Packing tamper-proofing method and device for client
By hierarchical encryption and subcontract encryption of client code, the client's tamper-proof accuracy and low efficiency are solved, and more efficient tamper-proof capabilities are achieved, and the client's operation security and stability are improved.
Patent Information
- Application Number
- CN202510198833.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-07-18
AI Technical Summary
The existing client tamper-proof method has problems with anti-tamper accuracy and low efficiency, especially in large-scale projects, manual review is inefficient, making it difficult to effectively prevent third-party decoding and tampering.
By distinguishing the client's pending code, the main process code and the rendering process code are respectively encrypted layer by layer, and the encryption result is generated using preset encryption methods, and when starting, it is determined whether the information tampering conditions are met, generating a software corruption prompt or ending the program.
It improves the pertinence, diversity and flexibility of client code encryption, enhances the comprehensiveness and rationality of tamper-proof, improves the timeliness, accuracy and efficiency of tamper-proof response, and enhances the security and stability of client operation.
Smart Images

Figure CN120337207A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular, to a method and device for preventing tampering with client packages. Background Art
[0002] In the current digital age, the security of client applications has become the focus of common concern for enterprises and users. Specifically, through the official unpacking tool for code decoding, the decoding threshold is low, and there is a certain code security. Further, since decoding can be carried out arbitrarily, it is easy to occur that third parties obtain improper benefits after decoding and tampering. Therefore, preventing tampering with the client is particularly important.
[0003] Currently, the main method for preventing tampering with the client is to manually check the code to discover potential security vulnerabilities or logical defects and repair them. It depends on the experience and ability of developers and is prone to omissions. For large projects, the efficiency of manual review is low. Therefore, the existing methods for preventing tampering with the client have problems of low accuracy and efficiency in preventing tampering. It can be seen that it is particularly important to provide a new method for preventing tampering with the client to improve the accuracy and efficiency of preventing tampering with the client. Summary of the Invention
[0004] The present invention provides a method and device for preventing tampering with client packages, which can improve the accuracy and efficiency of preventing tampering with the client.
[0005] To solve the above technical problems, in a first aspect of the present invention, a method for preventing tampering with client packages is disclosed, and the method includes:
[0006] Determine the code to be processed that needs to be encrypted corresponding to the client, and perform corresponding process differentiation operations on the code to be processed to obtain the main process code and the rendering process code;
[0007] According to a preset first encryption processing method, perform corresponding encryption operations on the main process code to obtain a first encryption result, and according to a preset second encryption processing method, perform corresponding encryption operations on the rendering process code to obtain a second encryption result;
[0008] When it is detected that the client is started, judge whether the client meets a preset information tampering condition according to the first encryption result and the second encryption result;
[0009] When it is determined that the client meets the information tampering condition, generate a software damage prompt instruction and / or end the corresponding program of the client.
[0010] As an alternative implementation, in the first aspect of the present invention, performing corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result includes:
[0011] Performing corresponding code compilation operations on the main process code according to a preset bytecode compiler to obtain a first processing result;
[0012] Performing corresponding code injection operations according to the main process code and the first processing result to obtain a second processing result;
[0013] Performing corresponding decryption step addition operations on the second processing result to obtain a third processing result;
[0014] Determining the first encryption result according to the third processing result.
[0015] As an alternative implementation, in the first aspect of the present invention, performing corresponding encryption operations on the rendering process code according to a preset second encryption processing method to obtain a second encryption result includes:
[0016] Performing corresponding compression package packaging operations on the rendering process code to obtain a fourth processing result;
[0017] Performing corresponding key determination operations on the fourth processing result to obtain key information, and performing corresponding key encryption operations on the fourth processing result according to the key information to obtain a fifth processing result;
[0018] Determining the second encryption result according to the fifth processing result.
[0019] As an alternative implementation, in the first aspect of the present invention, performing corresponding key determination operations on the fourth processing result to obtain key information includes:
[0020] Determining the binary file data corresponding to the fourth processing result according to the fourth processing result;
[0021] Performing corresponding symmetric encryption operations on the binary file data to obtain a first key determination result;
[0022] Performing corresponding hash function processing operations on the first key determination result to obtain a second key determination result;
[0023] Performing corresponding random salt encryption operations on the second key determination result to obtain a third key determination result;
[0024] Determining the key information according to the third key determination result.
[0025] As an alternative implementation, in the first aspect of the present invention, the method further includes:
[0026] When it is determined that the client does not meet the information tampering condition, determine the binary file data corresponding to the rendering process code, and determine the key information corresponding to the rendering process code;
[0027] Based on the key information, perform a corresponding decoding operation on the binary file data to obtain a file decoding result;
[0028] Perform a corresponding file decompression operation on the file decoding result to obtain a hash linked list result;
[0029] According to the application resource address package information obtained by loading, determine the uniform resource locator information, and based on the uniform resource locator information, perform a corresponding data analysis operation on the hash linked list result to obtain an original file result.
