Data encryption method and device, medium and computer program product
Through virtual machine protection technology, randomized virtual machine codes are generated and combined with out-of-order processing, the problem of existing data encryption being easily cracked is solved, and a higher data protection intensity is achieved.
Patent Information
- Application Number
- CN202510749076.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Existing data encryption technology is easily cracked by attackers and has insufficient protection strength.
By using virtual machine protection technology, the data units to be encrypted and the virtual machine code are generated to be calculated to obtain the first data. The secure virtual machine is used to restore the original data during decryption, and combine random order and obfuscation to improve the cracking difficulty.
It improves the protection strength of data encryption, effectively resists reverse cracking, and achieves efficient data protection.
Smart Images

Figure CN120277697A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data encryption, and in particular, to a data encryption method, device, medium, and computer program product. Background Art
[0002] With the rapid development of information technology and the increasing demand for data security, data encryption technology has become a key means to protect the security of information assets and is widely used in many scenarios such as network communication, data storage, identity authentication, cloud computing, and the Internet of Things. However, current data encryption technologies usually use specific encryption algorithms for encryption, and all have relatively mature cracking methods, making them easy to be detected and reverse-engineered by attackers.
[0003] How to improve the data protection intensity of data encryption is a technical problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] The present invention provides a data encryption method, device, medium, and computer program product to at least solve the problem of low protection intensity of data encryption in related technologies.
[0005] The present invention provides a data encryption method, including: Obtain a string of data to be encrypted; Obtain a random number corresponding to the data volume according to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device; Generate a virtual machine code corresponding to the type of the secure virtual machine based on the random number; Calculate a first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code; Obtain an encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted.
[0006] The present invention also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of any of the above data encryption methods when executing the computer program.
[0007] The present invention also provides a computer-readable storage medium, in which a computer program is stored, and the computer program, when executed by a processor, implements the steps of any of the above data encryption methods.
[0008] The present invention also provides a computer program product, including a computer program, and the computer program, when executed by a processor, implements the steps of any of the above data encryption methods.
[0009] According to the present invention, by obtaining a random number corresponding to a data volume of a data unit to be encrypted in a string of data to be encrypted and the type of secure virtual machine adopted by a decryption device, generating a virtual machine code according to the type of secure virtual machine and the random number, and calculating a first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code, a connection between the data unit to be encrypted and the first data is established through the virtual machine code, that is, the data unit to be encrypted can be restored through the virtual machine code and the first data. Thus, according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted, an encryption result corresponding to the data to be encrypted is obtained, realizing an encryption scheme for generating a virtual machine code for the data to be encrypted. The content of the virtual machine code is complex and difficult to understand. At the same time, the virtual machine implementation supports protection methods such as code obfuscation. Without a virtual machine, it has no practical meaning by itself and can only restore the original data after being interpreted and executed by the virtual machine, which can achieve a relatively high data protection intensity and effectively resist reverse cracking. When decryption is required, the original data can be restored by the secure virtual machine performing operations according to the first data and the virtual machine code, which is simple to use and has strong scalability. Therefore, the present invention can solve the problem that encrypted data generated by a specific encryption algorithm in the related art is easily cracked and improve the protection intensity of data encryption. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0011] Figure 1 It is a flowchart of a data encryption method provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of a data encryption and decryption system provided by an embodiment of the present invention; Figure 3 It is a flowchart of a generation process of a virtual machine code provided by an embodiment of the present invention; Figure 4 It is a flowchart of an execution process of a virtual machine code provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0012] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the protection scope of the present invention.
[0013] It should be noted that in the description of the present invention, the terms "comprise", "include" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present invention are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0014] In order to enable those skilled in the art of the present technology to better understand the solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0015] Here, some key terms used in the embodiments of the present invention will be explained first.
[0016] A virtual machine (VM) is a software-simulated computer system that can simulate one or more virtual computer environments on a physical computer and can run its own operating system and applications, just like on a real physical computer.
[0017] The virtual machine in the embodiments of the present invention refers to a process virtual machine, that is, it simulates a running environment that includes an instruction interpretation execution engine that can execute custom instructions and register space required for data storage, and can be used to execute specific programs or codes. Different from virtual machine software such as vmware that runs an operating system in the general concept, the virtual machine in the embodiments of the present invention only simulates the working mechanism of the central processing unit (CPU) and can execute specific program codes, without fully simulating the hardware environment of the computer and without the ability to run an operating system, and is a relatively low-level and basic virtual machine.
[0018] Virtual Machine-based Code Protection (VMP) is an advanced code protection method that increases the difficulty of reverse engineering by converting the original instructions of a program into a custom virtual machine instruction set and executing these instructions in a virtual machine. The core of the virtual machine protection technology is to convert the original instructions of the program (such as x86 instructions) into a custom virtual machine instruction set (VM Bytecode) and execute these instructions in a custom virtual machine. Reverse engineers need to first understand the instruction set and operating mechanism of the virtual machine in order to restore the original code, which greatly increases the difficulty of reverse engineering. In related technologies, the virtual machine protection technology is often used for software code protection and has achieved good results.
[0019] Common data encryption schemes in related technologies include symmetric encryption, exclusive-or encryption, custom encryption algorithms, code obfuscation, and dynamic encryption, etc. Among them, symmetric encryption technology is used the most, but there are problems that the algorithm features are obvious and easy to discover and analyze, and the key is easy to be reverse-tracked; exclusive-or encryption technology is simple and easy to hide, but has low strength; custom encryption algorithms depend on specific design implementations, with uneven strength and low reliability; code obfuscation algorithms are fixed and easy to analyze and crack; dynamic encryption has relatively high strength and a more complex process, but since it also generates dynamically generated data through a specific method, it can still be cracked by reverse-tracking. Generally speaking, common data encryption schemes in related technologies encrypt data using specific encryption algorithms, and attackers can easily crack them by analyzing the patterns in the ciphertext.
[0020] To improve the data protection strength of data encryption technology, the embodiments of the present invention apply virtual machine protection technology to data encryption. Since the virtual machine code content is redundant and difficult to understand, and the virtual machine implementation supports protection methods such as code obfuscation, it has no practical meaning without a virtual machine. Only after being interpreted and executed by the virtual machine can the original data be restored, which can achieve a relatively high data protection strength and effectively resist reverse cracking.
[0021] However, data itself is not equivalent to software code. That is, software code is instructions, and virtual machine code is also instructions. Therefore, the generation scheme of generating virtual machine code from software code cannot be directly applied to data protection. Thus, in the embodiments of the present invention, the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device are used to obtain a random number corresponding to the data volume. The virtual machine code is generated according to the random number, and the first data corresponding to the data unit to be encrypted is calculated based on the data unit to be encrypted and the virtual machine code. Thus, a connection between the data unit to be encrypted and the first data is established through the virtual machine code, that is, the data unit to be encrypted can be restored through the virtual machine code and the first data.
[0022] Thus, the embodiments of the present invention realize generating virtual machine code from the data to be encrypted, and obtain the advantage that the generated virtual machine code in the virtual machine protection technology is not easy to be cracked. Even if an attacker obtains some or all of the virtual machine code, it is difficult to analyze the patterns therein. Further, since the embodiments of the present invention generate the virtual machine code through random numbers and do not establish a direct correspondence between the data and the virtual machine code, this further enhances the randomness compared with generating virtual machine code from software code in the virtual machine protection technology, thereby achieving a higher data protection strength.
