Application program security authentication method and device based on Windows platform
By encrypting and writing PE files of Windows platform applications, combined with target authentication and authentication, the problem that the existing technology cannot meet the requirements of confidential evaluation is solved, and high-security identity authentication is achieved in zero transformation, meeting the requirements of confidential evaluation and reducing authentication costs.
Patent Information
- Application Number
- CN202510706970.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-29
AI Technical Summary
The prior art cannot meet the requirements of confidential review without modifying the business software, and cannot improve the security of identity authentication of business software, resulting in compliance and security challenges.
By encrypting the PE file corresponding to the application of the Windows platform, and writing the encrypted PE file to the target resource section of the preset PE file, the target PE file is obtained. Then, run the target PE file and, when the target authentication and authentication are passed, obtain the encrypted PE file and decrypt it to obtain the decrypted file.
Under the premise of zero transformation, the identity authentication mechanism for Windows platform applications is realized, which meets the requirements of confidential evaluation, improves the security of identity authentication of original PE files, and reduces the authentication cost.
Smart Images

Figure CN120234784A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to an application program security authentication method and device based on the Windows platform. Background Art
[0002] The user identity authentication technology on the Windows platform has evolved from single static passwords to multi-factor authentication, but still faces challenges in meeting the requirements of cryptographic evaluation compliance.
[0003] At present, taking power plants as an example, the business software in Security Zone 1 are all PE files under the Windows platform. However, limited by foreign brand restrictions or due to their long existence, when facing the situation of non-compliance in cryptographic evaluation and undergoing transformation, code-level integration transformation cannot be carried out, and thus the high-risk transformation requirements for identity authentication on the business system side in the evaluation activities cannot be met, and both its compliance and security face challenges. Summary of the Invention
[0004] The present invention provides an application program security authentication method and device based on the Windows platform to solve the urgent business security demands in existing evaluation practices that the business software cannot be modified and thus cannot meet the requirements of cryptographic evaluation, or the security of identity authentication of the business software cannot be improved by modifying the software.
[0005] The present invention provides an application program security authentication method based on the Windows platform, including: Obtaining a portable executable (PE) file corresponding to an application program on the Windows platform; Encrypting the PE file and writing the encrypted PE file into a target resource segment of a preset PE file to obtain a target PE file; wherein, the preset PE file includes multiple resource segments, and the target resource segment belongs to the multiple resource segments; Running the target PE file, and when the target PE file passes target authentication and authorization, obtaining the encrypted PE file and decrypting it to obtain a decrypted file; wherein, the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
[0006] According to the application program security authentication method based on the Windows platform provided by the present invention, the encrypted PE file is associated with a target resource identifier, and the target authentication and authorization includes user identity authentication and user permission authentication; the user identity authentication includes at least one of dynamic password authentication and digital certificate challenge-response authentication: The obtaining the encrypted PE file when the target PE file passes target authentication and authorization includes: When it is determined that the encrypted PE file exists in the target resource segment according to the target resource identifier, user identity authentication and user permission authentication are sequentially performed on the encrypted PE file; When the user identity authentication and the user permission authentication are passed, the encrypted PE file is extracted from the target resource segment.
[0007] According to an application program security authentication method based on the Windows platform provided by the present invention, the obtaining of the portable executable PE file corresponding to the application program on the Windows platform includes: Performing binary reading on the application program to obtain the PE file.
[0008] According to an application program security authentication method based on the Windows platform provided by the present invention, after encrypting the PE file, the method further includes: Writing the encrypted PE file to the end of a preset PE file to obtain the target PE file.
[0009] According to an application program security authentication method based on the Windows platform provided by the present invention, the encrypting of the PE file includes: Performing symmetric encryption on the PE file.
[0010] According to an application program security authentication method based on the Windows platform provided by the present invention, after obtaining the decrypted file, the method further includes: Writing the decrypted file to the corresponding path of the target PE file to obtain a temporary file; the corresponding path of the target PE file is the same as the corresponding path of the PE file; Hiding the temporary file and running the hidden temporary file through the CreateProcess mechanism; Performing an operation of deleting or retaining the temporary file according to the running state of the temporary file.
