A method and device for preventing APK from being illegally installed
By inverting the magic number of the APK file and encrypting it, combined with client verification, we can prevent the APK file from being illegally installed and achieve effective protection.
Patent Information
- Application Number
- CN202510774236.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-06-11
AI Technical Summary
In the prior art, APK files of the Android system are easily illegally installed, endangering users and legitimate application developers, and there is a lack of effective protection measures.
By parsing the original magic number of the APK file, negating the magic number and adding the hexadecimal number agreed upon by the authorized client, a file to be installed with a custom suffix is generated and verified during installation to ensure that only legitimate devices can restore to the original APK file.
It effectively prevents APK files from being illegally installed, simplifies the protection process, and saves costs.
Smart Images

Figure CN120316743B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a method and device for preventing APK from being illegally installed. Background Art
[0002] APK (Android Package) is the Android installation package, the file format for application installation on the Android operating system, typically in ZIP format. With the rapid development of technology, the Android system has produced a large number of third-party applications, the result of the hard work of application developers. However, due to the open source nature of the Android system, third-party applications are often illegally installed, endangering not only users but also legitimate application developers. Summary of the Invention
[0003] In view of the existing deficiencies, the present invention provides a method and device for preventing APK from being illegally installed.
[0004] The technical solution adopted by the present invention to solve the technical problem is: a method for preventing APK from being illegally installed, comprising:
[0005] Parse the original APK file and obtain the original magic number in its header, then invert the original magic number bit by bit to obtain the inverted magic number;
[0006] Add a hexadecimal number agreed upon with the authorized client before the inverted magic number, and then write it into the original APK file instead of the original magic number to generate a file to be installed with a custom suffix. The hexadecimal number is different from the original magic number and is agreed upon with the authorized client.
[0007] The client's installation request is verified using the added hexadecimal number and the inverted magic number to verify whether the client is authorized. If the verification is successful, the file to be installed is reversed to restore it to the original APK file for installation. Otherwise, the installation is rejected. The verification includes the following steps:
[0008] a. Parse the client's file to be installed and obtain its magic number. Compare the magic number with the standard ZIP file header identifier. If the magic number of the client's file to be installed matches the standard ZIP file header identifier, the verification fails.
[0009] b. If the magic number of the file to be installed on the client is inconsistent with the standard ZIP file header identifier, then determine whether the magic number of the file to be installed is the inverted magic number after the standard ZIP file header identifier is bitwise inverted. If so, parse whether there is any preceding data before the inverted magic number. If not, the verification fails; if the magic number is inverted but there is no preceding data before the inverted magic number, the verification fails; if the magic number is inverted and there is preceding data before the inverted magic number, compare the preceding data before the inverted magic number with the added hexadecimal number. If the comparison is consistent, use the preceding data to verify the client. If the comparison is inconsistent, the verification fails.
[0010] Preferably, the steps of restoring the file to be installed to an APK file are as follows:
[0011] c. Parse the inverted magic number of the file to be installed and skip or delete the hexadecimal number before the inverted magic number;
[0012] d. Reverse the magic number bit by bit to restore it to the original magic number. Use the original magic number to replace the hexadecimal number and the reversed magic number in the file to be installed to restore the file to the original APK file.
[0013] Preferably, the hexadecimal number is an authorization token generated by asymmetric encryption or symmetric encryption based on client device information, a timestamp and a random number.
[0014] Preferably, the suffix of the file to be installed is FKG.
[0015] A device for preventing APK from being illegally installed, comprising:
[0016] Decompression module, used to decompress the original APK file and obtain its original magic number;
[0017] An encryption module is configured to bitwise invert the original magic number to obtain an inverted magic number, and to add a hexadecimal number agreed upon with the authorized client before the inverted magic number to replace the original magic number to form a to-be-installed file with a custom suffix, wherein the hexadecimal number is different from the original magic number and is agreed upon with the authorized client;
[0018] The verification module uses the added hexadecimal number and the negated magic number to verify whether the client is authorized. If the verification is successful, the decryption module is activated, otherwise the installation is rejected. The verification module includes a parsing unit and a comparison unit. The parsing unit is used to parse the magic number of the file to be installed and the preceding data before the magic number. The comparison unit is used to compare the magic number of the file to be installed with a standard ZIP file header identifier, and compare the preceding data before the magic number of the file to be installed with the added hexadecimal number and verify the client using the preceding data before the magic number of the file to be installed.
