specified directory of the target server to obtain a set of target binary files; performing data decryption on the set of target binary files in the specified directory of the target server, and using a custom class loader to load the successfully decrypted archive files and the non-encrypted archive files into the JVM memory of the target server, where the custom class loader is built based on the C++ language.
[0007] The second aspect disclosed in this application provides an apparatus for encrypting and deploying bytecode files. The apparatus includes an encryption key generation module: used to generate a secret key file in the Java runtime environment directory of the target server, obtain the creation time of the secret key file and the physical address of the target server, generate an encryption key based on the creation time and the physical address, and store it in the secret key file. The secret key file consists of 32 random characters; a compilation and packaging module: used to obtain the Java source file, compile and package the Java source file to obtain a set of target archive files, where the target archive files include multiple bytecode files; an archive file set identification module: used to identify the set of target archive files, determine the set of archive files to be encrypted and the set of non-encrypted archive files, where the archive files to be encrypted are the archive files related to predetermined business metrics; a symmetric encryption module: used to symmetrically encrypt the archive files to be encrypted using the DES data encryption algorithm based on the encryption key in the secret key file to obtain a set of encrypted archive files; a binary file set obtaining module: used to copy the set of non-encrypted archive files and the set of encrypted archive files to a specified directory of the target server to obtain a set of target binary files; a data decryption module: used to perform data decryption on the set of target binary files in the specified directory of the target server, and use a custom class loader to load the successfully decrypted archive files and the non-encrypted archive files into the JVM memory of the target server, where the custom class loader is built based on the C++ language.
[0008] In a third aspect, the present application also provides an electronic device, including: a memory for storing executable instructions; and a processor for implementing a method for encrypting and deploying bytecode files provided by the present application when executing the executable instructions stored in the memory.
[0009] In a fourth aspect, the present application also provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements a method for encrypting and deploying bytecode files provided by the present application.
[0010] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0011] Due to the technical solution of generating a secret key file in the Java runtime environment directory of the target server and generating an encryption key based on the creation time of the secret key file and the physical address of the target server, the problem that the encryption key may be reused and leaked in the traditional method is solved, ensuring that the encryption key on each server is unique. Through this method, the generated encryption key is tightly bound to a specific server environment, achieving the technical effect of enhancing the security of Java bytecode files. This solution effectively prevents unauthorized access and use, making the application highly secure and integral when deployed on different servers, and protecting the enterprise's core business logic and sensitive information.
[0012] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically gives the specific embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 It is a flowchart of a method for encrypting and deploying bytecode files of the present application.
[0014] Figure 2 It is a schematic structural diagram of a device for encrypting and deploying bytecode files of the present application.
[0015] Figure 3 It is a schematic structural diagram of an exemplary electronic device of the present application.
[0016] Figure 4 It is a flowchart of decrypting and loading an encrypted bytecode file of a method for encrypting and deploying bytecode files of the present application.
[0017] Explanation of the accompanying drawings: encryption key generation module 11, compilation and packaging module 12, archive file set identification module 13, symmetric encryption module 14, binary file set acquisition module 15, data decryption module 16, processor 31, memory 32, input device 33, output device 34. DETAILED DESCRIPTION
[0018] The overall idea of the technical solution provided by this application is as follows:
[0019] The embodiments of the present application provide a method, apparatus, device and storage medium for bytecode file encryption deployment. First, a Java source file is obtained and compiled to generate a target archive file set, which includes multiple bytecode files. Then, the archive files to be encrypted and non-encrypted are identified and distinguished according to business needs. For the files to be encrypted, the generated encryption key and DES algorithm are used for encryption processing. Subsequently, the encrypted and non-encrypted file sets are deployed to the specified directory of the target server. On the server, a custom class loader is used to perform the decryption and loading process of the encrypted file. The loader supports the decryption of encrypted files and the loading of standard files, thereby ensuring file security and the normal operation of the application.
[0020] After introducing the basic principles of the present application, various non-limiting implementation methods of the present application will be specifically described below in conjunction with the drawings in the specification.
