File protection method and device, electronic equipment and storage medium

By obfuscating Ruby bytecode, the problem that Ruby source code is easily cracked in bytecode form is solved, and effective protection of Ruby source code is achieved to ensure that it operates normally in a specific environment.

CN119989305APending Publication Date: 2025-05-13BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311503779.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

After the source code of the Ruby programming language is converted into bytecode, it is easily cracked by attackers, resulting in the risk of source code leakage.

Method used

By obfuscating Ruby bytecode, including replacing and inserting preset bytecodes, changing the position and order of bytecodes, increasing the difficulty of file loading and execution in external environments, and reducing the risk of reverse analysis.

Benefits of technology

Effectively prevent Ruby source code from being leaked, enhancing the security of the source code, so that it can only run normally in a specific Ruby environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989305A_ABST
    Figure CN119989305A_ABST
Patent Text Reader

Abstract

The invention provides a file protection method and device, electronic equipment and a storage medium, and relates to the technical field of network information security. The method comprises the following steps: defining a target byte code in the file to obtain an encrypted byte code corresponding to the target byte code; obtaining a first byte code and a second byte code in the encrypted byte code; replacing the first byte code with the second byte code; and / or acquiring a preset byte code in the encrypted byte code; the preset byte code is inserted into the file, the position of a third byte code is changed, and the third byte code is contained in the encrypted byte code. According to the method, the obfuscation of the byte codes can be realized, so that the difficulty degree of loading execution of the Ruby byte code sequence binary file in an external environment is increased, the risk of reverse analysis of the binary file is reduced, the Ruby source code is prevented from being leaked, and the Ruby source code is protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a file protection method, device, electronic device and storage medium in the field of network security technology. Background Art

[0002] With the rapid development of mobile Internet technology, communication between people and machines can be achieved through computer programming languages. People choose suitable computer programming languages ​​according to their needs, such as Python programming language, Java programming language and Ruby programming language. Among them, Ruby programming language is widely used in different technical fields because it can be quickly mastered and used by technicians, has strong scalability, and programs developed using it are easy to maintain.

[0003] In the related art, a variety of encryption methods are used to protect the source code of computer programming languages, and these protection methods are mostly applied to the source code of Python programming language, and the protection of the source code of Ruby programming language is rarely involved. In order to protect the source code of Ruby programming language, technicians convert the source code into a Ruby bytecode sequence binary file and publish it. However, if an attacker obtains the Ruby bytecode sequence binary file and cracks it, it is easy to obtain the Ruby programming language source code, which leads to the risk of Ruby source code leakage.

[0004] Therefore, how to protect the source code of the Ruby programming language has become an urgent problem to be solved. Summary of the invention

[0005] The present application provides a file protection method, device, electronic device and storage medium. The method can implement bytecode obfuscation, thereby increasing the difficulty of loading and executing a Ruby bytecode sequence binary file in an external environment, reducing the risk of the binary file being reverse analyzed, thereby preventing the Ruby source code from being leaked and protecting the Ruby source code.

[0006] In a first aspect, a file protection method is provided, the method comprising: defining a target bytecode in the above-mentioned file to obtain an encrypted bytecode corresponding to the above-mentioned target bytecode; obtaining a first bytecode and a second bytecode in the above-mentioned encrypted bytecode; replacing the above-mentioned first bytecode with the above-mentioned second bytecode; and / or obtaining a preset bytecode in the above-mentioned encrypted bytecode; inserting the above-mentioned preset bytecode into the above-mentioned file, and changing the position of a third bytecode, wherein the above-mentioned third bytecode is included in the above-mentioned encrypted bytecode.

[0007] In the above technical solution, an encrypted bytecode with a target bytecode definition is obtained, and two bytecodes (i.e., a first bytecode and a second bytecode) in the encrypted bytecode are replaced; and / or, a preset bytecode in the encrypted bytecode is inserted into a Ruby bytecode sequence binary file, and the position of a specific bytecode is changed to achieve the purpose of obfuscating the bytecode, thereby increasing the difficulty of loading and executing the Ruby bytecode sequence binary file in an external environment, reducing the risk of the binary file being reverse analyzed, thereby preventing the Ruby source code from being leaked, and protecting the Ruby source code.

[0008] In combination with the first aspect, in some implementations of the first aspect, the method further includes: defining the target bytecode in a target file, wherein the target file contains a mapping relationship between the target bytecode and the encrypted bytecode, and the mapping relationship is used to define the target bytecode.

[0009] In the above technical solution, by defining the target bytecode in the target file and establishing a mapping relationship between the target bytecode and the encrypted bytecode, it is easy to encrypt and modify the Ruby bytecode, thereby improving the efficiency of encrypting the Ruby source code and increasing the difficulty of deciphering the Ruby source code.

