Program running method and device, electronic equipment, vehicle and storage medium
By allocating encrypted and non-encrypted program instructions to different processor cores in the electronic devices of multi-core processors, physical isolation of encrypted program instructions is achieved, solving the security risks of encrypted codes at runtime, and improving security and operation efficiency.
Patent Information
- Application Number
- CN202510185036.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-30
AI Technical Summary
The encrypted code depends on the support of the software system during runtime. If there are vulnerabilities in the software system, there is still a risk of being tampered with or leaked.
By allocating encrypted program instructions to the first processor core to run in the electronic device of the multi-core processor, and non-encrypted program instructions to run in the second processor core, the physical isolation between the encrypted program instructions and the non-encrypted program instructions is realized.
It improves the difficulty of reverse analysis and tampering of encrypted program instructions, reduces the risk of accidental interference or information leakage by other non-related instructions, and enhances the security and confidentiality of private data and computing.
Smart Images

Figure CN120068117A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to a program running method, apparatus, electronic device, vehicle, and storage medium. Background Art
[0002] Code encryption refers to the technology of converting the source code or executable code of a computer program into encrypted code by using various encryption algorithms. Code encryption can increase the difficulty of code cracking and prevent unauthorized code from being accessed, understood, modified, and stolen.
[0003] The encrypted code depends on the support of a software system (such as an operating system) during runtime. If there are vulnerabilities in the software system or other code running on the software system, there is still a high risk of the encrypted code being tampered with or leaked. Summary of the Invention
[0004] In view of the above, embodiments of this application provide a program running method, apparatus, electronic device, vehicle, and storage medium, which are beneficial to reducing the risk of the encrypted code being tampered with or leaked.
[0005] In a first aspect, an embodiment of this application provides a program running method applied to an electronic device. The electronic device is configured with a multi-core processor, and the multi-core processor includes at least a first processor core and a second processor core. The program running method includes: In response to a running request for a target program, determine a first program instruction in the target program, where the first program instruction is the program instruction to be currently run; When the first program instruction belongs to an encrypted program instruction, run the first program instruction through the first processor core; where the encrypted program instruction is a program instruction encrypted by using a preset encryption technology; When the first program instruction does not belong to the encrypted program instruction, run the first program instruction through the second processor core.
[0006] In an embodiment of this application, there are encrypted program instructions in the target program. When the target program is reverse-analyzed, it is difficult to read the actual meaning of the encrypted program instructions, thereby increasing the difficulty of reverse analysis. In addition, during the process of running the target program by the electronic device in the embodiment of this application, the encrypted program instructions are allocated to the first processor core for running, and the non-encrypted program instructions are allocated to the second processor core for running, so that the encrypted program instructions and the non-encrypted program instructions can be physically isolated (on different processor cores), thereby increasing the difficulty of reverse analysis and tampering with the encrypted program instructions, reducing the risk of the encrypted program instructions being accidentally interfered with by other non-related instructions or information leakage, and helping to ensure the security and confidentiality of privacy data and calculations.
[0007] In some embodiments, the encrypted program instructions in the target program are stored in a first storage area, and the program instructions other than the encrypted program instructions in the target program are stored in a second storage area; Before running the first program instruction through the first processor core, it further includes: Reading the first program instruction from the first storage area through the first processor core; Before running the first program instruction through the second processor core, it further includes: Reading the first program instruction from the second storage area through the second processor core.
[0008] In the embodiments of the present application, the encrypted program instructions and the non-encrypted program instructions are stored in partitions. On the one hand, it can reduce the risk of the encrypted program instructions being accidentally accessed by non-related instructions or data leakage at the storage level, which is beneficial to further improving security. On the other hand, each processor core can obtain the required instructions from the corresponding storage area, which is beneficial to the division of labor of the processor cores, and thus improves the running efficiency of the target program. In some embodiments, running the first program instruction through the first processor core includes: When the first program instruction calls a first function, initiating a first core switching message through the first processor core, wherein the function body of the first function has not been encrypted; Running the first function through the second processor core in response to the first core switching message to obtain a first running result; Continuing to run the first program instruction through the first processor core based on the first running result.
[0009] In the embodiments of the present application, when the first processor core runs the first program instruction and the first program instruction calls a second function (i.e., a function whose function body has not been encrypted), the electronic device can perform a core switching operation, that is, after running the first function through the second processor core, return the first running result, so as to further ensure that the first processor core and the second processor core can run the code according to whether the program is encrypted, ensure that the function can be smoothly run by the corresponding processor core, and improve the running efficiency and security of the code.