[0030] As an alternative implementation, in the first aspect of the present invention, the step of determining whether the client meets a preset information tampering condition according to the first encryption result and the second encryption result includes:
[0031] Perform a corresponding self-decryption operation on the first encryption result to obtain a main process file decryption result, and based on the main process file decryption result, determine a decryption hash function result;
[0032] According to the second encryption result and its corresponding rendering process file, determine an original hash function result;
[0033] Determine whether the decryption hash function result matches the original hash function result;
[0034] When it is determined that the decryption hash function result matches the original hash function result, determine that the client does not meet the preset information tampering condition;
[0035] When it is determined that the decryption hash function result does not match the original hash function result, determine that the client meets the preset information tampering condition.
[0036] As an alternative implementation, in the first aspect of the present invention, the method further includes:
[0037] According to a preset global variable configuration storage method, perform a corresponding storage operation on the determined key information and / or hash function result corresponding to the rendering process code.
[0038] The second aspect of the present invention discloses a packaging anti-tampering device for a client, and the device includes:
[0039] A determination module, configured to determine the code to be processed that needs to be encrypted corresponding to the client;
[0040] A process differentiation module, configured to perform corresponding process differentiation operations on the code to be processed to obtain a main process code and a rendering process code;
[0041] An encryption module, configured to perform corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result, and perform corresponding encryption operations on the rendering process code according to a preset second encryption processing method to obtain a second encryption result;
[0042] A judgment module, configured to, when detecting the startup of the client, judge whether the client meets a preset information tampering condition according to the first encryption result and the second encryption result;
[0043] A response module, configured to generate a software damage prompt instruction and / or terminate the program corresponding to the client when the judgment module determines that the client meets the information tampering condition.
[0044] As an optional implementation manner, in the second aspect of the present invention, the manner in which the encryption module performs corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result specifically includes:
[0045] Performing corresponding code compilation operations on the main process code according to a preset bytecode compiler to obtain a first processing result;
[0046] Performing corresponding code injection operations according to the main process code and the first processing result to obtain a second processing result;
[0047] Performing corresponding decryption step addition operations on the second processing result to obtain a third processing result;
[0048] Determining the first encryption result according to the third processing result.
[0049] As an optional implementation manner, in the second aspect of the present invention, the manner in which the encryption module performs corresponding encryption operations on the rendering process code according to a preset second encryption processing method to obtain a second encryption result specifically includes:
[0050] Performing corresponding compression package packaging operations on the rendering process code to obtain a fourth processing result;
[0051] Performing corresponding secret key determination operations on the fourth processing result to obtain secret key information, and performing corresponding secret key encryption operations on the fourth processing result according to the secret key information to obtain a fifth processing result;
[0052] Determine the second encryption result according to the fifth processing result.
[0053] As an alternative implementation, in the second aspect of the present invention, the manner in which the encryption module performs a corresponding key determination operation on the fourth processing result to obtain key information specifically includes:
[0054] Determine the binary file data corresponding to the fourth processing result according to the fourth processing result;
[0055] Perform a corresponding symmetric encryption operation on the binary file data to obtain a first key determination result;
[0056] Perform a corresponding hash function processing operation on the first key determination result to obtain a second key determination result;
[0057] Perform a corresponding random salt encryption operation on the second key determination result to obtain a third key determination result;
[0058] Determine the key information according to the third key determination result.
[0059] As an alternative implementation, in the second aspect of the present invention, the response module is further configured to, when the judgment module determines that the client does not meet the information tampering condition, determine the binary file data corresponding to the rendering process code and determine the key information corresponding to the rendering process code; based on the key information, perform a corresponding decoding operation on the binary file data to obtain a file decoding result; perform a corresponding file decompression operation on the file decoding result to obtain a hash linked list result; determine the uniform resource locator information according to the loaded application resource address packet information, and perform a corresponding data analysis operation on the hash linked list result according to the uniform resource locator information to obtain the original file result.
[0060] As an alternative implementation, in the second aspect of the present invention, the manner in which the judgment module determines whether the client meets a preset information tampering condition according to the first encryption result and the second encryption result specifically includes:
[0061] Perform a corresponding self-decryption operation on the first encryption result to obtain a main process file decryption result, and determine a decryption hash function result according to the main process file decryption result;
[0062] Determine an original hash function result according to the second encryption result and its corresponding rendering process file;
[0063] Determine whether the decryption hash function result matches the original hash function result;
[0064] When it is determined that the result of the decryption hash function matches the result of the original hash function, it is determined that the client does not meet the preset information tampering condition;
[0065] When it is determined that the result of the decryption hash function does not match the result of the original hash function, it is determined that the client meets the preset information tampering condition.
[0066] As an optional implementation manner, in the second aspect of the present invention, the device further includes:
[0067] A storage module, configured to perform corresponding storage operations on the determined secret key information and / or hash function result corresponding to the rendering process code according to a preset global variable configuration storage method.
[0068] The third aspect of the present invention discloses another packaging anti-tampering device for a client, and the device includes:
[0069] A memory storing executable program code;
[0070] A processor coupled to the memory;
[0071] The processor calls the executable program code stored in the memory and executes a packaging anti-tampering method for a client disclosed in the first aspect of the present invention.
[0072] The fourth aspect of the present invention discloses a computer storage medium, and the computer storage medium stores computer instructions, which are used to execute a packaging anti-tampering method for a client disclosed in the first aspect of the present invention when being called.
