Data protection method and device, electronic equipment and readable storage medium

By using a white box key to encrypt the plaintext key in the ELF file and replacing it with a ciphertext key, the data leakage problem caused by the plaintext encoding of the key in the prior art is solved, and the data protection ability is improved.

CN120197215APending Publication Date: 2025-06-24VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510359905.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When the prior art encrypts and decrypts ELF files, the key is encoded in plain text, which makes it easy to be acquired by external personnel during storage and transmission, resulting in data leakage.

Method used

When compiling the data of the ELF file, the plaintext key is encrypted using the white box key to obtain the ciphertext key, and the plaintext key is replaced with the ciphertext key to avoid the leakage of the plaintext key.

Benefits of technology

By replacing the plaintext key with the ciphertext key, the risk of plaintext key leakage is reduced, the ability of electronic devices to protect data is improved, and data leakage is prevented during storage and transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197215A_ABST
    Figure CN120197215A_ABST
Patent Text Reader

Abstract

The invention discloses a data protection method and device, electronic equipment and a readable storage medium, and belongs to the technical field of computers.The method comprises the steps that under the condition that first data of a first file is compiled, a first plaintext key in the first file is encrypted according to a first key algorithm, and a first ciphertext key is obtained; the first plaintext key corresponds to first data; and replacing the first plaintext key in the first file with the first ciphertext key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer technology, and particularly relates to a data protection method, apparatus, electronic device, and readable storage medium. Background Art

[0002] Currently, in order to protect the security of important data in an electronic device, the electronic device can encrypt and protect the important data through encryption and decryption technology during the process of encoding a file image. Among them, the file can be an Executable and Linkable Format (ELF) file. Thus, the electronic device can store and use the key generated during the encryption and decryption process to avoid data leakage of important data in the ELF file.

[0003] However, in the above method, due to business requirements or technical limitations, the key generated during the encryption and decryption process during the compilation stage of the ELF file is encoded into the ELF file in plain text. Thus, during the process of storing the ELF file, if an external person obtains the ELF file, the key can be obtained from the ELF file through static decompilation, and further, the important data in the encrypted state can be decrypted using the obtained key to obtain the above important data, resulting in leakage of the important data. In this way, the data protection ability of the electronic device is poor. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a data protection method, apparatus, electronic device, and readable storage medium, which can improve the data protection ability of the electronic device.

[0005] In a first aspect, the embodiments of this application provide a data protection method, which includes: when compiling the first data of the first file, encrypting the first plaintext key in the first file according to the first key algorithm to obtain a first ciphertext key; the first plaintext key corresponds to the first data; replacing the first plaintext key in the first file with the first ciphertext key.

[0006] In a second aspect, the embodiments of this application provide a data protection apparatus, which includes: an encryption module and a replacement module; the encryption module is used to encrypt the first plaintext key in the first file according to the first key algorithm to obtain a first ciphertext key when compiling the first data of the first file; the first plaintext key corresponds to the first data; the replacement module is used to replace the first plaintext key in the first file with the first ciphertext key obtained by the encryption module.

[0007] Fourthly, an embodiment of the present application provides an electronic device, which includes a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.

[0008] Fifthly, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0009] Sixthly, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the method described in the first aspect.

[0010] Seventhly, an embodiment of the present application provides a computer program / program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the first aspect.

[0011] In the embodiment of the present application, when compiling the first data of the first file, the first plaintext key in the first file is encrypted according to the first key algorithm to obtain a first ciphertext key; the first plaintext key corresponds to the first data; the first plaintext key in the first file is replaced with the first ciphertext key. In this solution, since the electronic device can replace the first plaintext key in the first file with the first ciphertext key, and the first ciphertext key is obtained by encrypting the first plaintext key with a white-box key, that is to say, there will be no plaintext key in the replaced first file, that is, the first plaintext key. In this way, when the electronic device stores the replaced first file, even if an external person obtains the replaced first file, they cannot obtain the first plaintext key from the replaced first file through static decompilation, and even less can they further decrypt to obtain the encrypted data in the first file. Thus, the risk of plaintext key leakage is reduced, and the data protection ability of the electronic device is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 is one of the flowcharts of a data protection method provided by an embodiment of the present application;

[0013] Figure 2 is the second flowchart of a data protection method provided by an embodiment of the present application;

[0014] Figure 3 is the flowchart of a method for storing a ciphertext key provided by an embodiment of the present application;

[0015] Figure 4It is the third flowchart of a data protection method provided by an embodiment of the present application;

[0016] Figure 5 It is the flowchart of a data decryption method provided by an embodiment of the present application;

[0017] Figure 6 It is the structural schematic diagram of a data protection device provided by an embodiment of the present application;

[0018] Figure 7 It is one of the hardware structural schematic diagrams of an electronic device provided by an embodiment of the present application;

[0019] Figure 8 It is the second hardware structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0020] Next, the technical solutions in the embodiments of the present application will be clearly described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art belong to the scope protected by the present application.

[0021] The terms "first", "second", etc. in the specification of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. generally belong to the same category, and do not limit the number of objects. For example, the first object can be one or multiple. In addition, "and / or" in the specification means at least one of the connected objects, and the character " / " generally represents an "or" relationship between the associated objects before and after.

[0022] The terms "at least one (item)", "at least one of", etc. in the specification of the present application refer to any one, any two or more combinations of the objects they contain. For example, at least one (item) of a, b, and c can represent: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two (items)" means two or more, and its expressed meaning is similar to that of "at least one (item)".