[0010] In some embodiments, continuing to run the first program instruction through the first processor core based on the first running result includes: Encrypting the first running result through the first processor core to obtain an encrypted first running result; Continuing to run the first program instruction through the first processor core based on the encrypted first running result.
[0011] In the embodiments of the present application, the encryption operation is handed over to the first processor core, enabling the first processor core to specifically run the encrypted code and improving the security of the interactive data.
[0012] In some embodiments, running the first program instruction through the second processor core includes: When the first program instruction calls a second function, initiating a second core switching message through the second processor core, where the function body of the second function is encrypted; Running the second function through the first processor core in response to the second core switching message to obtain a second running result; Continuing to run the first program instruction through the second processor core based on the second running result.
[0013] In the embodiments of the present application, when the second processor core runs the first program instruction and the first program instruction calls a first function (i.e., a function with an encrypted function body), the electronic device can perform a core switching operation, that is, run the first function through the first processor core and return a second running result, further enabling the first processor core and the second processor core to run the code according to whether the program is encrypted, ensuring the smooth running of the corresponding processor core for the code, and improving the code running efficiency and security.
[0014] In some embodiments, after running the second function through the first processor core in response to the second core switching message to obtain a second running result, it further includes: Decrypting the second running result through the first processor core to obtain a decrypted second running result; The continuing to run the first program instruction through the second processor core based on the second running result includes: Continuing to run the first program instruction through the second processor core based on the decrypted second running result.
[0015] In the embodiments of the present application, handing over the decryption operation to the first processor core and then externally sending the decrypted second running result is beneficial to improving the security of the interactive data.
[0016] In some embodiments, the target program is a program obtained by compiling the source code; The source code includes a first code segment and a second code segment. The first code segment is the code segment to be encrypted, and the second code segment is the code segment in the source code other than the first code segment; the compilation steps of the source code include: In response to a compilation request for the source code, encrypt and compile a first code snippet based on a preset first compiler to obtain a first compilation result, and encrypt the program instructions corresponding to the first compilation result using the preset encryption technology; Compile a second code snippet based on a preset second compiler to obtain a second compilation result, and the program instructions corresponding to the second compilation result are not encrypted using the preset encryption technology; Determine the target program based on the first compilation result and the second compilation result. In the embodiments of the present application, the first code snippet (the code snippet to be encrypted) and the second code snippet (the remaining code snippets) in the source code are respectively compiled using different compilers, which is conducive to achieving targeted optimization of compilation and improving compilation performance. In some embodiments, the program running method further includes: Identify the code snippets carrying a first preset tag in the source code to determine the first code snippet, and / or identify the code snippets carrying a second preset code tag in the source code to determine the second code snippet.
[0017] In the embodiments of the present application, preset tags are used to identify whether a code snippet needs to be encrypted, that is, the code areas that need to be encrypted can be clearly divided at the source code level, which is conducive to relevant personnel to expand and maintain the code.
[0018] In some embodiments, the preset encryption technology includes homomorphic encryption technology.
[0019] Since homomorphic encryption technology allows specific calculations to be directly performed on the encrypted program (data), therefore, adopting homomorphic encryption technology can reduce the frequency of encryption and decryption during the operation of the first kernel program, improve the code running efficiency, and reduce the exposure risk.
[0020] In a second aspect, the embodiments of the present application provide a program running device, which is applied to an electronic device. The electronic device is configured with a multi-core processor, and the multi-core processor includes at least a first processor core and a second processor core. The program running device includes: A running instruction determination module, configured to determine a first program instruction in the target program in response to a running request for the target program, where the first program instruction is the program instruction to be currently run; An encrypted program running module, configured to run the first program instruction through the first processor core when the first program instruction belongs to an encrypted program instruction; Wherein, the encrypted program instruction is a program instruction encrypted using a preset encryption technology; The non-encrypted program running module is used to run the first program instruction through the second processor core when the first program instruction does not belong to the encrypted program instruction.
[0021] In a third aspect, an embodiment of the present application further provides an electronic device, which includes a multi-core processor and a memory. The multi-core processor includes at least a first processor core and a second processor core. The memory is used to store instructions, and the processor is used to make the electronic device execute the program running method as described in the first aspect through the instructions in the memory.