[0023] At the same time, the virtual machine itself does not depend on specific components or functions for implementation, has good cross-platform capabilities, and can encrypt and decrypt data through simple call methods, making it easy to integrate and use. The virtual machine only implements the instruction execution function and the maintenance function of the virtual machine environment. The actual data protection algorithms, etc., are all implemented using virtual machine codes, which can be flexibly added, reduced, modified, and have good scalability. The virtual machine itself also allows modification, and custom protection instructions can be flexibly added or reduced to achieve better data protection effects.
[0024] An embodiment of the present invention provides a data encryption method. In combination with the execution process of the data encryption method, the method will be described in detail below.
[0025] Figure 1 It is a flowchart of a data encryption method provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of the architecture of a data encryption and decryption system provided by an embodiment of the present invention.
[0026] As Figure 1 shown, the data encryption method provided by an embodiment of the present invention may include: S101: Obtain the string of data to be encrypted.
[0027] S102: According to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device, obtain a random number corresponding to the data volume.
[0028] S103: Based on the random number, generate a virtual machine code corresponding to the type of secure virtual machine.
[0029] S104: Calculate the first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code.
[0030] S105: According to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted, obtain the encryption result corresponding to the data to be encrypted.
[0031] To distinguish it from the virtual machine understood in the usual sense, in the embodiment of the present invention, the virtual machine used to execute the virtual machine code is called a "secure virtual machine".
[0032] As Figure 2 shown, the data encryption and decryption architecture provided by an embodiment of the present invention mainly consists of a virtual machine code generator and a secure virtual machine. The virtual machine code generator is used to read the data to be encrypted and generate a virtual machine code using a randomization method. The virtual machine code generator may include a data reading module, a virtual machine code generation module, a virtual machine code scrambling module, and a virtual machine code output module, which are respectively used to read the string of data to be encrypted, generate a virtual machine code, scramble the virtual machine code, and output the virtual machine code.
[0033] The secure virtual machine is used to read virtual machine codes and execute corresponding virtual machine instructions. Different virtual machine codes correspond to different operations, and different operations will process the data in the virtual register differently, such as addition, subtraction, multiplication, and division. When all the virtual machine codes have been executed, the data in the virtual register has undergone a series of processing and operations by the virtual machine codes, and then a string of the original data is generated, achieving the purpose of dynamically restoring the original data string. The secure virtual machine may include a virtual machine code reading module, a virtual machine code execution module, and an output module, which are respectively used to read the virtual machine code, execute the virtual machine code, and output the data plaintext.
[0034] In the embodiments of the present invention, the type of data to be encrypted may be privacy data, keys, network communication data, configuration files and sensitive parameters, log files, etc., or other data that needs to be encrypted.
[0035] The data encryption method provided by the embodiments of the present invention can be applied to data transmission. The sending device can generate a virtual machine code from the data to be encrypted, and send the virtual machine code and the first data to the receiving device. The receiving device calls the secure virtual machine to calculate according to the virtual machine code and the first data to restore the original data. At this time, the virtual machine code generator can be deployed on the sending device, and the secure virtual machine can be deployed on the receiving device.
[0036] The data encryption method provided by the embodiments of the present invention can also be applied to data storage. When writing data, generate a virtual machine code from the data to be encrypted, and write the virtual machine code and the first data into the storage medium. When reading data, call the secure virtual machine to calculate according to the read virtual machine code and the first data to restore the original data. At this time, the virtual machine code generator and the secure virtual machine can be deployed on the storage controller.
[0037] For S101, in order to calculate with the virtual machine code, the data to be encrypted in the form of a string is required. Then, the data to be encrypted in the form of a string can be obtained, or the data to be encrypted can be converted into the form of a string.
[0038] For S102, the data unit to be encrypted is a substring obtained from the string of the data to be encrypted, and this substring can be obtained by splitting the string of the data to be encrypted into multiple substrings. Specifically, according to the preset string length, starting from the starting position of the string of the data to be encrypted, substrings with the preset string length are intercepted in sequence until the entire string of the data to be encrypted is split. If the length of the last substring is less than the preset string length, characters can be added to the last substring to make it reach the preset string length. At this time, the string lengths of all data units to be encrypted are the same.
[0039] In some other alternative embodiments of the embodiments of the present invention, the string lengths of the data units to be encrypted may not be restricted to be the same. In this case, the sub-strings with a preset string length can be sequentially intercepted starting from the starting position of the string of the data to be encrypted until the entire string of the data to be encrypted is split. If the length of the last sub-string is less than the preset string length, no supplementary characters are added. Alternatively, the string of the data to be encrypted can be split using specific characters in the string as nodes, and in this case, multiple sub-strings with lengths that may be the same or different are obtained as the data units to be encrypted.
[0040] In the embodiments of the present invention, the length of the data unit to be encrypted can be 1 byte.
[0041] Next, generate the corresponding virtual machine code for the data unit to be encrypted.
[0042] The generation of virtual machine code requires an opcode and operands. The opcode is a key part of the virtual machine instruction, which is used to indicate what operation the virtual machine should perform. The opcode is usually a code with a fixed length, and each opcode corresponds to a specific operation or instruction.
[0043] The functions of the opcode include: determining the instruction type, such as indicating that the virtual machine performs arithmetic operations (such as addition, subtraction), logical operations (such as AND, OR), data movement (such as loading, storing), etc.; controlling the instruction flow, for example, some opcodes may be used to control the jump of the program (such as conditional jump, unconditional jump), thereby changing the execution order of the program; simplifying the instruction parsing. When the virtual machine executes an instruction, it first parses the opcode, and determines how to process the subsequent operands according to the value of the opcode. The existence of the opcode enables the virtual machine to quickly identify the type of the instruction, thereby simplifying the instruction parsing process and improving the execution efficiency.
[0044] The operand is the data part used in conjunction with the opcode in the virtual machine instruction. The operand provides the specific data or the address of the data required for the opcode to perform the operation. The functions of the operand include: providing the operation data. The operand directly provides the data required for the opcode to perform the operation. For example, in an arithmetic operation instruction, the operand can be the value participating in the operation. In a data movement instruction, the operand can be the source address and the target address of the data; specifying the operation object. The operand can specify the object on which the opcode acts. For example, in an instruction to access memory, the operand can specify the address of the memory, telling the virtual machine where to load the data or where to store the data; affecting the instruction behavior. The value of the operand will affect the specific execution behavior of the instruction. Different operands will cause the same opcode to produce different execution results. For example, for the same addition opcode, when the operands are 1 and 2, the result is 3, and when the operands are 2 and 3, the result is 5.
[0045] That is to say, in virtual machine instructions, the opcode and the operand are closely coordinated. The opcode determines what operation the virtual machine should perform, while the operand provides the specific data or the address of the data required for the operation. Together, they determine the complete meaning and execution behavior of the virtual machine instruction. For example, for the virtual machine instruction "ADD R1, R2, R3", the opcode "ADD" represents an addition operation, and the operands are R1 (destination register), R2 (first operand register), and R3 (second operand register). In this instruction: the opcode ADD tells the virtual machine to perform an addition operation, and the operands R1, R2, and R3 specify the registers participating in the addition operation. Specifically, the virtual machine will add the values in R2 and R3 and store the result in R1.