[0011] According to an application program security authentication method based on the Windows platform provided by the present invention, before the target PE file passes the target authentication and authorization, the method further includes: When there is a historically generated temporary file in the path corresponding to the PE file, deleting the historically generated temporary file.
[0012] The present invention also provides an application program security authentication device based on the Windows platform, including: An obtaining module, configured to obtain a portable executable PE file corresponding to an application program on the Windows platform; An encryption and writing module, configured to encrypt a PE file and write the encrypted PE file into a target resource segment of a preset PE file to obtain a target PE file; wherein, the preset PE file includes multiple resource segments, and the target resource segment belongs to the multiple resource segments; An authentication and decryption module, configured to run the target PE file, and obtain and decrypt the encrypted PE file to obtain a decrypted file when the target PE file passes target authentication and authorization; wherein, the target authentication and authorization includes user identity authentication and user privilege authentication, or user identity authentication.
[0013] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for secure authentication of an application based on the Windows platform as described in any one of the above is implemented.
[0014] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method for secure authentication of an application based on the Windows platform as described in any one of the above is implemented.
[0015] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, the method for secure authentication of an application based on the Windows platform as described in any one of the above is implemented.
[0016] The method and device for secure authentication of an application based on the Windows platform provided by the present invention encrypt the PE file corresponding to the application on the Windows platform and write it into the target resource segment of the preset PE file to obtain a target PE file. Finally, the target PE file is run, and when the target PE file passes target authentication and authorization, the encrypted PE file is obtained and decrypted, which can implement an identity authentication mechanism based on cryptography technology for the application on the Windows platform without any modification, meet the relevant requirements of cryptographic evaluation, improve the security of the original PE file identity authentication, and reduce the authentication cost. Description of the Drawings
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0018] Figure 1It is one of the flow diagrams of the application program security authentication method based on the Windows platform provided by the present invention.
[0019] Figure 2 It is the second flow diagram of the application program security authentication method based on the Windows platform provided by the present invention.
[0020] Figure 3 It is the third flow diagram of the application program security authentication method based on the Windows platform provided by the present invention.
[0021] Figure 4 It is one of the structural diagrams of the application program security authentication device based on the Windows platform provided by the present invention.
[0022] Figure 5 It is the second structural diagram of the application program security authentication device based on the Windows platform provided by the present invention.
[0023] Figure 6 It is the structural diagram of the electronic device provided by the present invention. Detailed implementation manners
[0024] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0025] The following combines Figures 1 - 5 to describe the application program security authentication method and device based on the Windows platform of the present invention.
[0026] Figure 1 It is one of the flow diagrams of the application program security authentication method based on the Windows platform provided by the present invention. As Figure 1 shown, the method includes the following steps: Step 110: Obtain the portable executable (PE) file corresponding to the application program on the Windows platform.
[0027] In this step, the application program on the Windows platform is an application program on the Windows platform, including application programs that can be displayed on the display interface of the Windows platform, such as common browsers, communication software, or video platforms; it also includes system applications that are not on the display interface of the Windows platform.
[0028] In this embodiment, the source code can be compiled into a file conforming to the PE format by a compiler (such as Visual Studio, MinGW), for example, a binary file or other specified multi - base format files.
[0029] Step 120: Encrypt the PE file and write the encrypted PE file into the target resource section of a preset PE file to obtain a target PE file; wherein, the preset PE file includes multiple resource sections, and the target resource section belongs to the multiple resource sections.
[0030] In this step, for the PE (Portable Executable) file format under the Windows platform, there are internal resource sections (Resource Section) for storing some resource files, such as bitmaps and binary data, etc.
[0031] In this embodiment, the multiple resource sections can be operated through API functions provided by Windows (BeginUpdateResource, UpdateResource or EndUpdateResource), for example, adding resources, rewriting resources, etc.
