Code protection method and device, electronic equipment and storage medium

By determining the target assembly instructions in the so dynamic library and executing jump instructions in the protection library, the problem that the so file is easily cracked is solved, and more efficient code protection is achieved.

CN120353470APending Publication Date: 2025-07-22BEIJING BANGCLE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410088192.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing so file protection method has the problem that so file is easy to be cracked.

Method used

By obtaining the protected program of the so dynamic library, the target assembly instructions are determined, and input them into the preset protection library with protection code function, the jump instructions corresponding to the target assembly instructions are set, and the target assembly instructions are executed from the protection library when the call instruction is received.

Benefits of technology

It enhances the security of so files, increases the difficulty of code protection, and makes so files more difficult to crack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120353470A_ABST
    Figure CN120353470A_ABST
Patent Text Reader

Abstract

The invention discloses a code protection method, belongs to the technical field of security of Android applications, and is used for solving the problem that a so file is easy to crack in an existing so file protection method. The method comprises the steps of obtaining a to-be-protected program of a so dynamic library, and determining a target assembly instruction based on the to-be-protected program; inputting the target assembly instruction into a preset protection library, wherein the preset protection library is a library with a code protection function; setting a jump instruction corresponding to the target assembly instruction based on the to-be-protected program; and when a calling instruction for calling the to-be-protected program is received, executing operation on a target assembly instruction from the protection library based on the jump instruction set for the to-be-protected program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of Android application security, and specifically relates to a code protection method, device, electronic device, and storage medium. Background Art

[0002] With the rapid development of Android technology, there are more and more applications developed under the Android system. How to protect the shared object (so) files in Android applications from decompilation has become an important issue. Currently, the main method for protecting so files is shelling. Specifically, on the server side, the so file is encrypted, and the shell file is compiled. Then, the encrypted so file is appended to the end of the shell file. When the so file is run on the terminal side, the so file is first decrypted from the shell file, and then the so file is dynamically loaded. At this time, on the terminal side, the system linker is required to perform the loading operation of the so file, and the system linker will perform memory mapping on the so file. An attacker can dump the entire so file from the memory. Since the so file conforms to the Executable and Linking Format (ELF), the attacker can easily crack the application program based on the file structure under ELF, and then decompile the application program.

[0003] It can be seen that the so file protection method in the prior art has the problem that the so file is easily cracked. Summary of the Invention

[0004] The embodiments of this application provide a code protection method, which can solve the problem that the so file in the existing so file protection method is easily cracked.

[0005] In a first aspect, the embodiments of this application provide a code protection method, which includes: obtaining a program to be protected in an so dynamic library, and determining target assembly instructions based on the program to be protected; inputting the target assembly instructions into a preset protection library, where the preset protection library is a library with a protection code function; setting a jump instruction corresponding to the target assembly instructions based on the program to be protected; and when a call instruction for calling the program to be protected is received, performing an execution operation on the target assembly instructions from the protection library based on the jump instruction set for the program to be protected.

[0006] In a second aspect, an embodiment of the present application provides a code protection device, which includes: a first determination module, configured to obtain a program to be protected in an so dynamic library and determine target assembly instructions based on the program to be protected; a first input module, configured to input the target assembly instructions into a preset protection library, where the preset protection library is a library with a code protection function; a first setting module, configured to set a jump instruction corresponding to the target assembly instructions based on the program to be protected; and a first execution module, configured to, when receiving a call instruction for calling the program to be protected, perform an execution operation on the target assembly instructions from the protection library based on the jump instruction set for the program to be protected.

[0007] In a third aspect, an embodiment of the present application provides an electronic device, which includes a processor, a memory, and a program or instruction stored in the memory and executable on the processor. When the program or instruction is executed by the processor, the steps of the method described in the first aspect are implemented.

[0008] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0009] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor, and the processor is configured to run a code protection method to implement the method described in the first aspect.

[0010] In the embodiment of the present application, by obtaining a program to be protected in an so dynamic library, determining target assembly instructions based on the program to be protected, inputting the target assembly instructions into a preset protection library, where the preset protection library is a library with a code protection function, setting a jump instruction corresponding to the target assembly instructions based on the program to be protected, and performing an execution operation on the target assembly instructions from the protection library based on the jump instruction set for the program to be protected when receiving a call instruction for calling the program to be protected, the problem that the existing so file protection method is prone to being cracked can be solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 is a schematic flowchart of a code protection method provided by an embodiment of the present application;

[0012] Figure 2 is a schematic flowchart of a second code protection method provided by an embodiment of the present application;

[0013] Figure 3 is a schematic diagram of a main program file format provided by an embodiment of the present application;

[0014] Figure 4 It is a schematic flowchart of a method for executing initialization instructions provided by an embodiment of the present application;

[0015] Figure 5 It is a schematic flowchart of the third code protection method provided by an embodiment of the present application;

[0016] Figure 6 It is a schematic flowchart of the fourth code protection method provided by an embodiment of the present application;

[0017] Figure 7 It is a schematic structural diagram of a code protection device provided by an embodiment of the present application;

[0018] Figure 8 It is a schematic structural diagram of a code protection device provided by an embodiment of the present application. Detailed implementation manners

[0019] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0020] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order different from those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means an "or" relationship between the associated objects before and after.