[0073] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:
[0074] In an embodiment of the present invention, the to-be-processed code that needs to be encrypted and corresponds to the client is determined, and corresponding process differentiation operations are performed on the to-be-processed code to obtain the main process code and the rendering process code; according to a preset first encryption processing method, corresponding encryption operations are performed on the main process code to obtain a first encryption result, and according to a preset second encryption processing method, corresponding encryption operations are performed on the rendering process code to obtain a second encryption result; when it is detected that the client is started, according to the first encryption result and the second encryption result, it is determined whether the client meets a preset information tampering condition; when it is determined that the client meets the information tampering condition, a software damage prompt instruction is generated and / or the program corresponding to the client is terminated. It can be seen that the present invention can perform hierarchical encryption and sub-packet encryption on the to-be-processed code, and the main process code and the rendering process code respectively match corresponding encryption processing methods. When the client meets the information tampering condition, it cannot be used continuously, which is beneficial to improving the pertinence, diversity and flexibility of the client code encryption method, and is beneficial to improving the comprehensiveness and rationality of the client code encryption method, thereby being beneficial to improving the encryption accuracy and reliability of the code. In addition, it is beneficial to improve the comprehensiveness and rationality of the client anti-tampering method, thereby being beneficial to improving the timeliness, accuracy and efficiency of the client's anti-tampering response, and thus being beneficial to improving the running security and stability of the client. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.
[0076] Figure 1 is a schematic flowchart of a method for preventing tampering with a client package disclosed in an embodiment of the present invention;
[0077] Figure 2 is a schematic flowchart of another method for preventing tampering with a client package disclosed in an embodiment of the present invention;
[0078] Figure 3 is a schematic structural diagram of a device for preventing tampering with a client package disclosed in an embodiment of the present invention;
[0079] Figure 4 is a schematic structural diagram of another device for preventing tampering with a client package disclosed in an embodiment of the present invention;
[0080] Figure 5 is a schematic structural diagram of yet another device for preventing tampering with a client package disclosed in an embodiment of the present invention;
[0081] Figure 6 It is a schematic flowchart of another method for preventing tampering with client-side packaging disclosed in the embodiments of the present invention. Detailed implementation manners
[0082] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0083] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or terminal including a series of steps or units is not limited to the listed steps or units, but optionally further includes unlisted steps or units, or optionally further includes other steps or units inherent to these processes, methods, products, or terminals.
[0084] Referring to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.
[0085] The present invention discloses a method and apparatus for preventing tampering with client-side packaging, which can perform hierarchical encryption and sub-packaging encryption on the code to be processed. The main process code and the rendering process code respectively match corresponding encryption processing methods. When the client meets the information tampering conditions, it cannot continue to be used, which is beneficial to improving the pertinence, diversity, and flexibility of the client code encryption method, and is beneficial to improving the comprehensiveness and rationality of the client code encryption method, thereby being beneficial to improving the encryption accuracy and reliability of the code. In addition, it is also beneficial to improving the comprehensiveness and rationality of the client tampering prevention method, and thus being beneficial to improving the timeliness, accuracy, and efficiency of the client's response to tampering, and thereby being beneficial to improving the running security and stability of the client. The following will be described in detail respectively.
[0086] Embodiment 1
[0087] Please refer to Figure 1 , Figure 1It is a schematic flowchart of a method for preventing tampering with client-side packages disclosed in an embodiment of the present invention. Among them, Figure 1 The described method can be applied to a device for preventing tampering with client-side packages. Among them, the device can include a server, where the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 1 shown, the method for preventing tampering with client-side packages includes the following operations:
[0088] 101. Determine the code to be processed that needs to be encrypted corresponding to the client, and perform corresponding process differentiation operations on the code to be processed to obtain the main process code and the rendering process code.
[0089] Optionally, the code to be processed is determined through the plugin at the start of the afterPack stage, which is not limited in the embodiments of the present invention.
[0090] Optionally, the main process code can be understood as the logic layer, such as window creation, data storage parts, etc., which is not limited in the embodiments of the present invention.
[0091] Optionally, the rendering process code can be understood as the visible part, such as specific buttons, pages, picture parts, etc., which is not limited in the embodiments of the present invention.
[0092] 102. According to the preset first encryption processing method, perform corresponding encryption operations on the main process code to obtain the first encryption result, and according to the preset second encryption processing method, perform corresponding encryption operations on the rendering process code to obtain the second encryption result.
[0093] Optionally, as Figure 6 shown, it discloses a schematic flowchart of another method for preventing tampering with client-side packages, which is not limited in the embodiments of the present invention.
[0094] Optionally, the first encryption result can be used to represent the encryption situation and / or encryption information content of the main process code, and can also be used to represent the generated main-c.cjs file, which is not limited in the embodiments of the present invention.
[0095] Optionally, the second encryption result can be used to represent the encryption situation and / or encryption information content of the rendering process code, and can also be used to represent the generated encrypt.render, which is not limited in the embodiments of the present invention.
[0096] Further optionally, when the first encryption result is obtained, it can be determined that the encryption of the main process code is completed; when the second encryption result is obtained, it can be determined that the encryption of the rendering process is completed, and then it can be determined that the encryption is ended, which is not limited in the embodiments of the present invention.
[0097] Optionally, the AES key is stored in the main process package encrypted by bytecode, which is not limited in the embodiments of the present invention.