[0021] Embodiment 1, as Figure 1 As shown, the embodiment of the present application provides a method for encrypting and deploying a bytecode file, the method comprising:
[0022] Step S100: Generate a key file in the Java runtime environment directory of the target server, obtain the creation time of the key file and the physical address of the target server, generate an encryption key based on the creation time and physical address, and store it in the key file, wherein the key file is 32-bit random characters.
[0023] Specifically, the target server refers to a computer or server that runs a Java application and is used to store and execute Java bytecode files. The Java runtime environment directory refers to the installation path of the Java runtime environment, which usually includes the JVM, Java class libraries, and related configuration files. The key file is a file used to store the generated encryption keys and is an essential element in the encryption and decryption operations. This file is identified by 32 random characters to ensure the uniqueness of the key files generated on each server. The creation time refers to the timestamp when the key file is generated, which can record the specific creation date and time to ensure the uniqueness and timeliness of the file. The physical address is the MAC address (Media Access Control Address), which is the hardware address of the network interface card and is used to uniquely identify a network device. The encryption key is a password string generated using the creation time and the physical address and is used to encrypt the Java bytecode files. The encryption key ensures the confidentiality of the bytecode files. The 32 random characters refer to the identifier of the key file, which consists of 32 randomly generated characters to increase security and unpredictability.
[0024] First, a key file is generated under the Java runtime environment directory of the target server. This file is named with 32 random characters. Next, the creation time of this key file and the physical address (MAC address) of the target server are obtained. These information (creation time and physical address) are concatenated into a string and then encrypted through the MD5 encryption algorithm to generate a unique encryption key.
[0025] In summary, this method enhances the security of Java bytecode files by generating unique encryption keys and uses various technical tools to ensure the security and effectiveness of the encryption process.
[0026] Step S200: Obtain the Java source file, compile and package the Java source file to obtain a set of target archive files, where the target archive file includes multiple bytecode files.
[0027] Specifically, the set of target archive files refers to the finally generated set that includes multiple bytecode files, usually packaged into one or more JAR files for deployment and execution.
[0028] First, developers write Java source files that contain specific business logics and functional implementations.
[0029] Use the Java compiler (javac) to compile Java source files into bytecode files. For example, running the command javac MyApp.java will generate a bytecode file named MyApp.class. Compilation is usually performed in a command-line environment or an integrated development environment (IDE). Common IDEs include Eclipse, IntelliJ IDEA, NetBeans, etc. These tools automate the compilation process. The compiler converts the source code into bytecode, and these bytecode files can be executed across platforms because they rely on the JVM rather than the operating system.
[0030] Use the Java Archive Tool (jar) to package multiple bytecode files into a JAR file. Running the command jar cvf MyApp.jar MyApp.class will generate an archive file named MyApp.jar, which contains MyApp.class. A JAR file can contain multiple files and directories, similar to a ZIP file. The directory structure is preserved during the packaging process, so that the package dependencies between classes are not lost. In addition to bytecode files, JAR files can also contain other resources, such as configuration files, icons, and documents. These files are compressed and stored together with the bytecode during packaging.
[0031] Through this step, developers can successfully convert Java source files into a set of target archive files that can be executed in various environments, enabling cross-platform deployment and running of applications.
[0032] Step S300: Identify the set of target archive files, determine the set of archive files to be encrypted and the set of non-encrypted archive files, where the archive files to be encrypted are the archive files related to the predetermined business metrics.
[0033] Specifically, the set of archive files to be encrypted refers to the set of files selected from the set of target archive files that contain key business logic or sensitive information and need to be encrypted for protection. The set of non-encrypted archive files refers to the set of files that do not involve sensitive information and do not need to be encrypted and can be directly deployed and executed. The predetermined business metrics are the criteria or rules for determining which archive files need to be encrypted, usually involving the enterprise's core business logic, proprietary algorithms, or sensitive data processing, etc.
[0034] Use Java decompilation tools (such as JD-GUI, CFR) and archive management tools (such as the jar command) to analyze the content of the JAR file. View the various classes and packages in the JAR file through the decompilation tool to understand its functions and business logic.