[0022] In a fourth aspect, an embodiment of the present application further provides a vehicle, which includes the electronic device described in the third aspect.
[0023] In a fifth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores computer instructions. When the computer instructions run on an electronic device, the electronic device is made to execute the program running method as described in the first aspect. Description of the Drawings
[0024] Figure 1 It is a flowchart of the steps of a program running method provided according to an embodiment of the present application.
[0025] Figure 2 It is a schematic diagram of the storage area structure of a target program provided according to an embodiment of the present application.
[0026] Figure 3 It is a flowchart of the steps of a code compilation method provided according to an embodiment of the present application.
[0027] Figure 4 It is a schematic diagram of the structure of a program running device provided according to an embodiment of the present application.
[0028] Figure 5 It is a schematic diagram of the structure of an electronic device provided according to an embodiment of the present application. Detailed Embodiments
[0029] In order to be able to more clearly understand the above-mentioned objects, features, and advantages of the present application, the present application will be described in detail below with reference to the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0030] Many specific details are set forth in the following description in order to provide a thorough understanding of the present application. The described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.
[0031] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs. The terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.
[0032] Further, it should be noted that in this text, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or device comprising such element.
[0033] In this application, "at least one" means one or more, and "a plurality" means two or more than two. "And / or" describes the associated relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, or B exists alone, where A and B may be singular or plural. The terms "first", "second", "third", "fourth", etc. (if any) in the specification, claims and drawings of this application are used to distinguish similar objects and not to describe a specific order or sequence.
[0034] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0035] The relevant concepts and background technologies related to the embodiments of this application are described below.
[0036] An executable program is a computer program file that can be directly loaded and run by an operating system. It includes machine language instructions that enable the processor of a computer to perform specific tasks, such as calculations, data processing, graphic display, etc.
[0037] For example, under the Windows operating system, an executable file can be in the PE (Portable Executable) format, and under the Unix operating system and Linux operating system, an executable file can be in the ELF (Executable and Linkable Format) format.
[0038] An executable program may include a text segment (TEXT) and a data segment (DATA).
[0039] The text segment is also known as the code segment, which includes compiled machine language instructions. Machine language instructions are the core part of the implementation of the program's logic and algorithms, and are the specific operation steps for the program to perform various functions. In the executable file format, the text segment has a specific structure and storage location. The file header may include information such as the size of the text segment and its offset in the file.
[0040] For example, the e_text field in the ELF file header indicates the starting position of the text segment. With this information, the operating system can read the content of the text segment to the correct position in memory when loading the program.
[0041] The data segment is mainly used to store data used during the program's operation, such as initialized global variables and static variables. The data in the data segment is the object of the program's operations. The program can read, modify, and process this data through the instructions in the text segment to achieve various functions, such as calculations and storing user input.
[0042] The core code in software may carry key functions, algorithms, and data processing logics of the software. Once the core code is leaked, tampered with, or maliciously exploited, it will bring serious consequences to the entire software and related businesses.
[0043] Taking software-defined vehicles as an example, the core code in automotive software may involve control algorithms for autonomous driving, key logics of vehicle safety systems, and core mechanisms of battery management systems. If this code is obtained and tampered with by lawbreakers, it may lead to serious situations such as the risk of out-of-control autonomous driving, the failure of vehicle safety protection, or battery failures, which seriously endanger the lives of passengers and the normal use of the vehicle. Therefore, its protection is particularly important.
[0044] Code encryption technology can encrypt code. For example, it can encrypt key core code to improve the security of key core code. However, the encrypted code depends on the support of a software system (such as an operating system) during operation. If there are vulnerabilities in the software system or other code running on the software system, the encrypted code will still have a high risk of being tampered with or leaked.
[0045] In some embodiments, an electronic device may implement encryption processing based on a virtual machine. For example, first, an encrypted application program is obtained by encrypting intermediate code, and then the encrypted application program is loaded and run by a virtual machine with encryption processing.
[0046] A virtual machine can provide a relatively independent operating environment, isolating the homomorphically encrypted application program from the host system to ensure the security of the encrypted code.
[0047] However, the above technology of running homomorphic encryption using a virtual machine still has the following problems: 1. The virtual machine simulates the hardware environment through software to run the program. Each instruction from the application program needs to be converted and processed by the virtual machine software layer before it can be executed on the physical hardware, which may lead to low operating efficiency.