[0046] Since the data unit to be encrypted may not have an instruction nature, and the virtual machine code is a computing instruction, it is impossible to directly convert the data unit to be encrypted into the virtual machine code. Therefore, in the embodiments of the present invention, the virtual machine code is generated according to a random number, and the random number is used as the opcode and / or operand required for generating the virtual machine code.
[0047] Then, for each data unit to be encrypted, it is necessary to obtain a random number corresponding to the data volume size (i.e., the string length) of the data unit to be encrypted and the type of the secure virtual machine adopted by the decryption device. For example, if generating a virtual machine code requires 1 opcode and 3 operands, then 4 random numbers need to be obtained, and the data volume size of each random number is the same as that of the data unit to be encrypted.
[0048] In the embodiments of the present invention, to further increase the cracking difficulty of the virtual machine code, the virtual machine code can be obtained from a random number stream. Then, obtaining the random number corresponding to the data volume in S102 may include: reading the random number corresponding to the data volume from the pre-generated random number stream. Pre-generating the random number stream may include: obtaining a random number seed; passing the random number seed into a stream cipher algorithm to generate a random number stream. This random number seed is essentially a random string of a specific length, and the length depends on the key length required by the subsequent stream cipher algorithm. Invoke the stream cipher algorithm and pass the random number seed as the algorithm key to generate a random number stream. The stream cipher algorithm is a symmetric encryption algorithm, and its core is to generate a key stream and perform byte-by-by-byte XOR with the plaintext to achieve encryption / decryption.
[0049] In the embodiments of the present invention, a stream cipher algorithm is used to generate a random number stream, and virtual machine codes are generated according to the random numbers read from the random number stream. Since the random number stream is data with an infinite length, using the random number stream as the basis for generating virtual machine codes can achieve high randomness and unpredictability in the process of generating virtual machine codes, and can avoid resource problems caused by reading extremely long random numbers from the operating system, thereby further increasing the difficulty of cracking the encryption result.
[0050] For S103, using the obtained random numbers as the operation codes and operands required for generating virtual machine codes to generate virtual machine codes.
[0051] For S104, the virtual machine codes generated in S103 only represent a calculation instruction, and there is no direct corresponding relationship with the data unit to be encrypted. Therefore, the data to be encrypted is calculated with the virtual machine codes to obtain the first data.
[0052] In some optional embodiments of the embodiments of the present invention, calculating the first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine codes in S104 may include: performing the inverse operation corresponding to the virtual machine codes on the data unit to be encrypted to obtain the first data. That is to say, denoting the calculation instruction corresponding to the virtual machine codes as the function , and its inverse operation as , then substituting the data unit to be encrypted into the function for calculation to obtain the first data (denoted as ), so that when decrypting on the decryption device, the first data can be substituted into the function corresponding to the virtual machine codes to restore the original data.
[0053] In some other optional embodiments of the embodiments of the present invention, the calculation instruction corresponding to the virtual machine codes may also be directly performed on the data unit to be encrypted to obtain the first data, and when decrypting on the decryption device, the inverse operation of the virtual machine codes is performed on the first data to restore the original data.
[0054] For S105, according to the virtual machine codes corresponding to the data units to be encrypted and the first data corresponding to the data units to be encrypted, the encryption result corresponding to the data to be encrypted is obtained. Specifically, the virtual machine codes corresponding to each data unit to be encrypted can be listed in sequence as a set of virtual machine codes, and the virtual machine codes and the first data are used as the encryption result. Or, the order of the virtual machine codes corresponding to each data unit to be encrypted can also be disrupted to further enhance randomness.
[0055] At this time, if an attacker obtains some or even all of the virtual machine codes and the first data, what they see is also a string of irregular characters, and they cannot analyze the rules from it to achieve cracking as in the encryption algorithm cracking solutions in the related art.
[0056] The data encryption method provided by the embodiments of the present invention, since it obtains a random number corresponding to the data volume of a data unit to be encrypted in the string of the data to be encrypted and the type of the secure virtual machine adopted by the decryption device, generates a virtual machine code based on the random number, and calculates the first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code. Thus, a connection between the data unit to be encrypted and the first data is established through the virtual machine code, that is, the data unit to be encrypted can be restored through the virtual machine code and the first data. Therefore, according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted, the encryption result corresponding to the data to be encrypted is obtained, realizing an encryption scheme for generating a virtual machine code for the data to be encrypted. The content of the virtual machine code is complex and difficult to understand. At the same time, the virtual machine implementation supports protection methods such as code obfuscation. Without a virtual machine, it has no practical meaning itself and can only restore the original data after being interpreted and executed by the virtual machine, which can achieve a relatively high data protection intensity and effectively resist reverse cracking. When decryption is required, the original data can be restored by the secure virtual machine performing operations according to the first data and the virtual machine code, which is simple to use and has strong scalability. Therefore, the present invention can solve the problem that the encrypted data generated by a specific encryption algorithm in the related art is easily cracked, and improves the protection intensity of data encryption.
[0057] In the embodiments of the present invention, in S102, obtaining a random number corresponding to the data volume of a data unit to be encrypted in the string of the data to be encrypted and the type of the secure virtual machine adopted by the decryption device may include: determining the number of operation codes of a virtual machine code and the number of operands of a virtual machine code according to the type of the secure virtual machine; taking the sum of the number of operation codes of a virtual machine code and the number of operands of a virtual machine code minus one as the number of random numbers; obtaining random numbers corresponding to the number, and the data volume of one random number is equal to the data volume of the data unit to be encrypted.
[0058] In S103, generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number may include: determining a parameter of the virtual machine code according to the position of the data unit to be encrypted in the string of the data to be encrypted, and determining the remaining parameters in the virtual machine code according to the random number; the parameters of the virtual machine code include the operation code of the virtual machine code and the operand of the virtual machine code; generating a virtual machine code according to the operation code of the virtual machine code and the operand of the virtual machine code.
[0059] That is to say, on the basis of randomly arranging the virtual machine codes corresponding to each data unit to be encrypted, the position of the data unit to be encrypted in the string of the data to be encrypted can be used as an operation code or an operand. At this time, the number of random numbers to be obtained is the sum of the number of operation codes and the number of operands required for the virtual machine code minus one.
[0060] In the embodiments of the present invention, the secure virtual machine may adopt a three-operand register-based virtual machine. At this time, in S102, obtaining a random number corresponding to the data volume according to the data volume of a data unit to be encrypted in the string of the data to be encrypted and the type of the secure virtual machine adopted by the decryption device may include: reading three random numbers of the same data volume according to the data volume of the data unit to be encrypted. In S103, generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number may include: determining the operation code of the virtual machine code according to one of the random numbers, determining two data source operands of the virtual machine code according to the other two random numbers, determining the target address operand of the virtual machine code according to the position of the data unit to be encrypted in the data to be encrypted, and generating the virtual machine code of the three-operand register-based virtual machine according to the operation code, the data source operands, and the target address operand.