[0019] Decryption module, which performs reverse operations on the installed file and restores it to the original APK file;
[0020] The installation module is used to install the original APK file after the decryption module decrypts the installation file.
[0021] Preferably, the decryption module includes an extraction unit and a restoration unit, the extraction unit is used to extract the hexadecimal number and the inverted magic number in the file to be installed, and the restoration unit is used to restore the hexadecimal number and the inverted magic number to the original magic number to form the installation file.
[0022] Preferably, the hexadecimal number is an authorization token generated by asymmetric encryption or symmetric encryption based on client device information, a timestamp, and a random number.
[0023] The beneficial effect of the present invention is that: the invention inverts the original magic number of the original APK file bit by bit and adds a hexadecimal number agreed with the authorized client in front of it to encrypt the APK file. The added hexadecimal number is agreed with the client. When the client is installed, it will verify whether the client is a legal device. After the verification is passed, the reverse operation is performed to parse the original APK file for installation. The method is simple, can effectively prevent the APK from being illegally installed, and also saves costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 This is a flow chart of a method for preventing an APK from being illegally installed according to an embodiment of the present invention;
[0025] Figure 2 This is a block diagram of the principle of preventing APK from being illegally installed according to an embodiment of the present invention;
[0026] The names and serial numbers of the components in the figure are: 1- decompression module 2- encryption module 3- verification module 30- parsing unit 31- comparison unit 4- decryption module 40- extraction unit 41- restoration unit 5- installation module. DETAILED DESCRIPTION
[0027] In order to more clearly illustrate the purpose, technical solutions and advantages of the embodiments of the present invention, the present invention will be further described below with reference to the accompanying drawings and embodiments for a clear and complete description. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work shall fall within the scope of protection of the present invention.
[0028] The present invention is implemented as follows Figure 1 As shown in , a method for preventing APK from being illegally installed includes:
[0029] Parse the original APK file and get the original magic number in its header. The original APK file is in ZIP format. Use a hexadecimal editor to open the APK file and read the original magic number in its header, which is 50 4B 03 04. Invert the original magic number bit by bit to get the inverted magic number, which is AF B4 FC FB.
[0030] A hexadecimal number agreed upon with the authorized client is added before the negated magic number and then written into the original APK file instead of the original magic number to generate a file to be installed with a custom suffix. The hexadecimal number is different from the original magic number and is agreed upon with the authorized client. In this way, a new file is formed using the hexadecimal number agreed upon with the authorized client and the negated magic number. The original APK file is encrypted, and the hexadecimal number is agreed upon with the authorized client, such as a hexadecimal number converted from the client device's unique information (serial number, MAC address); the suffix of the file to be installed is FKG; preferably, the hexadecimal number is an authorization token generated based on the client device information, timestamp, and random number through asymmetric encryption (RSA) or symmetric encryption (AES), such as using the following method to generate:
[0031] public String generateAuthToken(Context context) throws Exception {
[0032] StringdeviceId = getDeviceId(context);
[0033] longevitystamp = System.currentTimeMillis();
[0034] byte[] nonce = generateNonce(16);
[0035] Stringplaintext = deviceId + "|" + timestamp + "|" + bytesToHex(nonce);
[0036] return AESUtil.encrypt(plaintext.getBytes());
[0037] }
[0038] privatestatic String bytesToHex(byte[] bytes) {
[0039] StringBuildersb = newStringBuilder();
[0040] for (byte b : bytes) {
[0041] sb.append(String.format("%02x", b));
[0042] }
[0043] return sb.toString();
[0044] }
[0045] The client's installation request is verified using the added hexadecimal number and the inverted magic number to verify whether the client is authorized. Since the added hexadecimal number is agreed upon with the authorized client item, the authorized client can obtain data that matches the added hexadecimal number during verification. However, the unauthorized client has no way of knowing the added hexadecimal number, and therefore cannot obtain matching data from the unauthorized client during verification, and thus cannot pass the verification. The verification includes the following steps:
[0046] a. Parse the client's installation file and obtain its magic number. Compare the magic number with the ZIP standard file header identifier. If the magic number of the client's installation file matches the ZIP standard file header identifier, verification fails. The ZIP standard file header identifier is 50 4B 03 04. If the parsed magic number of the client's installation file is also 50 4B03 04, then the legitimate installation file has its magic number inverted and prepended with data. This indicates that the client's installation file has been tampered with and is an illegal installation file. Therefore, verification fails for the client, preventing installation.
