Method for realizing java source code file security encryption based on C + + dynamic library
By using the dual encryption mechanism and operating environment parameter monitoring implemented by C++ dynamic library in Java source file encryption technology, the problems of insufficient keys and insufficient decompilation protection in the existing technology are solved, and high-strength encryption and effective security protection are achieved.
Patent Information
- Application Number
- CN202510686559.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing Java source file encryption technology has problems such as insufficient single-key encryption algorithm, inability to deal with complex security threats, and lack of protection from decompilation and debugging tools.
The dual encryption mechanism based on C++ dynamic library is adopted to obtain a mixed key by generating dynamic keys and static keys, and secondary encryption is performed using AES encryption and elliptic curve cipher algorithms. The operating environment parameters of the Java virtual machine are monitored in real time during the decryption process, and the debugging mode is identified to terminate the decryption operation.
It significantly enhances encryption strength, prevents unauthorized access and reverse engineering, effectively protects the security of Java source files, and improves the overall performance of the system.
Smart Images

Figure CN120197202A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security encryption, and in particular to a method for implementing security encryption of Java source code files based on a C++ dynamic library. Background Art
[0002] With the rapid development of Internet technology, Java, as a widely used programming language, has been widely used in many fields such as enterprise application development, mobile application development, and Web service development. However, due to the high readability of Java programs, once the source code files are leaked, it will not only cause the loss of core enterprise technologies, but also may lead to malicious exploitation of software system security vulnerabilities. Therefore, the security protection of Java source code files has become an important issue that needs to be solved in the field of software development.
[0003] There are many Java source code protection technologies on the market, including code obfuscation, encryption protection, virtual machine protection, etc. Traditional Java source code protection methods usually use a single encryption algorithm or a simple key management mechanism, which has many shortcomings in practical applications.
[0004] The existing Java source code file encryption technology mainly has the following defects and shortcomings: First, existing encryption schemes mostly use a single fixed-key encryption algorithm. Once the key is leaked, the security of all protected source code files will be invalidated. They lack the ability to dynamically adjust the key and are unable to cope with the increasingly complex security threat environment.
[0005] Secondly, most Java source code encryption solutions lack effective protection measures against decompilation and debugging tools. Hackers can analyze the encrypted code through debugging mode or decompilation tools, gradually crack the encryption algorithm and key, and make the protection mechanism ineffective. Summary of the invention
[0006] The embodiment of the present invention provides a method for implementing secure encryption of java source code files based on a C++ dynamic library, which can solve the problems in the prior art.
[0007] A first aspect of an embodiment of the present invention provides a method for implementing secure encryption of a Java source code file based on a C++ dynamic library, comprising: Receive a Java source code file to be encrypted, and divide the Java source code file into a plurality of source code file blocks according to a preset file block size; For each of the source code file blocks, call the encryption module in the C++ dynamic library to perform encryption operations. The encryption module encrypts the source code file block using a dual encryption mechanism, including: generating a dynamic key based on the content eigenvalue of the source code file block, performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data using the elliptic curve cryptography algorithm to obtain the final encrypted data; Merge the final encrypted data corresponding to each source code file block to generate an encrypted Java source code file; During the decryption process of the Java source code file, by real-time monitoring the running environment parameters of the Java virtual machine, determine whether the current running environment is in the debug mode according to the degree of abnormality of the running environment parameters. If it is determined to be in the debug mode, terminate the decryption operation and clear the decryption cache; When it is determined that the current running environment is in the normal mode, call the decryption module in the C++ dynamic library and perform the decryption operation in the reverse order of the encryption process to restore the original Java source code file.
[0008] Generating a dynamic key based on the content eigenvalue of the source code file block and performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key includes: Extract the keyword fields in the source code file block and count the occurrence frequency of each keyword field; According to the file size, line number information, and the occurrence frequency of the keyword fields, construct a multi-dimensional feature matrix of the source code file block using the feature vector mapping algorithm, and perform dimensionality reduction processing on the multi-dimensional feature matrix based on the principal component analysis method to obtain a feature vector. Calculate the content eigenvalue by passing the feature vector through a hash function; Obtain a static key from a preset key pool, where the key pool contains multiple alternative static keys of different lengths; According to the numerical range of the content eigenvalue, select an alternative static key with the optimal length as the target static key, and reorganize the content eigenvalue in a grouped manner to generate a dynamic key, where the length of the dynamic key is the same as the length of the target static key; Perform an exclusive OR operation on the dynamic key and the target static key to generate a mixed key for subsequent encryption processing.
[0009] Using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data using the elliptic curve cryptography algorithm to obtain the final encrypted data includes: Group the source code file blocks according to the data block size required by the AES encryption algorithm; Dynamically expand the mixed key, and generate a round key sequence using a key expansion algorithm according to the number of groups of the source code file blocks. Among them, for each group of data, different round keys are used during the encryption process, and there is a correlation transformation between the round keys of adjacent groups; Call the AES encryption module, and perform an encryption operation on the grouped source code file blocks using the round key sequence to obtain primary encrypted data; Initialize the elliptic curve cryptosystem based on preset elliptic curve parameters, where the elliptic curve parameters include a curve equation, a base point coordinate, and an order; Map the primary encrypted data to a set of discrete points on the elliptic curve, and dynamically adjust the key length and the number of iterations of the elliptic curve according to the entropy value characteristics of the primary encrypted data, and perform an adaptive elliptic curve encryption operation to obtain the final encrypted data; Mapping the primary encrypted data to a set of discrete points on the elliptic curve, and dynamically adjusting the key length and the number of iterations of the elliptic curve according to the entropy value characteristics of the primary encrypted data, performing an adaptive elliptic curve encryption operation includes: Calculate the bit stream sequence of the primary encrypted data, and calculate the Shannon entropy value based on the bit stream sequence as the data entropy value; Select a curve in a preset elliptic curve family according to the data entropy value. Specifically, when the data entropy value is greater than the first threshold, select a 384-bit elliptic curve, and when the data entropy value is greater than the second threshold, select a 521-bit elliptic curve, and obtain the curve parameters corresponding to the selected elliptic curve, including the order of the finite field, the base point generator, and the curve coefficient; Segment the primary encrypted data according to the grouping length requirement of the selected elliptic curve to obtain a sequence of data segments, and calculate the local entropy value of each sequence of data segments; For each data segment in the sequence of data segments, perform the following mapping operations: Convert the sequence of data segments into elements in the field using Koblitz coding according to the local entropy value; map the field elements to discrete points on the curve through point multiplication operations on the elliptic curve; save the mapped discrete points to the point set; Perform an elliptic curve encryption operation on the point set, including: Perform a scalar multiplication operation using the adjusted sliding window; repeat the point addition operation according to the adjusted number of iterations; generate a temporary session key using the adjusted key length; Byte serialize the output result of the encryption operation, and combine and package the serialization result with the parameter adjustment record to generate the final encrypted data block.