[0035] Define which functions or data need special protection according to the business requirements and data security policies of the enterprise. Use business metrics (such as sensitive data processing, algorithm implementation) to identify the key types of files in the target archive file set. Divide the files into encrypted and non-encrypted file sets according to the identified business criticality. This process can be automated using scripts (such as Python or Bash), and files can be automatically identified and classified through file name or package name rules. Generate a list of files to be encrypted and record which files need to be encrypted. It can be saved in the form of a text file or a configuration file.
[0036] By identifying and classifying the files in the target archive file set, the enterprise can ensure that sensitive business logic is effectively protected and reduce the potential risks brought by code leakage. In this process, a reasonable definition of business metrics is the key to ensuring the accuracy and efficiency of the identification process.
[0037] Step S400: Based on the encryption key in the secret key file, use the DES data encryption algorithm to perform symmetric encryption on the archive file to be encrypted, obtaining an encrypted archive file set.
[0038] Specifically, the DES data encryption algorithm is a symmetric encryption algorithm, that is, the same key is used for encryption and decryption. DES realizes data encryption by performing multiple permutation and substitution operations on the data. Symmetric encryption is a type of encryption method that uses the same key for encryption and decryption, mainly used to protect the confidentiality of data. The encrypted archive file set refers to the set of files after encryption processing. These files contain sensitive information in the archive file set to be encrypted and cannot be directly read or decompiled without authorization.
[0039] Use the javax.crypto package in Java to implement DES encryption. First, initialize a DES key object and create an encryption key object using the generated encryption key through SecretKeySpec. Use the Cipher class to configure the DES encryption algorithm and encrypt each bytecode file to be encrypted one by one. Save the encrypted data as a new encrypted archive file. The encrypted files are packaged into an encrypted archive file set, and these files can be safely deployed to the server to prevent unauthorized access and reverse engineering.
[0040] By using the encryption key in the secret key file and the DES data encryption algorithm, the enterprise can effectively protect the archive files containing sensitive information in the Java application. This encryption process ensures the secure transmission and deployment of files, reducing the risks of information leakage and unauthorized access.
[0041] Step S500: Copy the non-encrypted archive file set and the encrypted archive file set to the specified directory on the target server, obtaining a target binary file set.
[0042] Specifically, the specified directory refers to a specific file path on the target server for storing Java archive files, usually the working directory or deployment directory of the application. The set of target binary files refers to the collection of all Java archive files in the specified directory, ready to be executed in the Java Virtual Machine (JVM).
[0043] Create the specified directory on the target server for storing archive files. Use a file transfer tool (such as scp, rsync, or an FTP client) to upload the set of non-encrypted archive files and encrypted archive files from the local machine to the specified directory on the target server. Ensure that all archive files (encrypted and non-encrypted) have been correctly copied to the target directory to form a complete set of target binary files. Check the integrity and correctness of the files to ensure that all necessary files exist and are not corrupted, which can be verified through file hash verification (such as md5sum or sha256sum). On the target server, set the appropriate permissions for the archive files to ensure that the Java application can correctly access and execute these files. Use Linux command-line to set file permissions, and set more restrictive access permissions for encrypted files containing sensitive information to prevent unauthorized access. After completing the file copy, perform a simple test run to ensure that all files can be correctly loaded and executed. Check the application logs to ensure that there are no loading or execution errors.
[0044] By copying the set of non-encrypted and encrypted archive files to the specified directory on the target server, an enterprise can effectively deploy a Java application. This process includes steps such as preparing the target directory, uploading files, verifying file integrity, setting permissions, and performing a test run. It can ensure the security and reliability of the application, reducing potential errors and security risks during the deployment process.
[0045] Step S600: Execute data decryption of the set of target binary files in the specified directory on the target server, and use a custom class loader to load the successfully decrypted archive files and non-encrypted archive files into the JVM memory of the target server, where the custom class loader is built based on the C++ language.