[0032] In this embodiment, encrypting the PE file includes: performing symmetric encryption on the PE file.
[0033] Specifically, this embodiment can use symmetric encryption technology to encrypt the PE file. For example, when using the dynamic shelling technology to encrypt the PE file through a symmetric encryption algorithm, the code segment, data segment and import table are encrypted, and then the decryption operation is completed by the shell program file during runtime.
[0034] In this embodiment, encrypting the PE file includes: asymmetric encryption (for example, when encrypting, using the recipient's public key to symmetrically encrypt the PE file, and when decrypting, the recipient uses the private key to obtain the decrypted file and then decrypts the data) or encrypting in the way of resource segment embedding and information hiding (for example, embedding the encrypted DLL module into the resource segment in the RT_RCDATA type, dynamically loading and decrypting it during runtime), etc.
[0035] In this embodiment, the PE resource segment adopts a three - level directory structure (type → name → language); the following parameters need to be assigned to the target resource segment: Resource type: Custom type (such as RT_RCDATA or CUSTOM_DATA).
[0036] Resource identifier: Unique ID or string name (such as IDR_ENCRYPTED_PE).
[0037] Language code page: By default, MAKELANGID(LANG_NEUTRAL, SUBLANG_NEUTRAL) is used.
[0038] In this embodiment, the resource section can be dynamically modified using the Windows API, and the encrypted PE file can be written into the resource section of the preset PE file in a way of adding (deleting and replacing if existing), and finally a target PE file with a ciphertext resource section is output.
[0039] In this embodiment, when the data of the encrypted PE file is written into the target resource section, the data is stored according to the alignment rules of the preset PE file to avoid loading errors.
[0040] In this embodiment, taking a defined preset PE file as a template, the application on the Windows platform is converted into a corresponding PE file, and after encryption processing, it is written into the resource end of the preset PE file. While hiding the application on the Windows platform, a corresponding authentication mechanism can be added depending on the logic of the preset PE file itself, and finally the ultimate goal of securely starting the application on the Windows platform is achieved.
[0041] Step 130: Run the target PE file, and when the target PE file passes the target authentication and authorization, obtain the encrypted PE file and decrypt it to obtain the decrypted file; wherein, the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
[0042] In this step, the target authentication and authorization can include user identity authentication. For example, at the front end, one or more of inputting a smart password key, verifying the PIN password of a digital certificate, or user identification + dynamic password are required for user identity authentication; the target authentication and authorization can also include user permission authentication. If the current user identity does not have access permission to the target PE file, the authentication fails.
[0043] In this step, the above target authentication and authorization can be to first perform user identity authentication, and if the identity authentication passes, then perform user permission authentication; or it can be to only perform user identity authentication.
[0044] In this step, the decryption method can be determined according to the encryption method. For example, if the PE file is encrypted using a symmetric encryption algorithm, the encrypted PE file can be decrypted with the corresponding key to obtain the corresponding decrypted file; if the PE file is encrypted using an asymmetric encryption algorithm, the corresponding decryption key can be obtained from the receiving end or a third party, and the encrypted PE file can be decrypted.
[0045] In this embodiment, in the stage of running the target PE file, it is possible to query whether there is a ciphertext field and its content by querying the ciphertext resource section.
[0046] In this embodiment, when querying the ciphertext resource segment (corresponding to the target resource segment), the data characteristics of all resource segments of the target PE file can be checked one by one to find the encrypted PE file in the target resource segment; or by identifying a specific resource identifier in all resource segments to quickly locate the target resource segment and the encrypted PE file corresponding to the resource identifier.
[0047] In this embodiment, after obtaining the encrypted PE file during the running stage of the target PE file, when accessing data, multiple security authentications are required to decrypt the original PE file from the encrypted PE file and run it to ensure data security.