[0010] The operating environment parameters include time series parameters, hardware parameters, and process behavior parameters. The time series parameters are time interval values for consecutive instruction executions. The hardware parameters include the processor serial number and the unique motherboard identification code. The process behavior parameters include the number of process identification changes and the process hierarchy mark.
[0011] By real-time monitoring the operating environment parameters of the Java virtual machine, determine whether the current operating environment is in the debug mode according to the degree of abnormality of the operating environment parameters. If it is determined to be in the debug mode, terminate the decryption operation and clear the decryption cache, including: Calculate the average value and standard deviation of adjacent time intervals in the time series parameters, compare the standard deviation with a preset time threshold to obtain a time abnormality score; calculate the matching degree between the processor serial number and the unique motherboard identification code in the hardware parameters and the pre-stored reference parameters to obtain a hardware abnormality score; calculate a process abnormality score according to the number of process identification changes and the process hierarchy mark per unit time; Assign weight coefficients to the time abnormality score, the hardware abnormality score, and the process abnormality score respectively, and add the weighted abnormality scores to obtain an environmental abnormality total score; Determine a reference judgment threshold according to historical monitoring records, dynamically adjust the reference judgment threshold based on the change trend of the environmental abnormality total score to obtain a real-time judgment threshold, and divide the real-time judgment threshold into three protection level intervals; When the environmental abnormality total score is in the first protection level interval, reduce the sampling time interval of the environmental parameters to half of the original sampling time interval and record the abnormal characteristic parameters; when the environmental abnormality total score is in the second protection level interval, pause the sensitive operation currently being executed and copy the key data to the secure storage area; when the environmental abnormality total score is in the third protection level interval, immediately terminate the decryption process; Divide the memory cache data into data blocks of a fixed size, generate a random key sequence equal to the number of data blocks, and perform multiple rounds of exclusive OR operations on the random key sequence and the data block sequence to achieve secure clearing of the cache data.
[0012] In the second aspect of the embodiments of the present invention, a Java source code file security encryption system implemented based on a C++ dynamic library is provided, including: A first unit for receiving a Java source code file to be encrypted and dividing the Java source code file into multiple source code file blocks according to a preset file block size; A second unit, which is configured to, for each of the source code file blocks, call an encryption module in a C++ dynamic library to perform an encryption operation, where the encryption module encrypts the source code file block by using a dual encryption mechanism, including: generating a dynamic key based on the content feature value of the source code file block, performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data by using an elliptic curve cryptography algorithm to obtain final encrypted data; A third unit, which is configured to merge the final encrypted data corresponding to each of the source code file blocks to generate an encrypted Java source code file; A fourth unit, which is configured to, during the decryption process of the Java source code file, determine whether the current running environment is in a debug mode by real-time monitoring the running environment parameters of the Java virtual machine, and if it is determined that the current running environment is in the debug mode, terminate the decryption operation and clear the decryption cache; A fifth unit, which is configured to, when it is determined that the current running environment is in a normal mode, call a decryption module in the C++ dynamic library and perform a decryption operation in an order opposite to the encryption process to restore the original Java source code file.
[0013] In a third aspect of the embodiments of the present invention, there is provided an electronic device, including: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0014] In a fourth aspect of the embodiments of the present invention, there is provided a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0015] The beneficial effects of the present application are as follows: The present invention uses a C++ dynamic library to implement a method for securely encrypting a Java source code file. The Java source code file is encrypted in blocks and then merged, which improves the efficiency of processing large source code files, avoids the risk of memory overflow, and at the same time reduces the time overhead of the encryption and decryption processes, improving the overall performance of the system.
[0016] The present invention uses a dual encryption mechanism, combines a dynamic key and a static key to generate a mixed key, and sequentially uses AES encryption and an elliptic curve cryptography algorithm for secondary encryption, significantly enhancing the encryption strength. Even if an attacker obtains some encrypted information, it is difficult to crack the complete source code, effectively protecting intellectual property rights.
[0017] By monitoring the running environment parameters of the Java virtual machine in real time, the present invention can identify the debugging mode, automatically terminate the decryption operation, and clear the cache, preventing reverse engineering attacks through debugging tools. At the same time, since the core encryption and decryption functions are implemented using a C++ dynamic library, the key algorithms cannot be directly called by Java code, further enhancing the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 FIG. is a schematic flowchart of a method for securely encrypting a Java source code file based on a C++ dynamic library according to an embodiment of the present invention; Figure 2 FIG. is a schematic flowchart of obtaining the final encrypted data according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0020] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0021] Figure 1 FIG. is a schematic flowchart of a method for securely encrypting a Java source code file based on a C++ dynamic library according to an embodiment of the present invention, as Figure 1 shown, the method includes: Receiving a Java source code file to be encrypted, and dividing the Java source code file into multiple source code file blocks according to a preset file block size; For each of the source code file blocks, calling an encryption module in the C++ dynamic library to perform an encryption operation, wherein the encryption module encrypts the source code file block using a dual encryption mechanism, including: generating a dynamic key based on the content feature value of the source code file block, performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data using an elliptic curve cryptography algorithm to obtain the final encrypted data; Merging the final encrypted data corresponding to each of the source code file blocks to generate an encrypted Java source code file; During the decryption process of the Java source code file, by monitoring the running environment parameters of the Java virtual machine in real time, determine whether the current running environment is in the debug mode according to the degree of abnormality of the running environment parameters. If it is determined to be in the debug mode, terminate the decryption operation and clear the decryption cache; When it is determined that the current running environment is in the normal mode, call the decryption module in the C++ dynamic library and perform the decryption operation in the reverse order of the encryption process to restore the original Java source code file.