[0048] 2. Since the virtual machine is implemented based on software, its own code and operating mechanism can be analyzed and understood. Reverse analysts can try to find vulnerabilities or key execution logics in the virtual machine software by means of decompiling the binary file of the virtual machine software, dynamic debugging, etc. If there are security vulnerabilities in the virtual machine, attackers can also use these vulnerabilities to break through the isolation boundary of the virtual machine and directly access or tamper with the programs or data inside the virtual machine from the outside.
[0049] 3. In the above, the virtual machine intermediate code file is homomorphically encrypted as a whole, and the encryption granularity is relatively large, restricting the flexibility of code operation and making it difficult to meet the needs of refined security management and code maintenance.
[0050] In view of the above, the embodiments of the present application provide a program running method, device, electronic device, vehicle, and computer-readable storage medium.
[0051] The program running method provided by the embodiments of the present application is applied to an electronic device. The electronic device can be a portable electronic device (such as a mobile phone, a tablet computer), a personal computer, a server, a vehicle-mounted computer, etc.
[0052] The electronic device is configured with a multi-core processor. The multi-core processor includes at least a first processor core and a second processor core.
[0053] In this program running method, the electronic device can, in response to a running request for a target program, determine a first program instruction in the target program, where the first program instruction is the program instruction to be currently run.
[0054] When the first program instruction belongs to an encrypted program instruction, the first program instruction is run by the first processor core.
[0055] Wherein, the encrypted program instruction is a program instruction encrypted using a preset encryption technology.
[0056] When the first program instruction does not belong to the encrypted program instruction, the first program instruction is run by the second processor core.
[0057] During the operation of the target program by the electronic device according to the embodiments of the present application, the encrypted program instructions are allocated to the first processor core for operation, and the non-encrypted program instructions are allocated to the second processor core for operation, so that the encrypted program instructions and the non-encrypted program instructions can be isolated at the hardware physical level (different processor cores), thereby increasing the difficulty of reverse analysis and tampering of the encrypted program instructions, reducing the risk of accidental interference or information leakage of the encrypted program instructions by other non-related instructions, and helping to ensure the security and confidentiality of private data and calculations.
[0058] Moreover, by running the target program on a multi-core processor, it is beneficial to improve the running efficiency of the target program.
[0059] Figure 1 It is a flowchart of the steps of an embodiment of the program running method of the present application. According to different requirements, the order of the steps in the flowchart can be changed, and some steps can be omitted.
[0060] Refer to Figure 1 As shown, the program running method may include the following steps.
[0061] Step 101, in response to a running request for the target program, determine the first program instruction in the target program.
[0062] Wherein, the first program instruction is the program instruction to be currently run, and the program instruction is the basic operation command that the electronic device can understand and execute. The program instruction may include an operation code and an operand.
[0063] The target program is the program obtained by compiling the source code. For example, the target program may be an executable file, or a binary code library (i.e., a library file).
[0064] The target program may include program instructions encrypted by a preset encryption technology (denoted as encrypted program instructions), and program instructions not encrypted by the preset encryption technology (denoted as non-encrypted program instructions).
[0065] Wherein, the preset encryption technology may include: symmetric encryption technology, asymmetric encryption technology, code obfuscation technology, homomorphic encryption technology.
[0066] In some embodiments, referring to Figure 2 As shown, the encrypted program instructions in the target program may be stored in the first storage area, and the program instructions in the target program other than the encrypted program instructions may be stored in the second storage area.
[0067] Furthermore, the first storage area may include a first text segment (.hoentext) and a first data segment (.hoendata); the second storage area may include a second text segment (.text) and a second data segment (.data).
[0068] The first processor core can read the first program instruction from the first storage area and then run the first program instruction.
[0069] The second processor core can read the first program instruction from the second storage area and then run the first program instruction through the second processor core.
[0070] In the embodiments of the present application, encrypted program instructions and non-encrypted program instructions are stored in partitions. On the one hand, it can reduce the risk of encrypted program instructions being accidentally accessed by non-related instructions or data leakage at the storage level, which is beneficial to further improving security. On the other hand, each processor core can obtain the required instructions from the corresponding storage area, which is beneficial to the division of labor of the processor cores, thereby improving the running efficiency of the target program.