[0023] The following is a glossary of the technical terms involved in the embodiments of the present application:

[0024] Compilation: Compilation is the process of converting high-level programming language code into binary code executable by a computer.

[0025] Decompilation: Decompilation is the process of reversely converting binary code back to a higher-level code to understand the program logic.

[0026] The following will, in conjunction with the accompanying drawings, explain in detail the data protection method provided by the embodiments of the present application through specific embodiments and their application scenarios.

[0027] The data protection method provided by the embodiments of the present application can be applied to scenarios of protecting data based on an electronic device. For example, in a scenario where a user needs to use services such as maps and location services provided by Google through an electronic device, the electronic device needs to update the Google key in real time. Thus, during the process of updating the Google key, the electronic device can obtain a white-box key and encrypt the plaintext Google key based on this white-box key to obtain a ciphertext Google key. Then, replace the plaintext Google key in the code with the ciphertext Google key and store the replaced code.

[0028] It should be noted that the above is only an example of a scenario where the embodiments of the present application may be applied. In actual implementation, the embodiments of the present application can also be applied to more scenarios such as any possible data protection scenarios, and the embodiments of the present application are not limited thereto.

[0029] Based on the above scenarios applied by the embodiments of the present application, for the data protection method provided by the embodiments of the present application, when compiling the first data of the first file, encrypt the first plaintext key in the first file according to the first key algorithm to obtain a first ciphertext key; the first plaintext key corresponds to the first data; replace the first plaintext key in the first file with the first ciphertext key. In this solution, since the electronic device can replace the first plaintext key in the first file with the first ciphertext key, and this first ciphertext key is obtained by encrypting the first plaintext key with a white-box key, that is to say, there will be no plaintext key in the replaced first file, that is, this first plaintext key. In this way, when the electronic device stores the replaced first file, even if an external person obtains the replaced first file, they cannot obtain the first plaintext key from the replaced first file through static decompilation, and even less can they further decrypt to obtain the encrypted data in the first file. Thus, the risk of plaintext key leakage is reduced, and the data protection ability of the electronic device is improved.

[0030] The execution subject of the data protection method provided by the embodiments of the present application is a data protection device. This device can be an electronic device, or a functional module or entity in an electronic device. The embodiments of the present application are not limited thereto. The following will take an electronic device as an example to exemplarily explain the data protection method provided by the embodiments of the present application.

[0031] An embodiment of the present application provides a data protection method. Figure 1 The flowchart of a data protection method provided by an embodiment of the present application is shown. As Figure 1 shown, the data protection method provided by an embodiment of the present application may include the following steps 201 and 202.

[0032] Step 201: When compiling the first data of the first file, the electronic device encrypts the first plaintext key in the first file according to the first key algorithm to obtain the first ciphertext key.

[0033] In the embodiment of the present application, the above first plaintext key corresponds to the first data.

[0034] In some embodiments of the present application, the above first file may be an ELF file. Of course, the first file may also be other files, and the embodiments of the present application do not limit this.

[0035] It should be noted that the above ELF is a standard file format used to define program executable files, object codes, and shared libraries. In the linux operating system, an ELF file can be obtained by compiling code.

[0036] The file structure of the above ELF file may include: ELF Header, Program Header Table, Section Header Table, and Sections.

[0037] Among them, the above ELF header is used to describe the overall layout of the ELF file, and at least one of the key information such as file type, target architecture, and entry point address may be included in the ELF header table;

[0038] The above program header table is used to describe information about each section in the file, such as at least one of the section type, memory address, and file offset;

[0039] The above section header table is an index of the sections in the ELF file for storing content such as code, data, and debugging information, and it can be used to describe detailed information about each section in the file, such as at least one of the section name, section type, and section size;

[0040] The above sections in the ELF file are the basic units of the ELF file and are divided by the electronic device based on logical functions. The sections can be used to store at least one of the executable parts in the program of the ELF file, such as the code section (.text), data section (.data), uninitialized data section (.bss), symbol table (.symtab), and string table (.strtab), etc.

[0041] In some embodiments of the present application, the above-mentioned first data may be at least part of the data that the user requires the electronic device to encrypt and protect.

[0042] In some embodiments of the present application, the code of the above-mentioned first data may include special statements, so that when the electronic device runs to these special statements, it can be determined that the first data is the data that the user requires the electronic device to encrypt and protect.

[0043] In some embodiments of the present application, when the first file is an ELF file, the above-mentioned first data may be the data stored in any section of the ELF file. For example, the first data may be the data stored in the code section, or may be the data stored in the data section; or may be the data read in from other places when the ELF file runs, where the other places may be databases, IPC communications, etc.

[0044] In some embodiments of the present application, the process of "compiling the first data of the first file" may include: the electronic device may first modify the text of the source program through a preprocessor for preprocessing, then assemble the program through a compiler, and then convert the assembly code into an object file through an assembler, and finally link multiple object files and system libraries and other dependent shared libraries through a linker, so that the electronic device can finally obtain an ELF file.

[0045] In some embodiments of the present application, the above-mentioned first key algorithm may be a white-box key algorithm.

[0046] In some embodiments of the present application, the above-mentioned white-box key WK may be a globally encrypted key dynamically generated by the electronic device based on white-box encryption.