[0047] b. If the magic number of the client's file to be installed is inconsistent with the ZIP standard file header identifier, then determine whether the magic number of the client's file to be installed is the inverted magic number after the bitwise inversion of the ZIP standard file header identifier. If so, parse whether there is any preceding data before the inverted magic number. If not, the verification fails. If it is the inverted magic number but there is no preceding data before the inverted magic number, the verification fails. If it is the inverted magic number and there is preceding data before the inverted magic number, compare the preceding data before the inverted magic number with the added hexadecimal number. If the comparison is consistent, use the preceding data to verify the client. If the comparison is inconsistent, the verification fails. That is, use a hexadecimal editor to parse whether the client's file to be installed contains the inverted magic number after the bitwise inversion of the ZIP standard file header identifier. If there is no such inverted magic number, since the legal installation file has the inverted magic number, the absence of the magic number means that the client's file to be installed is illegal and the verification fails. If there is such an inverted magic number, locate the location of the inverted magic number, that is, AF B4 FC. The location of FB, after locating the location of the inverted magic number, determine whether there is any preceding data in front of it. If not, the verification will fail for the same reason. If there is preceding data before the inverted magic number, record the offset of the inverted magic number, then extract the preceding data before the inverted magic number, and compare the preceding data with the added hexadecimal number. If the comparison is consistent, it means that the file to be installed on the client is a legal file, not a tampered file. If the comparison is inconsistent, it means that the file to be installed on the client is an illegal file after tampering, and the verification fails. After the preceding data before the inverted magic number is compared with the added hexadecimal number and is consistent, the preceding data is used to verify the client. Since the added hexadecimal number is agreed with the authorized client, it is an authorization token generated based on the client device information, timestamp, and random number through asymmetric encryption (RSA) or symmetric encryption (AES). After the verification is qualified, it means that the client is an authorized device, otherwise it is an unauthorized device; the client can be verified using the preceding data as follows:
[0048] public boolean validateAuthToken(Context context, StringencryptedToken) {
[0049] try {
[0050] byte[] decrypted = AESUtil.decrypt(encryptedToken);
[0051] String plaintext = new String(decrypted, StandardCharsets.UTF_8);
[0052] String[] parts = plaintext.split("\\|");
[0053] if (parts.length != 3) {
[0054] return false;
[0055] }
[0056] String storedDeviceId = parts[0];
[0057] long storedTimestamp = Long.parseLong(parts[1]);
[0058] String storedNonce = parts[2];
[0059] String currentDeviceId = getDeviceId(context);
[0060] if (!currentDeviceId.equals(storedDeviceId)) {
[0061] return false;
[0062] }
[0063] long currentTime = System.currentTimeMillis();
[0064] if (Math.abs(currentTime - storedTimestamp)>300_000) {
[0065] return false;
[0066] }
[0067] if (isNonceUsed(storedNonce)) {
[0068] return false;
[0069] }
[0070] markNonceAsUsed(storedNonce);
[0071] return true;
[0072] } catch (Exception e) {
[0073] return false;
[0074] }
[0075] }
[0076] private static final Set <string>usedNonces =Collections.synchronizedSet(new HashSet<>());
[0077] private boolean isNonceUsed(String nonce) {
[0078] return usedNonces.contains(nonce);
[0079] }
[0080] private void markNonceAsUsed(String nonce) {
[0081] usedNonces.add(nonce);
[0082] }
[0083] If the verification is successful, the file to be installed will be restored to the original APK file for installation. Otherwise, the installation will be rejected. After the client is verified to be an authorized device, the file to be installed on the client will be restored to the original APK file for installation. The restoration steps are as follows:
[0084] c. Parse the inverted magic number of the file to be installed and skip or delete the hexadecimal number before the inverted magic number. That is, after the client is verified, the preceding data before the inverted magic number, that is, the hexadecimal number, is skipped or deleted based on the position of the inverted magic number located in the verification phase, and then proceed to the next step;
[0085] d. Reverse the magic number bit by bit to restore it to the original magic number. That is, reverse the magic number AF B4 FC FB bit by bit to restore it to the original magic number 50 4B 03 04. Use the original magic number to replace the hexadecimal number and the reversed magic number in the file to be installed to restore the file to be installed to the original APK file.