[0071] For example, an electronic device can create a program counter, which can be used to store the address of the program instruction to be executed in the memory. When the electronic device starts the target program, the program counter will be initialized to the memory address of the entry point of the target program.
[0072] In the case of sequential instruction execution, after each instruction is executed, the program counter will be automatically updated to the address of the next instruction. The electronic device can determine the address of the first program instruction based on the program counter.
[0073] Step 102, detect whether the first program instruction belongs to an encrypted program instruction.
[0074] Among them, the encrypted program instruction is a program instruction encrypted using a preset encryption technology.
[0075] In some embodiments, the target program can carry a tag, which can be used to indicate whether each program instruction belongs to an encrypted program instruction, so as to detect whether the first program instruction belongs to an encrypted program instruction.
[0076] In the case where the first program instruction belongs to an encrypted program instruction, execute step 103.
[0077] In the case where the first program instruction does not belong to the encrypted program instruction, execute step 104.
[0078] Step 103, run the first program instruction through the first processor core.
[0079] The first processor core is a processor core for processing homomorphic encryption program instructions. The electronic device can include one or more first processor cores, and the embodiments of the present application do not limit the number of first processor cores.
[0080] In the case where the first program instruction belongs to an encrypted program instruction, the first processor core may read the first program instruction from the first storage area to run the first program instruction.
[0081] In some embodiments, the target program may include program instructions for calling a first function, where the function body of the first function has not been encrypted, that is, the first function is a function whose function body is not encrypted using a preset encryption technique.
[0082] In the case where the first program instruction calls the first function, the electronic device may initiate a first core switching message through the first processor core; the second processor core may run the first function in response to the first core switching message to obtain a first operation result; the first processor core may continue to run the first program instruction based on the first operation result.
[0083] Among them, the first core switching message is used to indicate that the second processor core runs the first function.
[0084] The first core switching message may include the input parameters of the first function.
[0085] The first operation result may include the return value of the first function, whether the operation is successful, etc.
[0086] In the embodiments of the present application, during the running of the target program, core switching can be flexibly performed according to whether the program instructions in the target program are encrypted, which is beneficial to encrypting a certain function or a certain code segment, reducing the encryption granularity, improving the flexibility of code encryption, and being beneficial to the maintenance and management of the code.
[0087] Further, the first processor core continuing to run the first program instruction based on the first operation result can be achieved in the following manner: The first processor core encrypts the first operation result to obtain an encrypted first operation result; the first processor core continues to run the first program instruction based on the encrypted first operation result.
[0088] The above encryption algorithm may adopt a homomorphic encryption algorithm, but is not limited thereto.
[0089] The embodiments of the present application use the first processor core for encryption, which is beneficial to isolating the running of non-encrypted program instructions, thereby reducing the interference of the running process of ordinary code on the encryption process and improving security. Next, the embodiments of the present application directly use the encrypted first operation result for the running of program instructions, which can make full use of the homomorphic operation properties of ciphertext and is beneficial to improving the running efficiency of the program.
[0090] The above step 103 is the process of the electronic device running the first program instruction when the first program instruction belongs to an encrypted program instruction. When the first program instruction does not belong to an encrypted program instruction, the electronic device can execute the following step 104.
[0091] Step 104, run the first program instruction through the second processor core.
[0092] The second processor core is a processor core for processing program instructions of non - homomorphic encryption. The electronic device includes one or more second processor cores, and the embodiments of the present application do not limit the number of second processor cores.
[0093] When the first program instruction does not belong to an encrypted program instruction, the second processor core can read the first program instruction from the second storage area to execute the first program instruction.
[0094] In some embodiments, the target program may further include a second function, and the second function is a function whose function body is encrypted based on a preset encryption technology, such as homomorphic encryption technology.
[0095] When the first program instruction calls the second function, the electronic device can initiate a second core switching message through the second processor core; the first processor core can run the second function in response to the second core switching message to obtain a second running result; then, the second processor core continues to run the first program instruction based on the second running result.
[0096] Among them, the second core switching message is used to indicate that the second function is run by the first processor core.
[0097] The second core switching message may include the input parameters of the second function.
[0098] The second running result may include the return value of the second function, whether it runs successfully, etc.
[0099] Further, in some embodiments, after the first processor core runs the second function in response to the second core switching message to obtain a second running result, the first processor core may decrypt the second running result to obtain a decrypted second running result; the second processor core continues to run the first program instruction based on the decrypted second running result.
