Data hiding execution method and terminal
By setting a blank code area in the program, copying and filling the sub-page code to be hidden and executed, the hidden execution of data is achieved, solving the problems of code security and performance impact in the prior art, and improving the concealment and security of the code.
Patent Information
- Application Number
- CN202510171773.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-13
AI Technical Summary
When implementing data hiding, the prior art usually needs to change the original program, which increases the complexity and security risks of the code, and encryption methods may be deciphered, affecting performance.
By setting a preset blank code area in the program, obtaining and copying the address page of the code to be hidden, generating a sub-page code, and filling it into the blank code area, realizing hidden execution of the code.
Without changing the original program, hidden execution of data is achieved, the security of the code is improved, and malware or attackers are prevented from discovering the actual execution logic of the code through conventional analysis methods.
Smart Images

Figure CN120145372A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data protection, and particularly to a method and a terminal for executing data hiding. Background Art
[0002] Currently, the memory hiding technology is an important technical means, aiming to store specific information, programs or data in the computer memory and ensure that these contents are invisible or difficult to discover for the conventional operating system, other programs or ordinary users. This technology has broad application prospects, such as protecting sensitive information from illegal access, preventing malware from being easily detected by the detection system, and conducting system security research and other fields. In the prior art, the memory hiding technology can be realized through virtualization technology, process HOOK technology or memory encryption technology: The virtualization technology creates a virtual environment at the hardware level, so that the programs and data running in the virtual environment are isolated from the host environment, thereby achieving the purpose of hiding. However, as a global system technology, it affects the entire computer system and has extremely high requirements for the compatibility of hardware and software, which limits its application in certain specific scenarios.
[0003] The process HOOK technology realizes memory hiding by modifying or intercepting specific function calls in the operating system or application programs. This method requires operations such as injecting into the target process, which can achieve memory hiding to a certain extent, but at the same time brings risks in terms of compatibility, stability and security, and due to the need to spend a lot of effort on development and debugging, it increases the difficulty and cost of technical implementation.
[0004] The memory encryption technology encrypts and decrypts memory blocks, so that the data in the memory is encrypted or decrypted during execution, thereby achieving the purpose of covert access. Although this method has the property of high hiding, with the continuous development of cracking technology, the encryption method may be deciphered. At the same time, the encryption and decryption processes consume a large amount of CPU resources, affecting the performance of the program. Especially in the case of high execution frequency, excessive memory encryption may even affect the main logic efficiency of the program. Summary of the Invention
[0005] The technical problem to be solved by the present invention is: to provide a method and a terminal for executing data hiding, which can realize the hidden execution of data without changing the original program and improve the security of the code.
[0006] To solve the above technical problem, the technical solution adopted by the present invention is: A method for executing data hiding, comprising the steps: When the program runs to a preset blank code area, the service device obtains and copies the address page of the code to be hidden and executed to obtain a secondary page code, and fills the secondary page code address into the blank code area; Jump to the secondary page code through the secondary page code address filled in the blank code area for execution, and after the execution ends, jump back to the page where the program is located.
[0007] To solve the above technical problems, another technical solution adopted by the present invention is: A terminal for data hidden execution includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements each step of the above method for data hidden execution.
[0008] The beneficial effects of the present invention are as follows: By copying the address page of the code to be hidden and executed to generate a secondary page code and filling it into a preset blank code area, the program jumps to the secondary page code for execution during execution, and then jumps back to the original program page after the execution ends. This jump mechanism hides the execution path of the code, increases the concealment of code execution, and can effectively prevent malware or attackers from discovering the actual execution logic of the code through conventional code analysis means. Since the execution path of the code is hidden, even if the attacker obtains the code of the program, it is difficult to determine which code is actually executed, thereby increasing the difficulty of code tampering or malicious exploitation and improving the security of the code. After the execution ends, it can accurately jump back to the page where the program is located, ensuring that the normal operation logic of the program is not affected, and realizing the compatibility between hidden execution and normal program operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 It is a flowchart of a method for data hidden execution according to an embodiment of the present invention; Figure 2 It is a schematic diagram of a terminal for data hidden execution according to an embodiment of the present invention; Figure 3 It is a program flowchart of a method for data hidden execution according to an embodiment of the present invention; Figure 4 It is an internal flowchart of the service device according to an embodiment of the present invention; Figure 5 It is a flowchart of generating a secondary page code according to an embodiment of the present invention; Figure 6 It is a flowchart of the blank code triggering the execution of the secondary page according to an embodiment of the present invention.