[0010] In combination with the first aspect and the above-mentioned implementation methods, in some implementation methods of the first aspect, the method also includes: obtaining the first position of the above-mentioned first bytecode; obtaining the second position of the above-mentioned second bytecode; placing the above-mentioned first bytecode at the above-mentioned second position to replace the above-mentioned second bytecode; placing the above-mentioned second bytecode at the above-mentioned first position to replace the above-mentioned first bytecode.

[0011] In the above technical solution, the first bytecode and the second bytecode are interchanged, which changes the order of operation codes corresponding to the bytecodes, so that the attacker obtains wrong operation results when cracking. Therefore, the purpose of protecting the Ruby bytecode sequence binary file is achieved by obfuscating the bytecode, and the possibility of Ruby source code being leaked is reduced.

[0012] In combination with the first aspect and the above-mentioned implementation methods, in some implementation methods of the first aspect, the method also includes: obtaining a target value range of the original operation code corresponding to the above-mentioned encrypted bytecode; and determining the value of the above-mentioned preset bytecode based on the above-mentioned target value range.

[0013] In the above technical solution, the value of the preset bytecode can be accurately obtained through the value range of the original operation code, which promotes the encryption process of the Ruby source code.

[0014] In combination with the first aspect and the above-mentioned implementation methods, in some implementation methods of the first aspect, the method also includes: moving the position of the above-mentioned third bytecode to a preset position of the above-mentioned file, wherein the above-mentioned preset position includes the end of the above-mentioned file, so as to change the position of the above-mentioned third bytecode.

[0015] In the above technical solution, by randomly inserting bytecodes and changing the positions of specific bytecodes, the running order of Ruby codes can be changed, so that the Ruby codes cannot be run smoothly, thereby improving the security of Ruby source code.

[0016] In combination with the first aspect and the above-mentioned implementation manners, in some implementation manners of the first aspect, the method further includes: serializing the original bytecode to obtain a binary target bytecode; and defining the above-mentioned binary target bytecode.

[0017] In the above technical solution, the original bytecode is serialized into binary data, which can facilitate the storage and conversion of Ruby source code, making the Ruby source code easier to be recognized by the machine, thereby promoting the operation efficiency of the Ruby source code.

[0018] In combination with the first aspect and the above-mentioned implementation methods, in some implementation methods of the first aspect, the method also includes: compiling an abstract syntax tree (AST) to obtain the above-mentioned original bytecode, wherein the above-mentioned abstract syntax tree is used to represent the grammatical structure of the above-mentioned original bytecode.

[0019] In the above technical solution, by compiling the abstract syntax tree to obtain the original bytecode, the Ruby source code can be clearly described, which is conducive to modification and transformation in the subsequent writing stage.

[0020] In summary, this application uses the defined target bytecode as the encrypted bytecode, replaces two bytecodes in the encrypted bytecode; and / or inserts the preset bytecode in the encrypted bytecode into the Ruby bytecode sequence binary file, and changes the position of the specific bytecode to protect the file. The above two methods can achieve the purpose of obfuscating bytecodes, thereby increasing the difficulty of loading and executing the Ruby bytecode sequence binary file in the external environment, reducing the risk of the binary file being reverse analyzed, and thus preventing the Ruby source code from being leaked, and protecting the Ruby source code.

[0021] In a second aspect, a file protection device is provided, which includes: a definition module, used to define the target bytecode in the above-mentioned file and obtain the encrypted bytecode corresponding to the above-mentioned target bytecode; an acquisition module, used to obtain the first bytecode and the second bytecode in the above-mentioned encrypted bytecode; a replacement module, used to replace the above-mentioned first bytecode with the above-mentioned second bytecode; the above-mentioned acquisition module is also used to obtain the preset bytecode in the above-mentioned encrypted bytecode; an insertion module, used to insert the above-mentioned preset bytecode into the above-mentioned file and change the position of the third bytecode, wherein the above-mentioned third bytecode is included in the above-mentioned encrypted bytecode.

[0022] In combination with the second aspect, in certain implementations of the second aspect, the definition module is specifically used to: define the above-mentioned target bytecode in a target file, wherein the above-mentioned target file contains a mapping relationship between the above-mentioned target bytecode and the above-mentioned encrypted bytecode, and the above-mentioned mapping relationship is used to define the above-mentioned target bytecode.

[0023] In combination with the second aspect and the above-mentioned implementation methods, in some implementation methods of the second aspect, the acquisition module is also used to: obtain the first position of the above-mentioned first bytecode; obtain the second position of the above-mentioned second bytecode; place the above-mentioned first bytecode at the above-mentioned second position to replace the above-mentioned second bytecode; place the above-mentioned second bytecode at the above-mentioned first position to replace the above-mentioned first bytecode.

