Program protection method and related device

Through the main process and kernel, the security and integrity of JIT code and the memory area permissions are modified, the problem that the existing technology cannot effectively protect JIT code is solved, effective protection of JIT code is achieved, and the risk of malicious code execution is reduced.

CN120020775APending Publication Date: 2025-05-20HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311542422.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2025-05-20

AI Technical Summary

Technical Problem

The existing technology cannot effectively protect the source and integrity of JIT code generated through instant compilation, resulting in the browser's JIT technology becoming the target of attackers.

Method used

The security and integrity of the JIT code are detected through the main process and the kernel. After the detection is passed, the permissions in the memory area where the JIT code are stored are modified to be readable, unwritable and executable to ensure that the JIT code cannot be tampered with before execution.

Benefits of technology

It realizes source verification and integrity protection of JIT code, reduces the probability of executing malicious code, and improves the security of electronic devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120020775A_ABST
    Figure CN120020775A_ABST
Patent Text Reader

Abstract

The invention discloses a program protection method and a related device. The electronic equipment runs an operating system and a specified application, the specified application comprises a host process and a rendering process, and the operating system comprises a kernel. After the specified application obtains the interpreted language code sent by the server, the rendering process compiles the interpreted language code to obtain a JIT code, the JIT code is written into the first memory area, and the permission of the first memory area is readable, writable and non-executable. And the host process calculates the integrity information based on the JIT code. And the host process sends a permission modification request to the kernel to notify the kernel to modify the permission of the first memory area. The kernel computes integrity information of the code of the JIT. When the kernel determines that the completeness information obtained through calculation is the same as the completeness information provided by the host process, the permission of the first memory area is modified to be readable, non-writable and executable. And when the rendering process runs the interpreted language code, executing the JIT code of the first memory area.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of terminals, and in particular, to a program protection method and related devices. Background Art

[0002] Some application programs (for example, browser applications) can download web page code from a remote server, parse the web page code locally, and then provide an interface and functions to users. If a browser application downloads web page code provided by an untrusted source, it may cause losses to users. Currently, browser applications usually use the code signature security mechanism technology to ensure the security of the downloaded web page code. The code signature technology includes two links: 1. After a program authentication or provider signs a program, the signature and the program are sent to the client together. 2. When the client runs the program, it verifies the integrity information of the program through the signature to protect the integrity of the program, and can also verify whether the program source is trusted to prevent the client from executing a malicious program with an untrusted source. In this way, through the code signature mechanism that forces all running processes to only load signed program code, the reliability of the program source can be ensured, and the probability of obtaining malicious code can be greatly reduced.

[0003] To improve the execution speed and make the page respond more quickly, browser applications use just-in-time compilation (JIT compilation) technology to compile the code written in an interpreted language used in a web page into machine code (i.e., JIT code), and execute the JIT code to replace the execution of the code by an interpreter, thereby improving the running speed of the program.

[0004] However, the JIT code is dynamically compiled code generated by the client, and the generated JIT code is related to the instruction set used by the client and the functions provided by the client, making it impossible to predict the source of the code generated from the code written in the interpreted language. Therefore, it is impossible to verify the source and protect the integrity of the JIT code through the code signature mechanism. This makes the JIT technology of browsers become the target of attackers. Attackers use browser vulnerabilities to tamper with the executable JIT code to achieve the purpose of executing malicious code, or attackers can also construct malformed web page inputs so that the JIT code compiled by the JIT compiler is used to execute malicious behaviors. Summary of the Invention

[0005] The present application provides a program protection method and related devices, which realizes that when the interpreted language code is compiled into JIT code through the rendering process, the main process and the kernel detect the security and integrity of the JIT code. After the detection passes, the permissions of the memory area storing the JIT code are modified to be readable, non-writable, and executable. So that before the electronic device executes the JIT code through the rendering process, no process can modify the JIT code, ensuring the security of the JIT code.

[0006] In a first aspect, the present application provides a program protection method, which is applied to an electronic device. The electronic device runs an operating system and a specified application. The specified application includes a main process and a rendering process, and the operating system includes a kernel. The method includes: after the main process obtains the interpreted language code sent by the web server, calling the rendering process to compile the interpreted language code to obtain a just-in-time compilation JIT code; the rendering process writes the JIT code into a first memory area, and the permissions of the first memory area are readable, writable, and non-executable; the main process calculates the first integrity information of the JIT code; the main process sends a permission modification request to the kernel, and the permission modification request is used to notify the kernel to modify the permissions of the first memory area to be readable, non-writable, and executable; after receiving the permission modification request, the kernel calculates the second integrity information of the JIT code; when the kernel determines that the first integrity information is the same as the second integrity information, it modifies the permissions of the first memory area to be readable, non-writable, and executable; when the rendering process runs the interpreted language code, it executes the JIT code in the first memory area.

[0007] In this way, the electronic device calculates the integrity information through the main process and verifies the integrity information in the kernel, preventing the JIT code from being tampered with and achieving the effect of protecting the integrity of the JIT code. At the same time, the electronic device verifies the legality of the permission modification through the kernel. The rendering process that executes the untrusted program does not directly set the memory area storing the JIT code to an executable permission. Before the electronic device executes the unsigned untrusted program, it must pass the verification of the main process and the kernel, and the code executed in the main process is all trusted code, reducing the probability of the JIT code being tampered with before the JIT code is executed, and reducing the probability of the electronic device executing malicious code.

[0008] In a possible implementation manner, the main process sending a permission modification request to the kernel specifically includes: the main process detecting whether the JIT code includes malicious code; when the main process detects that the JIT code does not include malicious code, the main process sends a permission modification request to the kernel.

[0009] In this way, by setting the execution permissions and performing malicious code scanning on untrusted code without a code signature, the electronic device reduces the risk of the specified application being attacked, solves the problem that JIT code cannot be protected by code signature technology, and reduces the probability of the electronic device 100 executing malicious code.

[0010] In a possible implementation, after the rendering process writes the JIT code into the first memory area, the method further includes: the main process detecting whether the JIT code includes malicious code; if the main process detects that the JIT code includes malicious code, sending first risk data to the risk server, where the first risk data is used to indicate that the JIT code is risky. In this way, the risk server can obtain information about the electronic device executing risky code, facilitating maintenance personnel to analyze the reason why the JIT code includes malicious code based on this, enabling the maintenance personnel to improve the program of the electronic device and avoid the electronic device obtaining malicious code again.

[0011] In some examples, after the main process obtains the interpreted language code sent by the web server, the method further includes: the main process obtaining untrusted source information from the risk server, where the untrusted source information is used to indicate an untrusted source; the main process detecting whether the source of the interpreted language code belongs to an untrusted source based on the untrusted source information; if the main process detects that the source of the interpreted language code belongs to an untrusted source, stopping the execution of the interpreted language code. Invoking the rendering process to compile the interpreted language code to obtain just-in-time compiled (JIT) code specifically includes: when the main process detects that the source of the interpreted language code does not belong to an untrusted source, invoking the rendering process to compile the interpreted language code to obtain just-in-time compiled (JIT) code. In this way, by detecting the source of the interpreted language code, the probability of the electronic device 100 obtaining malicious code from an untrusted source can be reduced.

[0012] In a possible implementation, before the rendering process writes the JIT code into the first memory area, the method further includes: the main process calling the kernel to apply for a second memory area, where the second memory area includes the first memory area. The main process sends the address of the second memory area to the rendering process; the rendering process searches for the first memory area based on the data volume of the JIT code. In this way, the main process applies for the second memory area, and the rendering process can search for a suitable memory area in the second memory area to store the JIT code according to the data volume of the JIT code, without the main process repeatedly applying for memory areas multiple times.

[0013] In some examples, the second memory area is a shared memory area, and both the main process and the rendering process can access the second memory area.

[0014] In a possible implementation, before the rendering process writes the JIT code into the first memory area, the method further includes: the rendering process sending the data volume of the JIT code to the main process; the main process calling the kernel to apply for the first memory area based on the data volume of the JIT code; and the main process sending the address of the first memory area to the rendering process. In this way, the main process allocates the memory area based on the JIT code data volume, saving the free memory space.

[0015] In a possible implementation, after the main process obtains the interpreted language code sent by the web server, the method further includes: the main process verifying the signature of the interpreted language code; calling the rendering process to compile the interpreted language code, specifically including: when the main process verifies that the signature of the interpreted language code passes, calling the rendering process to compile the interpreted language code. In this way, the main process verifies the code signature of the interpreted language code, which can reduce the probability of the electronic device 100 executing malicious code.

[0016] In some examples, when the main process verifies that the signature information of the interpreted language code passes, it specifically includes: the main process determining that the signature belongs to a trusted source.

[0017] In a possible implementation, if the main process verifies that the signature of the interpreted language code does not pass, the operation of executing the interpreted language code is stopped. In some examples, when the main process verifies that the signature of the interpreted language code does not pass, it specifically includes: the main process determining that the signature belongs to an untrusted source.