[0022] In an optional implementation manner, generating a dynamic key based on the content feature value of the source code file block and performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key includes: Extract the keyword fields in the source code file block and count the occurrence frequency of each keyword field; According to the file size, line number information, and the occurrence frequency of the keyword fields, construct a multi-dimensional feature matrix of the source code file block by using the feature vector mapping algorithm, and perform dimensionality reduction processing on the multi-dimensional feature matrix based on the principal component analysis method to obtain a feature vector. Calculate the content feature value by passing the feature vector through a hash function; Obtain a static key from a preset key pool, where the key pool contains multiple alternative static keys with different lengths; According to the numerical range of the content feature value, select an alternative static key with an optimal length as the target static key, and reorganize the content feature value in a grouped manner to generate a dynamic key, where the length of the dynamic key is the same as the length of the target static key; Perform an exclusive OR operation on the dynamic key and the target static key to generate a mixed key for subsequent encryption processing.
[0023] The system extracts file blocks from the source code file to be encrypted, and each file block contains a certain number of code lines. For example, for a source code file with 5000 lines of code, it can be divided into 50 file blocks, and each file block contains 100 lines of code. The system will record the size of each file block (such as 15KB) and the line number information (such as 100 lines) as initial features.
[0024] The system extracts keyword fields from source code file blocks and counts their frequencies. The keyword fields include, but are not limited to, reserved words of programming languages, function names, variable names, operators, etc. For example, for a Java source code file block, the system may extract the following keyword fields and their frequencies: {"class": 5, "public": 12, "private": 8, "if": 25, "for": 10, "return": 15, "new": 18}, etc. These statistical data reflect the structural characteristics of the source code.
[0025] Specifically, first convert the file size and line number information into standardized values (e.g., convert 15KB to 15000 and 100 lines to 100), and then form a feature matrix together with the keyword field frequency values. For example, the feature matrix may be [15000, 100, 5, 12, 8, 25, 10, 15, 18...].
[0026] To reduce the computational complexity and extract key features, the system performs dimensionality reduction on the multi-dimensional feature matrix. The system first calculates the covariance matrix of the feature matrix, then calculates the eigenvalues and eigenvectors of the covariance matrix, and selects the eigenvectors corresponding to the largest several eigenvalues to form the dimensionality-reduced feature vector. For example, the original 20-dimensional feature can be reduced to an 8-dimensional feature vector [1.25, 0.87, -0.56, 2.13, 0.32, -1.45, 0.91, 0.22].
[0027] The system calculates the content feature value by passing the feature vector through a hash function. Here, the SHA-256 hash algorithm is selected. After concatenating the 8-dimensional feature vector into a string, the hash value is calculated to obtain a 256-bit feature value, which is represented as a 64-bit hexadecimal string. The system obtains a static key from a preset key pool. The key pool contains multiple alternative static keys of different lengths, such as 128 bits, 192 bits, and 256 bits. Each key pool of a certain length contains multiple alternative keys. For example, the 256-bit key pool may contain 100 different keys.
[0028] The system selects the alternative static key with the optimal length according to the numerical range of the content feature value; For example, if the value of the first byte of the feature value is in the range of 0 - 85, select a 128-bit key; if it is in the range of 86 - 170, select a 192-bit key; if it is in the range of 171 - 255, select a 256-bit key.
[0029] The system reorganizes the content feature values in a grouped manner to generate a dynamic key. The reorganization method is to divide the 64 hexadecimal characters of the feature value into 32 groups, with 2 characters in each group, and then rearrange each group according to a specific rule (such as the parity of the group number). For example, the odd-numbered groups and even-numbered groups can be arranged alternately to obtain the reorganized feature value. If the selected target static key length is 256 bits (64 hexadecimal characters), then the dynamic key length is also 256 bits.
[0030] The system performs an exclusive OR operation on the dynamic key and the target static key to generate a mixed key. The exclusive OR operation is performed bit by bit. The specific process is: convert the dynamic key and the static key into binary form, and then perform an exclusive OR operation on the corresponding positions (the same is 0, different is 1). For example: Dynamic key (hexadecimal): "8a7b2e1f3c9d5a4b..."; Static key (hexadecimal): "7f6e5d4c3b2a1f6e..."; Result after exclusive OR (hexadecimal): "f5154353079f4525..."; The mixed key obtained in this way not only contains the dynamics of the source code file content features but also has the randomness of the static key, significantly improving the encryption strength. This mixed key is then used for the actual encryption process of the source code file, such as encrypting the source code content through the AES-256 algorithm.
[0031] Through the above method, even if an attacker obtains the static key, due to the different content features of each source code file block, the generated dynamic keys are different, and the final mixed key is unique for each file block, greatly enhancing the security of the encryption system. At the same time, this method can effectively resist statistical analysis attacks and dictionary attacks, providing a more reliable source code protection mechanism.
[0032] In an alternative embodiment, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally using the elliptic curve cryptography algorithm to perform secondary encryption on the primary encrypted data to obtain the final encrypted data includes: Group the source code file block according to the data block size required by the AES encryption algorithm; Dynamically expand the mixed key, and generate a round key sequence according to the grouping number of the source code file block using the key expansion algorithm. Among them, for each grouped data, different round keys are used during the encryption process, and there is a correlation transformation between the round keys of adjacent groups; Call the AES encryption module, and perform an encryption operation on the grouped source code file block using the round key sequence to obtain primary encrypted data; Initialize the elliptic curve cryptosystem based on preset elliptic curve parameters, where the elliptic curve parameters include a curve equation, base point coordinates, and order; Map the primary encrypted data to a set of discrete points on the elliptic curve, and dynamically adjust the key length and iteration times of the elliptic curve according to the entropy value characteristics of the primary encrypted data, and perform adaptive elliptic curve encryption operations to obtain the final encrypted data.