[0010] Label Description: 1. A terminal for data hidden execution; 2. Memory; 3. Processor. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0011] To describe the technical content, achieved objectives and effects of the present invention in detail, the following will be described in conjunction with the embodiments and with reference to the accompanying drawings.
[0012] Please refer to Figure 1 , an embodiment of the present invention provides a method for executing data hiding, including the steps of: When the program runs to a preset blank code area, the service device acquires and copies the address page of the code to be hidden and executed to obtain a secondary page code, and fills the address of the secondary page code into the blank code area; Jump to and execute in the secondary page code through the address of the secondary page code filled in the blank code area, and after the execution is completed, jump back to the page where the program is located.
[0013] As can be seen from the above description, the beneficial effects of the present invention are as follows: By copying the address page of the code to be hidden and executed to generate a secondary page code and filling it into a preset blank code area, the program jumps to the secondary page code for execution when running, and jumps back to the original program page after the execution is completed. This jumping mechanism hides the execution path of the code, increases the concealment of code execution, and can effectively prevent malware or attackers from discovering the actual execution logic of the code through conventional code analysis means. Since the execution path of the code is hidden, even if the attacker obtains the code of the program, it is difficult to determine which code is actually executed, thereby increasing the difficulty of code tampering or malicious exploitation and improving the security of the code. After the execution is completed, it can accurately jump back to the page where the program is located, ensuring that the normal running logic of the program is not affected, and realizing the compatibility between hidden execution and normal program running.
[0014] Further, the service device acquires and copies the address page of the code to be hidden and executed to obtain a secondary page code, including: The service device acquires the address page of the code to be hidden and executed, establishes a copy page, and aligns the memory size of the secondary page with that of the address page; Fill the data of the address page of the code to be hidden and executed into the copy page to obtain a secondary page code.
[0015] As can be seen from the above description, by establishing a copy page, aligning the memory size of the copy page with that of the address page, and then filling the data of the address page of the code to be hidden and executed, it can be ensured that the secondary page code has the same structure and data as the original code in memory, guaranteeing the integrity and executability of the secondary page code. The clear copying process and memory alignment operation enable the secondary page code to accurately reflect the characteristics of the original code, reducing code execution errors caused by errors in the copying process and improving the reliability of code hidden execution.
[0016] Further, obtaining the address page of the execution code to be hidden by the service device further includes: Obtaining the corresponding address according to the address page of the execution code to be hidden, and calculating the offset and start address of the page according to the address; The secondary page is aligned with the memory size of the address page according to the offset and start address of the address page.
[0017] As can be seen from the above description, by obtaining the address corresponding to the address page of the execution code to be hidden and calculating the offset and start address of the page, the specific position of the address page in the memory can be accurately determined, providing an accurate basis for the subsequent alignment of the memory size of the secondary page with the address page. Memory alignment according to the offset and start address of the address page makes the layout of the secondary page in the memory highly consistent with the address page, further improving the compatibility and executability of the secondary page code and reducing code execution exceptions caused by memory alignment problems. Precise address positioning and memory alignment operations enable the secondary page code to more accurately simulate the execution environment of the original code, enhancing the effect of code hiding and making the hidden code more difficult to be discovered and analyzed.
[0018] Further, to obtain the secondary page code, it further includes: Storing the secondary page code and the address of the blank code area in a doubly linked list; Filling the address of the secondary page code into the blank code area includes: Querying the corresponding address of the secondary page code in the doubly linked list according to the address of the blank code area, and filling the address of the secondary page code into the blank code area.
[0019] As can be seen from the above description, marking the address space of the blank code area as the secondary page code and storing the secondary page code and the address of the blank code area in a doubly linked list can efficiently manage the correspondence between the secondary page code and the blank code area, facilitating quick query and access. When filling the address of the secondary page code, the corresponding address of the secondary page code can be quickly queried in the doubly linked list according to the address of the blank code area and filled into the blank code area, improving the efficiency of code hiding execution and reducing the latency during program operation. The storage method of the doubly linked list makes the relationship between the secondary page code and the blank code area more flexible, and can be dynamically adjusted and managed according to needs, further enhancing the flexibility and adaptability of code hiding.
[0020] Further, when the program runs to the preset blank code area, it further includes: When the program runs to the preset access of the preset blank code area, the service device obtains the preset access and obtains the address of the corresponding blank code area.