[0061] Three-operand means that a virtual machine instruction contains one operation code and three operation numbers. The three operands respectively correspond to two data sources and one destination address of the data. For example, in "1 + 2 = 3", "1" and "2" are the two source data (which may be the data itself or read from a register. In short, there are two data sources); "+" is the operation code, representing addition; "3" corresponds to the operation destination address, that is, the position where the result of the instruction execution needs to be stored.
[0062] The register-based virtual machine refers to a virtual machine based on a register architecture. A register is a space that can store data of a fixed size, and the virtual machine contains multiple registers. Virtual machine instructions can directly operate on the data in the registers, rather than operating on the data through a stack like a stack-based virtual machine (the stack requires data to enter first and exit last, so when processing multiple data simultaneously, sequential management and multiple operations are required, while registers can achieve the same purpose by specifying different registers for separate processing). Therefore, the register-based virtual machine is usually superior to the stack-based virtual machine in performance because it reduces the number of memory accesses.
[0063] In some other embodiment modes of the embodiments of the present invention, when adopting other types of secure virtual machines (such as a stack-based virtual machine) or other types of register-based virtual machines (such as a single-operand register-based virtual machine), after obtaining a random number according to the number of operation codes and the number of operands required to generate the virtual machine code, and generating the corresponding virtual machine code, details are not described one by one here.
[0064] In the embodiments of the present invention, when generating a virtual machine code for a data unit to be encrypted, a data unit to be encrypted can be randomly taken out, without necessarily processing it in sequence, and the position of the data unit to be encrypted in the string of the data to be encrypted is reflected by using the operand or operation code of the virtual machine code.
[0065] Alternatively, in the embodiments of the present invention, the operation codes and operands required to generate virtual machine codes can be completely determined by random numbers. That is, in S102, according to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of the secure virtual machine adopted by the decryption device, obtaining random numbers corresponding to the data volume may include: determining the number of operation codes of a virtual machine code and the number of operands of a virtual machine code according to the type of the secure virtual machine; obtaining random numbers corresponding to the quantities according to the number of operation codes and the number of operands, and the data volume size of one random number is equal to the data volume size of the data unit to be encrypted.
[0066] In S103, generating a virtual machine code corresponding to the type of the secure virtual machine based on the random numbers may include: respectively determining the operation code of the virtual machine code and the operands of the virtual machine code according to the random numbers, so as to generate a virtual machine code according to the operation code of the virtual machine code and the operands of the virtual machine code.
[0067] Taking the three-operand register type virtual machine adopted by the secure virtual machine as an example, at this time, in S102, according to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of the secure virtual machine adopted by the decryption device, obtaining random numbers corresponding to the data volume may include: reading four random numbers of the same data volume size according to the data volume size of the data unit to be encrypted. In S103, generating a virtual machine code corresponding to the type of the secure virtual machine based on the random numbers may include: determining the operation code of the virtual machine code according to one of the random numbers, determining two source operands of the virtual machine code according to two of the random numbers, determining the target address operand of the virtual machine code according to the remaining one random number, and generating a virtual machine code of the three-operand register type virtual machine according to the operation code, the source operands and the target address operand.
[0068] At this time, in the encryption result of the data to be encrypted, the virtual machine codes corresponding to each data unit to be encrypted can be arranged in the order agreed upon by the encryption device and the decryption device, for example, arranged in the original order of the data units to be encrypted in the data to be encrypted, or arranged in a pre-agreed disordered manner.
[0069] As introduced in the above embodiments, in S104, calculating the first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code may include: performing the inverse operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data.
[0070] On this basis, to further increase data security, performing the inverse operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data may include: performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data.
[0071] In an embodiment of the present invention, the number of rounds of performing the inverse operation of the virtual machine code on the data unit to be encrypted can be determined according to the complexity control parameter generated from the pre-input virtual machine code. Then, performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data may include: performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted according to the complexity control parameter generated from the virtual machine code, and using the result obtained in the last round as the first data.
[0072] In some optional implementation manners of the embodiment of the present invention, for each data unit to be encrypted, the same virtual machine code can be used in each round of inverse operation, and the first data obtained in the last round is used as the reserved first data. At this time, the decryption device determines the number of rounds of inverse operation according to the complexity control parameter generated from the virtual machine code, and performs the operation of the virtual machine code for the corresponding number of rounds on the first data, and the original data can be restored.
[0073] In some other optional implementation manners of the embodiment of the present invention, to further improve data security, multiple virtual machine codes can be generated for each data unit to be encrypted. At this time, performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data may include: in the current round of inverse operation, using the data unit to be encrypted or the output result of the previous round of inverse operation as the input data, and performing the inverse operation of the virtual machine code corresponding to the current round of inverse operation on the input data of the current round of inverse operation to obtain the output result of the current round of inverse operation; if the preset generation times are reached, using the output result of the current round of inverse operation as the first data; if the preset generation times are not reached, using the output result of the current round of inverse operation to obtain a random number with the corresponding data volume according to the data volume size of the data unit to be encrypted and the type of the secure virtual machine used by the decryption device. Among them, the preset generation times are determined according to the complexity control parameter generated from the virtual machine code.
[0074] At this time, multiple virtual machine codes are generated for each data unit to be encrypted. To further improve data security, the multiple virtual machine codes corresponding to each data unit to be encrypted can be scrambled. Then, obtaining the encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted may include: scrambling the virtual machine codes corresponding to each data unit to be encrypted, so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encryption result of the data to be encrypted is the same as the generation order of the virtual machine code, and obtaining the scrambled result of the virtual machine code; using the scrambled result of the virtual machine code and the first data as the encryption result corresponding to the data to be encrypted.
[0075] As long as the arrangement order of multiple virtual machine codes corresponding to the same data unit to be encrypted in the virtual machine code scrambling result is consistent with the generation order of the virtual machine codes, when the decryption device calls the secure virtual machine to sequentially execute the virtual machine codes in the virtual machine code scrambling result, the data units to be encrypted can still be restored respectively.
[0076] For example, for the data unit to be encrypted and , the inverse calculations corresponding to the virtual machine codes are respectively: ; ; ; Among them, and are intermediate calculation results (i.e., the output results of the previous inverse operation), is corresponding first data.
[0077] The inverse calculations corresponding to the virtual machine codes are respectively: ; ; ; Among them, and are intermediate calculation results (i.e., the output results of the previous inverse operation), is corresponding first data.
[0078] After scrambling the virtual machine codes corresponding to and , and ensuring that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted is the same as the generation order of the virtual machine codes, when the decryption device calls the secure virtual machine to execute the virtual machine code scrambling result, it can still restore and : ; ; ; ; ; .
[0079] Note that since it is an inverse operation, the order in which the decryption device executes the out-of-order results of the virtual machine codes should be opposite to the generation order of the virtual machine codes.
[0080] In an embodiment of the present invention, the virtual machine codes corresponding to each data unit to be encrypted are shuffled so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encryption result of the data unit to be encrypted is the same as the generation order of the virtual machine codes, and an out-of-order result of the virtual machine codes is obtained, which may include: randomly taking out the outermost virtual machine code from the virtual machine codes corresponding to a data unit to be encrypted and listing it in the encryption result queue of the data unit to be encrypted until all the virtual machine codes are added to the encryption result queue, so as to obtain the out-of-order result of the virtual machine codes.