[0098] 103. When it is detected that the client is started, determine whether the client meets the preset information tampering condition according to the first encryption result and the second encryption result.
[0099] 104. When it is determined that the client meets the information tampering condition, generate a software damage prompt instruction and / or end the corresponding program of the client.
[0100] Optionally, the above generation of the software damage prompt instruction, for example: pop-up window software loss / custom prompt, which is not limited in the embodiments of the present invention.
[0101] Optionally, the above ending of the corresponding process of the client, for example: program ending, which is not limited in the embodiments of the present invention.
[0102] It can be seen that a packaging anti-tampering method for the client described in the embodiments of the present invention can perform hierarchical encryption and sub-packet encryption on the code to be processed. The main process code and the rendering process code respectively match the corresponding encryption processing methods. When the client meets the information tampering condition, it cannot be used continuously, which is beneficial to improving the pertinence, diversity and flexibility of the client code encryption method, and is beneficial to improving the comprehensiveness and rationality of the client code encryption method, and further beneficial to improving the encryption accuracy and reliability of the code. In addition, it is also beneficial to improve the comprehensiveness and rationality of the client anti-tampering method, and further beneficial to improving the timeliness, accuracy and efficiency of the client's anti-tampering response, thereby being beneficial to improving the running security and stability of the client.
[0103] In an optional embodiment, the above-mentioned performing corresponding encryption operations on the main process code according to the preset first encryption processing method to obtain the first encryption result may include:
[0104] Performing corresponding code compilation operations on the main process code according to the preset bytecode compiler to obtain the first processing result;
[0105] Performing corresponding code injection operations according to the main process code and the first processing result to obtain the second processing result;
[0106] Performing corresponding decryption step addition operations on the second processing result to obtain the third processing result;
[0107] Determining the first encryption result according to the third processing result.
[0108] Optionally, the bytecode editor can be bytenode or other device equipment that can achieve a code compilation function similar to bytenode, which is not limited in the embodiments of the present invention.
[0109] Optionally, the first processing result can be understood as an encrypted main process file; further, according to the main process code and the first processing result, perform the corresponding code injection operation to obtain the second processing result. For example, before injecting the encrypted main process file into the original main process code, the embodiments of the present invention do not make any limitations.
[0110] Optionally, the above decryption step addition operation can specifically be adding the decryption content regarding the decryption stage of the encryption plug-in recorded in this solution. The embodiments of the present invention do not make any limitations.
[0111] Optionally, the above determining the first encryption result according to the third processing result may include: determining the third processing result as the first encryption result. The embodiments of the present invention do not make any limitations.
[0112] It can be seen that this optional embodiment can implement the main process code encryption method through code compilation operations, code injection operations, and decryption step addition operations, which is beneficial to improving the comprehensiveness and rationality of the main process code encryption method, and further beneficial to improving the pertinence of the main process code encryption method, thereby being beneficial to improving the accuracy and reliability of the obtained first encryption result, and further beneficial to improving the encryption accuracy and reliability of the main process code.
[0113] In another optional embodiment, the above performing the corresponding encryption operation on the rendering process code according to the preset second encryption processing method to obtain the second encryption result may include:
[0114] Performing the corresponding compression package packaging operation on the rendering process code to obtain the fourth processing result;
[0115] Performing the corresponding key determination operation on the fourth processing result to obtain the key information, and according to the key information, performing the corresponding key encryption operation on the fourth processing result to obtain the fifth processing result;
[0116] Determining the second encryption result according to the fifth processing result.
[0117] Optionally, the above performing the corresponding compression package packaging operation on the rendering process code to obtain the fourth processing result. For example, packaging the rendering process code into a compression package (i.e., the fourth processing result). The embodiments of the present invention do not make any limitations.
[0118] Optionally, the above performing the corresponding key encryption operation on the fourth processing result according to the key information to obtain the fifth processing result. For example, encrypting the compression package data (i.e., the fourth processing result) based on the key information to obtain the fifth processing result; further, replacing the original compression package data with the source code of the rendering process to obtain the encrypted rendering process file. The embodiments of the present invention do not make any limitations.
[0119] Optionally, determining the second encryption result based on the fifth processing result may include: determining the fifth processing result as the second encryption result, which is not limited in the embodiments of the present invention.
[0120] It can be seen that this optional embodiment can implement the rendering process code encryption method through operations such as compression package packaging, key determination, and key encryption, which is beneficial to improving the comprehensiveness and rationality of the rendering process code encryption method, and thus beneficial to improving the pertinence of the rendering process code encryption method, thereby being beneficial to improving the accuracy and reliability of the obtained second encryption result, and further being beneficial to improving the encryption accuracy and reliability of the rendering process code.
[0121] In another optional embodiment, performing the corresponding key determination operation on the fourth processing result to obtain the key information may include:
[0122] Determining the binary file data corresponding to the fourth processing result according to the fourth processing result;
[0123] Performing the corresponding symmetric encryption operation on the binary file data to obtain the first key determination result;
[0124] Performing the corresponding hash function processing operation on the first key determination result to obtain the second key determination result;
[0125] Performing the corresponding random salt encryption operation on the second key determination result to obtain the third key determination result;
[0126] Determining the key information according to the third key determination result.