[0033] Figure 2 It is a schematic flowchart of the process for obtaining the final encrypted data in an embodiment of the present invention. As Figure 2 shown, receive the source code file to be encrypted, which can be, for example, code files in programming languages such as Java, Python, and C++. The system reads the source code file and splits it into several source code file blocks, and the size of each file block can be set to 4KB. For a 100KB source code file, it will be split into 25 file blocks.
[0034] The system generates a mixed key, which is composed of a password key input by the user and a random key generated by the system. For example, the user inputs the password "Secure@2023", and the system generates a 128-bit random key "8f7d6a9c2e1b4f5a", and combines the two through the hash algorithm SHA-256 to generate the final mixed key "a7c42e9f58b31d67e094fb2a5c1d8936".
[0035] In the process of performing AES encryption on the source code file block to obtain the primary encrypted data, first group the source code file block according to the data block size required by the AES encryption algorithm. Taking AES-128 as an example, the size of each data block is 16 bytes, and a 4KB source code file block needs to be divided into 256 groups.
[0036] Then dynamically expand the mixed key, and generate a round key sequence using the key expansion algorithm according to the number of groups of the source code file block. Assuming the AES-128 algorithm is used, the standard process needs to generate 11 round keys. On this basis, the present invention designs different round keys for each group of data, and there is a correlation transformation between the round keys of adjacent groups.
[0037] The specific implementation method is as follows: For the first group, use the original mixed key "a7c42e9f58b31d67e094fb2a5c1d8936" to generate 11 standard round keys; for the second group, perform a byte circular shift operation (for example, shift right by 3 bits) on the last round key of the first group to get "936a7c42e9f58b31d67e094fb2a5c1d", and then generate 11 new round keys based on this; and so on. The initial round key of each group is the transformation result of the last round key of the previous group.
[0038] Call the AES encryption module and perform an encryption operation on the grouped source code file blocks using the generated sequence of round keys. For each 16-byte data block, use the sequence of round keys corresponding to the group for encryption. For example, for the first data block "public class Main", after AES-128 encryption, the ciphertext "e7a901d56f8c3b42d9763a1f4e2b8c5d" is obtained. After all data blocks are encrypted, they are concatenated to form the primary encrypted data.
[0039] The system maps the primary encrypted data to a set of discrete points on an elliptic curve. For every 32 bytes in the primary encrypted data as a group, the first 16 bytes are mapped to the x coordinate of the point on the curve, and the last 16 bytes are used to calculate the y coordinate. The complete curve point is determined by solving the curve equation. For example, for the data segment "e7a901d56f8c3b42d9763a1f4e2b8c5d7f52a8e643c1b9d2a85f6c7319e4b0", the point mapped to the curve is (148395612930906425175952558522797914267, 361342509566342586044022999894495702102).
[0040] The system will dynamically adjust the key length and the number of iterations of the elliptic curve according to the entropy value characteristics of the primary encrypted data. The entropy value is calculated based on the byte distribution of the primary encrypted data. If the entropy value is greater than 4.5, it indicates high data complexity, and the system uses a 256-bit key length and 3 iterations; if the entropy value is between 3.5 and 4.5, it uses a 224-bit key length and 4 iterations; if the entropy value is less than 3.5, it uses a 192-bit key length and 5 iterations. For example, for the primary encrypted data with an entropy value of 4.2, the system selects a 224-bit key length and 4 iterations.
[0041] During the elliptic curve encryption process, the system generates a random integer k (1 ≤ k ≤ n - 1) as a temporary private key. For each mapped curve point P, calculate kG to get the public point R, and k·P to get the shared point S. The final encrypted data consists of R and S.
[0042] For example, when k = 28734629 and the base point G is a specific point on the curve, for the curve point P, the calculated R = (672943521867435, 984562178546372) and S = (237896543210498, 534782109875643), and the encryption result is "6729435218674359845621785463722378965432104985347821098756430".
[0043] Through the dual protection of the above-mentioned AES encryption and elliptic curve secondary encryption, the source code file is provided with high-strength security protection, effectively preventing unauthorized access and reverse engineering.
[0044] In an alternative embodiment, mapping the primary encrypted data to a set of discrete points on the elliptic curve, and dynamically adjusting the key length and iteration times of the elliptic curve according to the entropy value characteristics of the primary encrypted data, and performing adaptive elliptic curve encryption operations includes:[[]] Calculating the bit stream sequence of the primary encrypted data, and calculating the Shannon entropy value based on the bit stream sequence as the data entropy value; Selecting a curve from a preset family of elliptic curves according to the data entropy value, specifically including: selecting a 384-bit elliptic curve when the data entropy value is greater than the first threshold, selecting a 521-bit elliptic curve when the data entropy value is greater than the second threshold, and obtaining the curve parameters corresponding to the selected elliptic curve, including the order of the finite field, the base point generator, and the curve coefficients; Segmenting the primary encrypted data according to the grouping length requirement of the selected elliptic curve to obtain a sequence of data segments, and calculating the local entropy value of each data segment sequence; For each data segment in the data segment sequence, perform the following mapping operations: Converting the data segment sequence into an element in the field by using Koblitz coding according to the local entropy value; mapping the field element to a discrete point on the curve through point multiplication operation on the elliptic curve; saving the mapped discrete point into the point set; Performing elliptic curve encryption operations on the point set, including: Performing scalar multiplication operations using the adjusted sliding window; repeating the point addition operation according to the adjusted iteration times; generating a temporary session key using the adjusted key length; Byte serializing the output result of the encryption operation, and combining and packing the serialized result with the parameter adjustment record to generate the final encrypted data block.
[0045] The system receives the primary encrypted data, which can be the result of the first-round symmetric encryption or hashing process. The system maps the primary encrypted data to a set of discrete points on an elliptic curve and dynamically adjusts the encryption parameters according to the data entropy value characteristics.
[0046] In actual implementation, the system first calculates the bitstream sequence of the primary encrypted data and then calculates its Shannon entropy value. For example, when processing a 128-byte primary encrypted data block, the system converts it into a binary sequence to obtain a 1024-bit bitstream, and statistically analyzes the probability distribution of each bit. Assuming the probability of "1" appearing is 0.49 and the probability of "0" appearing is 0.51, the entropy value is calculated to be approximately 0.9994 according to the Shannon entropy formula, indicating that the data chaos degree is close to the ideal state.