[0081] As introduced in the above embodiment, calculating the first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code in S104 may also include: performing an operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data.
[0082] On this basis, to further enhance data security, performing an operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data may include: performing operations of multiple rounds of virtual machine codes on the data unit to be encrypted to obtain the first data.
[0083] In an embodiment of the present invention, the number of rounds of operations of the virtual machine code performed on the data unit to be encrypted may be determined according to a pre-input complexity control parameter for generating the virtual machine code. Then, performing operations of multiple rounds of virtual machine codes on the data unit to be encrypted to obtain the first data may include: performing operations of multiple rounds of virtual machine codes on the data unit to be encrypted according to the complexity control parameter for generating the virtual machine code, and taking the result obtained in the last round as the first data.
[0084] In some optional implementation manners of the embodiment of the present invention, for each data unit to be encrypted, the same virtual machine code may be used in each round of operation, and the first data obtained in the last round is used as the retained first data. At this time, the decryption device determines the number of rounds of the inverse operation according to the complexity control parameter for generating the virtual machine code, and performs the inverse operation of the virtual machine code for the corresponding number of rounds on the first data, and the original data can be restored.
[0085] In some other alternative embodiments of the embodiments of the present invention, to further improve data security, multiple virtual machine codes can be generated for each data unit to be encrypted. At this time, performing multiple rounds of operations on the virtual machine codes for the data unit to be encrypted to obtain the first data may include: in the current round of operation, using the data unit to be encrypted or the output result of the previous round of operation as the input data, and performing the operation of the virtual machine code corresponding to the current round of operation on the input data of the current round of operation to obtain the output result of the current round of operation; if the preset generation times are reached, using the output result of the current round of operation as the first data; if the preset generation times are not reached, using the output result of the current round of operation to obtain a random number corresponding to the data volume according to the data volume size of the data unit to be encrypted and the type of the secure virtual machine used by the decryption device. Among them, the preset generation times are determined according to the virtual machine code generation complexity control parameter.
[0086] At this time, multiple virtual machine codes are generated for each data unit to be encrypted. To further improve data security, the multiple virtual machine codes corresponding to each data unit to be encrypted can be shuffled. Then, obtaining the encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted may include: shuffling the virtual machine codes corresponding to each data unit to be encrypted so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encryption result of the data to be encrypted is the same as the generation order of the virtual machine codes, to obtain the virtual machine code shuffling result; using the virtual machine code shuffling result and the first data as the encryption result corresponding to the data to be encrypted.
[0087] As described in the above embodiments, since the arrangement order of the multiple virtual machine codes corresponding to the same data unit to be encrypted in the virtual machine code shuffling result is kept consistent with the generation order of the virtual machine codes, when the decryption device calls the secure virtual machine to sequentially execute the inverse operation of the virtual machine codes in the virtual machine code shuffling result, the data units to be encrypted can still be restored respectively to obtain the original data.
[0088] To further improve data security, in the embodiments of the present invention, generating the virtual machine code corresponding to the type of the secure virtual machine based on the random number in S103 may include: generating an initial virtual machine code according to the random number; obtaining the variable parameter agreed upon by the device where it is located and the decryption device; using the variable parameter to generate the virtual machine code from the initial virtual machine code. The variable parameter can adopt the value of the agreed register, system environment variable parameter, user ID, etc. For example, it can adopt one or more of the timestamp of the encryption device, the product serial number of the encryption device, and the location information of the encryption device. When the decryption device executes the virtual machine code, it first restores the virtual machine code to the initial virtual machine code according to the agreed variable parameter, and then executes to restore the original data.
[0089] In an embodiment of the present invention, a many-to-many relationship between virtual machine codes and instructions can also be established, that is, a virtual machine code is not strongly correlated with a specific instruction, but there is a many-to-many correspondence. Here, lowercase letters are used to represent virtual machine codes and uppercase letters are used to represent instructions for example. That is, virtual machine code a is not completely correlated with instruction A, but may represent instructions A, B, C, and D; correspondingly, instruction A is not necessarily only triggered by virtual machine code a, but may be triggered by virtual machine codes a, b, c, and d. Then, in the embodiment of the present invention, in S104, calculating the first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code may include: determining the calculation type corresponding to the virtual machine code according to the variable parameter, and then calculating the first data according to the data unit to be encrypted and the calculation type corresponding to the virtual machine code. Among them, the variable parameter may also adopt the value of a convention register, a system environment variable parameter, a user ID, etc. For example, it may adopt one or more of the timestamp of the encryption device, the product serial number of the encryption device, and the location information of the encryption device.
[0090] Thus, the relationship between the virtual machine code and the real instruction is many-to-many. During the process of the decryption device calling the secure virtual machine to execute the virtual machine code, the calculation type corresponding to the virtual machine code is determined according to the agreed variable parameter, and then the original data is restored accordingly.
[0091] In the embodiment of the present invention, through the many-to-many relationship between the virtual machine code and the instruction, the corresponding relationship between the virtual machine code and the instruction is complicated, further improving the security of the encrypted data.
[0092] In the embodiment of the present invention, in S103, generating the virtual machine code corresponding to the type of the secure virtual machine based on the random number may further include: generating an initial virtual machine code according to the random number; replacing the initial virtual machine code with an equivalently calculated virtual machine code, and the calculation complexity of the virtual machine code is higher than that of the initial virtual machine code.
[0093] That is to say, for the calculation instruction corresponding to the virtual machine code, when the virtual machine code is executed, the calculation instruction will be directly executed. For example, the "+" in "1 + 2 = 3", its core process is to add two source data. This process is relatively simple to implement in the code and is easy to reverse and analyze. Then, in the embodiment of the present invention, on the basis of generating the initial virtual machine code, it can be replaced with an equivalently calculated virtual machine code with higher calculation complexity. For example, replacing "1 + 2 = 3" with " ", the latter has the same calculation result as the former, but the corresponding instruction complexity is higher, thereby further increasing the difficulty of data cracking.
[0094] In an embodiment of the present invention, in S105, obtaining the encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted may include: after arranging the encryption results of each data unit to be encrypted, performing at least one of the following processes on the arranged result: adding the first virtual machine code corresponding to the invalid process, adding the second virtual machine code corresponding to the false process, and performing control flow flattening on the process of the virtual machine code, to obtain the encryption result of the data to be encrypted.
[0095] That is to say, performing obfuscation processing on the virtual machine code corresponding to each data unit to be encrypted may include the processes of reading and identifying the virtual machine code, calling instruction execution, and the processes inside the instruction, etc. For example, an invalid process (that is, the process itself has no meaning and can be there or not. Such as it will not perform any operations, or will perform some operations, but the data before and after the execution is exactly the same, etc.), a false process (that is, inserting codes such as if-else to generate various branch processes, but the new branch processes will actually not be executed at all, and are only placed here as false processes to deceive reverse engineers), control flow flattening (dividing the originally sequentially executed process into multiple blocks, and placing these blocks in a while loop, and using a control variable and switch-case codes to control which process block to execute in each loop, so as to achieve the process execution effect equivalent to the original process. But in terms of code, each process block is completely at the same level and cannot distinguish who comes first and who comes later, and the execution order cannot be judged), etc., so as to complicate the virtual machine code process and increase the difficulty of reverse engineering.