[0048] The application program security authentication method based on the Windows platform provided by the embodiments of the present invention encrypts the PE file corresponding to the application program on the Windows platform and writes it into the target resource segment of the preset PE file to obtain the target PE file. Finally, the target PE file is run, and when the target PE file passes the target authentication and authorization, the encrypted PE file is obtained and decrypted, which can add an identity authentication mechanism based on cryptographic technology to the application program on the Windows platform without any modification, meet the relevant requirements of cryptographic evaluation, improve the security of the original PE file identity authentication, and reduce the authentication cost.
[0049] In some embodiments, the encrypted PE file is associated with the target resource identifier, and the target authentication and authorization include user identity authentication and user permission authentication; the user identity authentication includes at least one of dynamic password authentication and digital certificate challenge-response authentication; when the target PE file passes the target authentication and authorization, obtaining the encrypted PE file includes: when it is determined that there is an encrypted PE file in the target resource segment according to the target resource identifier, performing user identity authentication and user permission authentication on the encrypted PE file in sequence; when passing the user identity authentication and user permission authentication, extracting the encrypted PE file from the target resource segment.
[0050] In this embodiment, the encrypted PE file has a mapping relationship with the target resource identifier; for example, after the encrypted PE file is stored in the target resource segment, it is recorded as resource A (corresponding to the resource identifier).
[0051] In this embodiment, the PE file can be appended to the preset PE file in the form of a resource through a packaging software. For example, the PE file corresponding to the application program on the Windows platform is defined as resource A, and then resource A is added to the target resource segment of the preset PE file, and the packaging software outputs the final target PE file.
[0052] In this embodiment, during the user identity authentication phase, one of the following authentication methods can be selected: (a) Dynamic password authentication: A one-time dynamic password (such as the TOTP algorithm) is generated when the target PE file runs and is transmitted to the user via SMS or a hardware token; (b) Digital certificate challenge-response authentication: The client signs the server random number using the private key, and the server verifies the legitimacy through the pre-stored public key.
[0053] In this embodiment, after the above user identity authentication, user permission authentication is performed in the following order: Confirm whether the user who has passed the identity authentication has the permission to call the decryption key. This permission can be bound to the key used in the above encryption process. If the current user identity is determined to be legal after the above user identity authentication, then authenticate the access permission of the target PE file with the current user identity. If the authentication passes, the encrypted PE file can be directly extracted from the target resource segment of the target PE.
[0054] In this embodiment, after the encrypted PE file passes both the above user identity authentication and user permission authentication, the encrypted PE file can be decrypted using the key associated with the encryption key to obtain the corresponding decrypted file, that is, the original PE file.
[0055] The application program security authentication method based on the Windows platform provided by the embodiment of the present invention further improves the security of information authentication on the Windows platform through a multi-layer authentication mechanism by extracting the encrypted PE file from the target resource segment when the encrypted PE file is determined according to the target resource identifier and passes the user identity authentication and user permission authentication.
[0056] In some embodiments, obtaining the portable executable (PE) file corresponding to the application program on the Windows platform includes: performing binary reading on the application program to obtain the PE file.
[0057] In this embodiment, the binary file (i.e., the PE file) is read from the application program on the Windows platform through a packaging software; the binary file includes: MZ header (used to identify the file as an executable program); Offset pointing to the PE file header (e_lfanew field); PE file header (used to define the architecture, such as x86 / x64); PE file header (including metadata such as the number of section tables NumberOfSections and the entry point AddressOfEntryPoint); The section table and section data (including the code segment ".text", data segment ".data"), and source segment ".rsrc", etc., are used to describe the attributes and locations of each section.
[0058] In this embodiment, the section data of the PE file is stored in the resource segment of the preset PE file according to specific alignment rules to ensure the compatibility of memory mapping during loading.