[0024] In combination with the second aspect and the above-mentioned implementation methods, in some implementation methods of the second aspect, the acquisition module is also used to: obtain the target value range of the original operation code corresponding to the above-mentioned encrypted bytecode; and determine the value of the above-mentioned preset bytecode based on the above-mentioned target value range.

[0025] In combination with the second aspect and the above-mentioned implementation methods, in some implementation methods of the second aspect, the insertion module is also used to: move the position of the above-mentioned third bytecode to a preset position of the above-mentioned file, wherein the above-mentioned preset position includes the end of the above-mentioned file, so as to change the position of the above-mentioned third bytecode.

[0026] In combination with the second aspect and the above-mentioned implementation manner, in some implementation manners of the second aspect, the definition module is also used to: serialize the original bytecode to obtain a binary target bytecode; and define the above-mentioned binary target bytecode.

[0027] In combination with the second aspect and the above-mentioned implementation methods, in some implementation methods of the second aspect, the definition module is also used to: compile the abstract syntax tree to obtain the above-mentioned original bytecode, wherein the above-mentioned abstract syntax tree is used to represent the grammatical structure of the above-mentioned original bytecode.

[0028] In a third aspect, an electronic device is provided, comprising a memory and a processor. The memory is used to store executable program code, and the processor is used to call and run the executable program code from the memory, so that the electronic device executes the method in the first aspect or any possible implementation of the first aspect.

[0029] In a fourth aspect, a computer program product is provided, comprising: a computer program code, which, when executed on a computer, enables the computer to execute the method in the first aspect or any possible implementation of the first aspect.

[0030] In a fifth aspect, a computer-readable storage medium is provided, which stores a computer program code. When the computer program code runs on a computer, the computer executes the method in the above-mentioned first aspect or any possible implementation manner of the first aspect.

[0031] In the technical solution provided by the present application, the defined target bytecode is used as the encrypted bytecode, and two bytecodes in the encrypted bytecode are replaced; and / or, the preset bytecode in the encrypted bytecode is inserted into the Ruby bytecode sequence binary file, and the position of the specific bytecode is changed. It can be seen that in the file protection method provided by the embodiment of the present application, the Ruby bytecode is obfuscated through two implementation methods, or a combination of the two implementation methods, so that the Ruby bytecode sequence binary file can only run in a specific Ruby environment, thereby increasing the difficulty of loading and executing the binary file, and reducing the risk of the binary file being reverse analyzed, thereby preventing the Ruby source code from being leaked, and achieving the purpose of protecting the Ruby source code.

[0032] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 is a schematic flow chart of a file protection method provided in an embodiment of the present application;

[0034] Figure 2 It is a schematic diagram of a file protection method based on bytecode replacement provided in an embodiment of the present application;

[0035] Figure 3 It is a schematic diagram of a file protection method based on bytecode insertion provided in an embodiment of the present application;

[0036] Figure 4 It is a schematic diagram of a file protection method in a hybrid manner provided in an embodiment of the present application;

[0037] Figure 5 is a structural schematic diagram of a file protection device provided in an embodiment of the present application;

[0038] Figure 6 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0039] The technical solution in the present application will be described clearly and in detail below in conjunction with the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B: "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0040] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as suggesting or implying relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.

[0041] When running programs written in the Ruby programming language on the terminal, technicians will encrypt the Ruby programming language source code in a variety of ways to increase the difficulty for attackers to crack the Ruby programming language source code, thereby preventing the Ruby source code from being leaked.

[0042] It should be understood that the terminal refers to a terminal device through a motherboard, an integrated device and a central processing unit, including but not limited to: personal computers, tablet computers and smart phones.

[0043] In an exemplary embodiment, Figure 1 FIG. 1 is a schematic flow chart of a file protection method provided in an embodiment of the present application. Figure 1 As shown, the method 100 includes the following implementation process:

[0044] In S110, the target bytecode in the file is defined, and the defined target bytecode is used as the encrypted bytecode.

[0045] Among them, the above-mentioned file refers to the binary file obtained after parsing the source code written in the Ruby programming language (that is, the Ruby bytecode sequence binary file). Bytecode is a binary file that contains an execution program and consists of a sequence of operation code / data pairs. It is an intermediate layer code between the program source code and the machine code.

[0046] The target bytecode may refer to a portion of bytecodes to be defined in the Ruby source code, or may refer to a portion of bytecodes to be defined in the binary data.

[0047] In the embodiment of the present application, the target bytecode in the Ruby bytecode sequence binary file is defined, and the defined target bytecode is used as the encrypted bytecode. The target bytecode is defined as needed, so that the target bytecode has rich definition content, thereby making the Ruby source code more secure.

[0048] In order to obfuscate the published Ruby bytecode sequence binary file so that the binary file can only be executed in a specific Ruby code environment, this application provides two implementation methods:

[0049] The first implementation method specifically includes S120 and S130.

[0050] In S120, the first bytecode and the second bytecode in the encrypted bytecode are obtained.