[0096] In an embodiment of the present invention, if the data to be encrypted is the data in the software to be encrypted, and at this time, the confidentiality issues of both the software code and the data are involved, then the corresponding virtual machine codes can be generated for the software code to be encrypted and the data to be encrypted respectively, and the virtual machine codes corresponding to the software code to be encrypted and the virtual machine codes corresponding to the data to be encrypted are obfuscated and arranged, and then transmitted or stored, so as to further increase the difficulty of data cracking and also increase the difficulty of software code cracking.
[0097] Based on the above embodiments, an embodiment of the present invention provides an implementation manner of the generation process and execution process of the virtual machine code.
[0098] Figure 3 It is a flowchart of a generation process of the virtual machine code provided by an embodiment of the present invention; Figure 4 It is a flowchart of an execution process of the virtual machine code provided by an embodiment of the present invention.
[0099] As Figure 3 shown, the steps of generating a virtual machine code for encrypting the data to be encrypted provided by an embodiment of the present invention may include: S301: Obtain the string of the data to be encrypted and the virtual machine code generation complexity control parameter.
[0100] Obtain the string of the data to be encrypted specified by the user and the virtual machine code generation complexity control parameter. The virtual machine code generation complexity control parameter is used to control the number of randomly generated virtual machine codes to avoid generating too many or too few non-compliant virtual machine codes (too many will affect performance, too few will affect the protection strength, and the user can specify an appropriate complexity control parameter according to the requirements). After the program obtains the string of the data to be encrypted specified by the user and the virtual machine code generation complexity control parameter, it starts to generate random virtual machine codes.
[0101] S302: Generate a random number seed.
[0102] The program generates a random number seed, which is essentially a random string of a specific length, and the length depends on the key length required by the stream cipher algorithm to be used later.
[0103] S303: Call the stream cipher algorithm with the random number seed to generate a random number stream.
[0104] Call the stream cipher algorithm and pass the random number seed as the algorithm key to generate a random number stream. The stream cipher algorithm is a symmetric encryption algorithm, and its core is to generate a key stream and perform byte-by-byte exclusive OR with the plaintext to achieve encryption / decryption.
[0105] The reason for using this algorithm in the embodiment of the present invention is that during the virtual machine code generation process, a data with high randomness and unpredictability and an infinite length is required as the basis for randomly generating virtual machine codes, and the key stream generated by the stream cipher algorithm just meets this requirement and can avoid resource problems caused by reading an extremely long random number from the operating system. Therefore, here is to use the random number seed generated in S302 to call the stream cipher algorithm to further generate a random number stream.
[0106] S304: Determine whether there is an unprocessed data unit to be encrypted; if yes, enter S305; if no, enter S311.
[0107] Try to read a byte from the string of the data to be encrypted specified by the user for processing.
[0108] If data can be read, then enter the process of generating virtual machine codes, that is, S305; if the reading fails (for example, the user specifies an empty string, or the string has been processed and there are no remaining characters), then enter the virtual machine code scrambling protection process, that is, S311.
[0109] S305: Read a byte of the data unit to be encrypted.
[0110] Read a byte of data unit to be encrypted from the unprocessed part of the string of data to be encrypted.
[0111] S306: Read three - byte data from the random number stream as a benchmark to generate virtual machine code.
[0112] After reading the data unit to be encrypted, the virtual machine code generator reads three - byte random data from the random number stream. These three bytes are the benchmark for generating virtual machine code. The virtual machine code generator checks the content of these three - byte data, judges and predicts what virtual machine code will be generated from the first byte, and then judges what the two source operands in the virtual machine code are from the last two bytes. The destination operand in the three - operand instruction is determined by the current data position being processed (i.e., the position of the data unit to be encrypted in the string of data to be encrypted) and will not be randomized.
[0113] Due to the randomness and unpredictability of the random number stream, the generated virtual machine code is also random, and will perform random processing on the data at the specified destination address.
[0114] S307: Determine the calculation type corresponding to the virtual machine code according to the variable parameters.
[0115] After initially generating the virtual machine code, the virtual machine code generator reads some environmental conditions, that is, the "many - to - many design of virtual machine code - instructions" introduced in the above embodiments.
[0116] After reading the variable parameters, combining the already generated virtual machine code, determine the true virtual machine instruction corresponding to the virtual machine code and know its calculation type.
[0117] S308: Perform the inverse operation of the calculation type corresponding to the virtual machine code on the data unit to be encrypted to obtain the calculated character.
[0118] Since the ultimate goal of the virtual machine is to generate the specified data through random instructions, and after the processing of the foregoing steps, the virtual machine code generated by the virtual machine code generator can only generate random data. Therefore, it is necessary to use the inverse operation of the arithmetic operation corresponding to the instruction of the virtual machine code to perform an operation with the original data unit to be encrypted (or the calculated character generated in the previous loop) to obtain the calculated character output by the current round of inverse operation.
[0119] For example, if the data unit to be encrypted is 5 and the randomly generated virtual machine instruction is a = a + 1. Then the operation to be performed here is to execute the inverse operation "-1" of the "+1" operation on the original data 5, so as to obtain the calculated character as 4.
[0120] The operation characters obtained in this way can execute the instruction operation "4 + 1" corresponding to the virtual machine code when executed in the secure virtual machine, and then generate the original target data character 5.
[0121] S309: Determine whether the number of calculation rounds corresponding to the virtual machine code generation complexity control parameter is reached; if so, proceed to S310; if not, proceed to S306.
[0122] At this time, the generation of a random virtual machine code has been completed. According to the design, a character can be processed and dynamically generated by one to any number of virtual machine codes. The more virtual machine codes, the higher the strength, but the corresponding performance is worse. Therefore, it is necessary for the user to specify the virtual machine code generation complexity control parameter to control the number of generated virtual machine codes.
[0123] This step is to detect the virtual machine code generation complexity control parameter input by the user in S101, compare it with the current virtual machine code generation status, and decide whether to generate more virtual machine codes according to the comparison result. If the generation of virtual machine codes does not meet the user's requirements, then jump to execute S306 to further read random data to generate virtual machine codes; if the virtual machine code generation complexity control parameter has been met, then no more virtual machine codes are generated, and proceed to S310.
[0124] S310: Use the operation character output by the last round of inverse operation corresponding to the data unit to be encrypted as the first data, generate an initialization data virtual machine code, and write the first data.
[0125] The generated multiple virtual machine codes have met the conditions of the virtual machine code generation complexity control parameter. At this time, multiple virtual machine codes corresponding to the data unit to be encrypted and a first data after multiple rounds of inverse operations have been obtained. To ensure that the first data after multiple rounds of operations can participate in the execution of the virtual machine code in the virtual machine and finally generate the target character, a load instruction needs to be generated at this time to load the first data into the virtual register.
[0126] When executed in the secure virtual machine, the first data will first be loaded into the register by the load instruction, and then processed by the previously generated virtual machine codes to finally obtain the target data character.
[0127] Thus, a complete randomized virtual machine code block containing multiple virtual machine codes for a single-byte data unit to be encrypted is realized. After this step is completed, it jumps to S304 and reads the next data unit to be encrypted to start a new round of randomized virtual machine code generation process.
[0128] S311: Virtual machine code scrambling processing.