[0059] For example, the file alignment FileAlignment is usually 512 bytes, and the memory alignment SectionAlignment is 4KB. By adjusting the alignment parameters, the file size and loading efficiency can be optimized. The application program security authentication method based on the Windows platform provided by the embodiment of the present invention reads a PE file that conforms to the Windows specification from the binary code of the application program, which facilitates subsequent hiding of the PE file through the preset PE file, improving the compilability and security of the application program.
[0060] In some embodiments, after encrypting the PE file, the application program security authentication method based on the Windows platform further includes: writing the encrypted PE file to the end of the preset PE file to obtain a target PE file.
[0061] In this embodiment, the end position of the preset PE file can be determined by parsing the section table (Section Table) of the preset PE file; for example, by calculating the offset at the end of the preset PE file through the PointerToRawData and SizeOfRawData fields of IMAGE_SECTION_HEADER to determine the end position, that is, the writing position of the encrypted PE file.
[0062] It should be noted that if the preset file has a certificate directory (Certificate Table), the digital signature area needs to be bypassed to avoid destroying the signature validity.
[0063] In this embodiment, after determining that data can be written at the end position of the preset PE file, a symmetric encryption algorithm such as AES-CBC can be used to encrypt the original PE file, generate a ciphertext and append it to the end of the preset file to obtain the corresponding target PE file.
[0064] In this embodiment, if it is necessary to hide the encrypted PE file at the end of the preset PE file, the tail data can be disguised as a resource segment (.rsrc), and the encrypted PE file can be dynamically written using the UpdateResource API.
[0065] The application program security authentication method based on the Windows platform provided by the embodiments of the present invention obtains a target PE file by writing an encrypted PE file to the end of a preset PE file, which increases the way of writing the PE file to the preset PE file and improves the acquisition efficiency of the target PE file.
[0066] In some embodiments, after obtaining the target PE file by writing the encrypted PE file to the end of the preset PE file, in the decryption stage, the encrypted PE file at the end of the target PE file can be directly read and decrypted, which can improve the encryption and decryption efficiency of the PE file.
[0067] In some embodiments, after obtaining the decrypted file, the security authentication method of the Windows platform further includes: writing the decrypted file to the corresponding path of the target PE file to obtain a temporary file; the corresponding path of the target PE file is the same as the corresponding path of the PE file; hiding the temporary file and running the hidden temporary file through the CreateProcess mechanism; performing an operation of deleting or retaining the temporary file according to the running state of the temporary file.
[0068] In this embodiment, the preset PE file obtains the storage path of the PE file by calling the Windows API (such as GetModuleFileName or GetModuleFileNameEx), ensuring that the current user has write permission; then generating a unique file name through a GUID or timestamp to avoid conflicts with other processes; finally, writing the decrypted byte stream (corresponding to the decrypted file) to the corresponding path of the preset PE file to generate a temporary file.
[0069] In this embodiment, by calling the Windows API SetFileAttributes, the FILE_ATTRIBUTE_HIDDEN attribute is added to the temporary file to make it invisible by default in the Explorer, realizing the hiding of the temporary file.
[0070] In this embodiment, the CreateProcess can be used to start the temporary file and hide the window through the STARTUPINFO structure; if the temporary file requires administrator privileges, ShellExecuteEx needs to be called before CreateProcess and the runas verb needs to be specified.
[0071] In this embodiment, after detecting that the process of the temporary file is in the exited state (waiting for the end through WaitForSingleObject), the DeleteFile can be called to delete the temporary file to reduce the system memory occupancy.
[0072] In some embodiments, the name of the decrypted file may include a specific identifier (e.g., "Dec") to ensure that the target PE file can accurately read the decrypted file during runtime; after decryption, the file attributes also need to be set to hidden attributes to prevent the file from being accidentally deleted.
[0073] For example, a feasible name format for the decrypted file includes: "Dec - 8 - digit time information - specific character (which can be defined in combination with business requirements (such as user ID, task number, etc.)) + suffix", and the hidden attribute is set through the instruction "attrib +h 'file name'".