[0046] Specifically, use the javax.crypto library in Java or a third-party library to implement the decryption operation of DES encrypted files. It is necessary to generate a decryption key by reading the key file and decrypt the encrypted.class.sec file. Read the content of the encrypted file into memory and use the generated decryption key to decrypt the file content through the DES decryption algorithm to restore the original bytecode data. Use the information in the key file, such as creation time and physical address, to generate the decryption key through MD5.
[0047] Since the target JVM is a customized version, the customized class loader is written in C++ and is compatible with loading encrypted.class.sec and ordinary.class files. The customized class loader interacts with the C++ code through JNI (Java Native Interface) to implement the decryption and loading logic of encrypted files. The class loader determines whether a file is encrypted based on its file extension. If it is an encrypted file, it first performs decryption and then loads the decrypted bytecode into the JVM memory.
[0048] Use the customized class loader to load and execute the Java application, and load all required class files through a custom ClassLoader instance. The customized class loader supports loading ordinary bytecode files that are not encrypted, ensuring compatibility with the standard Java class loader. Start the application and test the key functions to ensure that all class files (encrypted and unencrypted) can be correctly loaded and executed.
[0049] By performing data decryption on the target server and using the customized class loader to load Java bytecode files, enterprises can effectively protect the security of their Java applications. While being compatible with the standard class loader, the customized class loader adds a decryption function, enabling the application to utilize the cross-platform features of Java while ensuring the security of its core logic.
[0050] Furthermore, generate an encryption key, including: obtaining the creation time of the key file under the Java runtime environment directory, and reading the physical address of the target server; concatenating the creation time and the physical address, and encrypting the concatenated content using the MD5 encryption algorithm to generate an encryption key.
[0051] Specifically, the MD5 encryption algorithm is a hashing algorithm used to convert input data into a fixed-length hash value, usually used for data integrity verification.
[0052] During the secure deployment process of a Java application, in order to generate a unique encryption key, it is first necessary to obtain the creation time of the key file under the Java runtime environment directory of the target server and the physical address of the server. The creation time can be obtained through file attributes or operating system commands. For example, on a Linux system, the stat command can be used to view the detailed information of a file, while the physical address can be obtained through system commands such as ipconfig / all (Windows) or ifconfig (Linux). Assume that the creation time of the key file is "2024-08-01 10:30:45" and the physical address is "00:1A:2B:3C:4D:5E".
[0053] Next, concatenate the creation time and the physical address into a string: "2024-08-01 10:30:45 00:1A:2B:3C:4D:5E". This concatenated string combines the time and the hardware identification information of the device, ensuring its uniqueness. Then, use the MD5 encryption algorithm to encrypt this string to generate a 32-character hash value as the encryption key. The use of the MD5 algorithm can be implemented through library functions in various programming languages. For example, in Java, the java.security.MessageDigest class can be used to implement MD5 encryption. Assume the generated MD5 hash value is "e99a18c428cb38d5f260853678922e03", and this value is the key used to encrypt the bytecode file.
[0054] By obtaining the creation time of the secret key file and the physical address of the server and using the MD5 algorithm to generate an encryption key, enterprises can generate a unique and secure encryption key for their Java applications. This ensures the security and protection capabilities of the application, preventing unauthorized access and use.
[0055] Furthermore, determine the set of files to be encrypted and the set of non-encrypted files, including: configuring predetermined business metrics based on the business logic of the target enterprise; screening the target set of archive files according to the predetermined business metrics, setting the target archive files related to the predetermined business metrics as the files to be encrypted, and setting the target archive files not related to the predetermined business metrics as non-encrypted files, to obtain the set of files to be encrypted and the set of non-encrypted files.
[0056] Specifically, the business logic of the target enterprise refers to the specific functions and operation rules implemented in its application programs, and these logics are usually closely related to the core business and competitiveness of the enterprise.
[0057] Analyze the core business processes and application program architectures of the enterprise to identify which functions and logics are critical or sensitive. For example, the transaction processing module, customer information management module, etc. in financial software.
[0058] Based on the analysis results, define which files need to be encrypted and protected. Business metrics may include: modules involved in financial calculations, user authentication and authorization modules, data encryption and decryption algorithms, etc.