[0086] A device to prevent APK from being illegally installed, such as Figure 1 and Figure 2 As shown in , including:
[0087] Decompression module 1, used to decompress the original APK file and obtain its original magic number;
[0088] Encryption module 2 is configured to bitwise invert the original magic number to obtain an inverted magic number, and append a hexadecimal number agreed upon with the authorization client before the inverted magic number to replace the original magic number to form a to-be-installed file with a custom suffix. The hexadecimal number is a number different from the original magic number and agreed upon with the authorization client. The hexadecimal number is an authorization token generated using asymmetric encryption (RSA) or symmetric encryption (AES) based on client device information, a timestamp, and a random number.
[0089] The verification module 3 uses the added hexadecimal number and the inverted magic number to verify whether the client is authorized. After the verification is passed, the decryption module is started, otherwise the installation is rejected; the verification module 3 includes a parsing unit 30 and a comparison unit 31. The parsing unit 30 is used to parse the magic number of the file to be installed and the preceding data before the magic number, and use a hexadecimal editor to parse and read the client file to be installed and obtain its magic number. After determining the position of the obtained magic number, if there is any preceding data before the obtained magic number, the preceding data is extracted at the same time; the comparison unit 31 is used to compare the magic number of the file to be installed with the standard file header identifier of ZIP. If there is no preceding data before the obtained magic number, the preceding data before the magic number of the file to be installed is compared with the added hexadecimal number and the preceding data before the magic number of the file to be installed is used to verify the client.The magic number of the parsed file to be installed is compared with the standard ZIP file header identifier. If the magic number of the client file to be installed is consistent with the ZIP standard file header identifier, the verification fails. The ZIP standard file header identifier is 50 4B 03 04. At this time, if the magic number of the parsed client file to be installed is also 50 4B 03 04, since the magic number of the legal file to be installed is inverted and there is prefix data added before the magic number, this means that the client file to be installed has been tampered with and is an illegal installation file. The verification on the client fails and it cannot be installed. If the magic number of the client file to be installed is inconsistent with the ZIP standard file header identifier, the file to be installed is parsed to see whether there is a magic number that is the bitwise inversion of the ZIP standard file header identifier and whether there is prefix data before the inverted magic number. If the inverted magic number does not exist, the verification fails. If the inverted magic number exists but there is no prefix data before the inverted magic number, the verification fails. If there is a prefix data before the inverted magic number, the verification fails. If the magic number is negated and there is a prefix before the negated magic number, the prefix before the negated magic number will be compared with the added hexadecimal number. If the comparison is consistent, the client will be verified using the prefix data. If the comparison is inconsistent, the verification fails. That is, a hexadecimal editor is used to parse whether the client's file to be installed contains the negated magic number after the standard file header identifier of ZIP is bitwise negated. If there is no such negated magic number, since the legal installation file has the negated magic number, the absence of the magic number indicates that the client's file to be installed is illegal and the verification fails. If there is such a negated magic number, the location of the negated magic number is located, that is, AF The location of B4 FC FB, after locating the location of the inverted magic number, determines whether there is any preceding data in front of it. If not, the verification fails for the same reason. If there is preceding data before the inverted magic number, record the offset of the inverted magic number, then extract the preceding data before the inverted magic number, and compare the preceding data with the added hexadecimal number. If the comparison is consistent, it means that the file to be installed on the client is a legal file and not a tampered file. If the comparison is inconsistent, it means that the file to be installed on the client is an illegal file after being tampered with, and the verification fails. After the preceding data before the inverted magic number is compared with the added hexadecimal number and is consistent, the preceding data is used to verify the client, that is, to verify whether the device information in the preceding data matches the current client, and check the validity of the timestamp. If the verification passes, it is determined that the client is a legal and authorized client.
[0090] The decryption module 4 performs a reverse operation on the installation file to restore it to the original APK file. The decryption module 4 includes an extraction unit 40 and a restoration unit 41. The extraction unit 40 is used to extract the hexadecimal number and the inverted magic number from the installation file. The restoration unit 41 is used to restore the extracted hexadecimal number and the inverted magic number to the original magic number to form the installation file. The extracted hexadecimal number is skipped or deleted, and the inverted magic number is bitwise inverted to restore it to the original magic number of the APK file. That is, the inverted magic number AF B4 FC FB is restored to the original magic number 50 4B 03 04. At the same time, the original magic number replaces the hexadecimal number and the inverted magic number. The client file to be installed is restored to the original APK file, which can be installed on the client.