[0018] In a possible implementation, after the kernel receives a permission modification request, the method further includes: the kernel determining whether the process sending the permission modification request is the main process; calculating the second integrity information of the JIT code, specifically including: when the kernel determines that the process sending the permission modification request is the main process, calculating the second integrity information. In this way, the electronic device verifies whether the process sending the permission modification request is the main process, which can prevent the rendering process from skipping the main process to modify the permission of the first memory area.

[0019] In some examples, if the kernel determines that the process sending the permission modification request is not the main process, it detects whether the code in the first memory area is code with a code signature. When the kernel detects that the code in the first memory area has a code signature and the code signature verification passes, it modifies the permission of the first memory area according to the permission modification request. When the kernel detects that the code in the first memory area does not have a code signature or the code signature verification fails, it rejects the modification of the permission of the first memory area. In this way, after the kernel receives a permission modification request sent by a process other than the main process, it verifies the code signature of the data in this memory area, which can ensure that the electronic device can smoothly execute the code with a code signature from a trusted source.

[0020] In a possible implementation, the method further includes: when the kernel determines that the first integrity information is different from the second integrity information, rejecting the permission to modify the first memory area. In this way, when the electronic device detects that the first integrity information is different from the second integrity information, it indicates that the JIT code has been tampered with, and the permission to modify the first memory area is rejected.

[0021] In a possible implementation, when the method further includes: after the rendering process executes the JIT code in the first memory area, reclaiming the first memory area.

[0022] In a possible implementation, the method further includes: before reclaiming the first memory area, the kernel calculates the third integrity information of the JIT code; when the third integrity information is different from the second integrity information, the electronic device sends second risk data to the risk server, and the second risk data is used to indicate that the JIT code is risky. In this way, before the electronic device reclaims the first memory area, it detects the integrity information of the JIT code, can timely discover whether to execute risky JIT code, enables the electronic device to repair the tampering vulnerability as soon as possible, and prevents the situation where the JIT code is tampered with again.

[0023] In a possible implementation, the method further includes: the electronic device calculates the first integrity information and the second integrity information based on a hash function.

[0024] In a possible implementation, the interpreted language code is JavaScript code.

[0025] In a second aspect, the present application provides an electronic device, including one or more processors and one or more memories. The one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer-executable programs. When the one or more processors execute the computer-executable programs, the electronic device executes the program protection method in any possible implementation of the first aspect above.

[0026] In a third aspect, an embodiment of the present application provides a computer storage medium, including a computer program, and when the computer program runs on an electronic device, the electronic device executes the program protection method in any possible implementation of the first aspect above.

[0027] In a fourth aspect, an embodiment of the present application provides a computer program product, and when the computer program product runs on a computer, the computer executes the program protection method in any possible implementation of the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1A FIG. 1 is a schematic diagram of a communication system 10 provided by an embodiment of the present application;

[0029] Figure 1B A process schematic diagram provided by an embodiment of the present application;

[0030] Figure 2 A process schematic diagram of a program protection method provided by an embodiment of the present application;

[0031] Figure 3 A process schematic diagram of an electronic device 100 provided by an embodiment of the present application for obtaining JIT code stored in a specified sub - memory area;

[0032] Figure 4 A process schematic diagram of an electronic device 100 provided by an embodiment of the present application for modifying the permissions of a specified sub - memory area;

[0033] Figure 5 A process schematic diagram of a kernel of an electronic device 100 provided by an embodiment of the present application for modifying the permissions of a JIT memory area;

[0034] Figure 6 A schematic diagram of software modules of an electronic device 100 provided by an embodiment of the present application;

[0035] Figure 7 A process schematic diagram of another program protection method provided by an embodiment of the present application;

[0036] Figure 8 A schematic diagram of the structure of an electronic device 100 provided by an embodiment of the present application. Detailed implementation manners

[0037] Next, the technical solutions in the embodiments of the present application will be clearly and elaborately described with reference to the accompanying drawings. Among them, in the description of the embodiments of the present application, unless otherwise specified, " / " means "or". For example, A / B can mean A or B; "and / or" in the text is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present application, "a plurality" means two or more than two.

[0038] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more than two.

[0039] Next, a communication system 10 provided by an embodiment of the present application will be introduced.

[0040] As shown Figure 1A in FIG. 1, the communication system 10 includes an electronic device 100 and one or more servers. The one or more servers include a server 200 and a server 300. Among them, the server 200 can be used to provide web page data for the electronic device (e.g., the electronic device 100). The web page data can include, but is not limited to, web page code, multimedia files, etc. The web page data can be used for the electronic device to generate a web page.

[0041] The server 300 can be used to receive risk data sent by the electronic device (e.g., the electronic device 100). The risk data can be used to indicate that the electronic device has obtained untrusted web page data (also known as risk web page data) that may harm the user's interests. In this way, the maintenance personnel can analyze the security vulnerabilities of the electronic device based on the risk data provided by each electronic device in the server 300, and patch the security vulnerabilities to maintain the security of the electronic device. In some examples, the risk data includes JIT code compiled based on the untrusted web page data and / or the untrusted web page data. The server 300 can also determine the provider of the untrusted web page data (also known as the untrusted source) based on the risk data. The server 300 can also send the identifier of the untrusted source to the electronic device (e.g., the electronic device 100) to prevent the electronic device from downloading the web page data provided by the untrusted source.

[0042] In some examples, the electronic device 100 can establish a communication connection with the server 200 and / or the server 300 through a network access device based on a wired connection or a Wi-Fi connection. For example, the network access device can be a third-party device such as a router, a gateway, or a smart device controller. Among them, the server 200 and / or the server 300 can be a hardware server or a cloud server implanted in a virtualized environment. The electronic device 100 can transmit data to the server 200 and / or the server 300 through a network interface.

[0043] In the embodiment of the present application, the electronic device 100 can download web page data from the server 200 and generate and display a web page based on the web page data. The electronic device 100 can check with the server 300 whether the downloaded web page data comes from an untrusted source. The electronic device 100 can also send risk data to the server 300.

[0044] It can be understood that the structure shown in this embodiment does not constitute a specific limitation on the communication system 10. In other embodiments of the present application, the communication system 10 can include more devices than shown in the figure.

[0045] In a possible implementation, the application of the electronic device 100 includes a main process and a rendering process. When the application runs the code of an interpreted language, the rendering process can compile the code of the interpreted language to obtain JIT code and run the JIT code through the rendering process. Among them, the electronic device 100 restricts the permissions of the rendering process to improve the security of running JIT code by the rendering process.

[0046] Exemplarily, as Figure 1B shown, the electronic device 100 can execute JIT code through the following steps.

[0047] S101. The main process 11 downloads web page data from the server 200.

[0048] Among them, the web page data is used for the electronic device 100 to construct a web page. For example, the web page data may include but is not limited to multimedia files, code written in an interpreted language, and so on.

[0049] S102. The main process 11 sends the code written in the interpreted language to the rendering process 12.

[0050] After downloading the web page data, the main process 11 can send some or all of the code written in the interpreted language in the web page data to the rendering process 12. For example, the main process 11 can send the code written in the interpreted language to the rendering process 12 through inter-process communication (IPC).

[0051] S103. The rendering process 12 compiles the code written in the interpreted language through a JIT compiler to obtain JIT code. Among them, the electronic device 100 can use the JIT code to replace some or all of the code written in the interpreted language.

[0052] S104. The rendering process 12 executes the JIT code.

[0053] After the rendering process 12 compiles to obtain JIT code, it can execute the JIT code. It should be noted that when the rendering process 12 runs the code written in the interpreted language, it can replace and execute the JIT code when running to some or all of the code written in the interpreted language. In this way, the electronic device 100 does not need to interpret and execute some or all of the code written in the interpreted language, saving code execution time.

[0054] Among them, the rendering process does not have the ability of network communication. In this way, the rendering process does not have the ability of network communication, so that attackers cannot directly remotely download JIT code, nor can they write remotely downloaded JIT code into executable JIT code, thus unable to achieve the attack purpose.

[0055] In some examples, the electronic device 100 can also adopt security mechanisms such as pointer compression deployed inside the sandbox to increase the difficulty for attackers to attack the electronic device 100.

[0056] The electronic device 100 executes Figure 1B the program protection method shown, so that the main process does not participate in the compilation and execution of JIT code. The JIT code compilation and execution are both restricted to the sandbox (rendering process), and the electronic device 100 also restricts the capabilities of the rendering process to reduce the risk of the electronic device 100 being attacked.

[0057] However, if the attacker bypasses the implemented security mechanism, they can still execute malicious code by tampering with the JIT code stored in memory and / or creating new executable memory, etc., to achieve the attack purpose (for example, leaking user personal information, etc.).

[0058] The embodiment of the present application provides a program protection method. The electronic device 100 runs an operating system and a specified application. The specified application includes a main process and a rendering process, and the operating system includes a kernel. After the specified application obtains the code of the interpreted language sent by the server 200, the rendering process of the specified application can compile the code of the interpreted language to obtain JIT code and store the JIT code in the first memory area. The permissions of the first memory area are readable, writable, and non-executable. The main process can calculate integrity information based on the JIT code. The main process can send a permission modification request to the kernel to notify the kernel to modify the permissions of the first memory area to be readable, non-writable, and executable. The kernel can calculate the integrity information of the JIT code here and detect whether the calculated integrity information is the same as the integrity information provided by the main process. When the kernel determines that the calculated integrity information is the same as the integrity information provided by the main process, it modifies the permissions of the specified sub-memory area to be readable, non-writable, and executable. The rendering process can execute the JIT code in the first memory area when running the code of the interpreted language.