[0074] The application program security authentication method based on the Windows platform provided by the embodiments of the present invention obtains a temporary file by writing the decrypted file to the corresponding path of the target PE file; hides the temporary file, and runs the hidden temporary file through the CreateProcess mechanism, realizing the secure execution of sensitive operations without the user's awareness, and at the same time improving the system operation stability.
[0075] In some embodiments, before the target PE file passes the target authentication and authorization, the application program security authentication method based on the Windows platform further includes: deleting the historically generated temporary file if there is a historically generated temporary file in the path corresponding to the PE file.
[0076] In this embodiment, the historically generated temporary file is the temporary file left in the path corresponding to the PE file when the user executed the application program security authentication method based on the Windows platform in the previous several times.
[0077] In this embodiment, before passing the target authentication and authorization for the running target PE file, all historically generated temporary files in the storage path of the PE file need to be deleted to release the storage space occupied and improve the running stability of the PE file.
[0078] Figure 2 It is the second flow chart of the application program security authentication method based on the Windows platform provided by the present invention. In Figure 2 the shown embodiment, writing the application program on the Windows platform (hereinafter corresponding to the target file B) into a preset PE file (hereinafter corresponding to file A) and hiding it are achieved through the following steps: (1) Read the target file B in binary mode (corresponding to inputting the target file B into the encryption process) to obtain its binary content, that is, the PE file.
[0079] (2) Send the read PE file to the password security control module for symmetric encryption to obtain ciphertext information, that is, the encrypted PE file (corresponding to the encryption process, where data encryption and decryption are performed by the password security control module and ciphertext information is output).
[0080] (3) Write the ciphertext information into the resource section of File A in a new (delete and replace if it exists) way to finally obtain the target PE file (corresponding to importing the ciphertext information into the resource section and combining it with the input template PE file A to output File A with a ciphertext resource section).
[0081] Figure 3 It is the third schematic diagram of the process of the application program security authentication method based on the Windows platform provided by the present invention. In Figure 3 In the illustrated embodiment, after obtaining the target PE file, the following steps can be performed for security authentication: (1) After the program of the target PE file is started, query whether there is a ciphertext field and its content by querying the ciphertext resource section. For example, query whether there is a specific resource in the target PE file. If it does not exist, alarm and exit (corresponding to the program startup, querying the specific resource. If the specific resource does not exist, the program terminates).
[0082] (2) If the ciphertext field exists and the content is not empty, perform the business processes of identity authentication and data decryption on the target PE file based on cryptographic techniques (corresponding to when the specific resource exists, successively enter the authentication based on cryptographic techniques and the current permission authentication. If both types of authentication pass, read the resource and write it to a specific path to start; if any of the above authentication fails, the program terminates).
[0083] Specifically, at the front end, send the content of the ciphertext field read based on the intelligent password key, digital certificate verification PIN password, user identification + dynamic password, and querying the ciphertext resource section to the password security control module for processing; the password security control module can perform identity authentication based on digital certificate challenge response or through dynamic passwords, etc.; if the identity authentication fails, alarm and exit.
[0084] In this embodiment, the password security control module can configure security policies to bind the user identity with the key for encrypting the above-converted PE file for permission. If the current identity does not have relevant access permissions, alarm and exit.
[0085] (3) If the current user has access rights, perform decryption operations through the password security control module, obtain the decrypted data, and send it back to File A. Then, write it to the current file path by File A to generate a temporary file T. Name T (corresponding to the resource) according to the preset naming rules, and set the file attribute to hidden mode. If T already exists, first perform a deletion operation and then write (corresponding to naming the resource according to the preset naming rules to prevent the resource from being accidentally deleted).
[0086] In this embodiment, File A starts T through the CreateProcess method and hides its own window. At this time, enter the original target B business process, and at the same time, File A monitors the process of T.
[0087] In this embodiment, when T exits, File A will monitor the relevant information and automatically delete the temporary file T. File A can release resources and exit.