[0047] It should be noted that the above-mentioned white-box encryption, also known as transparent encryption or white-box encryption, is a special encryption method. Compared with the encryption methods of related technologies, white-box encryption can integrate the encryption algorithm and the key into an executable program, so that the encryption and decryption operations are carried out in a completely transparent environment. Even if external personnel can access the encrypted data and the execution program, they cannot obtain the key or the decryption algorithm, and thus cannot decrypt the data encrypted and protected by white-box encryption.

[0048] In some embodiments of the present application, the electronic device may dynamically generate a white-box key WK before compiling the first data in the first file. For example, the electronic device may dynamically generate a white-box key WK at the same time as starting to compile the first file, and then call the generated white-box key when compiling the first data in the first file to perform subsequent other operations.

[0049] In some embodiments of the present application, the electronic device may dynamically generate a white-box key WK while compiling the first data in the first file for subsequent other operations.

[0050] In some embodiments of the present application, the electronic device may determine user requirements based on special codes in the program of the first file to call and obtain the white-box key and perform subsequent steps. The special code may be determined according to user requirements or program settings, and the embodiments of the present application do not limit this here.

[0051] In the embodiments of the present application, the above first plaintext key corresponds to the first data.

[0052] In some embodiments of the present application, the above first plaintext key may be used to encrypt or decrypt the first data.

[0053] In some embodiments of the present application, the electronic device may obtain the above first plaintext key K from the code of the first file by calling the encryption and decryption interface T.

[0054] It should be noted that the above encryption and decryption interface can be understood as the general name of two types of interfaces, namely, the encryption interface or the decryption interface. Among them, the encryption interface can be used to convert plaintext data into ciphertext data, and the decryption interface can be used to restore ciphertext data to plaintext data.

[0055] In some embodiments of the present application, the encryption algorithms for encrypting the first data may include but are not limited to any of the following: symmetric encryption algorithms, asymmetric encryption algorithms.

[0056] It should be noted that the above symmetric encryption algorithm refers to an encryption algorithm in which the same key can be used for encryption and decryption. For example, the Advanced Encryption Standard (AES) algorithm, the Data Encryption Standard (DES) algorithm, the Triple DES (3DES) algorithm, etc.

[0057] The above asymmetric encryption algorithm refers to an encryption algorithm in which different keys can be used for encryption and decryption. For example, data is encrypted with a public key and decrypted with a private key. Among them, the public key can be made public to any user, and the private key can be stored secretly. For example, the RSA algorithm, the Digital Signature Algorithm (DSA), the Elliptic Curve Cryptography (ECC), etc.

[0058] It should be noted that the encryption algorithm corresponding to the first plaintext key K can be determined according to actual requirements, and the embodiments of the present application do not limit this here.

[0059] In some embodiments of the present application, the encryption algorithm used for "encrypting the first plaintext key in the first file based on the white-box key" may include but is not limited to any one of the following: AES white-box algorithm, RSA white-box algorithm, SM4 white-box algorithm, and SM2 white-box algorithm.

[0060] It should be noted that the encryption algorithm corresponding to the white-box key WK can be determined according to actual requirements, and the embodiments of the present application do not limit this here.

[0061] In some embodiments of the present application, there is an association relationship between the above-mentioned first plaintext key K and the first ciphertext key K'.

[0062] In some embodiments of the present application, when there are multiple plaintext keys in the first file that need to be encrypted by the white-box key WK, the electronic device can perform an encryption operation through the white-box key WK during the compilation process of each plaintext key among the multiple plaintext keys, so as to obtain the ciphertext key corresponding to each plaintext key respectively, thereby obtaining multiple ciphertext keys, where the multiple plaintext keys and the multiple ciphertext keys are in one-to-one correspondence.

[0063] Step 202: The electronic device replaces the first plaintext key in the first file with the first ciphertext key.

[0064] In some embodiments of the present application, the electronic device can delete the first plaintext key stored in plaintext in the code of the first file, and add the content of the first ciphertext key at the original storage location of the first plaintext key, so as to replace the first plaintext key with the first ciphertext key.

[0065] It should be noted that during the process of replacing the first plaintext key with the first ciphertext key, it should be ensured as much as possible that the lengths of the first plaintext key and the first ciphertext key are the same, so as to avoid damage to the structure of the first file caused by key replacement.

[0066] In the data protection method provided in the embodiments of the present application, since the electronic device can replace the first plaintext key in the first file with the first ciphertext key, and the first ciphertext key is obtained by encrypting the first plaintext key with the white-box key, that is to say, there will be no plaintext key in the replaced first file, namely the first plaintext key. In this way, when the electronic device stores the replaced first file, even if an external person obtains the replaced first file, they cannot obtain the first plaintext key from the replaced first file through static decompilation, and even less can they further decrypt to obtain the encrypted data in the first file. Thus, the risk of plaintext key leakage is reduced, and the data protection ability of the electronic device is improved.

[0067] In some embodiments of the present application, in combination with Figure 1 , such as Figure 2 shown, after the above step 202, the data protection method provided in the embodiments of the present application may further include the following step 301 and step 302.

[0068] Step 301: The electronic device stores the first ciphertext key in the first list.

[0069] Step 302: The electronic device stores the first list in the first file.

[0070] In some embodiments of the present application, since the first ciphertext key is obtained by encrypting the first plaintext key based on the white-box key, there is an association relationship between the first ciphertext key and the first plaintext key.