[0021] As described above, when the program runs to the preset access of the preset blank code area, the service device obtains the preset access and obtains the address of the corresponding blank code area. This trigger mechanism based on the preset access makes the startup of the code hidden execution more flexible and controllable. It can trigger the hidden execution according to different access conditions, increasing the flexibility of code hiding. By obtaining the address of the blank code area corresponding to the preset access, the position of the blank code area can be accurately determined, providing accurate address information for the subsequent filling of the secondary page code address and improving the accuracy of the code hidden execution. The trigger mechanism based on the preset access makes the hidden execution process more concealed. It will only start the hidden execution under specific access conditions, reducing the possibility of the hidden execution process being discovered and further improving the concealment of code hiding.
[0022] Please refer to Figure 2 , another embodiment of the present invention provides a terminal for data hidden execution, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements each step of the above-mentioned method for data hidden execution.
[0023] The above-mentioned method and terminal for data hidden execution of the present invention are applicable to realizing the hidden execution of data without changing the original program, improving the security of the code. The following is an explanation through specific implementation manners: Please refer to Figure 1 , the first embodiment of the present invention is: A method for data hidden execution, including the steps of: S1. When the program runs to the preset blank code area, the service device obtains and copies the address page of the code to be hidden and executed to obtain the secondary page code, and fills the secondary page code address into the blank code area.
[0024] In this embodiment, when the program is designed, a blank code area needs to be set. The blank code area only occupies 16 bytes of space, including 8 bytes of address space, 4 bytes of data space, and 4 bytes of assembly code space for jumping. Among them, the maximum address under x64 is 8 bits, that is, PVOID64. Therefore, the 8-byte address space can store both 8-byte x64 addresses and 4-byte x86 addresses. In this embodiment, the blank code area is used to trigger a jump to the secondary page to process the code to be hidden and executed, and then jump back to the original page of the program to execute the next code.
[0025] Please refer to Figure 3 and Figure 4, the business device obtains a blank code area, determines whether the program address belongs to an x64 address or an x86 address according to the address of the blank code area. If it is an x64 address, an 8-bit address space is obtained; if it is an x86 address, a 4-bit address space is obtained. The corresponding address is obtained according to the address page of the code to be hidden for execution. Since the memory is aligned by 0x1000, the page offset and the page start address are calculated based on the obtained address. Specifically, the page offset = address & 0xFFF. Here, the operation is to mask the high part of the virtual address through a bitwise AND operation, and only keep the low 12 bits (0xFFF is 1111 1111 1111 in binary, a total of 12 1s). Because the page size is usually 4KB (i.e., 2^12 bytes), the low 12 bits exactly represent the offset of the address within the page. The page start address = address & 0xFFFFFFFFFFFFF000. Here, the operation is to mask the low 12 bits of the virtual address through a bitwise AND operation and only keep the high part. The purpose of this is to find the start address of the page to which the current address belongs. Since the page size is 4KB, the start address of the page must be a multiple of 4KB, that is, the low 12 bits of the address are 0. 0xFFFFFFFFFFFFF000 is a 64-bit mask with its low 12 bits being 0 and the rest being 1, used to mask the low 12-bit address. When performing page copying, it is necessary to know the start address of the original page and the offset within the page to correctly place the copied content in the target memory area, which can ensure that after the copying operation, the secondary page can be positioned to the code address to be executed currently. Therefore, it can be selected whether to execute the code of the original program page or the code of the secondary page.
[0026] For which, please refer to Figure 5 , when generating the secondary page, it is necessary to allocate a memory size of 0x1000. The alignment size can make the start address of the allocated memory, that is, the start address, end with 000. Starting from the start address, data is filled to make the data of the secondary page code exactly the same as the data of the code to be hidden for execution, and the address of the secondary page code is returned.
[0027] Furthermore, page features are marked for the blank code area, using the address of the blank code as the mark, so that after marking, the data can be returned for execution, that is, when the marked address is executed, a secondary page operation occurs. Subsequently, the secondary page can be triggered to execute through the blank code. After execution, it returns to the blank code to continue executing the next step, or the secondary page continues to execute the next program flow. The address relationship between the program blank code area and the secondary page is stored in a doubly linked list manner, which is convenient for two-way search and saves time.
[0028] S2. Jump to the secondary page code for execution through the address of the secondary page code filled in the blank code area, and after the execution ends, jump back to the page where the program is located.
[0029] Please refer to Figure 6, in some embodiments, an error access can be set in the blank code area. When the service device obtains this error, it can get the address of the blank code and the 16-bit data in the address. Then, it obtains the address in the linked list, jumps to execute the secondary page code according to the secondary page code address in the linked list, and jumps back to the original page where the program is located after the execution ends.
[0030] Therefore, in this embodiment, the normal process is not damaged, and the secondary page process is also executed normally. By the way of hidden execution on the secondary page, there is no need to encrypt the code, and the code data to be protected can be flexibly processed. Since the secondary page data cannot be modified and the execution logic runs to the secondary page for execution, the cracker cannot accurately obtain the intention, which improves the security of data execution.