[0127] Optionally, determining the binary file data corresponding to the fourth processing result according to the fourth processing result, for example: obtaining the binary file data of the compression package, which is not limited in the embodiments of the present invention.
[0128] Optionally, performing the corresponding symmetric encryption operation on the binary file data to obtain the first key determination result, for example: performing aes-256-cbc encryption, which is not limited in the embodiments of the present invention.
[0129] Optionally, performing the corresponding hash function processing operation on the first key determination result to obtain the second key determination result, for example: performing MD5 processing on the incoming key, which is not limited in the embodiments of the present invention.
[0130] Optionally, performing the corresponding random salt encryption operation on the second key determination result to obtain the third key determination result, for example: using random salt for encryption, which is not limited in the embodiments of the present invention.
[0131] Optionally, determining the key information based on the result of the third key may include: determining the result of the third key as the key information, which is not limited in the embodiments of the present invention.
[0132] It can be seen that this optional embodiment can provide a method for determining key information. By performing operations such as binary file data determination, symmetric encryption operation, hash function processing operation, and random salt encryption operation to obtain the key information, it is beneficial to improve the comprehensiveness, rationality, and progressive nature of the key information determination method. Furthermore, it is beneficial to improve the accuracy and reliability of the determined key information, and it is beneficial to improve the relevance between the determined key information and the rendering process code, thereby facilitating the improvement of the encryption pertinence, accuracy, and reliability of the rendering process code based on the key information.
[0133] In yet another optional embodiment, the method may further include the following operations:
[0134] According to the preset global variable configuration storage method, perform corresponding storage operations on the key information and / or hash function result corresponding to the determined rendering process code.
[0135] Optionally, the above-mentioned corresponding storage operations on the key information and / or hash function result corresponding to the determined rendering process code are exemplified as: storing the key information and / or hash function result in global variables, which is not limited in the embodiments of the present invention.
[0136] Optionally, the hash function result may correspond to the md5 of the above-mentioned compressed package, which is not limited in the embodiments of the present invention.
[0137] It can be seen that this optional embodiment can provide a storage method for key information and hash function results, which is beneficial to improve the pertinence and rationality of the storage method for key information and hash function results. Furthermore, it is beneficial to improve the storage accuracy, pertinence, and reliability of key information and hash function results, thereby facilitating the improvement of the application accuracy and reliability of subsequent key information and hash function results.
[0138] Embodiment 2
[0139] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of another method for preventing tampering with client packages disclosed in the embodiments of the present invention. Among them, Figure 2 the described method can be applied to a device for preventing tampering with client packages. Among them, the device may include a server, where the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 2 shown, this method for preventing tampering with client packages includes the following operations:
[0140] 201. Determine the code to be processed that needs to be encrypted for the client, and perform corresponding process differentiation operations on the code to be processed to obtain the main process code and the rendering process code.
[0141] 202. According to the preset first encryption method, perform corresponding encryption operations on the main process code to obtain the first encryption result, and according to the preset second encryption method, perform corresponding encryption operations on the rendering process code to obtain the second encryption result.
[0142] 203. When it is detected that the client starts, perform corresponding self-decryption operations on the first encryption result to obtain the decryption result of the main process file. According to the decryption result of the main process file, determine the decryption hash function result, and according to the second encryption result and its corresponding rendering process file, determine the original hash function result.
[0143] Optionally, the above-mentioned corresponding self-decryption operations on the first encryption result, for example: bytenode self-decrypts the main process file, which is not limited in the embodiments of the present invention.
[0144] Optionally, the original hash function result can be understood as the hash function result stored and recorded during the above-mentioned encryption operation; the decryption hash function result can be understood as the hash function result obtained after the current encryption plugin is decrypted, which is not limited in the embodiments of the present invention.
[0145] Optionally, both the original hash function result and the decryption hash function result correspond to md5, which is not limited in the embodiments of the present invention.
[0146] 204. Judge whether the decryption hash function result matches the original hash function result. When the judgment result is no, execute step 205; when the judgment result is yes, execute step 206.
[0147] 205. Generate a software damage prompt instruction and / or end the corresponding program of the client.
[0148] 206. Determine the binary file data corresponding to the rendering process code, and determine the secret key information corresponding to the rendering process code; based on the secret key information, perform corresponding decoding operations on the binary file data to obtain the file decoding result; perform corresponding file decompression operations on the file decoding result to obtain the hash linked list result; according to the loaded application resource address package information, determine the uniform resource locator information, and according to the uniform resource locator information, perform corresponding data analysis operations on the hash linked list result to obtain the original file result.
[0149] Optionally, the above-mentioned corresponding file decompression operations on the file decoding result to obtain the hash linked list result, for example: decompress the decoded file to generate a path-binary data hash linked list, which is not limited in the embodiments of the present invention.
[0150] Optionally, the application resource address package information can be obtained by loading the application, and the embodiments of the present invention do not make limitations.
[0151] Optionally, the uniform resource locator information can correspond to a URI address, and the embodiments of the present invention do not make limitations.
[0152] Optionally, according to the above uniform resource locator information, corresponding data analysis operations are performed on the hash linked list result to obtain the original file result. For example: the original file is obtained by obtaining hash linked list data through the loaded uri, and the embodiments of the present invention do not make limitations.