[0071] In some embodiments of the present application, when there are multiple ciphertext keys obtained by encrypting with the white-box key in the first file, the electronic device may store the multiple ciphertext keys in the first list in an associated manner.

[0072] In some embodiments of the present application, after replacing the first plaintext key in the first file with the associated ciphertext key, the electronic device may directly create a list, that is, the first list, and store the ciphertext key in the first list. Then, each time a plaintext key is replaced with a ciphertext key subsequently, the replaced ciphertext key is stored in the first list.

[0073] In some embodiments of the present application, at the last stage of compiling the first file, the electronic device may traverse the compilation process to obtain all the ciphertext keys obtained by encrypting with the white-box key, so as to generate the first list by packaging.

[0074] In some embodiments of the present application, the first list may be stored in a specified section in the first file, for example, a section named keyencrypt.

[0075] Exemplarily, as Figure 3 shown, assume that the above-mentioned first file is ELF file 1, and there are 3 plaintext keys in ELF file 1 that need to be encrypted by the white-box key WK, such as plaintext key K1, plaintext key K2, and plaintext key K3. Then, the electronic device can obtain the plaintext key K1 by calling the encryption and decryption interface T, and then use the white-box key WK to encrypt the plaintext key K1 to obtain the ciphertext key corresponding to the plaintext key K1, such as ciphertext key K1'; and, it can obtain the plaintext key K2 by calling the encryption and decryption interface T, and then use the white-box key WK to encrypt the plaintext key K2 to obtain the ciphertext key corresponding to the plaintext key K2, such as ciphertext key K2'; and, it can obtain the plaintext key K3 by calling the encryption and decryption interface T, and then use the white-box key WK to encrypt the plaintext key K3 to obtain the ciphertext key corresponding to the plaintext key K1, such as ciphertext key K3'. Then, at the last stage of compiling ELF file 1, the electronic device can generate a list based on the ciphertext keys K1', K2', and K3', such as the KL list, and further write the KL list into the keyencrypt section in ELF file 1.

[0076] In the embodiment of the present application, since the electronic device can store the ciphertext keys included in the first file in a list, when the electronic device runs the first file, other electronic devices can determine whether a key is a plaintext key or a ciphertext key based on the key data stored in the list, so that the electronic device can classify the keys more conveniently and accurately, thereby improving the convenience of encrypting or decrypting data based on the plaintext key.

[0077] In some embodiments of the present application, in combination with Figure 1 , as Figure 4 shown, after the above step 202, the data protection method provided by the embodiment of the present application may further include the following step 401 and step 402.

[0078] Step 401: When running the first file, the electronic device decrypts the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key.

[0079] In some embodiments of the present application, the above first plaintext key corresponds to the first data in the first file.

[0080] It can be understood that during the running process of the electronic device for the first file, if it runs to a preset node, such as running to the specific code in the first data, the electronic device can start to obtain the key corresponding to the first data based on the running state, that is, the above first ciphertext key.

[0081] In some embodiments of the present application, the above first key algorithm may be a white-box key algorithm.

[0082] It can be understood that since the above first ciphertext key is obtained by the electronic device encrypting the first plaintext key based on the white-box key, the electronic device can decrypt the first ciphertext key based on the white-box key to obtain the first plaintext key.

[0083] In some embodiments of the present application, for the decryption algorithm used in the above decryption, reference may be made to the description of the encryption algorithm in the above embodiments, and details are not elaborated herein in the embodiments of the present application.

[0084] It should be noted that the decryption algorithm used in the above decryption process corresponds to the encryption algorithm used for encrypting the first plaintext key based on the white-box key. The specific decryption method can be determined according to the actual encryption algorithm used, and no limitation is made herein in the embodiments of the present application.

[0085] Step 402: The electronic device performs encryption and decryption operations on the first data using the first plaintext key.

[0086] In some embodiments of the present application, after the electronic device obtains the first plaintext key, the electronic device can call the encryption and decryption interface to perform encryption and decryption operations on the first data using the first plaintext key.

[0087] It should be noted that the above encryption and decryption interface may be the encryption and decryption interface T in step 202 above.

[0088] In some embodiments of the present application, for the encryption algorithm or decryption algorithm used in the above encryption and decryption operations, reference may be made to the description of the encryption algorithm in the above embodiments, and details are not elaborated herein in the embodiments of the present application.

[0089] In some embodiments of the present application, the electronic device encrypts or decrypts the first data using the first plaintext key based on the business requirements of the electronic device for executing the first file.

[0090] It should be noted that the above business can be determined according to actual needs, and no limitation is made herein in the embodiments of the present application.

[0091] Exemplarily, assume that the above business is to log in to a communication application. When the user inputs the account password of the communication application, the electronic device can obtain the ciphertext key 1, decrypt the ciphertext key using the white-box key to obtain the plaintext key 1. Since the electronic device needs to transmit the account password to the server for verification, the electronic device can encrypt the account password using the plaintext key 1, and then transmit the encrypted account password to the server for subsequent verification steps.

[0092] Further, assume that the above electronic device is a server side. In the case where the server side receives the encrypted account password, the server side can obtain the corresponding ciphertext key 2, decrypt the ciphertext key 2 through the white-box key to obtain the plaintext key 2, and decrypt the encrypted login key through the plaintext key 2 to obtain the login key for subsequent verification steps.