[0100] The embodiments of the present application use the first processor core (the processor core for running encrypted program instructions) to decrypt the data, so that the second processor core can smoothly understand the second running result and ensure the security of the second running result.
[0101] In some embodiments, in addition to encrypting the above first operation result, the first processor core may also encrypt other received messages, so that processing can be performed based on the encrypted messages during the processing.
[0102] Similarly, in addition to decrypting the above second operation result, the second processor core may also decrypt other messages sent out, so that other components in the electronic device can accurately understand the message.
[0103] After executing step 103 or step 104, the electronic device may determine the next program instruction to be executed (i.e., the second program instruction), and then continue to step 102 until the target program runs to completion.
[0104] In some embodiments, the electronic device may create at least two threads or processes, and execute the target program in parallel through the at least two threads or processes, thereby improving the execution efficiency of the target program.
[0105] For example, the electronic device may create at least two threads (such as a first thread and a second thread). The first thread may be set as a thread dedicated to processing encrypted program instructions, and the second thread may be set as a thread dedicated to processing non-encrypted program instructions. The first thread may be bound to the first processor core to process encrypted program instructions, and the second thread may be bound to the second processor core to process non-encrypted program instructions. The first processor core and the second processor core may process the target program in parallel to improve the execution efficiency of the target program.
[0106] In the case where the thread is not bound to the processor core, the electronic device may allocate encrypted program instructions to the first processor core for running, and allocate non-encrypted program instructions to the second processor core for running.
[0107] If there is no mutual call between the encrypted program instructions and the unencrypted program instructions, the two can be processed in parallel, making full use of the advantages of the multi-core processor to improve the throughput and processing capacity of the system. When there is a mutual call between the encrypted program instructions and the unencrypted program instructions, since they run on different processor cores, inter-core switching and process synchronization operations are required.
[0108] During the running of the target program by the electronic device according to the embodiments of the present application, the encrypted program instructions are allocated to the first processor core for running, and the non-encrypted program instructions are allocated to the second processor core for running, so that the encrypted program instructions and the non-encrypted program instructions can be physically isolated (on different processor cores), thereby increasing the difficulty of reverse analysis and tampering of the encrypted program instructions, reducing the risk of accidental interference or information leakage of the encrypted program instructions by other non-related instructions, and helping to ensure the security and confidentiality of private data and computing.
[0109] An embodiment of the present application also provides a code compilation method. The code compilation method can be executed on a compilation device, which can be the same device as the above-mentioned electronic device or a different device from the above-mentioned electronic device. The embodiments of the present application do not limit this.
[0110] This code compilation method can be used to compile source code to obtain the above-mentioned target program.
[0111] Among them, the source code includes a first code segment and a second code segment.
[0112] The first code segment is the code segment to be encrypted. That is, the first code segment is the code segment to be encrypted using a preset encryption technology.
[0113] The second code segment is the code segment in the source code other than the first code segment.
[0114] Reference Figure 3 As shown, the compilation steps of the source code include: Step 301, in response to a compilation request for the source code, identify the first code segment and the second code segment in the source code.
[0115] In some embodiments, the compilation device can identify the code segment carrying a first preset tag in the source code to determine the first code segment, and then use the other code segments except the first code segment as the second code segment.
[0116] The first preset code tag is used to indicate the code segment to be encrypted. For example, when developing, a developer can mark this first preset code tag at certain code segments or functions, so that the compilation device can identify this first preset code tag and use it as the first code segment.
[0117] For another example, the compilation device can identify the segment carrying a second preset code tag in the source code to determine the second code segment, and then use the other code segments except the second code segment as the first code segment.
[0118] Step 302, perform encrypted compilation on the first code segment based on a preset first compiler to obtain a first compilation result.
[0119] The program instructions corresponding to the first compilation result are encrypted using the preset encryption technology. The preset encryption technology can be a homomorphic encryption technology.
[0120] For example, the first compiler can be a homomorphic encryption compiler, and the compilation device can perform homomorphic encryption compilation on the first code segment based on the homomorphic encryption compiler to obtain a first compilation result.
[0121] That is, the first compiler can perform homomorphic encryption on the first code snippet during the process of compiling the first code snippet.
[0122] Step 303: compile the second code snippet based on a preset second compiler to obtain a second compilation result.
[0123] The program instructions corresponding to the second compilation result are not encrypted using the preset encryption technology.