[0153] Further optionally, according to the above uniform resource locator information, performing corresponding data analysis operations on the hash linked list result to obtain the original file result may include:
[0154] Judging whether the target data exists according to the uniform resource locator information and the data query;
[0155] When it is judged that the target data exists, return the target data and determine that the loading is successful, and the target data is used to determine the original file result;
[0156] When it is judged that the target data does not exist, determine that the loading fails.
[0157] In the embodiments of the present invention, for other descriptions of steps 201-step 206, please refer to the detailed descriptions of steps 101-104 in Embodiment 1, and the embodiments of the present invention will not be elaborated herein.
[0158] It can be seen that the embodiments of the present invention can perform hierarchical encryption and sub-packet encryption on the code to be processed. The main process code and the rendering process code respectively match corresponding encryption processing methods. When the client meets the information tampering conditions, it cannot be used continuously, which is beneficial to improving the pertinence, diversity and flexibility of the client code encryption method, and is beneficial to improving the comprehensiveness and rationality of the client code encryption method. Furthermore, it is beneficial to improve the encryption accuracy and reliability of the code. In addition, it is also beneficial to improve the comprehensiveness and rationality of the client anti-tampering method, and then is beneficial to improve the timeliness, accuracy and efficiency of the client's anti-tampering response, thereby being beneficial to improving the running security and stability of the client; and, it can also determine the decryption hash function result and the original hash function result, and then determine the satisfaction result of the information tampering condition according to the matching situation between the decryption hash function result and the original hash function result, which is beneficial to improving the comprehensiveness, integrity and rationality of the information tampering condition satisfaction result determination method. Furthermore, it is beneficial to improve the accuracy and reliability of the determined information tampering condition satisfaction result, thereby being beneficial to improving the execution timeliness, rationality, accuracy and reliability of the subsequent operation triggered based on the information tampering condition satisfaction result; and, it can also obtain the original file result through decoding operation, file decompression operation and data analysis operation on the hash linked list result, which is beneficial to improving the comprehensiveness and rationality of the decryption method and the original file result determination method. Furthermore, it is beneficial to improve the decryption accuracy and reliability of the client file, and is beneficial to improving the accuracy and reliability of the determined original file result.
[0159] Embodiment III
[0160] Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of a packaging anti-tampering device for a client disclosed in the embodiments of the present invention. Among them, Figure 3 the described device may include a server, where the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 3 shown, the packaging anti-tampering device for a client may include:
[0161] A determination module 301, configured to determine the code to be processed that needs to be encrypted corresponding to the client.
[0162] A process differentiation module 302, configured to perform corresponding process differentiation operations on the code to be processed to obtain the main process code and the rendering process code.
[0163] An encryption module 303, configured to perform corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result, and perform corresponding encryption operations on the rendering process code according to a preset second encryption processing method to obtain a second encryption result.
[0164] A judgment module 304, configured to determine whether the client meets a preset information tampering condition according to a first encryption result and a second encryption result when it is detected that the client is started.
[0165] A response module 305, configured to generate a software damage prompt instruction and / or terminate the corresponding program of the client when the judgment module determines that the client meets the information tampering condition.
[0166] It can be seen that implementing Figure 3 The described anti-tampering device for client packaging can perform hierarchical encryption and sub-packaging encryption on the code to be processed. The main process code and the rendering process code respectively match corresponding encryption processing methods. When the client meets the information tampering condition, it cannot be used continuously, which is beneficial to improving the pertinence, diversity and flexibility of the client code encryption method, and is beneficial to improving the comprehensiveness and rationality of the client code encryption method, thereby being beneficial to improving the encryption accuracy and reliability of the code. In addition, it is also beneficial to improving the comprehensiveness and rationality of the client anti-tampering method, and thus being beneficial to improving the timeliness, accuracy and efficiency of the client's anti-tampering response, and thereby being beneficial to improving the running security and stability of the client.
[0167] In an optional embodiment, the manner in which the encryption module 303 performs corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result specifically includes:
[0168] Performing corresponding code compilation operations on the main process code according to a preset bytecode compiler to obtain a first processing result;
[0169] Performing corresponding code injection operations according to the main process code and the first processing result to obtain a second processing result;
[0170] Performing corresponding decryption step addition operations on the second processing result to obtain a third processing result;
[0171] Determining the first encryption result according to the third processing result.
[0172] It can be seen that implementing Figure 4 The described device can implement the main process code encryption method through code compilation operations, code injection operations and decryption step addition operations, which is beneficial to improving the comprehensiveness and rationality of the main process code encryption method, and thus being beneficial to improving the pertinence of the main process code encryption method, and thereby being beneficial to improving the accuracy and reliability of the obtained first encryption result, and further being beneficial to improving the encryption accuracy and reliability of the main process code.
[0173] In another alternative embodiment, the encryption module 303 performs corresponding encryption operations on the rendering process code according to a preset second encryption processing method. The specific method for obtaining the second encryption result includes:
[0174] Performing corresponding compression package packaging operations on the rendering process code to obtain a fourth processing result;
[0175] Performing corresponding key determination operations on the fourth processing result to obtain key information, and according to the key information, performing corresponding key encryption operations on the fourth processing result to obtain a fifth processing result;
[0176] Determining the second encryption result according to the fifth processing result.