[0051] Exemplarily, when opt_plus and opt_minus exist in the encrypted bytecode, opt_plus can be used as the first bytecode and opt_minus can be used as the second bytecode. When encrypting the Ruby bytecode sequence binary file, opt_plus and opt_minus in the encrypted bytecode are obtained.

[0052] It should be understood that the encrypted bytecode also includes one or more of opt_div, opt_neq and opt_aref, which can be selected according to actual conditions, and the embodiments of the present application do not limit this.

[0053] In S130, the first byte code is replaced with the second byte code.

[0054] For example, when the first bytecode obtained is opt_plus and the second bytecode is opt_minus, opt_plus is replaced by opt_minus. By changing the order of the bytecodes, the bytecodes can be obfuscated so that the Ruby bytecode sequence binary file can only run in a specific Ruby environment, thereby increasing the difficulty of loading and executing the binary file in an external environment and reducing the risk of the binary file being reverse analyzed, thereby achieving the purpose of protecting the Ruby source code.

[0055] The second implementation method specifically includes S140 and S150.

[0056] In S140, a preset bytecode in the encrypted bytecode is obtained.

[0057] Exemplarily, the bytecode nop may be used as a preset bytecode in the encrypted bytecode, and nop may be obtained through S140.

[0058] It should be understood that the preset bytecode may also be opt_neq or opt_aref, or other bytecodes, which should be selected according to actual conditions, and the embodiments of the present application do not limit this.

[0059] In S150, the preset bytecode is inserted into the file, and the position of the third bytecode is changed.

[0060] Among them, the above-mentioned third bytecode is included in the above-mentioned encrypted bytecode.

[0061] Exemplarily, the preset bytecode nop is inserted into any position of the Ruby bytecode sequence binary file. Furthermore, when opt_mult is used as the third bytecode, the position of opt_mult is changed to achieve the purpose of confusing the order of the Ruby bytecode, thereby causing the Ruby bytecode sequence binary file to be unable to be run smoothly in an external environment, so that the binary file can only be run in a specific Ruby environment, and the effect of protecting the Ruby source code can also be achieved.

[0062] It should be understood that in the embodiments of the present application, there is no limitation on the position of nop insertion, nor on the number of preset bytecodes inserted, which can be 1, 3 or 5, and can be set according to actual conditions.

[0063] exist Figure 1 In the provided technical solution, the encrypted bytecode with the target bytecode definition is obtained, and two bytecodes in the encrypted bytecode are replaced; and / or, the preset bytecode in the encrypted bytecode is inserted into the Ruby bytecode sequence binary file, and the position of the specific bytecode is changed. The Ruby bytecode is obfuscated by two implementation methods, so that the Ruby bytecode sequence binary file can only run in a specific Ruby environment, thereby increasing the difficulty of loading and executing the binary file, and reducing the risk of the binary file being reverse analyzed, thereby preventing the Ruby source code from being leaked, and achieving the purpose of protecting the Ruby source code.

[0064] refer to Figure 1 It can be understood that, in a method for protecting a file that can be implemented, executing S110, S120 and S130 can achieve the above technical effects. Figure 2 In another possible file protection method, executing S110, S140 and S150 can achieve the above technical effect. Figure 3 In another possible file protection method, executing S110, S120 and S130, as well as S140 and S150, can also achieve the above technical effects. Figure 4 The scheme is described in detail with reference to the accompanying drawings and the corresponding embodiments.

[0065] In an exemplary embodiment, Figure 2 Schematic diagram of a file protection method based on bytecode replacement provided by an embodiment of the present application. Figure 2 As shown, the method 200 includes the following implementation process:

[0066] In S210, the abstract syntax tree is compiled to obtain the above original bytecode.

[0067] The abstract syntax tree is used to represent the syntax structure of the original bytecode, which contains the target bytecode that needs to be defined.

[0068] It should be understood that AST is an abstract representation of the grammatical structure of the source code, which expresses the grammatical structure of a programming language (e.g., the Ruby programming language) in a tree-like form. Each node on the tree represents a structure in the source code and is usually used in a compiler to parse the source code and generate machine code.

[0069] Illustratively, during the execution of source code written in the Ruby programming language, the Ruby 1.9 parser can be used to obtain AST nodes related to syntax in the Ruby source code, and the AST nodes can be compiled to further obtain YARV (YetAnother Ruby VM, which refers to stack-based interpreter technology, also known as Ruby bytecode) instruction sequences, thereby converting the Ruby source code files written by technicians into machine language that can be executed by the terminal, which can clearly describe the Ruby source code and facilitate modifications and transformations in subsequent writing stages.

[0070] After obtaining the original bytecode of the file by compiling the syntax, S110 is executed. As an implementation of S110, S1101 and S1102 are executed. Specifically, in S1101, the original bytecode is serialized to obtain a binary target bytecode; and in S1102, the above binary target bytecode is defined.