[0059] In this way, the electronic device 100 calculates the integrity information through the main process and verifies the integrity information in the kernel, preventing the JIT code from being tampered with, and achieving the effect of protecting the integrity of the JIT code. At the same time, the electronic device 100 verifies the legality of the permission modification through the kernel. The rendering process that executes the untrusted program does not directly set the memory area storing the JIT code to an executable permission. Before the electronic device 100 executes an unsigned and untrusted program, it must pass the verification of the main process and the kernel, and the code executed in the main process is all trusted code, reducing the probability of executing malicious code.

[0060] In some examples, before sending the permission modification request to the kernel, the main process may also detect whether the JIT code includes malicious code. When the main process detects that the JIT code does not include malicious code, it sends the permission modification request to the kernel. When the main process detects that the JIT code includes malicious code, it refuses to modify the permission of the first memory area. In this way, through the setting of execution permissions and the malicious code scanning of untrusted code without code signing, the electronic device 100 reduces the risk of the specified application being attacked, solves the problem that JIT code cannot be protected by code signing technology, and reduces the probability of the electronic device 100 obtaining malicious code from untrusted sources.

[0061] In some examples, before compiling the code of the interpreted language through the rendering process, the electronic device 100 may also verify the signature of the code of the interpreted language. When the verification of the signature of the code of the interpreted language passes, the electronic device 100 compiles the code of the interpreted language through the rendering process. When the verification of the signature of the code of the interpreted language fails, the electronic device 100 cancels the execution of the code of the interpreted language. In this way, the electronic device 100 can ensure the security of the specified code obtained.

[0062] In some examples, when the electronic device 100 determines through the kernel that the calculated integrity information is the same as the integrity information provided by the main process, it can save the address, size, and the integrity information of the first memory area. Before the electronic device 100 reclaims the first memory area, the electronic device 100 can calculate the integrity information of the JIT code stored in the specified sub-memory area through the kernel. When the electronic device 100 detects that the calculated integrity information is different from the stored integrity information, it can send the risk data to the server 300. Among them, the electronic device 100 can perform a memory recovery operation when the rendering process stops running the JIT code, or exits the specified application, etc. In this way, the electronic device 100 can record the integrity information of the JIT code and discover the attack risk after executing the JIT code. The kernel can check whether there is corresponding integrity information in the reclaimed memory area and verify the integrity information. When the verification of the integrity fails, the kernel can notify the main process to report the risk to avoid potential risks that may occur later. Optionally, after the electronic device 100 discovers the attack risk, it can also check the program of the electronic device 100 that has been attacked to solve the attack problem.

[0063] Exemplarily, as Figure 2 shown, the program protection method includes the following steps:

[0064] S201. After the electronic device 100 obtains the specified code sent by the server 200, it obtains, through the main process, a specified memory area for storing JIT code, and the permission of the specified memory area is readable, writable, and non-executable.

[0065] Among them, the specified application can be used to execute the web page code obtained from the server 200, generate and display the web page. For example, the specified application can be a browser application. The specified code is code written based on an interpreted language.

[0066] Among them, when the main process calls the kernel to initialize the specified memory area, it can obtain a shared memory area of a specified size (for example, 4G). The specified memory area has readable and writable permissions but not executable permissions, and both the main process and the rendering process can access the specified memory area.

[0067] In this way, the electronic device 100 does not allow the rendering process to allocate executable memory for unsigned code. The rendering process can only store the JIT code in the specified memory area and wait for the main process to set the executable permission for the specified memory area. The electronic device 100 can thus ensure that only the program written into the specified memory area can be set with executable permission by the main process. When the electronic device 100 obtains the JIT code, the electronic device 100 cannot confirm the security of the JIT code. Therefore, the electronic device 100 writes the JIT code into the specified memory area to prevent other processes from executing the JIT code, realizing the function of protecting the electronic device 100.

[0068] In some examples, after the main process obtains the specified code from the server 200, it can also obtain untrusted source information from the server 300. The untrusted source information is used to indicate an untrusted source. The main process can, based on the untrusted source information, detect whether the source of the interpreted language code belongs to an untrusted source. If the main process detects that the source of the interpreted language code belongs to an untrusted source, it stops executing the interpreted language code. If the main process detects that the source of the interpreted language code does not belong to an untrusted source, it calls the rendering process to compile the interpreted language code to obtain the just-in-time compiled JIT code. In this way, by detecting the source of the interpreted language code, the probability that the electronic device 100 obtains malicious code from an untrusted source can be reduced.

[0069] In some examples, after the main process obtains the specified code from the server 200, it can also verify the signature information of the specified code. If the main process fails to verify the signature information, it stops executing the interpreted language code. If the main process passes the verification of the signature information, it calls the rendering process to compile the interpreted language code to obtain the just-in-time compiled JIT code. In this way, by verifying the code signature of the interpreted language code, the probability that the electronic device 100 executes malicious code can be reduced. It can be understood that the electronic device 100 can simultaneously verify the signature information of the specified code and determine whether the source of the specified code belongs to an untrusted source. The embodiments of the present application do not make any limitations in this regard.

[0070] S202. The electronic device 100 compiles the specified code through the rendering process to obtain JIT code, and the JIT code is stored in a specified sub - memory area of the specified memory area.

[0071] The electronic device 100 compiles the specified code constructed by an interpreted language through the rendering process to obtain machine code, and the machine code is JIT code. The electronic device 100 searches for the specified sub - memory area for storing the JIT code in the specified memory area according to the data volume of the JIT code through the rendering process. In some examples, the interpreted language can be the JavaScript programming language.

[0072] Among them, the rendering process can use the specified memory area in segments. The rendering process can mark the used memory areas in the specified memory area. The rendering process can select the unmarked free memory areas in the specified memory area and write the JIT code. For example, the rendering process can mark the occupied memory area by saving the address and size of the already used memory area.

[0073] Among them, after writing the JIT code into the specified sub - memory area, the rendering process can send the address and size of the specified sub - memory area to the main process. For example, the rendering process can send the address and size of the specified sub - memory area to the main process through IPC.

[0074] S203. The electronic device 100 calculates the integrity information of the JIT code through the main process and detects whether the JIT code includes malicious code.

[0075] Among them, after the main process receives the address and size of the specified sub - memory area of the JIT code sent by the rendering process, the electronic device 100 can calculate the integrity information of the JIT code through the main process. For example, the integrity information can be the digest value calculated by the electronic device 100 based on the JIT code stored in the specified sub - memory area using a hash function (such as SHA256 / SHA512 and other functions).

[0076] The electronic device 100 can also detect whether the JIT code includes malicious code. When the electronic device 100 detects that the JIT code does not include malicious code, it can execute step S204. After the electronic device 100 detects that the JIT code includes malicious code, it refuses to execute the JIT code. In this way, the electronic device 100 can perform a malicious code scan on the JIT code and refuse to execute the program including malicious code segments.

[0077] In some examples, after the electronic device 100 detects that the JIT code includes malicious code, it can also send risk data to the server 300, and the risk data is used to indicate that the JIT code includes malicious code. In this way, the electronic device 100 can send the risk data to the server 300, and the server 300 can analyze the attack path of the electronic device 100 based on this, improving the security of the electronic device 100.

[0078] It can be understood that the electronic device 100 can simultaneously perform the operation of calculating the integrity information of the JIT code and the operation of detecting whether the JIT code includes malicious code. Alternatively, the electronic device 100 can first detect whether the JIT code includes malicious code, and when it detects that the JIT code does not include malicious code, calculate the integrity information of the JIT code. The embodiments of the present application do not make any limitations in this regard.

[0079] S204. After the main process of the electronic device 100 determines that the JIT code does not include malicious code, it sends a permission modification request to the kernel, and the permission modification request is used to notify the kernel to modify the permission of the specified sub - memory area to be readable, non - writable, and executable.

[0080] After the electronic device 100 determines through the main process that the JIT code does not include malicious code, it can call the kernel to modify the permission of the specified sub - memory area to be readable, non - writable, and executable. Here, the main process can send the address, size, and integrity information of the specified sub - memory area to the kernel. For example, the main process can pass the calculated integrity information to the kernel through the parameters of the system call.

[0081] S205. The electronic device 100 verifies through the kernel whether the permission indicated by the permission modification request includes writable and executable permissions.

[0082] After receiving the permission modification request for modifying the permission of the specified sub - memory area by the main process, the kernel of the electronic device 100 can verify whether the permission indicated by the permission modification request includes writable and executable permissions. When the electronic device 100 determines through the kernel that the permission indicated by the permission modification request includes writable and executable permissions, the electronic device 100 fails to modify the permission of the specified sub - memory area. In this way, the electronic device 100 refuses to modify the permission of the specified sub - memory area storing the JIT code to be writable and executable, avoiding the situation where the JIT code stored in the specified sub - memory area of the electronic device 100 is tampered with and the electronic device 100 executes the tampered JIT code.