[0088] Next, the application program security authentication device based on the Windows platform provided by the present invention will be described. The application program security authentication device based on the Windows platform described below can be mutually corresponding and referred to with the application program security authentication method based on the Windows platform described above.
[0089] Figure 4 is one of the structural schematic diagrams of the application program security authentication device based on the Windows platform provided by the present invention, as Figure 4 shown, the application program security authentication device based on the Windows platform includes: an acquisition module 410, an encryption and writing module 420, and an authentication and decryption module 430.
[0090] The acquisition module 410 is used to acquire the portable executable (PE) file corresponding to the application program on the Windows platform; The encryption and writing module 420 is used to encrypt the PE file and write the encrypted PE file to the target resource segment of the preset PE file to obtain the target PE file. Among them, the preset PE file includes multiple resource segments, and the target resource segment belongs to the multiple resource segments; The authentication and decryption module 430 is used to run the target PE file, and when the target PE file passes the target authentication and authorization, acquire the encrypted PE file and decrypt it to obtain the decrypted file. Among them, the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
[0091] The application program security authentication device based on the Windows platform provided by the embodiment of the present invention encrypts the PE file corresponding to the application program on the Windows platform and writes it into the target resource segment of the preset PE file to obtain the target PE file. Finally, the target PE file is run, and when the target PE file passes the target authentication and authorization, the encrypted PE file is obtained and decrypted, which can realize the addition of a password technology-based identity authentication mechanism to the application program on the Windows platform without any modification, meet the relevant requirements of cryptographic evaluation, improve the security of the original PE file identity authentication, and reduce the authentication cost.
[0092] Figure 5 It is the second structural schematic diagram of the application program security authentication device based on the Windows platform provided by the present invention. In the Figure 5 embodiment shown, the application program security authentication device based on the Windows platform further includes: a PE generation module 510, a PE file running module 520, and a password security control module 530.
[0093] The PE generation module 510 is used to read the portable executable (PE) file and send it to the password security control module for encryption operation to obtain the encrypted PE file; The PE file running module 520 is used to write the ciphertext into the target resource segment of the preset PE file, generate the target PE file and run it; The password security control module 530 is used to perform user identity authentication and user permission authentication on the target PE file in sequence when the target PE file is running. When the user identity authentication and user permission authentication are passed, the encrypted PE file is obtained and decrypted to obtain the decrypted file; The PE file running module 520 is further used to write the decrypted file into the storage path of the current target PE file, generate a temporary file T, name T according to the preset naming rule, and set the file attribute to the hidden mode; if T already exists, the deletion operation is performed first and then writing is carried out.
[0094] Figure 6 Illustrates the entity structural schematic diagram of an electronic device, such as Figure 6As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640. Among them, the processor 610, the communications interface 620, and the memory 630 complete communication with each other through the communication bus 640. The processor 610 can call the logical instructions in the memory 630 to execute an application security authentication method based on the Windows platform. The method includes: obtaining a portable executable (PE) file corresponding to an application on the Windows platform; encrypting the PE file and writing the encrypted PE file into a target resource segment of a preset PE file to obtain a target PE file; where the preset PE file includes multiple resource segments, and the target resource segment belongs to the multiple resource segments; running the target PE file, and when the target PE file passes the target authentication and authorization, obtaining the encrypted PE file and decrypting it to obtain a decrypted file; where the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
[0095] In addition, when the logical instructions in the above-mentioned memory 630 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0096] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the application program security authentication method based on the Windows platform provided by the above-mentioned various methods. The method includes: obtaining a portable executable (PE) file corresponding to an application program on the Windows platform; encrypting the PE file and writing the encrypted PE file into a target resource segment of a preset PE file to obtain a target PE file; wherein the preset PE file includes multiple resource segments, and the target resource segment belongs to the multiple resource segments; running the target PE file, and when the target PE file passes the target authentication and authorization, obtaining the encrypted PE file and decrypting it to obtain a decrypted file; wherein the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
[0097] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the application program security authentication method based on the Windows platform provided by the above-mentioned various methods. The method includes: obtaining a portable executable (PE) file corresponding to an application program on the Windows platform; encrypting the PE file and writing the encrypted PE file into a target resource segment of a preset PE file to obtain a target PE file; wherein the preset PE file includes multiple resource segments, and the target resource segment belongs to the multiple resource segments; running the target PE file, and when the target PE file passes the target authentication and authorization, obtaining the encrypted PE file and decrypting it to obtain a decrypted file; wherein the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
[0098] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative efforts.