[0047] In a specific embodiment, two thresholds are preset: the first threshold is 0.75, and the second threshold is 0.9. When the entropy value of 0.9994 is greater than the second threshold of 0.9, the system selects a 521-bit elliptic curve (such as NIST P-521); if the entropy value is greater than the first threshold of 0.75 but less than the second threshold, a 384-bit elliptic curve (such as NIST P-384) is selected; if the entropy value is lower than the first threshold, a 256-bit elliptic curve (such as NIST P-256) is selected. The system then obtains the parameters of the selected curve, including the finite field order, the base point generator, and the curve coefficient.
[0048] Taking the selected NIST P-521 curve as an example, its finite field order is 2^521 - 1, and the curve equation is y² = x³ - 3x + b, where b is a specific constant, and the order is n, which is a large prime number close to 2^521.
[0049] The system then segments the primary encrypted data according to the grouping length requirements of the selected elliptic curve. For example, for a 521-bit curve, considering the coding efficiency and security, 58 bytes (464 bits) of data are processed each time. The 128-byte primary encrypted data is divided into 3 complete 58-byte segments, and the remaining data is filled for processing.
[0050] For each data segment, the system calculates its local entropy value. For example, the local entropy value of the first 58-byte segment is calculated to be 0.987, indicating that the data distribution uniformity of this segment is good.
[0051] The system performs a mapping operation on each data segment and converts the data segment into an element in the domain using Koblitz coding according to the local entropy value. In an embodiment, assume that after the first data segment is converted, the domain element m = 243598762345982734623 is obtained. Then, the domain element is mapped to a discrete point on the curve through a dot product operation. Specifically, the system attempts to find an x value such that x^3 - 3x + b is a square number in the domain until a valid x value and the corresponding y value are found to form a point (x, y) on the curve.
[0052] At this time, the system has successfully mapped all data segments to a set of discrete points {P1, P2, P3,...} on the elliptic curve.
[0053] For this set of points, the system performs adaptive elliptic curve encryption operations. First, the sliding window size is adjusted based on the data entropy value. In the example, the entropy value is 0.9994, and the system sets the window size to 6, which improves the computing efficiency compared to the standard 4-bit window.
[0054] At the same time, the system adjusts the number of iterations according to the entropy value. For example, for data with a high entropy value (>0.9), 3 iterations are set; for medium entropy values (0.75 - 0.9), 4 iterations are set; for low entropy values (<0.75), 5 iterations are set. The more iterations, the higher the security, but the greater the computational overhead.
[0055] The system also adjusts the length of the temporary session key according to the entropy value. For the example with an entropy value of 0.9994, the system generates a 256-bit temporary session key k = 38762873468723487264676 and uses this key to perform the dot product operation C = k·P, where P is the mapped point.
[0056] The system serializes the result of the encryption operation into bytes and combines and packages the result with the parameter adjustment records (such as the selected curve type, window size, number of iterations) to generate the final encrypted data block. For example, the first 4 bytes of the encrypted data block record the parameter information, followed by the sequence of encrypted point coordinates.
[0057] Through this method, the system realizes a technical mechanism for adaptively adjusting the elliptic curve encryption parameters according to data characteristics, which not only improves the encryption strength but also optimizes the computing performance, and is particularly suitable for application scenarios with high requirements for security and performance.
[0058] In an alternative embodiment, the operating environment parameters include time series parameters, hardware parameters, and process behavior parameters, where the time series parameters are time interval values for consecutive instruction executions, the hardware parameters include the processor serial number and the motherboard unique identification code, and the process behavior parameters include the number of process identity changes and the process hierarchy marker.
[0059] The acquisition of time - series parameters is achieved by monitoring the time - interval values of consecutive instruction executions. In actual implementation, during the operation of the computer, the system samples the time - interval of CPU instruction execution every 100 milliseconds through the system - level interface, and records the time difference between the executions of two adjacent instructions. For example, if the first instruction is executed at time point T1(13:45:22.105) and the second instruction is executed at time point T2(13:45:22.108), the recorded time - interval value is 3 milliseconds. The system continuously samples 100 such time - interval values to form a time - series array [3,4,2,3,5,2,3,4,3,2,...,3], and this array will be used as part of the system - running environment parameters.
[0060] For the acquisition of hardware parameters, this implementation focuses on the processor serial number and the motherboard unique identification code. The acquisition of the processor serial number is achieved by calling the underlying CPUID instruction.
[0061] In the specific implementation process, the system obtains the serial number of the CPU, such as "Intel - 7700K - 89AB3342FD", by calling the API interface provided by the operating system, such as using the GetSystemFirmwareTable function in the Windows system. For the motherboard unique identification code, the system obtains it by reading the DMI (Desktop Management Interface) information stored in the motherboard BIOS, which contains information such as the motherboard manufacturer, model, and serial number, such as "ASUS - ROG - Z270 - 9923ABCD4567". These hardware parameters are generally acquired once at system startup and remain unchanged throughout the monitoring process.
[0062] The acquisition of process - behavior parameters mainly focuses on the number of process - identifier changes and the process - hierarchy marker. The number of process - identifier changes refers to the total number of changes in the process PID in the monitoring period (usually 10 minutes). For example, in a 10 - minute period, if 5 processes end (PID disappears) and 8 new processes are created (new PID appears) in the system, the number of process - identifier changes is recorded as 13. This parameter can reflect the frequency of process activities in the system and helps to identify abnormal process behaviors.
[0063] The process hierarchy label is implemented by constructing a process tree. The system first obtains a list of all currently running processes, and then constructs a process tree based on the parent-child process relationship. For each process, its depth in the process tree is recorded as its hierarchy label. For example, if process A is the system's initial process (such as the System process in Windows with a PID of 4), its hierarchy label is 0; if process B is a child process of A, its hierarchy label is 1; and so on. In this way, the system can obtain an array of process hierarchy labels, such as [0, 1, 1, 2, 2, 2, 3, 1, 2, 3, 3, 4], which represents the hierarchical distribution of processes in the system.