[0093] In the embodiments of the present application, when the electronic device runs the first file, the electronic device can decrypt the first ciphertext key to obtain the first plaintext key. Thus, during the process of storing the first file, even if an external person obtains the replaced first file, they cannot obtain the first plaintext key from the replaced first file through static decompilation, and even less can they further decrypt to obtain the encrypted data in the first file. In this way, the risk of plaintext key leakage is reduced, and the data protection ability of the electronic device is improved.

[0094] In some embodiments of the present application, the above first file includes a first list, and the first list includes at least one identifier of a ciphertext key. Before the step of "the electronic device decrypts the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key" in the above step 401, the data protection method provided by the embodiments of the present application may further include the following step 501 and step 502.

[0095] Step 501: The electronic device calls the encryption and decryption interface to obtain each key included in the first file.

[0096] In some embodiments of the present application, the above encryption and decryption interface T1 may be an interface rewritten based on the encryption and decryption interface T in the above step 202.

[0097] Step 502: For one of the keys, when the first list includes the identifier of the key, the electronic device determines the key as the first ciphertext key.

[0098] In some embodiments of the present application, the electronic device can call the encryption and decryption interface T1 to match the key with the key identifier included in the first list to determine whether the key is a ciphertext key.

[0099] In some embodiments of the present application, the above first list may be stored at a specified position in the above first file. For example, Figure 3 the key encryption section in the ELF file structure shown.

[0100] Exemplarily, such as Figure 5As shown, the electronic device can first call the encryption and decryption interface T1 to obtain each key included in the first file. For the key corresponding to one of the data, such as the key Kn corresponding to the data n, the electronic device can call the encryption and decryption interface T1 to match the key Kn with the key identifier included in the first list to determine whether the key Kn is stored in the KL list. In the case where the KL list includes the identifier of the key Kn, the electronic device can determine the key Kn as the ciphertext key. Then, the electronic device can call the white-box key WK to decrypt the key Kn to obtain the plaintext key corresponding to the key Kn, and then call the encryption and decryption interface T to perform encryption and decryption operations on the data n based on the plaintext key corresponding to the key Kn, so as to obtain the data n in the first file.

[0101] In the embodiments of the present application, the electronic device can determine whether the obtained key is a ciphertext key based on the first list, and then, in the case where it is determined that the key corresponding to the data is a ciphertext key, obtain the corresponding plaintext key based on the ciphertext key. In this way, the accuracy of the electronic device in obtaining the key can be improved.

[0102] In some embodiments of the present application, the data protection method provided by the embodiments of the present application may further include the following step 503.

[0103] Step 503: For one of the keys, in the case where the first list does not include the identifier of the key, the electronic device performs encryption and decryption operations on the key according to the second key algorithm.

[0104] It should be noted that, in the case where the first list does not include the identifier of the key, the electronic device can determine that the key is not encrypted based on the white-box key, that is, the key corresponding to the one data is the plaintext key.

[0105] In some embodiments of the present application, after the electronic device obtains the first plaintext key, the electronic device can call the encryption and decryption interface to encrypt and decrypt the first data through the first plaintext key.

[0106] It should be noted that the above encryption and decryption interface can be the encryption and decryption interface T in the above step 202.

[0107] In some embodiments of the present application, the above second key algorithm can refer to the description of the encryption algorithm in the above embodiments, and the embodiments of the present application will not elaborate here.

[0108] It should be noted that the second key algorithm used in the above encryption and decryption process corresponds to the algorithm used for encrypting and decrypting the first data. The specific algorithm can be determined according to actual needs, and the embodiments of the present application do not limit it here.

[0109] Exemplarily, in combination with Figure 5, the electronic device can first call the encryption and decryption interface T1 to obtain each key included in the first file. For the key corresponding to one of the data, such as the key Kn corresponding to the data n, the electronic device can call the encryption and decryption interface T1 to match the key Kn with the key identifier included in the first list to determine whether the key Kn is stored in the KL list. When the KL list does not include the identifier of the key Kn, the electronic device can determine that the key is not encrypted based on the white-box key, that is, the key corresponding to the one data is a plaintext key. Then, the electronic device can call the encryption and decryption interface T, and directly perform encryption and decryption operations on the data n based on the encryption and decryption algorithm corresponding to the data n, that is, the above-mentioned second key algorithm, using the key Kn, so as to obtain the data n in the first file.

[0110] In the embodiments of the present application, the electronic device can determine whether the obtained key is a ciphertext key based on the first list, and then, when it is determined that the key corresponding to the data is not a ciphertext key, perform encryption and decryption operations on the key using the second key algorithm. In this way, the accuracy of the electronic device in obtaining the key can be improved.

[0111] For each scenario applicable to the embodiments of the present application, combined with the above-mentioned implementation solutions of the embodiments of the present application, specific examples are given below to illustrate the implementation process of the embodiments of the present application in specific scenarios.

[0112] Scenario 1: The electronic device needs to transmit the account password A of the communication application, that is, sensitive data, to the server through the network.

[0113] When the electronic device needs to transmit the account password A of the communication application to the server through the network, the electronic device can, when compiling the ELF file corresponding to the communication application, first compile the plaintext key B used for encrypting and decrypting the account password into the ELF file, and then encrypt the plaintext key B with the white-box key WK to obtain the ciphertext key C, and replace the plaintext key B in the ELF file with the ciphertext key C. Further, in the last stage of the compilation of the ELF file, the electronic device can traverse all the ciphertext keys included in the ELF file to generate a KL list based on all the ciphertext keys, and write the KL list into the keyencrypt section in the ELF file. The KL list includes the ciphertext key C.