[0099] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. An application security authentication method based on the Windows platform, characterized in that, Including: Obtain the portable executable PE file corresponding to the application on the Windows platform; Encrypt the PE file and write the encrypted PE file into the target resource section of the preset PE file to obtain the target PE file; wherein, the preset PE file includes multiple resource sections, and the target resource section belongs to the multiple resource sections; Run the target PE file, and when the target PE file passes the target authentication and authorization, obtain the encrypted PE file and decrypt it to obtain the decrypted file; wherein, the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
2. The application program security authentication method based on the Windows platform according to claim 1, characterized in that, The encrypted PE file is associated with a target resource identifier, and the target authentication and authorization includes user identity authentication and user permission authentication; the user identity authentication includes at least one of dynamic password authentication and digital certificate challenge-response authentication; The obtaining the encrypted PE file when the target PE file passes the target authentication and authorization includes: When it is determined according to the target resource identifier that the encrypted PE file exists in the target resource section, perform user identity authentication and the user permission authentication on the encrypted PE file in sequence; When passing the user identity authentication and the user permission authentication, extract the encrypted PE file from the target resource section.
3. The application program security authentication method based on the Windows platform according to claim 1, wherein The obtaining the portable executable PE file corresponding to the application on the Windows platform includes: Read the application in binary to obtain the PE file.
4. The application program security authentication method based on the Windows platform according to claim 1, characterized in that After encrypting the PE file, the method further includes: Write the encrypted PE file to the end of the preset PE file to obtain the target PE file.
5. The application program security authentication method based on the Windows platform according to claim 1, characterized in that, The encrypting the PE file includes: Perform symmetric encryption on the PE file.
6. The application program security authentication method based on the Windows platform according to claim 1, characterized in that After obtaining the decrypted file, the method further includes: Write the decrypted file to the corresponding path of the target PE file to obtain a temporary file; the corresponding path of the target PE file is the same as the corresponding path of the PE file; Hide the temporary file and run the hidden temporary file through the CreateProcess mechanism; According to the running status of the temporary file, perform an operation of deleting or retaining the temporary file.
7. The application program security authentication method based on the Windows platform according to claim 1, wherein Before the target PE file passes the target authentication and authorization, the method further includes: Delete the historically generated temporary file if there is a historically generated temporary file in the path corresponding to the PE file.
8. An application program security authentication device based on the Windows platform, characterized in that, Including: An obtaining module, configured to obtain the portable executable PE file corresponding to the application on the Windows platform; An encrypting and writing module, configured to encrypt the PE file and write the encrypted PE file into the target resource section of the preset PE file to obtain the target PE file; wherein, the preset PE file includes multiple resource sections, and the target resource section belongs to the multiple resource sections; The authentication and decryption module is used to run the target PE file, and when the target PE file passes the target authentication and authorization, obtain the encrypted PE file and decrypt it to obtain the decrypted file; wherein, the target authentication and authorization includes user identity authentication and user permission authentication, or user identity authentication.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the application program security authentication method based on the Windows platform according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the application program security authentication method based on the Windows platform according to any one of claims 1 to 7.
Citation Information
Patent Citations
File encryption method and device based on Andriod equipment authentication
CN103955652A
File access authority authentication method and electronic equipment
CN110059499A
Memory loading method based on PE file transformation
CN112632536A
PE file data protection method and device, equipment and medium
CN115828190A
Display terminal, server and information security issuing system
US20240372725A1