[0064] In a specific embodiment, a trading system of a financial enterprise uses this method for security monitoring. The system automatically collects three types of operating environment parameters every day and compares them with historical baseline values. One day during monitoring, it was found that although the hardware parameters remained unchanged, the fluctuation range of the time series parameters changed from the normal 2 - 5 milliseconds to a fixed 2 milliseconds. At the same time, an abnormal deep level (depth reaching 8 levels) appeared in the process hierarchy label array, and the number of process identifier changes also increased from an average of 13 times every 10 minutes to 47 times. The system immediately issued a security alert. After investigation by the operation and maintenance personnel, it was found that a malicious program hidden deep in a normal system process had been implanted in the server. This program attempted to tamper with trading data and send out information.
[0065] Another embodiment is in an office network. The system detected through monitoring the operating environment parameters that the hardware parameters of a certain computer had changed overnight. The processor serial number changed from "Intel - 7700K - 89AB3342FD" to "Intel - 7700K - 89AB3342FF". Although the change was small, the system still captured this anomaly. Subsequent investigation found that the physical hardware of this computer had been replaced, posing a serious physical security risk.
[0066] Through the above implementation methods, this technical solution can effectively perform security monitoring based on operating environment parameters, promptly detect abnormal situations during system operation, and enhance the system's security protection capabilities.
[0067] In an alternative implementation, by real-time monitoring the operating environment parameters of the Java virtual machine, determining whether the current operating environment is in the debug mode according to the degree of abnormality of the operating environment parameters, if it is determined to be in the debug mode, then terminate the decryption operation and clear the decryption cache, including: Calculate the average value and standard deviation of adjacent time intervals in the time series parameters, and compare the standard deviation with a preset time threshold to obtain a time anomaly score; calculate the matching degree between the processor serial number and the motherboard unique identification code in the hardware parameters and the pre-stored reference parameters to obtain a hardware anomaly score; calculate the process anomaly score according to the number of process identifier changes and the process level mark within a unit time; Assign weight coefficients to the time anomaly score, the hardware anomaly score, and the process anomaly score respectively, and add the weighted anomaly scores to obtain an environmental anomaly total score; Determine a reference judgment threshold according to the historical monitoring records, dynamically adjust the reference judgment threshold based on the change trend of the environmental anomaly total score to obtain a real-time judgment threshold, and divide the real-time judgment threshold into three protection level intervals; When the environmental anomaly total score is in the first protection level interval, reduce the sampling time interval of the environmental parameters to half of the original sampling time interval, and record the anomaly characteristic parameters; when the environmental anomaly total score is in the second protection level interval, pause the sensitive operation currently being executed and copy the key data to the secure storage area; when the environmental anomaly total score is in the third protection level interval, immediately terminate the decryption process; Divide the memory cache data into data blocks of a fixed size, generate a random key sequence equal to the number of data blocks, and perform multiple rounds of exclusive OR operations on the data block sequence using the random key sequence to achieve secure clearing of the cache data.
[0068] In a specific implementation, the device runs a Java virtual machine and executes an application program containing a decryption operation. The system continuously collects operating environment parameters through a monitoring module, including time series parameters, hardware parameters, and process parameters. The time series parameters include instruction execution timestamps and method call intervals; the hardware parameters include the processor serial number and the motherboard unique identification code; the process parameters include the process identifier and the process level mark.
[0069] The monitoring module collects parameters every 100 milliseconds and stores the collected parameters in a circular buffer, retaining the most recent 200 sampling points. The sampling data is stored in the form of key-value pairs, such as {"timestamp": 1632456789, "cpu_id": "AMD-X86-64", "process_id": 4578}.
[0070] The system calculates the time anomaly score. It extracts the execution timestamps of the last 100 instructions and calculates the interval sequence of adjacent timestamps. For example, if the timestamp sequence is [1623456780, 1623456782, 1623456785], the interval sequence is [2, 3]. It calculates the average value avg_interval and the standard deviation std_interval of the interval sequence. In a normal operating environment, avg_interval may be 1.2 milliseconds and std_interval may be 0.3 milliseconds; while in a debugging environment, avg_interval may increase to 15.7 milliseconds and std_interval may increase to 12.5 milliseconds.
[0071] The system calculates the hardware anomaly score. When the application is first installed, the system has collected and encrypted and stored the hardware reference parameters, including the processor serial number "Intel-i7-10700K" and the motherboard identification code "ASUS-ROG-Z490". The system compares the currently collected hardware parameters with the stored reference parameters to calculate the matching degree. If the processor serial number and the motherboard identification code are completely matched, the matching degree is 1.0; if only the processor serial number is matched, the matching degree is 0.5; if neither is matched, the matching degree is 0. The hardware anomaly score score_hardware = 1.0 - the matching degree. When running in a simulator environment, the processor serial number may become "QEMU-Virtual-CPU" and the motherboard identification code may become "Virtual-Platform", at this time the matching degree is 0 and score_hardware is 1.0.
[0072] The system calculates the process anomaly score. The system monitors the number of process identity changes process_change_count within a unit of time (such as 10 seconds). Under normal circumstances, this value is 0-2, and in the debugging state, it may reach 5-10. At the same time, it detects the process hierarchy mark process_hierarchy_level, which represents the hierarchical depth at which the current process is debugged by other processes. It is 0 during normal operation and at least 1 when being debugged.
[0073] Combining the above three anomaly scores, the system performs a weighted calculation using weight coefficients. The weight for time anomaly weight_time is 0.5, the weight for hardware anomaly weight_hardware is 0.3, and the weight for process anomaly weight_process is 0.2. The total environmental anomaly score total_score = weight_time * score_time + weight_hardware * score_hardware + weight_process * score_process. Continuing with the above example calculation: total_score = 0.5 * 2.5 + 0.3 * 1.0 + 0.2 * 1.24 = 1.25 + 0.3 + 0.248 = 1.798.