[0177] It can be seen that implementing Figure 4 The described device can also implement the rendering process code encryption method through compression package packaging operations, key determination operations, and key encryption operations, which is beneficial to improving the comprehensiveness and rationality of the rendering process code encryption method, and further beneficial to improving the pertinence of the rendering process code encryption method, thereby being beneficial to improving the accuracy and reliability of the obtained second encryption result, and further beneficial to improving the encryption accuracy and reliability of the rendering process code.
[0178] In yet another alternative embodiment, the specific method for the encryption module 303 to perform corresponding key determination operations on the fourth processing result to obtain key information includes:
[0179] Determining the binary file data corresponding to the fourth processing result according to the fourth processing result;
[0180] Performing corresponding symmetric encryption operations on the binary file data to obtain a first key determination result;
[0181] Performing corresponding hash function processing operations on the first key determination result to obtain a second key determination result;
[0182] Performing corresponding random salt encryption operations on the second key determination result to obtain a third key determination result;
[0183] Determining the key information according to the third key determination result.
[0184] It can be seen that implementing Figure 4The described device is also capable of providing a method for determining key information. By performing operations such as binary file data determination operations, symmetric encryption operations, hash function processing operations, and random salt encryption operations on the binary file data, the key information is obtained. This is beneficial to improving the comprehensiveness, rationality, and progressive nature of the key information determination method, thereby facilitating the improvement of the accuracy and reliability of the determined key information, as well as enhancing the relevance between the determined key information and the rendering process code. Consequently, it is conducive to improving the encryption pertinence, accuracy, and reliability of the rendering process code based on the key information.
[0185] In yet another alternative embodiment, the response module 305 is further configured to, when the judgment module 304 determines that the client does not meet the information tampering condition, determine the binary file data corresponding to the rendering process code and determine the key information corresponding to the rendering process code; based on the key information, perform corresponding decoding operations on the binary file data to obtain a file decoding result; perform corresponding file decompression operations on the file decoding result to obtain a hash linked list result; according to the loaded application resource address packet information, determine the uniform resource locator information, and based on the uniform resource locator information, perform corresponding data analysis operations on the hash linked list result to obtain the original file result.
[0186] It can be seen that implementing Figure 4 The described device is also capable of obtaining the original file result through decoding operations, file decompression operations, and data analysis operations on the hash linked list result, which is beneficial to improving the comprehensiveness and rationality of the decryption method and the original file result determination method. Consequently, it is conducive to improving the decryption accuracy and reliability of the client file, as well as enhancing the accuracy and reliability of the determined original file result.
[0187] In yet another alternative embodiment, the manner in which the judgment module 304 determines whether the client meets the preset information tampering condition based on the first encryption result and the second encryption result specifically includes:
[0188] Perform corresponding self-decryption operations on the first encryption result to obtain the main process file decryption result, and based on the main process file decryption result, determine the decryption hash function result;
[0189] Based on the second encryption result and its corresponding rendering process file, determine the original hash function result;
[0190] Judge whether the decryption hash function result matches the original hash function result;
[0191] When it is determined that the decryption hash function result matches the original hash function result, it is determined that the client does not meet the preset information tampering condition;
[0192] When it is determined that the result of the decryption hash function does not match the result of the original hash function, it is determined that the client meets the preset information tampering condition.
[0193] It can be seen that implementing Figure 4 The described device can also determine the result of the decryption hash function and the result of the original hash function, and then determine the satisfaction result of the information tampering condition based on the matching situation between the result of the decryption hash function and the result of the original hash function, which is beneficial to improving the comprehensiveness, integrity, and rationality of the method for determining the satisfaction result of the information tampering condition, and further beneficial to improving the accuracy and reliability of the determined satisfaction result of the information tampering condition, thereby being beneficial to improving the execution timeliness, rationality, accuracy, and reliability of the subsequent operations triggered based on the satisfaction result of the information tampering condition.
[0194] In another optional embodiment, as Figure 4 shown, the device may further include:
[0195] A storage module 306, configured to perform corresponding storage operations on the determined secret key information and / or hash function result corresponding to the rendering process code according to the preset global variable configuration storage method.
[0196] It can be seen that implementing Figure 4 The described device can also provide a storage method for the secret key information and the hash function result, which is beneficial to improving the pertinence and rationality of the storage method for the secret key information and the hash function result, and further beneficial to improving the storage accuracy, pertinence, and reliability of the secret key information and the hash function result, thereby being beneficial to improving the application accuracy and reliability of the subsequent secret key information and the hash function result.
[0197] Embodiment 4
[0198] Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of another device for preventing tampering with the package for the client disclosed in the embodiments of the present invention. Among them, Figure 5 The described device may include a server, where the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 5 shown, the device may include:
[0199] A memory 401 storing executable program code;
[0200] A processor 402 coupled to the memory 401;
[0201] Further, it may further include an input interface 403 and an output interface 404 coupled to the processor 402;
[0202] Among them, the processor 402 calls the executable program code stored in the memory 401 to execute the steps in a method for preventing tampering with a package for a client described in Embodiment 1 or Embodiment 2.