[0083] When the electronic device 100 determines through the kernel that the permission indicated by the permission modification request does not include writable and executable permissions, that is, the modified permission of the specified sub - memory area does not include writable and executable permissions simultaneously. The electronic device 100 can execute step S206.

[0084] S206. When the electronic device 100 determines through the kernel that the permissions indicated by the permission modification request do not include writable and executable permissions, the kernel is used to verify the integrity information of the JIT code.

[0085] When the electronic device 100 determines through the kernel that the permissions indicated by the permission modification request do not include writable and executable permissions, the kernel can be used to verify the integrity information of the JIT code. Specifically, the electronic device 100 can calculate the integrity information of the JIT code in the specified sub-memory area through the kernel. Then, the electronic device 100 can determine through the kernel whether the integrity information calculated by the kernel is the same as the integrity information provided by the main process. When the electronic device 100 determines that the integrity information calculated by the kernel is the same as the integrity information provided by the main process, the verification of the integrity information of the JIT code passes, and the electronic device 100 can execute step S207. When the electronic device 100 determines that the integrity information calculated by the kernel is different from the integrity information provided by the main process, the verification of the integrity information of the JIT code fails, and the electronic device 100 fails to modify the permissions of the specified sub-memory area. It can be understood that the algorithm used by the kernel to calculate the integrity information is the same as the algorithm used by the main process to calculate the integrity information.

[0086] In some examples, after the kernel of the electronic device 100 fails to modify the permissions of the specified sub-memory area, it can notify the main process that the permission modification of the specified sub-memory area fails. The main process can stop the operation of executing the specified code. Optionally, the electronic device 100 can also display a risk prompt message, which is used to prompt the user that the current web page is a risky web page. In this way, the electronic device 100 can prevent entering a risky web page and protect the interests of the user. In other examples, after the electronic device 100 fails to modify the permissions of the specified sub-memory area, it can re-execute step S201.

[0087] In some examples, when the electronic device 100 determines through the kernel that the permissions indicated by the permission modification request do not include writable and executable permissions, it can detect whether the permissions indicated by the permission modification request include executable permissions. When the kernel detects that the permissions indicated by the permission modification request include executable permissions, the kernel can detect whether the process sending the permission modification request is the main process. When the kernel detects that the permissions indicated by the permission modification request do not include executable permissions, it can modify the permissions of the specified sub-memory area according to the permission modification request.

[0088] Among them, when the kernel detects that the process sending the permission modification request is the main process, it can detect whether the main process provides the integrity information of the JIT code in the specified sub-memory area, and when it detects that the main process provides the integrity information of the JIT code, verify the integrity information of the JIT code. When the kernel detects that the process sending the permission modification request is not the main process, it can detect whether the data in the specified sub-memory area is data with a code signature, and when it detects that the data in the specified sub-memory area has a code signature, verify the code signature. When the kernel passes the code signature verification, it can modify the permission of the specified sub-memory area according to the permission modification request. When the kernel detects that the data in the specified sub-area does not have a code signature or the kernel fails to verify the code signature, it rejects the permission modification of the specified sub-memory area. In this way, the electronic device 100 can ensure that the rendering process can independently execute the code with a code signature from a trusted source, and can prevent the rendering process from skipping the main process to modify the permission of the storage area where the JIT code is stored.

[0089] In some examples, after the electronic device 100 fails to modify the permission of the specified sub-memory area, it can also send risk data including the reason for the permission modification failure to the server 300.

[0090] S207. After the electronic device 100 passes the verification of the integrity information of the JIT code, the kernel modifies the permission of the specified sub-memory area to be readable, non-writable, and executable.

[0091] Among them, after the electronic device 100 modifies the permission of the specified sub-memory area to be readable, non-writable, and executable through the kernel, it can notify the main process that the permission modification of the specified sub-memory area is successful. After the main process determines that the permission modification of the specified sub-memory area is successful, it can notify the rendering process to execute the JIT code.

[0092] S208. The electronic device 100 executes the JIT code through the rendering process.

[0093] After the permission modification of the specified sub-memory area of the electronic device 100 is successful, it can execute the JIT code in the specified sub-memory area through the rendering process.

[0094] In this way, after the permission modification of the specified sub-memory area of the electronic device 100 is successful, each time the specified code is executed through the rendering process, the JIT code can be executed in the specified sub-memory area through the rendering process, saving compilation time. And during the process from the electronic device 100 modifying the permission of the specified sub-memory area to the electronic device 100 executing the JIT code, since the permission of the specified sub-memory area has been modified to be readable, non-writable, and executable, attackers cannot tamper with the data in the specified sub-memory area, improving the security of the electronic device 100 when executing the JIT code.

[0095] S209. When the electronic device 100 reclaims a specified sub - memory area, the kernel verifies the integrity information of the specified sub - memory area. When the verification of the integrity information by the electronic device 100 fails, risk data is sent to the server 200.

[0096] Among them, the electronic device 100 can reclaim the specified sub - memory area when the rendering process does not execute the generated JIT code for a long time, or exits a specified application (for example, exits the specified application), etc.

[0097] Among them, after the electronic device 100 verifies that the integrity information of the JIT code passes through the kernel, it can save the integrity information of the JIT code. The saved integrity information can be used to detect risk data when the electronic device 100 reclaims the specified sub - memory area.

[0098] For example, the electronic device 100 can store the integrity information of the specified sub - memory area in the form of a mapping table. Among them, the mapping table includes one or more integrity information entries. Each integrity information entry includes the address, size of a partial memory area in the specified memory area, and the integrity information of the stored JIT code. Here, the one or more integrity information entries include a specified integrity information entry. The specified integrity information entry includes the address, size of the specified sub - memory area, and the integrity information of the JIT code of the specified sub - memory area. Among them, the integrity information of the JIT code of the specified sub - memory area can be the integrity information calculated by the main process, or the integrity information calculated by the kernel.

[0099] The electronic device 100 can verify the integrity information of the specified sub - memory area through the kernel when reclaiming the specified sub - memory area. Specifically, the electronic device 100 can obtain the saved integrity information of the JIT code of the specified sub - memory area. The electronic device 100 can also determine the JIT code based on the saved address and size of the specified sub - memory area, and then calculate the integrity information based on the JIT code. The electronic device 100 can verify whether the integrity information of the specified sub - memory area passes through the saved integrity information and the calculated integrity information.

[0100] Among them, when the electronic device 100 detects that the saved integrity information is different from the calculated integrity information, the verification of the integrity information of the specified sub - memory area fails, and the electronic device 100 can send risk data to the server 200. Among them, the risk data can indicate that the electronic device 100 executes untrusted web page data. Specifically, reference can be made to Figure 1B the illustrated embodiments, which will not be elaborated here.

[0101] Among them, when the electronic device 100 reclaims a specified sub - memory area, it can mark the specified sub - memory area as a free memory area and delete the address, size, and integrity information of the specified sub - memory area saved by the electronic device 100.

[0102] It should be noted that when the electronic device 100 executes non - JIT code, it needs to verify the security of the non - JIT code based on the code signature of the non - JIT code. The electronic device 100 only executes the non - JIT code when the security verification of the non - JIT code passes based on the code signature of the non - JIT code. Optionally, the electronic device 100 can use the rendering process to execute non - JIT code. In this way, the electronic device 100 implements system - enforced code signing, that is, all executable programs except JIT code need to have a code signature to ensure the security of non - JIT code.

[0103] In this way, the electronic device 100 separates the functions of the main process and the renderer process of the specified application, uses the renderer process to run JIT code, uses the main process to verify the security and integrity of JIT code, and uses the main process to set the executable permission of JIT code, so that the attacker cannot execute malicious code by tampering with the generated JIT code, creating new executable memory, etc., protecting the security of the electronic device 100.

[0104] Next, the process by which the electronic device 100 in the embodiment of the present application compiles JIT code through the renderer process and stores the JIT code will be introduced in detail.

[0105] Exemplarily, as Figure 3 shown, the steps for the electronic device 100 to obtain the JIT code stored in the specified sub - memory area are as follows:

[0106] S301. The renderer process compiles the specified code of the interpreted language to obtain JIT code.

[0107] Among them, after receiving the address and size of the specified memory area sent by the main process, the renderer process can compile the code of the interpreted language to obtain JIT code. Optionally, after sending the address and size of the specified memory area to the renderer process, the main process can also send a compilation notification message to the renderer process, and the compilation notification message is used to notify the renderer process to compile the specified code of the interpreted language. Optionally, the compilation notification message can be used to indicate the memory area where the specified code is stored.

[0108] S302. The renderer process finds the specified sub - memory area from the specified memory area.

[0109] After compiling the JIT code, the renderer process can find the specified sub - memory area for storing the JIT code in the specified memory area based on the data volume of the JIT code.