[0074] The system determines the baseline judgment threshold base_threshold based on historical monitoring records. Initially, base_threshold is set to 1.5. Each time an anomaly is detected, the anomaly characteristics are recorded and the baseline judgment threshold is fine-tuned. If anomalies with a similar pattern are detected continuously for 3 times, the system lowers base_threshold by 5%; if there are no anomalies for 10 consecutive times, the system raises base_threshold by 3%, but not exceeding 120% of the initial value. In addition, the system detects the change trend of the total environmental anomaly score. If total_score shows an upward trend within 5 minutes (the slope calculated by the least squares method is greater than 0.05), the baseline judgment threshold is lowered by 8%. The adjusted threshold is the real-time judgment threshold real_threshold.
[0075] The system divides the real-time judgment threshold into three protection level intervals: the first protection level interval [0.6 * real_threshold, 0.8 * real_threshold), the second protection level interval [0.8 * real_threshold, real_threshold), and the third protection level interval [real_threshold, +∞). If real_threshold is 1.5, then the first interval is [0.9, 1.2), the second interval is [1.2, 1.5), and the third interval is [1.5, +∞).
[0076] When the total environmental anomaly score is within the first protection level interval, the system reduces the environmental parameter sampling interval from 100 milliseconds to 50 milliseconds, and at the same time records the anomaly characteristic parameters, including the anomaly time, anomaly score, and main contributing factors.
[0077] When the total environmental anomaly score is within the second protection level range, the system pauses the sensitive operations being executed currently, such as the process of decrypting files. The partially decrypted data is encrypted using a temporary key and then copied to a secure storage area, which is a memory partition with special permissions and cannot be accessed by ordinary debugging tools.
[0078] When the total environmental anomaly score is within the third protection level range, the system immediately terminates the decryption process and clears the decryption cache. During the clearing process, the system divides the memory cache data into data blocks of 4KB in size. For 100KB of cache data, it will be divided into 25 data blocks. The system generates 25 random keys, each key being 32 bytes in length, such as "7f1e3a2d8c5b9f0e4d7c1a3b5d8e2f1a". The system performs three rounds of exclusive OR operations on these random keys and the data blocks: the first round uses the original random keys, the second round uses the bit-reversed result of the keys, and the third round uses a sequence of all 1 bits. After three rounds of operations, the original data is completely overwritten and cannot be recovered even by using advanced memory forensics tools.
[0079] Through the above method, the system can effectively identify whether the Java virtual machine is in a debugging environment and take corresponding security protection measures according to the degree of anomaly to protect the security of sensitive operations and data.
[0080] The embodiment of the present invention implements a Java source code file security encryption system based on a C++ dynamic library, including: The first unit is used to receive the Java source code file to be encrypted and divide the Java source code file into multiple source code file blocks according to a preset file block size; The second unit is used to, for each of the source code file blocks, call the encryption module in the C++ dynamic library to perform an encryption operation. Among them, the encryption module encrypts the source code file block using a dual encryption mechanism, including: generating a dynamic key based on the content feature value of the source code file block, performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data using the elliptic curve cryptography algorithm to obtain the final encrypted data; The third unit is used to merge the final encrypted data corresponding to each of the source code file blocks to generate an encrypted Java source code file; The fourth unit is used to, during the decryption process of the Java source code file, determine whether the current running environment is in a debugging mode by real-time monitoring the running environment parameters of the Java virtual machine, and if it is determined to be in a debugging mode, terminate the decryption operation and clear the decryption cache; The fifth unit is used to call the decryption module in the C++ dynamic library when it is determined that the current operating environment is in the normal mode, and perform decryption operations in the reverse order of the encryption process to restore the original Java source code file.
[0081] In a third aspect of the embodiments of the present invention, there is provided an electronic device, including: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0082] In a fourth aspect of the embodiments of the present invention, there is provided a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0083] The present invention may be a method, an apparatus, a system, and / or a computer program product. The computer program product may include a computer-readable storage medium, on which computer-readable program instructions for executing various aspects of the present invention are loaded.
[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for securely encrypting a Java source code file based on a C++ dynamic library, characterized in that Including: Receiving a Java source code file to be encrypted, and dividing the Java source code file into multiple source code file blocks according to a preset file block size; For each of the source code file blocks, calling an encryption module in a C++ dynamic library to perform an encryption operation, wherein the encryption module encrypts the source code file block by using a dual encryption mechanism, including: generating a dynamic key based on the content feature value of the source code file block, performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data by using an elliptic curve cryptography algorithm to obtain final encrypted data; Merging the final encrypted data corresponding to each of the source code file blocks to generate an encrypted Java source code file; During the decryption process of the Java source code file, by monitoring the running environment parameters of the Java virtual machine in real time, determining whether the current running environment is in a debug mode according to the degree of abnormality of the running environment parameters, and if it is determined to be in the debug mode, terminating the decryption operation and clearing the decryption cache; When it is determined that the current running environment is in a normal mode, calling a decryption module in the C++ dynamic library and performing a decryption operation in the reverse order of the encryption process to restore the original Java source code file.
2. The method according to claim 1, characterized in that Generating a dynamic key based on the content feature value of the source code file block, and performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key includes: Extracting key fields from the source code file block and counting the occurrence frequency of each key field; According to the file size, line number information and the occurrence frequency of the key fields, constructing a multi-dimensional feature matrix of the source code file block by using a feature vector mapping algorithm, performing dimensionality reduction processing on the multi-dimensional feature matrix based on the principal component analysis method to obtain a feature vector, and calculating the content feature value by passing the feature vector through a hash function; Obtaining a static key from a preset key pool, wherein the key pool contains multiple alternative static keys with different lengths; According to the numerical range of the content feature value, selecting an alternative static key with an optimal length as the target static key, and reorganizing the content feature value in a grouped manner to generate a dynamic key, wherein the length of the dynamic key is the same as the length of the target static key; Performing an exclusive OR operation on the dynamic key and the target static key to generate a mixed key for subsequent encryption processing.