[0071] The target bytecode refers to the Ruby bytecode that needs to be defined in the binary data.

[0072] For example, the Ruby source code provides RubyVM::InstructionSequence#to_binary, which can serialize the Ruby bytecode into binary data that can be run by the machine, and can also provide RubyVM::InstructionSequence.load_from_binary, which is used to load binary data and deserialize the binary data into Ruby bytecode to obtain the Ruby source code. Serializing the Ruby bytecode into binary data can facilitate the storage and conversion of the Ruby source code, making the Ruby source code more easily recognized by the machine, thereby improving the running efficiency of the Ruby source code.

[0073] In the embodiment of the present application, the obtained Ruby bytecode includes the target bytecode to be defined, and the defined target bytecode is used as the encrypted bytecode.

[0074] For example, the target bytecodes to be defined are opt_plus, opt_minus, and opt_mult, and opt_plus, opt_minus, and opt_mult are defined respectively. Specifically, opt_plus represents addition (i.e., "+") in the four arithmetic operations, opt_minus represents subtraction (i.e., "-") in the four arithmetic operations, and opt_mult represents multiplication (i.e., "*") in the four arithmetic operations. Define opt_plus as operation code (OPCode) 1, define opt_minus as OPCode2, and define opt_mult as OPCode3. After the target bytecode is defined, the encrypted bytecode can be obtained. That is to say, in the Ruby source code, OPCode1 represents "+", OPCode2 represents "-", and OPCode3 represents "*".

[0075] It should be understood that the target bytecode may also be one or more of opt_div, opt_neq, opt_aref, etc., which may be selected according to actual conditions, and the embodiments of the present application do not limit this.

[0076] It should also be understood that the target bytecode can be randomly defined in the definition phase, and it is not necessary to define OPCode1 only for "opt_plus". In other words, "opt_plus" can also be defined as OPCode6 without affecting the execution of the Ruby source code.

[0077] In S240, the target bytecode is defined in a target file.

[0078] Among them, the above-mentioned target file contains a mapping relationship between the above-mentioned target bytecode and the above-mentioned encrypted bytecode, and the above-mentioned mapping relationship is used to define the above-mentioned target bytecode.

[0079] The mapping relationship can be understood as that when opt_plus is selected as the target bytecode, "opt_plus" and "OPCode1" are obtained by encrypting the bytecode, which corresponds to each other. In other words, there is a mapping relationship between "opt_plus" and "OPCode1". When OPCode1 is executed during the running of the Ruby source code, it can represent "opt_plus". The establishment of the mapping relationship makes it easier to encrypt and change the Ruby bytecode, improves the efficiency of encrypting the Ruby source code, and increases the difficulty of deciphering the Ruby source code.

[0080] It should be understood that the target file can be any file used to define the target bytecode and the mapping relationship between the target bytecode and the encrypted bytecode, for example, an insns.def file, and this embodiment of the present application does not limit this.

[0081] Exemplarily, the target bytecode defined in the insns.def file and the mapping relationship between the target bytecode and the encrypted bytecode are shown in Table 1. For example, the position of opt_plus is OPCode1, and the position of opt_minus is OPCode2.

[0082] Continue to refer Figure 2 In S120, the first bytecode and the second bytecode in the above encrypted bytecode are obtained.

[0083] Understandably, the S120 Figure 1 The corresponding embodiments have been described in detail and will not be repeated here.

[0084] After the first byte code and the second byte code are obtained, S130 is executed. As an implementation of S130, S1301 to S1304 are executed. Specifically, in S1301 to S1304, the first position of the first byte code is obtained; the second position of the second byte code is obtained; the first byte code is placed in the second position to replace the second byte code; the second byte code is placed in the first position to replace the first byte code.

[0085] Exemplarily, the definition order of the target bytecode can determine the value of OPCode. Corresponding to Table 1, in Table 1, the definition order of opt_plus is first, and the definition order of opt_minus is second, and the corresponding OPCode values ​​are OPCode1 and OPCode2. When the definition order of opt_plus and the definition order of opt_minus are interchanged, as shown in Table 2, it can be obtained that OPCode1 represents opt_minus and OPCode2 represents opt_plus, thereby changing the meaning of the bytecode represented by OPCode. By changing the order of opcodes corresponding to the bytecodes, the attacker will get the wrong running results when cracking, thereby achieving the purpose of protecting the Ruby bytecode sequence binary file by obfuscating the bytecode, reducing the possibility of Ruby source code leakage.