[0031] Please refer to Figure 2 , Embodiment 2 of the present invention is as follows: A terminal 1 for hidden execution of data includes a memory 2, a processor 3, and a computer program stored on the memory 2 and executable on the processor 3. When the processor 3 executes the computer program, it implements each step of the method for hidden execution of data in Embodiment 1.
[0032] In summary, the method and terminal for hidden execution of data provided by the present invention generate a secondary page code by copying the address page of the code to be hidden and executed, and fill it into a preset blank code area, so that the program jumps to the secondary page code for execution when it is executed, and then jumps back to the original program page after the execution ends. This jump mechanism hides the execution path of the code, increases the concealment of code execution, and can effectively prevent malware or attackers from discovering the actual execution logic of the code through conventional code analysis means. Since the execution path of the code is hidden, even if the attacker obtains the code of the program, it is difficult to determine which code is actually executed, thereby increasing the difficulty of code tampering or malicious exploitation and improving the security of the code. After the execution ends, it can accurately jump back to the page where the program is located, ensuring that the normal operation logic of the program is not affected, and realizing the compatibility between hidden execution and normal operation of the program.
[0033] The above are only the embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in the related technical field, shall be equally included in the patent protection scope of the present invention.
Claims
1. A method for performing data hiding, characterized in that: Includes steps: When the program runs to the preset blank code area, the service device obtains and copies the address page of the execution code to be hidden to obtain the secondary page code, and fills the secondary page code address into the blank code area; The program jumps to the sub-page code through the sub-page code address filled in the blank code area for execution, and jumps back to the page where the program is located after the execution is completed.
2. A method for data hiding execution according to claim 1, characterized in that: The service device obtains and copies the address page of the execution code to be hidden to obtain the secondary page code, including: The service device obtains the address page of the execution code to be hidden, creates a copy page, and aligns the memory size of the secondary page with that of the address page; The copy page is filled with data of the address page of the execution code to be hidden to obtain a secondary page code.
3. A method for data hiding execution according to claim 1, characterized in that: The business device obtains the address page of the execution code to be hidden, and also includes: Obtaining a corresponding address according to the address page of the execution code to be hidden, and calculating the offset and the first address of the page according to the address; The secondary page is aligned with the memory size of the address page according to the offset and the first address of the address page.
4. A method for data hiding execution according to claim 1, characterized in that: To get the subpage code, it also includes: The addresses of the secondary page code and the blank code area are stored in a bidirectional linked list; Filling the secondary page code address into the blank code area includes: The corresponding sub-page code address is searched in the bidirectional linked list according to the address of the blank code area, and the sub-page code address is filled into the blank code area.
5. A method for data hiding execution according to claim 4, characterized in that: When the program runs to the preset blank code area, it also includes: When the program runs to a preset access of a preset blank code area, the service device obtains the preset access and obtains the address of the corresponding blank code area.
6. A terminal for executing data hiding, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the following steps are implemented: When the program runs to the preset blank code area, the service device obtains and copies the address page of the execution code to be hidden to obtain the secondary page code, and fills the secondary page code address into the blank code area; The program jumps to the sub-page code through the sub-page code address filled in the blank code area for execution, and jumps back to the page where the program is located after the execution is completed.
7. A terminal for executing data hiding according to claim 6, characterized in that: The service device obtains and copies the address page of the execution code to be hidden to obtain the secondary page code, including: The service device obtains the address page of the execution code to be hidden, creates a copy page, and aligns the memory size of the secondary page with that of the address page; The copy page is filled with data of the address page of the execution code to be hidden to obtain a secondary page code.
8. A terminal for executing data hiding according to claim 6, characterized in that: The business device obtains the address page of the execution code to be hidden, and also includes: Obtaining a corresponding address according to the address page of the execution code to be hidden, and calculating the offset and the first address of the page according to the address; The secondary page is aligned with the memory size of the address page according to the offset and the first address of the address page.
9. A terminal for executing data hiding according to claim 6, characterized in that: To get the subpage code, it also includes: The addresses of the secondary page code and the blank code area are stored in a bidirectional linked list; Filling the secondary page code address into the blank code area includes: The corresponding sub-page code address is searched in the bidirectional linked list according to the address of the blank code area, and the sub-page code address is filled into the blank code area.
10. A terminal for executing data hiding according to claim 9, characterized in that: When the program runs to the preset blank code area, it also includes: When the program runs to a preset access of a preset blank code area, the service device obtains the preset access and obtains the address of the corresponding blank code area.