3. The method according to claim 1, wherein Using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data by using an elliptic curve cryptography algorithm to obtain final encrypted data includes: Grouping the source code file block according to the data block size required by the AES encryption algorithm; Performing dynamic expansion on the mixed key, and generating a round key sequence by using a key expansion algorithm according to the number of groups of the source code file block, wherein for each group of data, different round keys are used during the encryption process, and there is a correlation transformation between the round keys of adjacent groups; Call the AES encryption module, and perform encryption operations on the grouped source code file blocks using the round key sequence to obtain primary encrypted data; Initialize the elliptic curve cryptosystem based on preset elliptic curve parameters, where the elliptic curve parameters include a curve equation, base point coordinates, and order; Map the primary encrypted data to a set of discrete points on the elliptic curve, and dynamically adjust the key length and number of iterations of the elliptic curve according to the entropy value characteristics of the primary encrypted data, and perform adaptive elliptic curve encryption operations to obtain the final encrypted data.
4. The method according to claim 3, characterized in that, Mapping the primary encrypted data to a set of discrete points on the elliptic curve, and dynamically adjusting the key length and number of iterations of the elliptic curve according to the entropy value characteristics of the primary encrypted data, performing adaptive elliptic curve encryption operations includes: Calculate the bit stream sequence of the primary encrypted data, and calculate the Shannon entropy value based on the bit stream sequence as the data entropy value; Select a curve in a preset elliptic curve family according to the data entropy value, specifically including: selecting a 384-bit elliptic curve when the data entropy value is greater than the first threshold, and selecting a 521-bit elliptic curve when the data entropy value is greater than the second threshold, and obtaining the curve parameters corresponding to the selected elliptic curve, including the order of the finite field, the base point generator, and the curve coefficient; Segment the primary encrypted data according to the grouping length requirements of the selected elliptic curve to obtain a data segment sequence, and calculate the local entropy value of each data segment sequence; For each data segment in the data segment sequence, perform the following mapping operations: Convert the data segment sequence into an element in the field using Koblitz coding according to the local entropy value; map the field element to a discrete point on the curve through point multiplication operations on the elliptic curve; save the mapped discrete point to the point set; Perform elliptic curve encryption operations on the point set, including: Perform scalar multiplication operations using the adjusted sliding window; repeat the point addition operation according to the adjusted number of iterations; generate a temporary session key using the adjusted key length; Byte serialize the output result of the encryption operation, and combine and package the serialized result with the parameter adjustment record to generate the final encrypted data block.
5. The method according to claim 1, characterized in that The running environment parameters include time series parameters, hardware parameters, and process behavior parameters, where the time series parameters are the time interval values of consecutive instruction executions, the hardware parameters include the processor serial number and the motherboard unique identification code, and the process behavior parameters include the number of process identification changes and the process hierarchy mark.
6. The method according to claim 5, characterized in that By real-time monitoring the running environment parameters of the java virtual machine, determine whether the current running environment is in the debugging mode according to the degree of abnormality of the running environment parameters. If it is determined to be in the debugging mode, terminate the decryption operation and clear the decryption cache, including: Calculate the average value and standard deviation of adjacent time intervals in the time series parameters, compare the standard deviation with a preset time threshold to obtain a time anomaly score; calculate the matching degree between the processor serial number and the motherboard unique identification code in the hardware parameters and the pre-stored reference parameters to obtain a hardware anomaly score; calculate the process anomaly score according to the number of process identifier changes and the process hierarchy markers within a unit time; Assign weight coefficients to the time anomaly score, the hardware anomaly score, and the process anomaly score respectively, and add the weighted anomaly scores to obtain the total environmental anomaly score; Determine the reference judgment threshold according to the historical monitoring records, dynamically adjust the reference judgment threshold based on the change trend of the total environmental anomaly score to obtain the real-time judgment threshold, and divide the real-time judgment threshold into three protection level intervals; When the total environmental anomaly score is within the first protection level interval, reduce the sampling time interval of the environmental parameters to half of the original sampling time interval and record the anomaly characteristic parameters; when the total environmental anomaly score is within the second protection level interval, pause the sensitive operation currently being executed and copy the key data to the secure storage area; when the total environmental anomaly score is within the third protection level interval, immediately terminate the decryption process; Divide the memory cache data into data blocks of a fixed size, generate a random key sequence equal in number to the number of data blocks, and perform multiple rounds of exclusive OR operations on the data block sequence using the random key sequence to achieve the secure clearing of the cache data.
7. A Java source file security encryption system implemented based on a C++ dynamic library, which is used to implement the method described in any one of claims 1-6, characterized in that, Include: The first unit is used to receive the java source code file to be encrypted and divide the java source code file into multiple source code file blocks according to a preset file block size; The second unit is used to, for each of the source code file blocks, call the encryption module in the C++ dynamic library to perform encryption operations. Among them, the encryption module encrypts the source code file block using a dual encryption mechanism, including: generating a dynamic key based on the content feature value of the source code file block, performing an exclusive OR operation on the dynamic key and a preset static key to obtain a mixed key, using the mixed key to perform AES encryption on the source code file block to obtain primary encrypted data, and finally performing secondary encryption on the primary encrypted data using the elliptic curve cryptography algorithm to obtain the final encrypted data; The third unit is used to merge the final encrypted data corresponding to each of the source code file blocks to generate an encrypted java source code file; The fourth unit is used to, during the decryption process of the java source code file, determine whether the current running environment is in the debug mode according to the anomaly degree of the running environment parameters by real-time monitoring of the running environment parameters of the java virtual machine. If it is determined to be in the debug mode, terminate the decryption operation and clear the decryption cache; The fifth unit is used to, when it is determined that the current running environment is in the normal mode, call the decryption module in the C++ dynamic library and perform the decryption operation in the reverse order of the encryption process to restore the original java source code file.
8. An electronic device, characterized in that, Include: A processor; A memory for storing instructions executable by the processor; Wherein, the processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Code reinforcement method and system
CN115048110A
Intersystem data exchange method based on secondary encryption
CN115906125A
Expressway lane software safety protection method based on shell-added anti-virus technology
CN118051902A
Opy
KR1020000032464A
Cited By
Intelligent encryption method, device and system for application sensitive data
CN121333670A
Intelligent encryption methods, devices and systems for application-sensitive data
CN121333670B
Encryption method compatible with customized elliptic curve and standard elliptic curve and Java intelligent card
CN122226283A