[0086] Table 1

[0087] Opcode Name 1 opt_plus 2 opt_minus 3 opt_mult 4 opt_div 5 nop

[0088] Table 2

[0089] Opcode Name 1 opt_minus 2 opt_plus 3 opt_mult 4 opt_div 5 nop

[0090] For example, the content of the operation performed by the Ruby code is "4 1 2 = ''", and the position of the target bytecode is obtained through Table 1. Without replacing the bytecode position, the bytecode sequence represented by the OPCode is shown in Table 1. The position of opt_plus is OPCode1, and the position of opt_minus is OPCode2. After running the Ruby code, the calculation content obtained is "4+1-2 = ''", and the calculation result is "4+1-2 = '3'".

[0091] In the case of replacing the target bytecode position, it can be understood that the position of opt_minus and the position of opt_plus after replacement are as shown in Table 2. Specifically, the position of opt_minus is OPCode1, and the position of opt_plus is OPCode2. After running the Ruby code, the calculation content changes to "4-1+2=''", and the calculation result is "4-1+2='5'", which is an incorrect calculation result.

[0092] It is understandable that the execution order of S1301 and S1302 is not limited, and similarly, the execution order of S1303 and S1304 is not limited.

[0093] exist Figure 2In the provided technical solution, an encrypted bytecode with a target bytecode definition is obtained, and two bytecodes in the encrypted bytecode are replaced to achieve the purpose of obfuscating the bytecode by changing the order of operation codes corresponding to the bytecode, so that the Ruby bytecode sequence binary file can only be run in a specific Ruby environment, so that an attacker cannot load and execute the binary file in an external environment and can only obtain an erroneous running result, thereby reducing the possibility of the binary file being reverse analyzed, thereby achieving the purpose of protecting the Ruby source code.

[0094] In an exemplary embodiment, Figure 3 Schematic diagram of a file protection method based on bytecode insertion provided in an embodiment of the present application. Figure 3 As shown, the method 300 includes the following implementation process:

[0095] In S210, the abstract syntax tree is compiled to obtain the above original bytecode.

[0096] In S1101 and S1102, the original bytecode is serialized to obtain a binary target bytecode; and the binary target bytecode is defined.

[0097] In S240, the target bytecode is defined in a target file.

[0098] It is understandable that S210, S1101 and S1102, as well as S240, in Figure 2 The corresponding embodiments have been described in detail and will not be repeated here.

[0099] After defining the target bytecode through the mapping relationship, S140 is executed. As an implementation of S140, S1401 and S1402 are executed. Specifically, the target value range of the original operation code corresponding to the encrypted bytecode is obtained; and the value of the preset bytecode is determined according to the target value range.

[0100] For example, during the running of the code written in Ruby language, there is a corresponding OPCode for each bytecode execution. The definition of the target bytecode can determine the target value range of the OPCode, so that the value of the preset bytecode can be accurately obtained, which promotes the encryption process of the Ruby source code.

[0101] Specifically, it can be explained by Table 1, which defines five bytecodes of opt_plus, opt_minus, opt_mult, opt_div and nop. It can be seen from Table 1 that the value range of the corresponding OPCode is 0 to 5.

[0102] Optionally, 30 byte codes may be defined as shown in Table 3, and the corresponding OPCode value range is 0 to 30, which is not limited in the embodiment of the present application.

[0103] Table 3

[0104] Opcode Name 1 opt_plus 2 opt_minus 3 opt_mult 4 opt_div 5 nop …… …… 30 pop

[0105] For example, the preset bytecode is set to nop corresponding to OPCode5. When encrypting the Ruby code, the operation code corresponding to the preset bytecode nop can be obtained as OPCode5.

[0106] After the preset bytecode is obtained, S150 is executed. As an implementation of S150, S1501 and S1502 are executed. Specifically, in S1501, the preset operation bytecode is inserted into the file, and in S1502, the position of the third bytecode is moved to the preset position of the file.

[0107] The preset position includes the end of the file to change the position of the third bytecode.

[0108] For example, when encrypting a Ruby bytecode sequence binary file, opt_mult can be used as the third bytecode and moved to the end of the Ruby bytecode sequence binary file, thereby changing the position of opt_mult in the binary file. By randomly inserting bytecodes and changing the position of specific bytecodes, the running order of Ruby codes can be changed, so that Ruby codes cannot be run smoothly in an external environment, thereby improving the security of Ruby source code.

[0109] For example, nop is inserted into a Ruby bytecode sequence binary file, and the position of opt_mult is changed, opt_mult is moved to the end of the Ruby bytecode sequence binary file, and the result obtained after running the binary file may be "object index out of range: 21 (Indexerror)", which means "object index out of range (index error)", making the released Ruby bytecode sequence binary file unable to run in an external environment.

[0110] It should be understood that S1501 and S1502 are steps that can be performed simultaneously.

[0111] exist Figure 3In the provided technical solution, the encrypted bytecode with the target bytecode definition is obtained, the preset bytecode in the encrypted bytecode is inserted into the Ruby bytecode sequence binary file, and the position of the specific bytecode is changed. The insertion of the bytecode and the change of the order of the specific bytecode are used to confuse the order of the Ruby bytecode, so that the Ruby bytecode sequence binary file cannot be run smoothly in the external environment, so that the binary file can only be run in a specific Ruby environment, thereby improving the security of the Ruby source code and achieving the effect of protecting the Ruby source code.