[0129] After all the data units to be encrypted have been read and processed, the process of generating virtual machine code is completed.
[0130] However, at this time, the virtual machine code is distributed in blocks, and each virtual machine code block is specifically used to process one byte of the data unit to be encrypted at a specific position. To further increase the difficulty of data cracking, the embodiment of the present invention performs disorder processing on the virtual machine code. All the virtual machine code blocks are taken out separately, and then a certain virtual machine code block is randomly selected. A virtual machine code is extracted from the virtual machine code block from front to back and placed in the final virtual machine code area, and then another virtual machine code block is randomly selected to perform this operation.
[0131] This processing method can ensure that the virtual machine codes in all virtual machine code blocks are evenly and randomly distributed in the final complete virtual machine code, and the relative order of the virtual machine codes within each virtual machine code block remains unchanged (for example, for virtual machine code blocks ABC and XYZ, the disorder is XABYCZ, and the relative order of ABC remains unchanged), so as to ensure that the final execution result is correct.
[0132] S312: Output the virtual machine code file.
[0133] After the processing is completed, the final virtual machine code can be packaged and exported to a file, which is convenient to be compiled into the target program for reference.
[0134] As Figure 4 shown, the steps for the secure virtual machine to execute the virtual machine code include: S401: Read the virtual machine code file.
[0135] The secure virtual machine starts and receives the virtual machine code passed by the user.
[0136] S402: Determine whether there is unexecuted virtual machine code. If yes, enter; if no, enter.
[0137] The secure virtual machine reads a virtual machine code from the passed virtual machine code. If a virtual machine code can be read, then proceed to S403 to parse and execute the virtual machine code; if no virtual machine code is read, it means that the virtual machine code has been executed, and then jump to S405 to output data.
[0138] S403: Read variable parameters and determine the calculation type corresponding to the virtual machine code.
[0139] The secure virtual machine parses the read virtual machine code, reads the agreed variable parameters, determines the real virtual machine instruction corresponding to the virtual machine code according to the variable parameters, that is, the real calculation type, and then obtains the two source operands and the destination operand of the instruction, and calls the corresponding virtual machine instruction.
[0140] S404: Execute the operations corresponding to the virtual machine code.
[0141] After the virtual machine instruction is called, obtain the source operand and the destination operand, and execute the virtual machine instruction process. Perform arithmetic processing on the data of the source operand and store it in the destination.
[0142] At this point, the execution of a virtual machine instruction is completed and returns, returning to S402 to read the next virtual machine code and parse and execute it.
[0143] S405: Copy the register content to the target area.
[0144] When no new virtual machine code can be read in S402, it means that all virtual machine instructions have been executed. The data in the virtual machine register is already the string of the dynamically generated data to be encrypted. At this time, the virtual machine will execute the export process, copy the data in the register to the specified memory area, and the user can access this area to use this data.
[0145] S406: Clean up the environment and exit.
[0146] After the export is completed, the secure virtual machine will clean up various variables during the execution process and the used register area. After the cleanup is completed, the virtual machine will automatically exit.
[0147] It should be noted that during the execution of the secure virtual machine, the equivalent replacement of the instruction process described in the above embodiments, process obfuscation, etc. are all internalized in the virtual machine code and are executed without affecting the normal function process of the secure virtual machine. Therefore, it is not shown in Figure 4 the flowchart, but in fact each step in the flowchart includes these obfuscation protection designs.
[0148] These designs can hide the internal execution process of the secure virtual machine, thereby improving the strength of the secure virtual machine and ensuring that the execution process of the relevant virtual machine code cannot be reversed, thereby improving the security of the dynamic restoration process of the string of data to be encrypted.
[0149] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method.
[0150] An embodiment of the present invention further provides a data encryption device, which may include: a first acquisition unit configured to acquire a string of data to be encrypted; a second acquisition unit configured to acquire a random number corresponding to the data volume according to the data volume of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device; a generation unit configured to generate a virtual machine code corresponding to the type of secure virtual machine based on the random number; a calculation unit configured to calculate a first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code; and a determination unit configured to obtain an encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted.
[0151] In an embodiment of the present invention, the second acquisition unit acquires a random number corresponding to the data volume, which may include: reading a random number corresponding to the data volume from a pre-generated random number stream.
[0152] In an embodiment of the present invention, the second acquisition unit acquires a random number corresponding to the data volume according to the data volume of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device, which may include: determining the number of operation codes of a virtual machine code and the number of operands of a virtual machine code according to the type of secure virtual machine; taking the sum of the number of operation codes of a virtual machine code and the number of operands of a virtual machine code minus one as the number of random numbers; and acquiring random numbers corresponding to the number, wherein the data volume of one random number is equal to the data volume of the data unit to be encrypted.
[0153] In an embodiment of the present invention, the generation unit generates a virtual machine code corresponding to the type of secure virtual machine based on the random number, which may include: determining a parameter of the virtual machine code according to the position of the data unit to be encrypted in the string of data to be encrypted, and determining the remaining parameters in the virtual machine code according to the random number; the parameters of the virtual machine code include the operation code of the virtual machine code and the operands of the virtual machine code; and generating the virtual machine code according to the operation code of the virtual machine code and the operands of the virtual machine code.
[0154] In an embodiment of the present invention, the secure virtual machine may be a three-operand register virtual machine. The second obtaining unit obtains a random number corresponding to the data volume according to the data volume of a data unit to be encrypted in the string of the data to be encrypted and the type of the secure virtual machine adopted by the decryption device, which may include: reading three random numbers of the same data volume according to the data volume of the data unit to be encrypted. The generating unit generates a virtual machine code corresponding to the type of the secure virtual machine based on the random number, which may include: determining the operation code of the virtual machine code according to one of the random numbers, determining two data source operands of the virtual machine code according to the other two random numbers, determining the target address operand of the virtual machine code according to the position of the data unit to be encrypted in the data to be encrypted, and generating the virtual machine code of the three-operand register virtual machine according to the operation code, the data source operands, and the target address operand.
[0155] In an embodiment of the present invention, the calculation unit calculates a first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code, which may include: performing an inverse operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data.
[0156] In an embodiment of the present invention, the calculation unit performs an inverse operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data, which may include: performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data.
[0157] In an embodiment of the present invention, the calculation unit performs multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data, which may include: in the current round of inverse operation, using the data unit to be encrypted or the output result of the previous round of inverse operation as the input data, performing an inverse operation of the virtual machine code corresponding to the current round of inverse operation on the input data of the current round of inverse operation to obtain the output result of the current round of inverse operation; if the preset generation times are reached, using the output result of the current round of inverse operation as the first data; if the preset generation times are not reached, using the output result of the current round of inverse operation to enter the process of obtaining a random number corresponding to the data volume according to the data volume of the data unit to be encrypted and the type of the secure virtual machine adopted by the decryption device.
[0158] In an embodiment of the present invention, the determining unit obtains an encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted, which may include: scrambling the virtual machine codes corresponding to each data unit to be encrypted so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encryption result of the data to be encrypted is the same as the generation order of the virtual machine codes, to obtain a scrambled virtual machine code result; using the scrambled virtual machine code result and the first data as the encryption result corresponding to the data to be encrypted.