[0114] When the electronic device needs to transmit the account password A to the server for verification, that is, when the electronic device runs the ELF file, the electronic device can match the key to be used currently as the ciphertext key C based on the KL list. Then, the electronic device can decrypt the ciphertext key with the white-box key WK to obtain the plaintext key B. Further, the electronic device can call the encryption / decryption function T to encrypt the account password A with the plaintext key B and transmit the encrypted account password A to the server through the network.

[0115] It should be noted that in the above complete process, the plaintext key B does not exist in the ELF file, and the dynamic operation of the ELF file does not affect the business operation.

[0116] Scenario 2: Product usage scenario.

[0117] When the user needs to use services such as maps and location services provided by Google through the electronic device, the electronic device needs to update the Google key immediately. Thus, during the process of updating the Google key, the electronic device can obtain the white-box key to encrypt the plaintext Google key based on this white-box key to obtain the ciphertext Google key. Then, the electronic device can replace the plaintext Google key in the code with the ciphertext Google key and store the replaced code. At the same time, in the final stage of compilation, the electronic device can traverse the ciphertext keys to generate a KL list based on all the ciphertext keys and write this KL list into the keyencrypt section of the file. Among them, this KL list includes the ciphertext Google key.

[0118] Then, when the electronic device runs the above services such as maps and location services, the electronic device can determine the key to be used currently as the above ciphertext Google key based on the KL list. Then, the electronic device can decrypt the ciphertext Google key with the white-box key WK to obtain the above plaintext Google key and write this plaintext Google key into the electronic device to complete the entire update process.

[0119] Scenario 3: Assume that the first file is an ELF file, and this ELF file contains 3 data to be encrypted, namely Data 1 to Data 3. Each data corresponds to a plaintext key. For example, Data 1 corresponds to the plaintext key K1. And Data 1 and Data 3 are the data that developers need to protect emphatically, that is, the plaintext keys of Data 1 and Data 3 also respectively correspond to a ciphertext key. For example, the plaintext key K1 of Data 1 corresponds to the ciphertext key K1'.

[0120] During the process of an electronic device compiling data 1 in an ELF file, the electronic device can first add the plaintext key K1 corresponding to data 1 to the code of data 1. Then, in a similar manner, the plaintext key K2 corresponding to data 2 can be added to the code of data 2; the plaintext key K3 corresponding to data 3 can be added to the code of data 3. Then, since data 1 and data 3 are the data that developers need to protect with emphasis, during the process of compiling data 1, the electronic device can also use the white-box key WK to encrypt the plaintext key K1 to obtain the ciphertext key K1', and replace the plaintext key K1 in the ELF file with the ciphertext key K1'. Similarly, during the process of compiling data 3, the electronic device can use the white-box key WK to encrypt the plaintext key K3 to obtain the ciphertext key K3', and replace the plaintext key K3 in the ELF file with the ciphertext key K3'.

[0121] In the final stage of ELF file compilation, the electronic device can traverse the code of the ELF file to obtain all the ciphertext keys contained therein, namely the ciphertext key K1' and the ciphertext key K3', so as to generate a first list, such as the KL list, by packing, and store the KL list in a specified section of the ELF file, such as the keyencrypt section.

[0122] Then, when the electronic device runs the ELF file, the electronic device can load the KL list in the ELF file.

[0123] When running data 1 of the ELF file, obtain the key corresponding to data 1, and then call the encryption / decryption interface T1 to determine whether the key corresponding to data 1 is stored in the KL list. And when it is determined that the key is stored in the KL list, that is, the key is the ciphertext key K1', the electronic device can call the white-box key WK to decrypt the ciphertext key K1' to obtain the plaintext key K1 corresponding to the ciphertext key K1', and then call the encryption / decryption interface T to perform encryption / decryption operations on data 1 based on the execution requirements through the plaintext key K1.

[0124] When the electronic device runs data 2 of the ELF file, obtain the key corresponding to data 2, and then call the encryption / decryption interface T2 to determine whether the key corresponding to data 2 is stored in the KL list. And when it is determined that the key is not stored in the KL list, that is, the key is the plaintext key, the electronic device can call the encryption / decryption interface T to perform encryption / decryption operations on data 2 based on the execution requirements through the plaintext key K2.

[0125] When the electronic device runs the data 3 of the ELF file, obtain the key corresponding to the data 3, then call the encryption and decryption interface T3, and determine whether the key corresponding to the data 3 is stored in the KL list. And when it is determined that the key is stored in the KL list, that is, the key is the ciphertext key K3', the electronic device can call the white-box key WK to decrypt the ciphertext key K3' to obtain the plaintext key K3 corresponding to the ciphertext key K3', and then call the encryption and decryption interface T to perform encryption and decryption operations on the data 3 based on the execution requirements through the plaintext key K3.

[0126] It should be noted that the above-mentioned various method embodiments, or various possible implementation manners in the various method embodiments, can be executed independently, or, on the premise of no contradiction, can also be executed in combination with each other, which can be specifically determined according to actual usage requirements, and the embodiments of the present application do not limit this.

[0127] It should be noted that for the data protection method provided in the embodiments of the present application, the execution subject can be a data protection device. In the embodiments of the present application, taking the data protection device executing the data protection method as an example, the data protection device provided in the embodiments of the present application is described.