[0110] S303. The rendering process writes the JIT code into the specified sub - memory area.

[0111] After the rendering process finds the specified sub - memory area that can be used to store the JIT code in the specified memory area, it can write the JIT code into the specified sub - memory area.

[0112] It should be noted that, after the rendering process fails to find the specified sub - memory area that can be used to store the JIT code in the specified memory area, it can notify the main process that the JIT code cannot be placed in the specified memory area. The main process can call the kernel to apply for another memory area with read, write, and non - executable permissions, and send the address and size of the memory area to the rendering process. Among them, the capacity of the memory area applied by the main process is greater than the data volume of the JIT code. The rendering process can re - search for the sub - memory area used to store the JIT code within the memory area provided by the main process and write the JIT code into this sub - memory area.

[0113] S304. The rendering process marks the specified sub - memory area as occupied and notifies the main process of the address and size of the specified sub - memory area.

[0114] After the rendering process writes the JIT code into the specified sub - memory area, it can mark the specified sub - memory area as occupied and send the address and size of the specified sub - memory area to the main process.

[0115] Optionally, the rendering process can also send a security verification message to the main process. This security verification message can be used to notify the main process to verify the integrity information of the JIT code and verify whether the JIT code includes malicious code. Optionally, the rendering process can carry the address and size of the specified sub - memory area in the security verification message.

[0116] Among them, for the descriptions of steps S301 to S304, reference can also be made to Figure 2 the embodiments shown, which will not be elaborated here. In this way, the rendering process can compile the JIT code through the above steps and write the JIT code into the specified memory area indicated by the main process.

[0117] Next, the process of the electronic device 100 modifying the permissions of the specified sub - memory area in the embodiments of the present application will be introduced in detail.

[0118] Exemplarily, as Figure 4 shown, the steps for the electronic device 100 to modify the permissions of the specified sub - memory area are as follows:

[0119] S401. The main process calculates the integrity information 51 of the JIT code in the specified sub - memory area.

[0120] After receiving the address and size of the specified sub - memory area sent by the rendering process, the main process can calculate the integrity information 51 of the JIT code based on the JIT code in the specified sub - memory area. Optionally, the main process can execute step S401 after receiving the security verification message, which is not limited in the embodiments of the present application.

[0121] S402. The main process detects whether the JIT code contains malicious code.

[0122] After receiving the address and size of the specified sub - memory area sent by the rendering process, the main process can also detect whether the JIT code contains malicious code. For example, the main process can use a malicious code detection algorithm to detect whether the JIT code contains malicious code.

[0123] When the main process detects that the JIT code does not contain malicious code, the main process can execute step S403. When the main process detects that the JIT code contains malicious code, the execution of the JIT code is cancelled. In some examples, after the electronic device 100 detects that the JIT code contains malicious code, it can also send risk data to the server 300, and the risk data is used to indicate that the JIT code contains malicious code.

[0124] S403. The main process sends a permission modification request to the kernel, and the permission modification request is used to notify the kernel to modify the permission of the specified sub - memory area to be readable, non - writable and executable.

[0125] When the main process calculates the integrity information 51 and detects that the JIT code does not contain malicious code, it can send a permission modification request to the kernel. Among them, the permission modification request is used to notify the kernel to modify the permission of the specified sub - memory area to be readable, non - writable and executable.

[0126] S404. The kernel detects whether the permissions indicated by the permission modification request include writable and executable.

[0127] After receiving the permission modification request, the kernel can detect whether the permissions indicated by the permission modification request include writable and executable. When the kernel detects that the permissions indicated by the permission modification request include writable and executable, the electronic device 100 executes step S408. When the kernel detects that the permissions indicated by the permission modification request do not include writable and executable, the electronic device 100 executes step S405.

[0128] S405. The kernel detects whether there is corresponding integrity information in the specified sub - memory area.

[0129] When the kernel detects that the permissions indicated by the permission modification request do not include writable and executable, it can detect whether there is corresponding integrity information in the specified sub - memory area. For example, the electronic device 100 can provide a specified interface, which can be used to call the kernel to modify the permissions of the memory area. The parameters of the specified interface can include, but are not limited to, integrity information. The main process can call the specified interface to notify the kernel to modify the permissions of the specified sub - memory area and send the integrity information 51 to the kernel. Among them, when the main process sends a permission modification request to the kernel and carries the integrity information 51 of the specified sub - memory area, the kernel can determine that there is integrity information in the specified sub - memory area based on this and execute step S406. When the main process does not carry the integrity information 51 of the specified sub - memory area when sending a permission modification request to the kernel, the kernel can determine that there is no integrity information in the specified sub - memory area based on this and execute step S408.

[0130] In some examples, when the electronic device 100 determines through the kernel that the permissions indicated by the permission modification request do not include writable and executable, it can also detect whether the permissions indicated by the permission modification request include executable. When the kernel detects that the permissions indicated by the permission modification request include executable, the kernel can detect whether the process sending the permission modification request is the main process. When the kernel detects that the permissions indicated by the permission modification request do not include executable, it can modify the permissions of the specified sub - memory area according to the permission modification request.

[0131] Among them, when the kernel detects that the process sending the permission modification request is the main process, it can detect whether the main process provides the integrity information of the JIT code in the specified sub - memory area, and when it detects that the main process provides the integrity information of the JIT code, it can verify the integrity information of the JIT code. When the kernel detects that the process sending the permission modification request is not the main process, it can detect whether the data in the specified sub - memory area is data with a code signature, and when it detects that the data in the specified sub - memory area has a code signature, it can verify the code signature. After the kernel verifies the code signature and passes, it can modify the permissions of the specified sub - memory area according to the permission modification request. When the kernel detects that the data in the specified sub - area does not have a code signature or the kernel fails to verify the code signature, it refuses to modify the permissions of the specified sub - memory area. In this way, the electronic device 100 can ensure that the rendering process can independently execute code with a code signature from a trusted source and can prevent the rendering process from bypassing the main process to modify the permissions of the storage area where the JIT code is stored.

[0132] Optionally, the electronic device 100 can first execute step S405 and then execute step S404. The embodiments of the present application do not limit this.

[0133] S406. The kernel calculates integrity information 52 based on the JIT code in the specified sub - memory area, and detects whether integrity information 51 is the same as integrity information 52.

[0134] When the kernel detects that integrity information 51 is the same as integrity information 52, it executes step S407. When the kernel detects that integrity information 51 is different from integrity information 52, it executes step S408.

[0135] S407. The kernel changes the permissions of the specified sub - memory area to be readable, non - writable, and executable.

[0136] After the kernel detects that the permissions indicated by the permission modification request do not include writable and executable, integrity information 51 is the same as integrity information 52, and the JIT code does not include malicious code, it can change the permissions of the specified sub - memory area to be non - writable and executable.

[0137] Optionally, the kernel can also save the address, size, and integrity information of the specified sub - memory area for verifying the integrity of the JIT code before reclaiming the specified sub - memory area.

[0138] S408. The kernel fails to modify the permissions of the specified sub - memory area.

[0139] After the kernel detects that the permissions indicated by the permission modification request include writable and executable, there is no integrity information 51, integrity information 51 is different from integrity information 52, or the JIT code includes malicious code, it refuses to modify the permissions of the specified sub - memory area, and the permission modification of the specified sub - memory area fails.

[0140] Specifically, for the descriptions of steps S401 - S408, reference can also be made to Figure 2 the embodiments shown, which will not be elaborated here. In this way, the electronic device 100 can Figure 4 modify the permissions of the specified sub - memory area through the steps shown, and jointly modify the permissions of the specified sub - memory area by the main process and the kernel, reducing the probability that the attacker cannot tamper with the data in the specified sub - memory area.

[0141] In some examples, after receiving a permission modification request for modifying the permissions of the specified sub - memory area, the kernel of the electronic device 100 can determine whether to modify the permissions of the specified sub - memory area based on the permissions indicated by the permission modification request, the process that sends the permission modification request, and the integrity information of the specified sub - memory area. In this way, after receiving the permission modification request, the kernel can modify the permissions of the specified sub - memory area only when it determines that the code data stored in the specified sub - memory area is trusted data, ensuring the security of the electronic device 100.

[0142] Exemplarily, such as Figure 5As shown in the figure, the process by which the kernel of the electronic device 100 modifies the permissions of the JIT memory area is as follows:

[0143] S501. The kernel receives a permission modification request, which is used to modify the permissions of a specified sub - memory area.

[0144] The kernel receives a permission modification request sent by a process, and this permission modification request is used to request the kernel to modify the permissions of a specified sub - memory area.

[0145] S502. The kernel detects whether the permissions indicated by the permission modification request include writable and executable.

[0146] After receiving the permission modification request, the kernel can detect whether the permissions indicated by the permission modification request include writable and executable. When the kernel detects that the permissions indicated by the permission modification request include writable and executable, step S510 is executed. When the kernel detects that the permissions indicated by the permission modification request do not include writable and executable, step S503 is executed.

[0147] S503. The kernel detects whether the permissions indicated by the permission modification request include executable.