[0059] Utilize code analysis tools or scripts to automate the screening process. For example, use Java analysis tools (such as JDepend or SonarQube) to identify files related to specific packages or classes. Scan and analyze the bytecode files in the target set of archive files, and mark the files that match the predetermined business metrics. Use tools such as regular expressions to search for file names or package names to help identify the files that need to be encrypted.
[0060] Mark the files that match the business metrics as files to be encrypted. Mark the files that do not meet the business metrics as non-encrypted files. Record the lists of files to be encrypted and non-encrypted for subsequent encryption and deployment use. According to the generated list of files to be encrypted, use the previously generated encryption key to encrypt the files to be encrypted. Prepare the encrypted and non-encrypted file sets for deployment to the target server.
[0061] For example, in an online payment system, an enterprise identifies the modules involved in transaction processing and customer authentication as sensitive components. The bytecode files of these modules are screened as files to be encrypted to ensure protection during deployment. A medical software company develops an electronic health record management system, and the logic for processing patient data and medical decision support therein is identified as requiring encryption protection. Through the analysis of the business logic, the company screens out these key modules for encryption to ensure patient privacy and data security.
[0062] By configuring predefined business metrics based on the enterprise's business logic and screening the target set of archived files, the enterprise can effectively identify and encrypt the bytecode files that need to be protected. This process ensures that the enterprise's critical business logic and sensitive information are protected during deployment, reducing the risks brought by code leakage. By using automated tools and clear business metrics, the enterprise can efficiently implement this protection measure to ensure the security and reliability of its Java applications.
[0063] Furthermore, as Figure 4 shown, use a custom class loader to load the successfully decrypted archived files and unencrypted archived files into the JVM memory of the target server, including: in the specified directory of the target server, respectively determine whether each of the multiple target binary files in the target binary file set is encrypted; if the target binary file is an encrypted archived file, decrypt the data of the encrypted archived file, and use the custom class loader to load the successfully decrypted archived file into the JVM memory of the target server according to the encrypted loading method, where the custom class loader is written and constructed based on the C++ language and can execute the original loading method and the encrypted loading method.
[0064] Specifically, ensure that all target binary files (including encrypted and unencrypted files) are stored in the specified directory of the server. Determine whether a file is an encrypted archived file through the file extension (such as.class.sec) or file header identification. This can be achieved through simple file traversal and extension check.
[0065] Implement data decryption using encryption libraries in Java or C++ (such as OpenSSL, Bouncy Castle, etc.). By reading the content of the encrypted file, use the generated encryption key to decrypt it into the original bytecode. After reading the encrypted file, through a customized decryption algorithm, convert the data into a loadable original bytecode form for the customized class loader to load.
[0066] The customized class loader is written in C++ and uses JNI to interact with the JVM. It can select an appropriate loading strategy according to the encryption status of the file. For encrypted files, the customized class loader first calls the decryption function and then loads the decrypted bytecode into the JVM memory.
[0067] By using the customized class loader to load encrypted Java bytecode files on the target server, enterprises can ensure the security and functionality of the application. The customized class loader combines the decryption and loading functions, enabling the application to run securely in different environments.
[0068] Furthermore, as Figure 4 shown, if the target binary file is an unencrypted archive file, use the customized class loader to load the unencrypted archive file into the JVM memory of the target server according to the original loading method.
[0069] Specifically, for unencrypted files, the customized class loader directly calls the standard loading method to load the bytecode into the JVM memory. Among them, the original loading method is the loading process of the standard Java class loader for loading unencrypted bytecode files.
[0070] Furthermore, as Figure 4 shown, data decryption of the encrypted archive file includes: reading the second creation time of the key file under the Java runtime environment directory and the second physical address of the current server; concatenating the second creation time and the second physical address, and encrypting the second concatenated content using the MD5 encryption algorithm to generate a decryption key; based on the decryption key, using the DES data encryption algorithm to decrypt the encrypted archive file. If the decryption fails, report an error and exit.
[0071] Specifically, the second creation time refers to the last creation or modification time of the key file on the server, usually used to generate the decryption key. The second physical address refers to the MAC address of the current network interface card of the target server, providing a unique hardware identifier.