[0128] Figure 6 A possible structural schematic diagram of the data protection device involved in the embodiments of the present application is shown. As Figure 6 shown, the data protection device 70 may include: an encryption module 71 and a replacement module 72;

[0129] Among them, the encryption module 71 is used to encrypt the first plaintext key in the first file according to the first key algorithm when compiling the first data of the first file, to obtain the first ciphertext key; the first plaintext key corresponds to the first data;

[0130] The replacement module 72 is used to replace the first plaintext key in the first file with the first ciphertext key obtained by the encryption module 71.

[0131] In a possible implementation manner, the data protection device 70 provided in the embodiments of the present application further includes: a storage module; the storage module is used to replace the first plaintext key in the first file with the first ciphertext key, then store the first ciphertext key in the first list; and store the first list in the first file.

[0132] In a possible implementation manner, the above-mentioned first key algorithm is a white-box key algorithm.

[0133] In a possible implementation manner, the data protection device 70 provided by the embodiment of the present application further includes: a decryption module and an execution module; the decryption module is configured to, after replacing the first plaintext key in the first file with the first ciphertext key, decrypt the first ciphertext key in the first file according to the first key algorithm when the first file is run, so as to obtain the first plaintext key; the execution module is configured to perform encryption and decryption operations on the first data through the first plaintext key.

[0134] In a possible implementation manner, the above-mentioned first file includes a first list, and the first list includes at least one identifier of a ciphertext key; the data protection device 70 provided by the embodiment of the present application further includes: a call module and a judgment module; the call module is configured to, before decrypting the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key, call an encryption and decryption interface to obtain each key included in the first file; the judgment module is configured to, for one of the keys, determine the key as the first ciphertext key when the first list includes the identifier of the key.

[0135] In a possible implementation manner, the above-mentioned execution module is further configured to, for one of the keys, perform encryption and decryption operations on the key according to the second key algorithm when the first list does not include the identifier of the key.

[0136] In the data protection device provided by the embodiment of the present application, since the data protection device can replace the first plaintext key in the first file with the first ciphertext key, and the first ciphertext key is obtained by encrypting the first plaintext key with a white box key, that is to say, there will be no plaintext key in the replaced first file, that is, the first plaintext key. In this way, when the data protection device stores the replaced first file, even if an external person obtains the replaced first file, they cannot obtain the first plaintext key from the replaced first file through static decompilation, and even less can they further decrypt to obtain the encrypted data in the first file. Thus, the risk of plaintext key leakage is reduced, and the data protection ability of the data protection device is improved.

[0137] The data protection device in the embodiments of the present application can be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other devices other than terminals. Exemplarily, the electronic device can be a mobile phone, a tablet computer, a laptop computer, a handheld computer, an in-vehicle electronic device, a Mobile Internet Device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and can also be a server, a Network Attached Storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0138] The data protection device in the embodiments of the present application can be a device with an operating system. The operating system can be an Android operating system, an iOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0139] The data protection device provided in the embodiments of the present application can implement each process implemented in the above method embodiments. To avoid repetition, it will not be elaborated here.

[0140] Optionally, as Figure 7 shown, the embodiments of the present application further provide an electronic device 90, including a processor 91 and a memory 92. A program or instruction that can run on the processor 91 is stored on the memory 92. When the program or instruction is executed by the processor 91, each step of the above data protection method embodiments is implemented, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.

[0141] It should be noted that the electronic devices in the embodiments of the present application include the above-mentioned mobile electronic devices and non-mobile electronic devices.

[0142] Figure 8 Schematic diagram of the hardware structure of an electronic device for implementing the embodiments of the present application.

[0143] The electronic device 100 includes, but is not limited to, components such as a radio frequency unit 101, a network module 102, an audio output unit 103, an input unit 104, a sensor 105, a display unit 106, a user input unit 107, an interface unit 108, a memory 109, and a processor 110, etc.

[0144] Those skilled in the art can understand that the electronic device 100 may further include a power source (such as a battery) for supplying power to each component. The power source can be logically connected to the processor 110 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. Figure 8 The structure of the electronic device shown does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0145] Among them, the processor 110 is used to encrypt the first plaintext key in the first file according to the first key algorithm to obtain a first ciphertext key when compiling the first data of the first file; the first plaintext key corresponds to the first data; and replace the first plaintext key in the first file with the first ciphertext key.

[0146] Optionally, the memory 109 is used to store the first ciphertext key in the first list after replacing the first plaintext key in the first file with the first ciphertext key; and store the first list in the first file.

[0147] Optionally, the above first key algorithm is a white box key algorithm.

[0148] Optionally, the processor 110 is further used to decrypt the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key when running the first file after replacing the first plaintext key in the first file with the first ciphertext key; and perform encryption and decryption operations on the first data through the first plaintext key.

[0149] Optionally, the above first file includes a first list, and the first list includes at least one identifier of a ciphertext key; the processor 110 is further used to call an encryption and decryption interface to obtain each key included in the first file before decrypting the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key; and for one of the keys, determine the key as the first ciphertext key when the first list includes the identifier of the key.

[0150] Optionally, the processor 110 is further used to perform encryption and decryption operations on the key according to the second key algorithm for one of the keys when the first list does not include the identifier of the key.