[0148] When the kernel detects that the permissions indicated by the permission modification request do not include writable and executable, it can detect whether the permissions indicated by the permission modification request include executable. When the kernel detects that the permissions indicated by the permission modification request include executable, step S504 is executed. When the kernel detects that the permissions indicated by the permission modification request do not include executable, step S509 is executed. In this way, when the kernel detects that only the permissions of the specified sub - memory area need to be modified to non - executable permissions, it is determined that the situation where executable code will not be tampered with, and the permissions of the specified sub - memory can be directly modified according to the permission modification request.

[0149] S504. The kernel detects whether the process sending the permission modification request is the main process.

[0150] When the kernel detects that the modified permissions include executable and do not include writable, it detects whether the process sending this permission modification request is the main process. When the kernel detects that the process sending this permission modification request is the main process, step S507 can be executed. When the kernel detects that the process sending this permission modification request is not the main process, step S505 can be executed.

[0151] In some examples, when the main process of the electronic device 100 starts, the main process can be set with the label "browser_main" of Security-Enhanced Linux (SeLinux). In this way, the kernel can distinguish the main process from the rendering process based on the label of the process. When the kernel detects that the process sending the permission modification request includes the "browser_main" label, it determines that the process is the main process.

[0152] S505. The kernel detects whether the data in the specified sub-memory area is data with a code signature.

[0153] When the kernel detects that the process sending the permission modification request is not the main process, it can detect whether the data in the specified sub-memory area is data with a code signature. When the kernel detects that the data in the specified sub-memory area is data with a code signature, step S506 can be executed. When the kernel detects that the data in the specified sub-memory area is data without a code signature, step S510 can be executed. In this way, the kernel only allows the permission of the memory area with code-signed code data to be modified from readable, writable and non-executable permissions to readable, executable and non-writable permissions, ensuring the security of the electronic device 100 when executing non-JIT code data.

[0154] S506. The kernel verifies whether the code signature passes.

[0155] Among them, after detecting that the data in the specified sub-memory area is data with a code signature, the kernel can verify whether the code signature passes by determining whether the code signature of the data comes from a trusted source. When the kernel determines that the code signature of the data comes from a trusted source, the code signature verification passes. When the kernel determines that the code signature of the data comes from an untrusted source, the code signature verification fails. When the kernel verifies that the code signature passes, step S509 can be executed. When the kernel verifies that the code signature fails, step S510 can be executed.

[0156] S507. The kernel detects whether there is integrity information in the specified sub-memory area.

[0157] When the kernel detects that the process sending the permission modification request is the main process, it can detect whether there is integrity information in the specified sub-memory area. The kernel can detect whether the main process passes the integrity information of the specified sub-memory area. For example, the electronic device 100 can provide a specified interface, which can be used to call the kernel to modify the permission of the memory area. The parameters of the specified interface can include but are not limited to integrity information. The main process can send the integrity information to the kernel through this interface. Among them, if the main process carries the integrity information of the specified sub-memory area when sending a permission modification request to the kernel, the kernel can determine that there is integrity information in the specified sub-memory area accordingly and execute step S508.

[0158] If the main process does not carry the integrity information of the specified sub-memory area when sending a permission modification request to the kernel, or the value of the integrity information is a null value, the kernel can determine that there is no integrity information for the specified sub-memory area and execute step S510.

[0159] S508. The kernel checks whether the integrity information is correct.

[0160] The kernel can calculate the integrity information based on the data of the specified sub-memory area. The kernel can determine whether the integrity information is correct by checking whether the calculated integrity information is the same as the integrity information obtained from the main process. Among them, when the kernel detects that the calculated integrity information is the same as the integrity information obtained from the main process, it is detected that the integrity information is correct, and step S509 is executed. When the kernel detects that the calculated integrity information is different from the integrity information obtained from the main process, it is detected that the integrity information is incorrect, and step S510 is executed.

[0161] S509. The kernel modifies the permissions of the specified sub-memory area.

[0162] The kernel modifies the permissions of the specified sub-memory area according to the permission modification request.

[0163] S510. The kernel fails to modify the permissions of the specified sub-memory area.

[0164] The kernel refuses to modify the permissions of the specified sub-memory area, and the process's request to modify the kernel's permissions for the specified sub-memory area fails. Optionally, after the kernel fails to modify the permissions of the specified sub-memory area, it can also send risk data including the reason for the permission modification failure (for example, incorrect integrity information, no code signature, etc.) to the server 300. Specifically, Figure 5 The descriptions of the respective steps shown can be referred to Figure 2 and Figure 4 the embodiments shown, which will not be elaborated here.

[0165] Next, a schematic diagram of the software modules of the electronic device 100 provided in the embodiments of the present application will be introduced.

[0166] Exemplarily, as Figure 6 shown, the electronic device 100 runs an operating system (not shown in the figure) and a specified application 20. The operating system includes a kernel 23. Among them, the specified application 20 can be an application program for displaying web pages. For example, a browser application. Among them, the kernel 23 can be used to manage memory areas, for example, allocate memory areas, set the permissions of memory areas, and recycle memory areas, etc.

[0167] Among them, the specified application 20 includes a main process 21 and a rendering process 22. Among them, the main process 21 can be used to detect whether the JIT code includes malicious code, calculate the integrity information of the JIT code, call the kernel 23 to obtain the memory area for storing the JIT code, call the kernel 23 to modify the permissions of the memory area, and so on. The rendering process 22 can be used to compile the JIT code, store the JIT code in the memory area indicated by the main process 21, execute the JIT code, and so on. Among them, the main process 21 can include one or more modules, and the one or more modules can include but are not limited to an integrity calculation module 32, a malicious code detection module 33, and a risk perception module 34. Among them, the integrity calculation module 32 can be used to calculate the integrity information of the JIT code. The malicious code detection module 33 can be used to detect whether the JIT code includes malicious code. The risk perception module 34 can be used to send risk data to the server 300. Exemplarily, in the embodiment of the present application, the integrity calculation module 32 can be used to execute steps such as Figure 4 shown in step S401. The malicious code detection module 33 can be used to execute steps such as Figure 4 shown in step S402.

[0168] Among them, the rendering process 22 can include one or more modules, and the one or more modules can include but are not limited to a JIT memory management module 31, a JIT compiler 30, etc. The JIT compiler 30 can be used to compile the code constructed by the interpreted language to obtain the JIT code. The JIT memory management module 31 can be used to find the memory area for placing the JIT code obtained by the JIT compiler 30 in the memory area indicated by the main process 21, and write the JIT code into this memory area. The JIT memory management module 31 can also record the occupied memory areas in the memory area indicated by the main process 21. Exemplarily, in the embodiment of the present application, the JIT compiler 30 can be used to execute steps such as Figure 3 shown in step S301. The JIT memory management module 31 can be used to execute steps such as Figure 3 shown in steps S302 to S304.

[0169] Among them, the kernel 23 may include one or more modules, and the one or more modules may include but are not limited to a permission modification verification module 35, a memory release verification module 36, and an integrity information verification module 37. Among them, the permission modification verification module 35 may be used to verify whether the received permission modification request for a memory area complies with the permission modification rules. For example, the permission modification rule may be that the permissions after modification according to the permission modification request do not include both writable permission and executable permission at the same time. The memory release verification module 36 may be used to verify whether the integrity information of the released memory area is correct. The integrity information verification module 37 may be used to verify whether the integrity information corresponding to the memory area with permission modification is correct, and store the corresponding relationship between the storage memory area and the integrity information. For example, the integrity information verification module 37 may store the integrity information of the memory area in the form of a mapping table. The mapping table includes one or more integrity information entries, and the integrity information entry includes the address, size, and integrity information of the sub-memory area storing the JIT code. Exemplarily, in the embodiment of the present application, the permission modification verification module 35 may be used to execute steps such as Figure 4 shown in step S404. The integrity information verification module 37 may be used to execute steps such as Figure 4 shown in step S405 and step S406. Also exemplarily, in the embodiment of the present application, the permission modification verification module 35 may be used to execute steps such as Figure 5 shown in steps S502 to S505. The integrity information verification module 37 may be used to execute steps such as Figure 5 shown in step S507 and step S508.

[0170] In some examples, when the malicious code detection module 33 detects that the JIT code includes malicious code, it may notify the risk perception module 34. After receiving the notification from the malicious code detection module 33, the risk perception module 34 may send risk data including the JIT code to the server 300. In this way, the server 300 can analyze the reason for the malicious code in the electronic device 100 and prevent the electronic device 100 from having malicious code again. Optionally, the risk perception module 34 may also send the code of the interpreted language corresponding to the JIT code to the server 300, and the server 300 may mark the untrusted source accordingly to avoid the electronic device 100 from executing the code sent from the untrusted source again.

[0171] In some examples, when the permissions indicated by the permission modification request include writable and executable, the permission modification verification module 35 may notify the risk perception module 34. After receiving the notification from the permission modification verification module 35, the risk perception module 34 may send the identifier of the process that sent the permission modification request to the server 300. In this way, the server 300 can analyze the reason for the process to send the permission modification request and prevent the permission modification request from occurring again.