[0124] For example, the second compiler may be a common compiler, and the second compiler may compile the second code segment to obtain a second compilation result.
[0125] Step 304: determine the target program based on the first compilation result and the second compilation result.
[0126] For example, the compiling device may integrate the first compiling result and the second compiling result to obtain the target program.
[0127] Based on the same idea as the program running method in the above embodiment, the present application also provides a program running device, which can be used to execute the above program method. For ease of explanation, the structural diagram of the program running device embodiment only shows the parts related to the embodiment of the present application. It can be understood by those skilled in the art that the illustrated structure does not constitute a limitation on the device, and may include more or fewer components than shown in the diagram, or combine certain components, or arrange the components differently.
[0128] like Figure 4 As shown, the program running device includes an execution instruction determination module 401, an encrypted program running module 402, and a non-encrypted program running module 403. In some embodiments, the above modules may be programmable software instructions stored in a memory and executable by a processor. It is understood that in other embodiments, the above modules may also be program instructions or firmware solidified in the processor.
[0129] An execution instruction determination module 401 is used to determine a first program instruction in the target program in response to an execution request for the target program, wherein the first program instruction is a program instruction currently to be executed; An encrypted program running module 402, configured to run the first program instruction through the first processor core when the first program instruction is an encrypted program instruction; Wherein, the encrypted program instruction is a program instruction encrypted using a preset encryption technology; The non-encrypted program running module 403 is used to run the first program instruction through the second processor core when the first program instruction does not belong to the encrypted program instruction.
[0130] Figure 5 This is a schematic diagram of an embodiment of the electronic device of the present application.
[0131] The electronic device 100 includes a memory 20, a processor 30, and a computer program 40 stored in the memory 20 and executable on the processor 30. When the processor 30 executes the computer program 40, it implements the steps in the above-described embodiment of the program running method, such as Figure 1 the steps 101 to 104 shown.
[0132] Exemplarily, the computer program 40 can also be divided into one or more modules / units, and the one or more modules / units are stored in the memory 20 and executed by the processor 30. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program 40 in the electronic device 100. For example, it can be divided into Figure 3 the shown running instruction determination module 401, encryption program running module 402, and non-encryption program running module 403.
[0133] Those skilled in the art can understand that the schematic diagram is only an example of the electronic device 100, and does not constitute a limitation on the electronic device 100. It may include more or fewer components than shown, or combine some components, or different components. For example, the electronic device 100 may further include input / output devices, network access devices, buses, etc.
[0134] The processor 30 can be a central processing unit (CPU), or can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, a single-chip microcomputer, or the processor 30 can also be any conventional processor, etc. The processor 30 can include a first processor core and a second processor core.
[0135] The memory 20 can be used to store the computer program 40 and / or modules / units. The processor 30 realizes various functions of the electronic device 100 by running or executing the computer program and / or modules / units stored in the memory 20, and by the data stored in the memory 20.
[0136] The memory 20 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created according to the use of the electronic device 100 (such as audio data, etc.). In addition, the memory 20 may include a high-speed random access memory, and may also include a non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices.
[0137] If the modules / units integrated in the electronic device 100 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-described embodiment methods of this application, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.
[0138] The embodiment of this application also provides a vehicle, which may include the above-described electronic device. The electronic device may be a car machine, an Electronic Control Unit (ECU), etc., but is not limited thereto, and the embodiment of this application does not limit this.
[0139] In several embodiments provided by the present application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the electronic device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation.
[0140] In addition, in each embodiment of the present application, the functional units can be integrated in the same processing unit, or each unit can exist physically alone, or two or more units can be integrated in the same unit. The above integrated units can be implemented in the form of hardware, or in the form of hardware plus software function modules.
[0141] For those skilled in the art, it is obvious that the present application is not limited to the details of the above exemplary embodiments, and the present application can be implemented in other specific forms without departing from the spirit or basic characteristics of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. In addition, it is obvious that the word "including" does not exclude other units or steps, and the singular does not exclude the plural. The multiple units or electronic devices stated in the claims of the electronic device can also be implemented by the same unit or electronic device through software or hardware. The words such as first and second are used to represent names and do not represent any specific order.
[0142] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and not to limit them. Although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that the technical solutions of the present application can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present application.