[0159] In an embodiment of the present invention, the determining unit shuffles the virtual machine codes corresponding to each data unit to be encrypted, so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encrypted result of the data to be encrypted is the same as the generation order of the virtual machine codes, and a virtual machine code shuffling result can be obtained, which may include: randomly taking out the foremost virtual machine code from the virtual machine codes corresponding to a data unit to be encrypted and listing it in the encrypted result queue of the data to be encrypted until all the virtual machine codes are added to the encrypted result queue, thereby obtaining the virtual machine code shuffling result.
[0160] In an embodiment of the present invention, based on a random number, generating a virtual machine code corresponding to the type of a secure virtual machine may include: generating an initial virtual machine code according to the random number; obtaining a variable parameter agreed upon by the device where it is located and the decryption device; and using the variable parameter to generate a virtual machine code from the initial virtual machine code.
[0161] In an embodiment of the present invention, the generating unit generates a virtual machine code corresponding to the type of a secure virtual machine based on a random number, which may include: generating an initial virtual machine code according to the random number; replacing the initial virtual machine code with an equivalently calculated virtual machine code, and the computational complexity of the virtual machine code is higher than that of the initial virtual machine code.
[0162] For the description of the features in the corresponding embodiment of the data encryption device, reference may be made to the relevant description in the corresponding embodiment of the data encryption method, which will not be elaborated here.
[0163] An embodiment of the present invention further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above embodiments of the data encryption method.
[0164] An embodiment of the present invention further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any one of the above embodiments of the data encryption method when running.
[0165] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: a USB flash drive, a read-only memory (ROM for short), a random access memory (RAM for short), a mobile hard disk, a magnetic disk, or an optical disc and other various media that can store computer programs.
[0166] An embodiment of the present invention further provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above embodiments of the data encryption method.
[0167] An embodiment of the present invention also provides another computer program product, including a non-volatile computer-readable storage medium storing a computer program, and the computer program, when executed by a processor, implements the steps in any of the above-described embodiments of the data encryption method.
[0168] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0169] The above has introduced in detail a data encryption method, device, medium, and computer program product provided by the present invention. Specific examples are used herein to illustrate the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the present invention.
Claims
1. A data encryption method, characterized in that, Including: Obtaining a string of data to be encrypted; Obtaining a random number corresponding to a data volume according to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device; Generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number; Calculating a first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code; Obtaining an encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted.
2. The data encryption method according to claim 1, wherein Obtaining a random number corresponding to a data volume includes: Reading the random number corresponding to the data volume from a pre-generated random number stream.
3. The data encryption method according to claim 1, wherein Obtaining a random number corresponding to a data volume according to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device includes: Determining the number of operation codes of a virtual machine code and the number of operands of a virtual machine code according to the type of the secure virtual machine; Taking the sum of the number of operation codes of a virtual machine code and the number of operands of a virtual machine code minus one as the number of random numbers; Obtaining the corresponding number of random numbers, and the data volume size of one random number is equal to the data volume size of the data unit to be encrypted.
4. The data encryption method according to claim 3, wherein Generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number includes: Determining a parameter of the virtual machine code according to the position of the data unit to be encrypted in the string of data to be encrypted, and determining the remaining parameters in the virtual machine code according to the random number; the parameters of the virtual machine code include the operation code of the virtual machine code and the operands of the virtual machine code; Generating the virtual machine code according to the operation code of the virtual machine code and the operands of the virtual machine code.
5. The data encryption method according to claim 4, characterized in that, The secure virtual machine is a three-operand register-based virtual machine; Obtaining a random number corresponding to a data volume according to the data volume size of a data unit to be encrypted in the string of data to be encrypted and the type of secure virtual machine adopted by the decryption device includes: Reading three random numbers of the same data volume size according to the data volume size of the data unit to be encrypted; Generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number includes: Determining the operation code of the virtual machine code according to one of the random numbers, determining two data source operands of the virtual machine code according to the other two random numbers, determining the target address operand of the virtual machine code according to the position of the data unit to be encrypted in the data to be encrypted, and generating the virtual machine code of the three-operand register-based virtual machine according to the operation code, the data source operands and the target address operand.
6. The data encryption method according to claim 1, wherein Calculating a first data corresponding to the data unit to be encrypted according to the data unit to be encrypted and the virtual machine code includes: Performing an inverse operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data.
7. The data encryption method according to claim 6, wherein Performing an inverse operation corresponding to the virtual machine code on the data unit to be encrypted to obtain the first data, including: Performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data.
8. The data encryption method according to claim 7, wherein Performing multiple rounds of inverse operations of the virtual machine code on the data unit to be encrypted to obtain the first data, including: In the current round of inverse operation, using the data unit to be encrypted or the output result of the previous round of inverse operation as the input data, performing the inverse operation of the virtual machine code corresponding to the current round of inverse operation on the input data of the current round of inverse operation to obtain the output result of the current round of inverse operation; If the preset generation times are reached, using the output result of the current round of inverse operation as the first data; If the preset generation times are not reached, using the output result of the current round of inverse operation to obtain a random number with a corresponding data volume according to the data volume size of the data unit to be encrypted and the type of secure virtual machine used by the decryption device.
9. The data encryption method according to claim 8, wherein Obtaining the encryption result corresponding to the data to be encrypted according to the virtual machine code corresponding to the data unit to be encrypted and the first data corresponding to the data unit to be encrypted, including: Randomly arranging the virtual machine codes corresponding to each data unit to be encrypted so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encryption result of the data to be encrypted is the same as the generation order of the virtual machine codes, obtaining a scrambled virtual machine code result; Using the scrambled virtual machine code result and the first data as the encryption result corresponding to the data to be encrypted.
10. The data encryption method according to claim 9, characterized in that Randomly arranging the virtual machine codes corresponding to each data unit to be encrypted so that the arrangement order of the virtual machine codes corresponding to the same data unit to be encrypted in the encryption result of the data to be encrypted is the same as the generation order of the virtual machine codes, obtaining a scrambled virtual machine code result, including: Randomly taking out the foremost virtual machine code from the virtual machine codes corresponding to one data unit to be encrypted and listing it in the encryption result queue of the data to be encrypted until all the virtual machine codes are added to the encryption result queue, obtaining the scrambled virtual machine code result.
11. The data encryption method according to claim 1, wherein Generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number, including: Generating an initial virtual machine code based on the random number; Obtaining the variable parameters agreed upon by the device where it is located and the decryption device; Using the variable parameters to generate the virtual machine code from the initial virtual machine code.
12. The data encryption method according to claim 1, characterized in that Generating a virtual machine code corresponding to the type of the secure virtual machine based on the random number, including: Generating an initial virtual machine code based on the random number; Replacing the initial virtual machine code with an equivalently calculated virtual machine code, and the computational complexity of the virtual machine code is higher than that of the initial virtual machine code.
13. An electronic device, characterized in that, Including: A memory for storing a computer program; A processor for implementing the steps of the data encryption method according to any one of claims 1 to 12 when executing the computer program.
14. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the data encryption method according to any one of claims 1 to 12 when executed by a processor.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the data encryption method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Method and device of generating instruction set codes and systems
CN108121565A
Android application reinforcing method, system and equipment
CN115756480A
Data processing method and related device
CN120066668A
Making secure downloaded application in particular in a smart card
US20050218234A1