[0072] On the target server, obtain the second creation time and the physical address of the current server by reading the secret key file in the Java runtime environment directory. These pieces of information are used to generate the decryption key. To obtain the second creation time, the file system command or programming interface can be used to read the file attributes. For example, on Linux, the stat command can be used to obtain the creation or modification time of a file. To obtain the second physical address, the system command or API is used to obtain the MAC address of the server. On Windows, ipconfig / all can be used, and on Linux, ifconfig or ip addr commands can be used.
[0073] Concatenate the second creation time and the second physical address into a string, and use the MD5 algorithm to encrypt the concatenated content to generate a 32 - character hash value as the decryption key. Concatenation format: For example, assume the creation time is "2024 - 08 - 01 10:30:45" and the physical address is "00:1A:2B:3C:4D:5E", the concatenation result is "2024 - 08 - 01 10:30:4500:1A:2B:3C:4D:5E".
[0074] Use Java's java.security.MessageDigest or the hash library of other programming languages to perform MD5 encryption on the concatenated string to generate the decryption key (such as "e99a18c428cb38d5f260853678922e03").
[0075] Decrypt the encrypted bytecode file through the DES algorithm to restore its original content for loading. Use Java's javax.crypto package or other encryption libraries (such as OpenSSL) for decryption operations. When decrypting, ensure that the key length and format meet the requirements of the DES algorithm. Read the encrypted file, pass its content to the decryption function, and use the decryption key to restore it to the unencrypted bytecode.
[0076] If the decryption process fails, the system needs to report an error and exit to ensure that files in an unauthorized or incorrect environment cannot be loaded. Catch exceptions during the decryption process (such as key mismatch, file corruption, etc.), record the log, and terminate the loading operation. Ensure that when decryption fails, the application does not continue to load incomplete or incorrect bytecode files.
[0077] Through the decryption process of the encrypted archive file, this solution ensures the secure deployment and execution of Java applications on the target server. By generating a decryption key using the creation time of the key file and the physical address of the server, combined with the DES decryption algorithm, it provides a flexible and secure loading solution. Through a rigorous decryption process and error handling, enterprises can reduce the risks of code leakage and unauthorized access while ensuring the security of the application. This solution effectively enhances the security and deployment flexibility of Java applications and is applicable to various complex enterprise environments.
[0078] In summary, the method for encrypting and deploying bytecode files provided by the embodiments of this application has the following technical effects:
[0079] 1. By generating a key file in the Java runtime environment directory of the target server and generating an encryption key based on the file creation time and physical address, the uniqueness of the key for each server is ensured, thereby increasing the security of the application. This method can effectively prevent the reuse and leakage of encryption keys, improving the security of the system, especially when deploying between different servers. Its technical effect is to provide a unique encryption key for each deployment environment, preventing unauthorized access to the environment and the use of the bytecode files of the application, and enhancing the security and reliability of the overall deployment.
[0080] 2. By concatenating the creation time of the key file and the physical address of the target server and using the MD5 algorithm to generate the encryption key, the automation and uniqueness of the generation process are achieved. Using the hash value generated by MD5 as the encryption key ensures the uniqueness and security of the key, effectively preventing key collisions and forgery. This technical effect binds the encryption key to a specific server, increasing the difficulty of unauthorized access, thereby ensuring the secure deployment of Java bytecode files on different servers and enhancing the confidentiality of the application.
[0081] 3. By identifying and classifying the sets of encrypted and non-encrypted archive files in Java applications, enterprises can centrally protect critical business logic and sensitive information. Screening the files that need to be encrypted according to predefined business metrics ensures that the core functions and proprietary algorithms of the enterprise are not leaked. The technical effect of this method lies in optimizing the use of encryption resources, reducing the processing overhead of encryption and decryption, while ensuring that sensitive information is effectively protected, enhancing the security and performance of the application.