[0172] In some examples, when the integrity information verification module 37 and the memory release verification module 36 fail the verification, they can notify the risk perception module 34. After receiving the notification, the risk perception module 34 can send risk data indicating that the kernel verification fails to the server 300. In this way, the server 300 can analyze the reason why the code of the electronic device 100 is tampered, find vulnerabilities of the electronic device 100, patch the vulnerabilities of the electronic device 100, and avoid the situation where the code is tampered again.

[0173] Next, in combination with Figure 6 the schematic diagram of software modules shown below, the flowchart of a program protection method provided by an embodiment of the present application will be introduced.

[0174] Exemplarily, as Figure 7 shown below, the program protection method includes the following steps:

[0175] S701. After the main process 21 receives the code of the interpreted language sent by the server 200, it calls the kernel 23 to obtain a specified memory area, and sends the address of the specified memory area to the rendering process 22. The specified memory area has read, write, and non-executable permissions.

[0176] S702. The JIT compiler 30 compiles the code of the interpreted language to obtain JIT code.

[0177] After the rendering process 22 receives the address of the specified memory area, it can compile the code of the interpreted language to obtain JIT code.

[0178] In some examples, after the main process 21 receives the code of the interpreted language sent by the server 200, it can send the code of the interpreted language that needs to be compiled into JIT code to the rendering process 22, and notify the rendering process 22 to compile the code of the interpreted language. Optionally, the main process 21 can send the address of the code of the interpreted language that needs to be compiled into JIT code to the rendering process 22.

[0179] S703. The JIT compiler 30 sends the JIT code to the JIT memory management module 31.

[0180] S704. The JIT memory management module 31 stores the JIT code in a specified sub-memory area of the specified memory area.

[0181] Among them, the JIT memory management module 31 can find a specified sub-memory area in the specified memory area based on the size of the JIT code, and write the JIT code into the specified sub-memory area.

[0182] In some other examples, after receiving the JIT code, the JIT memory management module 31 may send the size of the JIT code to the main process 21. The main process 21 may, based on the size of the JIT code, call the kernel to obtain the specified sub-memory area and send the address of the specified sub-memory area to the JIT memory management module 31.

[0183] S705. The JIT memory management module 31 sends the address and size of the specified sub-memory area to the main process 21.

[0184] S706. The integrity calculation module 32 calculates integrity information 71 of the JIT code based on the JIT code.

[0185] S707. The malicious code detection module 33 detects whether the JIT code includes malicious code.

[0186] When the malicious code detection module 33 detects that the JIT code does not include malicious code, it may execute step S708. When the malicious code detection module 33 detects that the JIT code includes malicious code, it may cancel the execution of the JIT code. Optionally, the electronic device 100 may execute step S706 and step S707 simultaneously, or execute step S707 first and then step S706. The embodiments of the present application do not make any limitations in this regard.

[0187] Optionally, the JIT memory management module 31 may send the address of the specified sub-memory area to the integrity calculation module 32. After calculating the integrity information 71, the integrity calculation module 32 may then send the address of the specified sub-memory area to the malicious code detection module 33. Alternatively, the JIT memory management module 31 may send the address of the specified sub-memory area to the malicious code detection module 33. After the malicious code detection module 33 detects that the JIT code does not include malicious code, it may then send the address of the specified sub-memory area to the integrity calculation module 32, and the integrity calculation module 32 may then calculate the integrity information 71.

[0188] S708. The main process 21 sends a permission modification request and the integrity information 71 to the kernel 23. The permission modification request is used to notify the kernel 23 to modify the permission of the specified sub-memory area to be readable, non-writable, and executable.

[0189] S709. The permission modification verification module 35 detects whether the permission indicated by the permission modification request includes writable and executable.

[0190] When the permission modification verification module 35 detects that the permission indicated by the permission modification request does not include writable and executable, step S710 can be executed. When the permission modification verification module 35 detects that the permission indicated by the permission modification request includes writable and executable, the permission to modify the specified sub-memory area is refused. It should be noted that step S709 is only an example. The permission modification verification module 35 can also detect whether the permission indicated by the permission modification request includes executable, whether the process sending the permission modification request is the main process, and whether the main process provides the integrity information of the JIT code. Specifically, reference can be made to Figure 2 and Figure 5 the embodiments shown, which will not be elaborated here.

[0191] S710. The integrity information verification module 37 calculates the integrity information 72 based on the JIT code, and detects whether the integrity information 71 is the same as the integrity information 72.

[0192] When the integrity information verification module 37 detects that the integrity information 71 is the same as the integrity information 72, step S712 is executed. When the integrity information verification module 37 detects that the integrity information 71 is different from the integrity information 72, the permission to modify the specified sub-memory area is refused.

[0193] Optionally, when the integrity information verification module 37 detects that the integrity information 71 is the same as the integrity information 72, step S711 can also be executed.

[0194] It can be understood that the electronic device 100 can also execute step S710 first and then execute step S709, or the electronic device 100 can execute step S710 and step S709 simultaneously. The embodiments of the present application do not limit this.

[0195] S711. The integrity information verification module 37 saves the address, size, and integrity information 72 of the specified sub-memory area.

[0196] Among them, the integrity information saved by the integrity information verification module 37 can be used to verify the integrity of the JIT code of the specified sub-memory area when the electronic device 100 reclaims the specified sub-memory area.

[0197] S712. The kernel 23 modifies the permission of the specified sub-memory area to readable, non-writable, and executable.

[0198] S713. The kernel 23 notifies the main process 21 that the permission modification of the specified sub-memory area is successful.

[0199] S714. The main process 21 notifies the rendering process 22 to execute the JIT code.

[0200] S715. The rendering process 22 executes the JIT code.

[0201] Among them, for the partial descriptions of steps S701 - S715, reference can be made to Figures 2 to 6 the embodiments shown, which will not be elaborated here. In this way, through the above - mentioned various modules, the electronic device 100 jointly provides the security for the electronic device 100 to execute JIT code.

[0202] In some examples, before the electronic device 100 reclaims a specified sub - memory area, the memory release verification module 36 can obtain the integrity information 81 of the specified sub - memory area from the integrity information verification module 37. The memory release verification module 36 can also calculate the integrity information 82 based on the JIT code of the specified sub - memory area. The memory release verification module 36 can detect whether the integrity information 81 is the same as the integrity information 82. When the memory release verification module 36 detects that the integrity information 81 is different from the integrity information 82, it can send risk data to the risk perception module 34.

[0203] Among them, when the electronic device 100 reclaims a specified sub - memory area, the memory release verification module 36 can also notify the integrity information verification module 37 to delete the integrity information 81 of the specified sub - memory area. It can be understood that when the integrity information verification module 37 stores the integrity information in the form of a mapping table, the integrity information verification module 37 can delete the integrity information table entry corresponding to the specified sub - memory area.

[0204] In some examples, when the memory release verification module 36 detects that the integrity information 81 is different from the integrity information 82, it can send the address and size of the specified sub - memory area to the risk perception module 34. The risk perception module 34 can obtain JIT data from the specified sub - memory area based on the address and size of the specified sub - memory area.

[0205] Next, the electronic device 100 provided by the embodiments of the present application will be introduced.

[0206] The electronic device 100 can be a mobile phone, a tablet computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, an ultra - mobile personal computer (UMPC), a netbook, as well as a cellular phone, a personal digital assistant (PDA), an augmented reality (AR) device, a virtual reality (VR) device, an artificial intelligence (AI) device, a wearable device, a vehicle - mounted device, a smart home device, and / or a smart city device. The embodiments of the present application do not impose special restrictions on the specific type of this electronic device.

[0207] Figure 8 A schematic structural diagram of the electronic device 100 is shown.

[0208] Hereinafter, the embodiments will be specifically described by taking the electronic device 100 as an example. It should be understood that Figure 8 the illustrated electronic device 100 is merely an example, and the electronic device 100 may have more or fewer components than those Figure 8 shown in the figure, may combine two or more components, or may have different component configurations. The various components shown in the figure may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.

[0209] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. Among them, the sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0210] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than those shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0211] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0212] Among them, the controller may be the nerve center and command center of the electronic device 100. The controller may generate operation control signals according to the instruction operation code and timing signal to complete the control of fetching and executing instructions.

[0213] A memory may also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory may save the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can be directly called from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.

[0214] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.

[0215] It can be understood that the interface connection relationships between the modules illustrated in the embodiments of the present invention are only illustrative and do not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.

[0216] The charging management module 140 is configured to receive a charging input from a charger. The charger may be a wireless charger or a wired charger. In some embodiments of wired charging, the charging management module 140 may receive the charging input of the wired charger through the USB interface 130. In some embodiments of wireless charging, the charging management module 140 may receive the wireless charging input through the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 may also supply power to the electronic device through the power management module 141.

[0217] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives the inputs from the battery 142 and / or the charging management module 140 and supplies power to the processor 110, the internal memory 121, the external memory, the display screen 194, the camera 193, the wireless communication module 160, etc. The power management module 141 may also be used to monitor parameters such as the battery capacity, the number of battery cycles, and the battery health status (leakage, impedance). In some other embodiments, the power management module 141 may also be provided in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 may also be provided in the same device.