[0091] The installation module 5 is used to install the original APK file after the decryption module decrypts the installation file.
[0092] Although the present invention has been described in detail above using general descriptions and specific embodiments, it will be apparent to those skilled in the art that modifications and improvements may be made based on the present invention. Therefore, such modifications and improvements, which do not depart from the spirit of the present invention, are intended to fall within the scope of protection claimed herein.< / string>
Claims
1. A method for preventing APK from being illegally installed, characterized in that: include: Parse the original APK file and obtain the original magic number in its header, then invert the original magic number bit by bit to obtain the inverted magic number; Add a hexadecimal number agreed upon with the authorized client before the inverted magic number, and then write it into the original APK file instead of the original magic number to generate a file to be installed with a custom suffix. The hexadecimal number is different from the original magic number and is agreed upon with the authorized client. The client's installation request is verified using the added hexadecimal number and the inverted magic number to verify whether the client is authorized. If the verification is successful, the file to be installed is reversed to restore it to the original APK file for installation. Otherwise, the installation is rejected. The verification includes the following steps: a. Parse the client's file to be installed and obtain its magic number. Compare the magic number with the standard ZIP file header identifier. If the magic number of the client's file to be installed matches the standard ZIP file header identifier, the verification fails. b. If the magic number of the file to be installed on the client is inconsistent with the standard ZIP file header identifier, then determine whether the magic number of the file to be installed is the inverted magic number after the standard ZIP file header identifier is bitwise inverted. If so, parse whether there is any preceding data before the inverted magic number. If not, the verification fails; if the magic number is inverted but there is no preceding data before the inverted magic number, the verification fails; if the magic number is inverted and there is preceding data before the inverted magic number, compare the preceding data before the inverted magic number with the added hexadecimal number. If the comparison is consistent, use the preceding data to verify the client. If the comparison is inconsistent, the verification fails.
2. The method for preventing APK from being illegally installed according to claim 1, characterized in that: The steps for restoring the file to be installed to an APK file are as follows: c. Read the inverted magic number of the file to be installed and skip or delete the hexadecimal number before the inverted magic number; d. Reverse the magic number bit by bit to restore it to the original magic number. Use the original magic number to replace the hexadecimal number and the reversed magic number in the file to be installed to restore the file to the original APK file.
3. The method for preventing APK from being illegally installed according to claim 1, characterized in that: The hexadecimal number is an authorization token generated by asymmetric encryption or symmetric encryption based on client device information, a timestamp, and a random number.
4. The method for preventing APK from being illegally installed according to claim 1, characterized in that: The suffix of the file to be installed is FKG.
5. A device for preventing APK from being illegally installed, characterized in that: include: Decompression module, used to decompress the original APK file and obtain its original magic number; An encryption module is configured to bitwise invert the original magic number to obtain an inverted magic number, and to add a hexadecimal number agreed upon with the authorized client before the inverted magic number to replace the original magic number to form a to-be-installed file with a custom suffix, wherein the hexadecimal number is different from the original magic number and is agreed upon with the authorized client; The verification module uses the added hexadecimal number and the negated magic number to verify whether the client is authorized. If the verification is successful, the decryption module is activated, otherwise the installation is rejected. The verification module includes a parsing unit and a comparison unit. The parsing unit is used to parse the magic number of the file to be installed and the preceding data before the magic number. The comparison unit is used to compare the magic number of the file to be installed with a standard ZIP file header identifier, and compare the preceding data before the magic number of the file to be installed with the added hexadecimal number and verify the client using the preceding data before the magic number of the file to be installed. Decryption module, which performs reverse operations on the installed file and restores it to the original APK file; The installation module is used to install the original APK file after the decryption module decrypts the installation file.
6. The device for preventing APK from being illegally installed according to claim 5, characterized in that: The decryption module includes an extraction unit and a restoration unit. The extraction unit is used to extract the hexadecimal number and the inverted magic number from the file to be installed. The restoration unit is used to restore the hexadecimal number and the inverted magic number to the original magic number to form an installation file.
7. The device for preventing APK from being illegally installed according to claim 5, characterized in that: The hexadecimal number is an authorization token generated by asymmetric encryption or symmetric encryption based on client device information, a timestamp, and a random number.
Citation Information
Patent Citations
APK signature verification method and system
CN107980132A