[0082] 4. By using a custom class loader to decrypt and load encrypted archive files, it is ensured that only authorized files are loaded and executed in the correct environment. The custom class loader can identify encrypted files and automatically decrypt them, making the deployment process more secure and automated. Its technical effect is to improve the security of the application by increasing the transparency and control of the decryption process, avoiding unauthorized file loading and execution, and ensuring the secure operation of Java applications in different environments.
[0083] Embodiment 2. Based on the same inventive concept as the method for encrypting and deploying bytecode files in the foregoing embodiment, as Figure 2 shown, an embodiment of the present application provides a device for encrypting and deploying bytecode files, and the device includes:
[0084] Encryption key generation module: used to generate a key file in the Java runtime environment directory of the target server, obtain the creation time of the key file and the physical address of the target server, generate an encryption key based on the creation time and the physical address, and store it in the key file, where the key file is 32-bit random characters;
[0085] Compilation and packaging module: used to obtain Java source files, compile and package the Java source files to obtain a set of target archive files, where the target archive files include multiple bytecode files;
[0086] Archive file set identification module: used to identify the set of target archive files, determine the set of archive files to be encrypted and the set of non-encrypted archive files, where the archive files to be encrypted are archive files related to predetermined business metrics;
[0087] Symmetric encryption module: used to symmetrically encrypt the archive files to be encrypted based on the encryption key in the key file by using the DES data encryption algorithm to obtain a set of encrypted archive files;
[0088] Binary file set obtaining module: used to copy the set of non-encrypted archive files and the set of encrypted archive files to a specified directory of the target server to obtain a set of target binary files;
[0089] Data decryption module: used to perform data decryption on the set of target binary files in the specified directory of the target server, and use a custom class loader to load the successfully decrypted archive files and non-encrypted archive files into the JVM memory of the target server, where the custom class loader is built based on the C++ language.
[0090] Embodiment 3 Figure 3 The structural schematic diagram of the electronic device provided in Embodiment 3 of the present invention shows a block diagram of an exemplary electronic device suitable for implementing the embodiments of the present invention. Figure 3The electronic device shown is only an example and should not impose any limitations on the functions and scope of use of the embodiments of the present invention. As Figure 3 shown, the electronic device includes a processor 31, a memory 32, an input device 33, and an output device 34; the number of processors 31 in the electronic device can be one or more. Figure 3 Taking one processor 31 as an example, the processor 31, the memory 32, the input device 33, and the output device 34 in the electronic device can be connected through a bus or other means. Figure 3 Taking the connection through a bus as an example.
[0091] The memory 32, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the method for encrypting and deploying bytecode files in the embodiments of the present invention. The processor 31 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 32, that is, implements the above method for encrypting and deploying bytecode files.
[0092] The present application provides a method for encrypting and deploying bytecode files. Among them, the method is applied to a device for encrypting and deploying bytecode files. The method first obtains Java source files and compiles and packages them into a target archive file set, and then identifies the file set that needs to be encrypted according to predetermined business metrics. These files are encrypted using the encryption key in the key file and the DES algorithm, and the encrypted and unencrypted files are deployed to the target server. A customized class loader is used to load these files on the server, and it can perform decryption and loading operations according to the encryption status of the files. By reading the creation time of the key file and the physical address of the server, the system generates a decryption key to securely decrypt the files, ensuring that these bytecode files can only be accessed and executed in the correct environment. This solution effectively protects the enterprise's key business logic and sensitive information, prevents unauthorized access and reverse engineering, and enhances the security and deployment flexibility of the application.
[0093] Note that the above is only a preferred embodiment of the present invention and the technical principles applied. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, it can also include more other equivalent embodiments, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. A method for encrypting and deploying bytecode files, characterized in that, Including: Generate a key file in the Java runtime environment directory of the target server, obtain the creation time of the key file and the physical address of the target server, generate an encryption key based on the creation time and the physical address, and store it in the key file, where the key file is 32-bit random characters; Obtain the Java source file, compile and package the Java source file to obtain a set of target archive files, where the target archive files include multiple bytecode files; Identify the set of target archive files, determine the set of archive files to be encrypted and the set of non-encrypted archive files, where the archive files to be encrypted are the archive files related to the predetermined business metrics; Based on the encryption key in the key file, use the DES data encryption algorithm to symmetrically encrypt the archive files to be encrypted to obtain a set of encrypted archive files; Copy the set of non-encrypted archive files and the set of encrypted archive files to the specified directory of the target server to obtain a set of target binary files; Execute data decryption of the set of target binary files in the specified directory of the target server, and use a custom class loader to load the successfully decrypted archive files and the non-encrypted archive files into the JVM memory of the target server, where the custom class loader is built based on the C++ language.