[0218] The wireless communication function of the electronic device 100 may be implemented by the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modulation and demodulation processor, and the baseband processor, etc.

[0219] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 may be used to cover a single or multiple communication frequency bands. Different antennas may also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 may be multiplexed as the diversity antenna of the wireless local area network. In some other embodiments, the antenna may be used in combination with a tuning switch.

[0220] The mobile communication module 150 may provide solutions for wireless communications such as 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 may receive electromagnetic waves through the antenna 1, filter and amplify the received electromagnetic waves, and then transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 may also amplify the signal modulated by the modulation and demodulation processor and convert it into electromagnetic waves through the antenna 1 for radiation. In some embodiments, at least some functional modules of the mobile communication module 150 may be provided in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be provided in the same device.

[0221] The modulation and demodulation processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. Subsequently, the demodulator transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, receiver 170B, etc.), or displays an image or video through the display screen 194. In some embodiments, the modulation and demodulation processor may be an independent device. In other embodiments, the modulation and demodulation processor may be independent of the processor 110 and provided in the same device as the mobile communication module 150 or other functional modules.

[0222] The wireless communication module 160 may provide solutions for wireless communications applied to the electronic device 100, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite systems (GNSSs), frequency modulation (FM), near field communication (NFC), infrared (IR), etc. The wireless communication module 160 may be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 may also receive signals to be sent from the processor 110, perform frequency modulation and amplification on them, and convert them into electromagnetic waves through the antenna 2 for radiation.

[0223] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, such that electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS may include global positioning system (GPS), global navigation satellite system (GLONASS), beidou navigation satellite system (BDS), quasi-zenith satellite system (QZSS), and / or satellite based augmentation systems (SBAS).

[0224] Electronic device 100 implements a display function through a GPU, display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, and is connected to display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or change display information.

[0225] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD). The display screen panel can also adopt an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a miniLED, a microLED, a micro-OLED, a quantum dot light-emitting diode (QLED), etc. to manufacture. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than 1.

[0226] The electronic device 100 can implement the shooting function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor, etc.

[0227] The ISP is used to process the data fed back by the camera 193. For example, when taking a photo, the shutter is opened, and the light passes through the lens and is transmitted to the camera photosensitive element. The optical signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing and converts it into an image visible to the naked eye. The ISP can also perform algorithm optimization on the noise, brightness, etc. of the image. The ISP can also optimize parameters such as the exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.

[0228] The camera 193 is used to capture static images or videos. An object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then transmits the electrical signal to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in standard RGB, YUV, etc. formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.

[0229] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0230] The video codec is used to compress or decompress digital videos. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple coding formats, such as: Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.

[0231] The NPU is a neural-network (NN) computing processor. By learning from the biological neural network structure, such as learning from the transmission mode between human brain neurons, it can quickly process the input information and can also continuously self-learn. Through the NPU, applications such as intelligent cognition of the electronic device 100 can be realized, such as: image recognition, face recognition, speech recognition, text understanding, etc.

[0232] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to achieve the data storage function. For example, files such as music and videos are saved in the external memory card.

[0233] The internal memory 121 can be used to store computer-executable program code, and the executable program code includes instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, the image playback function, etc.). The data storage area can store the data created during the use of the electronic device 100 (such as audio data, phone book, etc.). In addition, the internal memory 121 can include high-speed random access memory and can also include non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0234] The electronic device 100 can implement audio functions through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor, etc. For example, music playback, recording, etc.

[0235] The audio module 170 is used to convert digital audio information into an analog audio signal for output, and is also used to convert an analog audio input into a digital audio signal. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 can be disposed in the processor 110, or some functional modules of the audio module 170 can be disposed in the processor 110.

[0236] The speaker 170A, also known as a "loudspeaker", is used to convert an audio electrical signal into a sound signal. The receiver 170B, also known as an "earpiece", is used to convert an audio electrical signal into a sound signal. The microphone 170C, also known as a "microphone" or "transmitter", is used to convert a sound signal into an electrical signal.

[0237] The headphone jack 170D is used to connect a wired headphone.

[0238] The pressure sensor 180A is used to sense a pressure signal and can convert the pressure signal into an electrical signal. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194. The gyroscope sensor 180B can be used to determine the motion posture of the electronic device 100. The barometric pressure sensor 180C is used to measure barometric pressure. The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of a flip leather case. The acceleration sensor 180E can detect the magnitude of the acceleration of the electronic device 100 in all directions (generally three axes). The distance sensor 180F is used to measure distance. The proximity light sensor 180G can include, for example, a light emitting diode (LED) and a light detector. The electronic device 100 can use the proximity light sensor 180G to detect when the user holds the electronic device 100 close to the ear during a call, so as to automatically turn off the screen to achieve the purpose of power saving. The ambient light sensor 180L is used to sense the ambient light brightness. The fingerprint sensor 180H is used to collect fingerprints. The temperature sensor 180J is used to detect temperature. The touch sensor 180K, also known as a "touch panel". The touch sensor 180K can be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, also known as a "touch control screen". The bone conduction sensor 180M can obtain a vibration signal. The keys 190 include a power on key, a volume key, etc. The keys 190 can be mechanical keys. They can also be touch keys. The motor 191 can generate a vibration prompt. The indicator 192 can be an indicator light, which can be used to indicate the charging state, the change in battery power, and can also be used to indicate messages, missed calls, notifications, etc. The SIM card interface 195 is used to connect a SIM card.

[0239] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than limiting it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A program protection method, characterized in that: Applied to an electronic device, the electronic device runs an operating system and a specified application, the specified application includes a main process and a rendering process, and the operating system includes a kernel; the method includes: After the main process obtains the interpreted language code sent by the webpage server, the rendering process is called to compile the interpreted language code to obtain a just-in-time compiled JIT code; The rendering process writes the JIT code into a first memory area, where the permissions of the first memory area are readable, writable and non-executable; The main process calculates first integrity information of the JIT code; The main process sends a permission modification request to the kernel, where the permission modification request is used to notify the kernel to modify the permission of the first memory area to be readable, non-writable and executable; After receiving the permission modification request, the kernel calculates the second integrity information of the JIT code; When the kernel determines that the first integrity information is the same as the second integrity information, modifying the permission of the first memory area to be readable, non-writable and executable; When the rendering process runs the interpreted language code, the JIT code in the first memory area is executed.

2. The method according to claim 1, characterized in that The main process sends a permission modification request to the kernel, specifically including: The main process detects whether the JIT code includes malicious code; When the main process detects that the JIT code does not include malicious code, the main process sends the permission modification request to the kernel.

3. The method according to claim 1, characterized in that After the rendering process writes the JIT code into the first memory area, the method further includes: The main process detects whether the JIT code includes malicious code; If the main process detects that the JIT code includes malicious code, first risk data is sent to the risk server, where the first risk data is used to indicate that the JIT code is risky.

4. The method according to any one of claims 1 to 3, characterized in that Before the rendering process writes the JIT code into the first memory area, the method further includes: The main process calls the kernel to apply for a second memory area, where the second memory area includes the first memory area; The main process sends the address of the second memory area to the rendering process; The rendering process searches for the first memory area based on the data amount of the JIT code.

5. The method according to any one of claims 1 to 4, characterized in that After the main process obtains the interpreted language code sent by the web page server, the method further includes: The main process verifies the signature of the interpreted language code; The calling of the rendering process to compile the interpreted language code specifically includes: The main process verifies that the signature of the interpreted language code is successful, and calls the rendering process to compile the interpreted language code.

6. The method according to any one of claims 1 to 5, characterized in that After the kernel receives the permission modification request, the method further includes: The kernel determines whether the process sending the permission modification request is the main process; The calculating the second integrity information of the JIT code specifically includes: The kernel determines that the process sending the permission modification request is the main process, and calculates the second integrity information.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: When the kernel determines that the first integrity information is different from the second integrity information, denying permission to modify the first memory area.

8. The method according to any one of claims 1 to 7, characterized in that When the method further comprises: After the rendering process finishes executing the JIT code in the first memory area, the first memory area is reclaimed.

9. The method according to claim 8, characterized in that The method further comprises: Before reclaiming the first memory area, the kernel calculates third integrity information of the JIT code; When the third integrity information is different from the second integrity information, the electronic device sends second risk data to the risk server, where the second risk data is used to indicate that the JIT code is risky.

10. The method according to any one of claims 1 to 9, characterized in that The method further comprises: The electronic device calculates the first integrity information and the second integrity information based on a hash function.

11. The method according to any one of claims 1 to 10, characterized in that The interpreted language code is JavaScript code.

12. An electronic device, characterized in that: include: One or more processors and one or more memories; the one or more memories are coupled to the one or more processors, and the one or more memories are used to store computer executable programs, so that when the one or more processors execute the computer executable programs, the electronic device executes the method as described in any one of claims 1-11.

13. A computer-readable storage medium storing a computer program, characterized in that: When the computer program runs on a processor of an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 11.