[0203] Embodiment 5
[0204] An embodiment of the present invention discloses a computer storage medium that stores a computer program for electronic data exchange. Among them, the computer program enables a computer to execute the steps in a method for preventing tampering with a package for a client described in Embodiment 1 or Embodiment 2.
[0205] Embodiment 6
[0206] An embodiment of the present invention discloses a computer program product. The computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps in a method for preventing tampering with a package for a client described in Embodiment 1 or Embodiment 2.
[0207] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.
[0208] Through the specific descriptions of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solutions, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, and the storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other computer-readable medium that can be used to carry or store data.
[0209] Finally, it should be noted that: The disclosed a method and device for preventing tampering with packages for clients in the embodiments of the present invention are only the preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than limiting them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: They can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for preventing tampering with packages for clients, characterized in that, The method includes: Determine the code to be processed that needs to be encrypted corresponding to the client, and perform corresponding process differentiation operations on the code to be processed to obtain the main process code and the rendering process code; According to a preset first encryption processing method, perform corresponding encryption operations on the main process code to obtain a first encryption result, and according to a preset second encryption processing method, perform corresponding encryption operations on the rendering process code to obtain a second encryption result; When it is detected that the client is started, determine whether the client meets a preset information tampering condition according to the first encryption result and the second encryption result; When it is determined that the client meets the information tampering condition, generate a software damage prompt instruction and / or end the program corresponding to the client.
2. The packaging anti-tampering method for a client according to claim 1, wherein The performing corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result includes: Perform corresponding code compilation operations on the main process code according to a preset bytecode compiler to obtain a first processing result; Perform corresponding code injection operations according to the main process code and the first processing result to obtain a second processing result; Perform corresponding decryption step addition operations on the second processing result to obtain a third processing result; Determine the first encryption result according to the third processing result.
3. A method for preventing tampering with a package for a client according to claim 1, characterized in that, The performing corresponding encryption operations on the rendering process code according to a preset second encryption processing method to obtain a second encryption result includes: Perform corresponding compression package packaging operations on the rendering process code to obtain a fourth processing result; Perform corresponding key determination operations on the fourth processing result to obtain key information, and according to the key information, perform corresponding key encryption operations on the fourth processing result to obtain a fifth processing result; Determine the second encryption result according to the fifth processing result.
4. A method for preventing tampering with a package for a client according to claim 3, characterized in that, The performing corresponding key determination operations on the fourth processing result to obtain key information includes: Determine the binary file data corresponding to the fourth processing result according to the fourth processing result; Perform corresponding symmetric encryption operations on the binary file data to obtain a first key determination result; Perform corresponding hash function processing operations on the first key determination result to obtain a second key determination result; Perform corresponding random salt encryption operations on the second key determination result to obtain a third key determination result; Determine the key information according to the third key determination result.
5. A method for preventing tampering with a package for a client according to claim 1, characterized in that, The method further includes: When it is determined that the client does not meet the information tampering condition, determine the binary file data corresponding to the rendering process code and determine the key information corresponding to the rendering process code; Based on the key information, perform corresponding decoding operations on the binary file data to obtain a file decoding result; Perform corresponding file decompression operations on the file decoding result to obtain a hash linked list result; Based on the application resource address package information obtained by loading, determine the uniform resource locator information, and perform corresponding data analysis operations on the hash linked list result according to the uniform resource locator information to obtain the original file result.
6. A method for preventing tampering with a package for a client according to claim 1, characterized in that, The determining whether the client meets the preset information tampering condition according to the first encryption result and the second encryption result includes: Perform corresponding self-decryption operations on the first encryption result to obtain the main process file decryption result, and determine the decryption hash function result according to the main process file decryption result; Determine the original hash function result according to the second encryption result and its corresponding rendering process file; Judge whether the decryption hash function result matches the original hash function result; When it is determined that the decryption hash function result matches the original hash function result, determine that the client does not meet the preset information tampering condition; When it is determined that the decryption hash function result does not match the original hash function result, determine that the client meets the preset information tampering condition.
7. A method for preventing tampering with a package for a client according to any one of claims 1-6, characterized in that, The method further includes: According to the preset global variable configuration storage method, perform corresponding storage operations on the determined secret key information and / or hash function result corresponding to the rendering process code.
8. A packaging anti-tampering device for a client, characterized in that, The device includes: A determination module, configured to determine the code to be processed that needs to be encrypted corresponding to the client; A process differentiation module, configured to perform corresponding process differentiation operations on the code to be processed to obtain the main process code and the rendering process code; An encryption module, configured to perform corresponding encryption operations on the main process code according to a preset first encryption processing method to obtain a first encryption result, and perform corresponding encryption operations on the rendering process code according to a preset second encryption processing method to obtain a second encryption result; A judgment module, configured to judge whether the client meets the preset information tampering condition according to the first encryption result and the second encryption result when it is detected that the client starts; A response module, configured to generate a software damage prompt instruction and / or terminate the program corresponding to the client when the judgment module determines that the client meets the information tampering condition.
9. A packaging anti-tampering device for a client, characterized in that The device includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory and executes a method for preventing tampering with a client package according to any one of claims 1-7.
10. A computer storage medium, characterized in that, The computer storage medium stores computer instructions, which are used to execute a method for preventing tampering with a client package according to any one of claims 1-7 when the computer instructions are called.