2. The method for encrypting and deploying bytecode files according to claim 1, wherein Generate an encryption key, including: Obtain the creation time of the key file in the Java runtime environment directory, and read the physical address of the target server; Concatenate the creation time and the physical address, and use the MD5 encryption algorithm to encrypt the concatenated content to generate an encryption key.
3. The method for encrypting and deploying bytecode files according to claim 1, wherein Determine the set of archive files to be encrypted and the set of non-encrypted archive files, including: Configure the predetermined business metrics based on the target enterprise business logic; Filter the set of target archive files according to the predetermined business metrics, set the target archive files related to the predetermined business metrics as the archive files to be encrypted, and set the target archive files not related to the predetermined business metrics as the non-encrypted archive files to obtain the set of archive files to be encrypted and the set of non-encrypted archive files.
4. The method for encrypting and deploying bytecode files according to claim 1, characterized in that, Use a custom class loader to load the successfully decrypted archive files and the non-encrypted archive files into the JVM memory of the target server, including: In the specified directory of the target server, respectively determine whether each of the multiple target binary files in the set of target binary files is encrypted; If the target binary file is an encrypted archive file, perform data decryption on the encrypted archive file, and use a custom class loader to load the successfully decrypted archive file into the JVM memory of the target server according to the encrypted loading method, where the custom class loader is built based on the C++ language and can execute the original loading method and the encrypted loading method.
5. The method for encrypting and deploying a bytecode file according to claim 4, wherein If the target binary file is a non-encrypted archive file, use a custom class loader to load the non-encrypted archive file into the JVM memory of the target server according to the original loading method.
6. The method for encrypting and deploying a bytecode file according to claim 4, wherein Perform data decryption on the encrypted archive file, including: Read the second creation time of the key file in the Java runtime environment directory and the second physical address of the current server; Concatenate the second creation time and the second physical address, and encrypt the concatenated content using the MD5 encryption algorithm to generate a decryption key; Based on the decryption key, use the DES data encryption algorithm to decrypt the encrypted archive file. If the decryption fails, report an error and exit.
7. An apparatus for encrypting and deploying bytecode files, characterized in that, For implementing the method according to any one of claims 1 to 6, the apparatus includes: Encryption key generation module: used to generate a key file in the Java runtime environment directory of the target server, obtain the creation time of the key file and the physical address of the target server, generate an encryption key based on the creation time and the physical address, and store it in the key file, where the key file is 32-bit random characters; Compilation and packaging module: used to obtain the Java source file, compile and package the Java source file to obtain a set of target archive files, where the target archive file includes multiple bytecode files; Archive file set identification module: used to identify the set of target archive files, determine the set of archive files to be encrypted and the set of non-encrypted archive files, where the archive files to be encrypted are archive files related to predetermined business metrics; Symmetric encryption module: used to symmetrically encrypt the archive files to be encrypted using the DES data encryption algorithm based on the encryption key in the key file to obtain a set of encrypted archive files; Binary file set obtaining module: used to copy the set of non-encrypted archive files and the set of encrypted archive files to a specified directory of the target server to obtain a set of target binary files; Data decryption module: used to perform data decryption on the set of target binary files in the specified directory of the target server, and use a custom class loader to load the successfully decrypted archive files and unencrypted archive files into the JVM memory of the target server, where the custom class loader is constructed based on the C++ language.
8. An electronic device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.
9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Protection method and protection system of file
CN103166958A
Document management system, document management server, document reproducing terminal, document managing method, document reproducing method, document management program, and document reproducing program
JP2006127226A