[0151] In the electronic device provided in the embodiment of the present application, since the electronic device can replace the first plaintext key in the first file with a first ciphertext key, and the first ciphertext key is obtained by encrypting the first plaintext key with a white-box key, that is to say, there will be no plaintext key in the replaced first file, namely the first plaintext key. In this way, when the electronic device stores the replaced first file, even if an external person obtains the replaced first file, they cannot obtain the first plaintext key from the replaced first file through static decompilation, let alone further decrypt the encrypted data in the first file. Thus, the risk of plaintext key leakage is reduced, and the data protection ability of the electronic device is improved.

[0152] The electronic device provided in the embodiment of the present application can implement each process implemented in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0153] For the beneficial effects of various implementation manners in this embodiment, reference may be specifically made to the beneficial effects of the corresponding implementation manners in the above method embodiment. To avoid repetition, it will not be elaborated here.

[0154] It should be understood that in the embodiment of the present application, the input unit 104 may include a Graphics Processing Unit (GPU) 1041 and a microphone 1042. The graphics processor 1041 processes the image data of static pictures or videos obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 106 may include a display panel 1061, and the display panel 1061 may be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 107 includes at least one of a touch panel 1071 and other input devices 1072. The touch panel 1071 is also called a touch screen. The touch panel 1071 may include a touch detection device and a touch controller. The other input devices 1072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, and a joystick, which will not be elaborated here.

[0155] The memory 109 can be used to store software programs and various data. The memory 109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area may store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 109 may include a volatile memory or a non-volatile memory, or the memory 109 may include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM). The memory 109 in the embodiments of the present application includes, but is not limited to, these and any other suitable types of memories.

[0156] The processor 110 may include one or more processing units; optionally, the processor 110 integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, and application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above modem processor may not be integrated into the processor 110 either.

[0157] The embodiments of the present application also provide a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above method embodiments and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0158] Among them, the processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media such as computer read-only memory ROM, random access memory RAM, magnetic disks, or optical discs, etc.

[0159] Another embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement each process of the above method embodiment, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0160] It should be understood that the chip mentioned in the embodiments of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0161] The embodiments of the present application provide a computer program product. The program product is stored in a storage medium and is executed by at least one processor to implement each process of the above method embodiment, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0162] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article, or device including that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the reverse order according to the functions involved. For example, the described method may be executed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, the features described with reference to certain examples may be combined in other examples.

[0163] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0164] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A data protection method, characterized in that: The method comprises: When compiling first data of a first file, encrypting a first plaintext key in the first file according to a first key algorithm to obtain a first ciphertext key; the first plaintext key corresponds to the first data; The first plaintext key in the first file is replaced by the first ciphertext key.

2. The method according to claim 1, characterized in that After replacing the first plaintext key in the first file with the first ciphertext key, the method further includes: Storing the first ciphertext key in a first list; The first list is stored in the first file.

3. The method according to claim 1, characterized in that The first key algorithm is a white box key algorithm.

4. The method according to claim 1, characterized in that After replacing the first plaintext key in the first file with the first ciphertext key, the method further includes: When the first file is executed, the first ciphertext key in the first file is decrypted according to the first key algorithm to obtain the first plaintext key; The first data is encrypted and decrypted using the first plaintext key.

5. The method according to claim 4, characterized in that The first file includes a first list, and the first list includes an identifier of at least one ciphertext key; Before decrypting the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key, the method further includes: Calling the encryption and decryption interface to obtain the keys included in the first file; For one of the keys, when the first list includes the identifier of the key, the key is determined to be the first ciphertext key.

6. The method according to claim 5, characterized in that The method further comprises: For one of the keys, when the first list does not include the identifier of the key, encryption and decryption operations are performed on the key according to the second key algorithm.

7. A data protection device, characterized in that: The data protection device comprises: an encryption module and a replacement module; The encryption module is used to encrypt a first plaintext key in the first file according to a first key algorithm to obtain a first ciphertext key when compiling the first data of the first file; the first plaintext key corresponds to the first data; The replacement module is used to replace the first plaintext key in the first file with the first ciphertext key obtained by the encryption module.

8. The device according to claim 7, characterized in that The data protection device further includes: a storage module; The storage module is used to replace the first plaintext key in the first file with the first ciphertext key, and then store the first ciphertext key in a first list; and store the first list in the first file.

9. The device according to claim 7, characterized in that The first key algorithm is a white box key algorithm.

10. The device according to claim 7, characterized in that The data protection device further includes: a decryption module and an execution module; The decryption module is configured to, after replacing the first plaintext key in the first file with the first ciphertext key, decrypt the first ciphertext key in the first file according to the first key algorithm when the first file is executed, to obtain the first plaintext key; The execution module is used to perform encryption and decryption operations on the first data using the first plaintext key.

11. The device according to claim 10, characterized in that The first file includes a first list, and the first list includes an identifier of at least one ciphertext key; The data protection device further includes: a calling module and a judging module; The calling module is used to call the encryption and decryption interface to obtain each key included in the first file before decrypting the first ciphertext key in the first file according to the first key algorithm to obtain the first plaintext key; The determination module is configured to determine, for one of the keys, if the first list includes an identifier of the key, that the key is the first ciphertext key.

12. The device according to claim 11, characterized in that The execution module is further configured to perform encryption and decryption operations on one of the keys according to a second key algorithm when the first list does not include an identifier of the key.

13. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the data protection method according to any one of claims 1 to 6 are implemented.

14. A readable storage medium, characterized in that: The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the data protection method according to any one of claims 1 to 6 are implemented.