[0112] In an exemplary embodiment, Figure 4 FIG. 1 is a schematic diagram of a file protection method in a hybrid manner provided in an embodiment of the present application. Figure 4 As shown, the method 400 includes the following implementation process:

[0113] In S210, the abstract syntax tree is compiled to obtain the above original bytecode.

[0114] In S1101 and S1102, the original bytecode is serialized to obtain a binary target bytecode; and the binary target bytecode is defined.

[0115] In S240, the target bytecode is defined in a target file.

[0116] In S120, the first bytecode and the second bytecode in the encrypted bytecode are obtained.

[0117] In S1301 to S1304, the first position of the first byte code is obtained; the second position of the second byte code is obtained; the first byte code is placed in the second position to replace the second byte code; the second byte code is placed in the first position to replace the first byte code.

[0118] In S1401 and S1402, a target value range of the original operation code corresponding to the encrypted bytecode is obtained; and the value of the preset bytecode is determined according to the target value range.

[0119] In S1501 and S1502, the preset operation bytecode is inserted into the file, and the position of the third bytecode is moved to a preset position of the file.

[0120] Understandably, Figure 4 All steps in Figure 1 , Figure 2 and Figure 3 The corresponding embodiments have been described in detail and will not be repeated here.

[0121] Figure 4 There are two ways to confuse bytecodes. The first way includes: S120 and S1301~S1304 can complete the exchange of the positions of the first bytecode and the second bytecode; the second way includes: S1401 and S1402, and S1501 and S1502, randomly inserting preset bytecodes and changing the order of specific bytecodes. Both methods can achieve the purpose of confusing the order of Ruby bytecodes.

[0122] It should be understood that the execution order of the first method and the second method can be interchanged. Figure 4 As shown, S120 and S1301~S1304 of the first method are executed first, and then S1401 and S1402, and S1501 and S1502 of the second method are executed; S1401 and S1402, and S1501 and S1502 of the second method may also be executed first, and then S120 and S1301~S1304 of the first method are executed. In other words, the execution order of the first method and the second method does not affect the solution.

[0123] exist Figure 4 The technical solutions provided include Figure 2 and Figure 3 Specifically, two bytecodes in the encrypted bytecode are replaced, and the preset bytecode in the encrypted bytecode is inserted into the Ruby bytecode sequence binary file, and the position of the specific bytecode is changed. The combination of the two solutions can also achieve the purpose of obfuscating the bytecode sequence, so that the Ruby bytecode sequence binary file can only be run in a specific Ruby environment, so that the attacker cannot get the correct running result, thereby improving the security of the Ruby source code and achieving the effect of protecting the Ruby source code.

[0124] In an exemplary embodiment, Figure 5 Schematic diagram of the structure of a file protection device provided in an embodiment of the present application. Figure 5 As shown, the device 500 includes:

[0125] Definition module 510: used to define the target bytecode in the above file and obtain the encrypted bytecode corresponding to the above target bytecode;

[0126] Acquisition module 520: used to acquire the first bytecode and the second bytecode in the above encrypted bytecode;

[0127] Replacement module 530: used to replace the first byte code with the second byte code;

[0128] The acquisition module 520 is also used to acquire the preset bytecode in the encrypted bytecode;

[0129] The inserting module 540 is used to insert the preset bytecode into the file and change the position of the third bytecode, wherein the third bytecode is included in the encrypted bytecode.

[0130] In a possible implementation, the definition module 510 is specifically used to: define the target bytecode in a target file, wherein the target file contains a mapping relationship between the target bytecode and the encrypted bytecode, and the mapping relationship is used to define the target bytecode.

[0131] In a possible implementation, the acquisition module 520 is further used to: acquire the first position of the first bytecode; acquire the second position of the second bytecode; place the first bytecode at the second position to replace the second bytecode; place the second bytecode at the first position to replace the first bytecode.

[0132] In a possible implementation, the acquisition module 520 is further used to: obtain a target value range of the original operation code corresponding to the encrypted bytecode; and determine the value of the preset bytecode according to the target value range.

[0133] In a possible implementation, the insertion module 540 is further used to: move the position of the third bytecode to a preset position of the file, wherein the preset position includes the end of the file, so as to change the position of the third bytecode.

[0134] In a possible implementation, the definition module 510 is further used to: serialize the original bytecode to obtain a binary target bytecode; and define the binary target bytecode.

[0135] In a possible implementation, the definition module 510 is further used to compile the abstract syntax tree to obtain the original bytecode, wherein the abstract syntax tree is used to represent the syntax structure of the original bytecode.