Claims
1. A program running method, characterized in that: An electronic device is used, the electronic device is configured with a multi-core processor, the multi-core processor includes at least a first processor core and a second processor core, and the program running method includes: In response to a request to execute a target program, determining a first program instruction in the target program, wherein the first program instruction is a program instruction currently to be executed; In the case where the first program instruction is an encrypted program instruction, executing the first program instruction by the first processor core; Wherein, the encrypted program instruction is a program instruction encrypted using a preset encryption technology; In a case where the first program instruction does not belong to the encrypted program instruction, the first program instruction is executed by the second processor core.
2. The program running method according to claim 1, characterized in that: The encrypted program instructions in the target program are stored in a first storage area, and the program instructions in the target program other than the encrypted program instructions are stored in a second storage area; Before executing the first program instruction by the first processor core, the method further includes: Reading the first program instruction from the first storage area by the first processor core; Before executing the first program instruction by the second processor core, the method further includes: The first program instructions are read from the second storage area by the second processor core.
3. The program running method according to claim 1, characterized in that: The executing the first program instruction by the first processor core includes: Initiating a first core switching message through the first processor core when the first program instruction calls a first function, wherein a function body of the first function has not been encrypted; In response to the first core switching message, the second processor core executes the first function to obtain a first execution result; The first program instructions are continued to be executed based on the first execution result by the first processor core.
4. The program running method according to claim 3, characterized in that: The continuing to execute the first program instruction based on the first execution result by the first processor core includes: Encrypting the first operation result by the first processor core to obtain an encrypted first operation result; The first program instruction continues to be executed based on the encrypted first execution result by the first processor core.
5. The program running method according to claim 1, characterized in that: The executing the first program instruction by the second processor core includes: In the case where the first program instruction calls a second function, initiating a second core switching message through the second processor core, wherein the function body of the second function is encrypted; In response to the second core switching message, the first processor core executes the second function to obtain a second execution result; The first program instructions are continued to be executed based on the second execution result by the second processor core.
6. The program running method according to claim 5, characterized in that: After the first processor core responds to the second core switching message and executes the second function to obtain a second execution result, the method further includes: Decrypting the second operation result by the first processor to obtain a decrypted second operation result; The continuing to execute the first program instruction based on the second execution result by the second processor core includes: The first program instruction continues to be executed based on the decrypted second execution result through the second processor core.
7. The program running method according to claim 1, characterized in that: The target program is a program obtained by compiling the source code; The source code includes a first code segment and a second code segment, the first code segment is a code segment to be encrypted, and the second code segment is a code segment in the source code other than the first code segment; The steps of compiling the source code include: In response to a compilation request for the source code, encrypting and compiling the first code fragment based on a preset first compiler to obtain a first compilation result, wherein the program instructions corresponding to the first compilation result are encrypted using the preset encryption technology; Compiling the second code snippet based on a preset second compiler to obtain a second compilation result, wherein the program instructions corresponding to the second compilation result are not encrypted using the preset encryption technology; The target program is determined based on the first compiling result and the second compiling result.
8. The program running method according to claim 7, characterized in that: The program running method also includes: A code snippet carrying a first preset tag is identified in the source code to determine the first code snippet, and / or a code snippet carrying a second preset code tag is identified in the source code to determine the second code snippet.
9. The program running method according to any one of claims 1 to 8, characterized in that: The preset encryption technology includes homomorphic encryption technology.
10. A program running device, characterized in that: An electronic device is used, the electronic device is configured with a multi-core processor, the multi-core processor includes at least a first processor core and a second processor core, and the program running device includes: An execution instruction determination module, configured to determine a first program instruction in the target program in response to an execution request for the target program, wherein the first program instruction is a program instruction currently to be executed; an encrypted program running module, configured to run the first program instruction through the first processor core when the first program instruction is an encrypted program instruction; Wherein, the encrypted program instruction is a program instruction encrypted using a preset encryption technology; The non-encrypted program running module is used to run the first program instruction through the second processor core when the first program instruction does not belong to the encrypted program instruction.
11. An electronic device, comprising a multi-core processor and a memory, characterized in that: The multi-core processor includes at least a first processor core and a second processor core, the memory is used to store instructions, and the processor is used to enable the electronic device to execute the program running method according to any one of claims 1 to 9 through the instructions in the memory.
12. A vehicle, characterized in that: The vehicle includes the electronic device as claimed in claim 11.
13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and when the computer instructions are executed on an electronic device, the electronic device executes the program execution method according to any one of claims 1 to 9.