[0136] Figure 6 It is a structural schematic diagram of an electronic device provided in an embodiment of the present application.

[0137] For example, Figure 6 As shown, the electronic device 600 includes: a memory 610 and a processor 620, wherein the memory 610 stores an executable program code 6101, and the processor 620 is used to call and execute the executable program code 6101 to perform a vehicle control method.

[0138] In this embodiment, the electronic device can be divided into functional modules according to the above method example. For example, each functional module can be corresponded to, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is schematic and is only a logical function division. There may be other division methods in actual implementation.

[0139] In the case of dividing each functional module according to each function, the electronic device may include: a definition module, an acquisition module, a replacement module, an insertion module, etc. It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, which will not be repeated here.

[0140] The electronic device provided in this embodiment is used to execute the above-mentioned file protection method, and thus can achieve the same effect as the above-mentioned implementation method.

[0141] In the case of an integrated unit, the electronic device may include a processing module and a storage module. The processing module may be used to control and manage the actions of the electronic device. The storage module may be used to support the electronic device in executing mutual program codes and data.

[0142] The processing module may be a processor or a controller, which may implement or execute various exemplary logic blocks, modules and circuits disclosed in conjunction with the present application. The processor may also be a combination that implements a computing function, such as a combination of one or more microprocessors, a combination of a digital signal processing (DSP) and a microprocessor, etc. The storage module may be a memory.

[0143] This embodiment also provides a computer-readable storage medium, in which a computer program code is stored. When the computer program code is executed on a computer, the computer executes the above-mentioned related method steps to implement a file protection method in the above-mentioned embodiment.

[0144] This embodiment also provides a computer program product. When the computer program product runs on a computer, it enables the computer to execute the above-mentioned related steps to implement a file protection method in the above-mentioned embodiment.

[0145] In addition, the electronic device provided in the embodiments of the present application may specifically be a chip, a component or a module, and the electronic device may include a connected processor and a memory; wherein the memory is used to store instructions, and when the electronic device is running, the processor may call and execute instructions so that the chip executes a file protection method in the above-mentioned embodiments.

[0146] Among them, the electronic device, computer-readable storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above and will not be repeated here.

[0147] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0148] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0149] The above contents are only specific implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A file protection method, characterized in that: The method comprises: Defining the target bytecode in the file, and obtaining the encrypted bytecode corresponding to the target bytecode; Obtaining a first bytecode and a second bytecode in the encrypted bytecode; and replacing the first bytecode with the second bytecode; And / or, obtaining a preset bytecode in the encrypted bytecode; inserting the preset bytecode into the file, and changing the position of a third bytecode, wherein the third bytecode is included in the encrypted bytecode.

2. The method according to claim 1, characterized in that Before obtaining the first bytecode and the second bytecode in the encrypted bytecode, the method further includes: The target bytecode is defined in a target file, wherein the target file contains a mapping relationship between the target bytecode and the encrypted bytecode, and the mapping relationship is used to define the target bytecode.

3. The method according to claim 1, characterized in that The using the second bytecode to replace the first bytecode in the file comprises: Obtaining a first position of the first bytecode; Obtaining a second position of the second bytecode; placing the first byte code at the second position to replace the second byte code; The second byte code is placed in the first position to replace the first byte code.

4. The method according to claim 1, characterized in that: The obtaining of the preset bytecode in the encrypted bytecode includes: Obtaining a target value range of the original operation code corresponding to the encrypted bytecode; According to the target value range, the value of the preset bytecode is determined.

5. The method according to claim 1, characterized in that: The changing the position of the third operation code comprises: The position of the third bytecode is moved to a preset position of the file, wherein the preset position includes the end of the file, so as to change the position of the third bytecode.

6. The method according to any one of claims 1, characterized in that: The target bytecode in the file is defined, including: Serialize the original bytecode to obtain the binary target bytecode; The binary target bytecode is defined.

7. The method according to any one of claims 1 to 6, characterized in that Before defining the target bytecode in the file, the method further includes: An abstract syntax tree is compiled to obtain the original bytecode, wherein the abstract syntax tree is used to represent the syntax structure of the original bytecode.

8. A file protection device, characterized in that: The device comprises: A definition module, used for defining the target bytecode in the file and obtaining the encrypted bytecode corresponding to the target bytecode; An acquisition module, used for acquiring a first bytecode and a second bytecode in the encrypted bytecode; A replacement module, used for replacing the first bytecode with the second bytecode; The acquisition module is further used to acquire the preset bytecode in the encrypted bytecode; The inserting module is used to insert the preset bytecode into the file and change the position of the third bytecode, wherein the third bytecode is included in the encrypted bytecode.

9. An electronic device, characterized in that: The electronic device comprises: A memory for storing executable program codes; A processor, configured to call and run the executable program code from the memory, so that the electronic device executes the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 7 is implemented.