[0021] Next, the code protection method provided by the embodiments of the present application will be described in detail in conjunction with the accompanying drawings through specific embodiments and their application scenarios.

[0022] Figure 1 A code protection method provided by an embodiment of the present invention is shown. This method can be executed by an electronic device, which can include: a server and / or a terminal device, where the terminal device can be, for example, an in-vehicle terminal or a mobile phone terminal, etc. In other words, this method can be executed by software or hardware installed in a code protection device. The method includes the following steps:

[0023] Step 102: Obtain the program to be protected in the so dynamic library, and determine the target assembly instruction based on the program to be protected;

[0024] Obtain the program content in the so dynamic library that needs to be protected, and determine the target assembly instruction according to the program to be protected. Among them, the program to be protected in the so dynamic library can be obtained from the APK installation package. The APK installation package can be decompressed to obtain the program to be protected in the so dynamic library. The target assembly instruction is the assembly instruction corresponding to the program to be protected. When determining the target assembly instruction based on the program to be protected, the binary machine code language in the so dynamic library is converted into assembly language (i.e., the target assembly instruction).

[0025] When obtaining the program to be protected in the so dynamic library and determining the target assembly instruction based on the program to be protected, the program in the so dynamic library can be obtained, and then the program to be protected can be determined based on the program in the so dynamic library, and the target assembly instruction corresponding to the program to be protected can be determined. It is also possible to obtain the program in the so dynamic library, and determine the assembly instruction corresponding to the so dynamic library program based on the program in the so dynamic library, and then determine the target assembly instruction that needs to be protected in the assembly instruction.

[0026] Specifically, when obtaining the program to be protected in the so dynamic library, the APK installation package can be decompressed first. After decompression, the program to be protected in the so dynamic library is extracted and converted based on the program to be protected, and the binary program to be protected is converted into assembly instructions, so as to determine the target assembly instruction corresponding to the program to be protected.

[0027] Step 104: Input the target assembly instruction into a preset protection library;

[0028] Among them, the preset protection library is a library with the function of protecting code.

[0029] After determining the target assembly instruction corresponding to the program to be protected, the target assembly instruction is input into a preset protection library. Among them, the protection library is a pre-set shared library with the function of protecting relevant code, and a large amount of empty functions are reserved in the shared library, so that the target assembly instruction can be input into the preset shared library and stored in the preset shared library. After the target assembly instruction is input into the preset protection library, the target assembly instruction in the preset protection library can be executed through instructions, but the relevant data of the target assembly instruction cannot be obtained from the preset protection library. Therefore, the preset protection library can protect the target assembly instruction.

[0030] Specifically, the preset protection library can be the shared library libCodeProtect.so with code functions related to protection, and there are a large number of empty functions reserved in the preset shared library libCodeProtect.so. The sufficient empty functions ensure that the target assembly instructions can be input into the shared library libCodeProtect.so. That is to say, the size of the target assembly instructions is smaller than the preset shared library libCodeProtect.so with code functions related to protection, and this libCodeProtect.so shared library can support the execution operation of the target assembly instructions stored therein, but does not support the data acquisition operation of the target assembly instructions stored therein.

[0031] Step 106: Set a jump instruction corresponding to the target assembly instruction based on the program to be protected.

[0032] After inputting the target assembly instructions into the preset protection library (Step 104), set a jump instruction corresponding to the target assembly instruction according to the program to be protected, so that when a call instruction for calling the program to be protected is received, it can jump to the target assembly instruction according to the jump instruction of the program to be protected.

[0033] Specifically, set the jump instruction according to the program to be protected. The set jump instruction will overwrite the original program to be protected, so that when a call request for calling the original program to be protected is received, the overwritten jump instruction can be executed. Moreover, the jump instruction corresponds to the target assembly instruction, that is to say, the jump instruction will jump the call request to the target assembly instruction and perform a call operation on the target assembly instruction.

[0034] Step 108: When a call instruction for calling the program to be protected is received, perform an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected.

[0035] When a call instruction for calling the program to be protected in the so dynamic library is received, determine the target assembly instruction corresponding to the program to be protected in the preset protection library according to the jump instruction set in Step 106, and perform an execution operation on the target assembly instruction. That is to say, when a call instruction for calling the program to be protected is received, the jump instruction will cause the call request to jump to the target assembly instruction, thereby performing a call process on the target assembly instruction.

[0036] Specifically, when invoking the program to be protected, it is possible to perform a jump operation on the jump instruction set based on the program to be protected and jump to the target assembly instruction, and when the call instruction jumps to the target assembly instruction, the target assembly instruction is invoked, that is, the target assembly instruction is determined from the protection library based on the jump instruction set for the program to be protected and the execution operation is performed on the target assembly instruction.

[0037] The code protection method provided by the embodiment of the present invention obtains the program to be protected in the so dynamic library, and determines the target assembly instruction based on the program to be protected; inputs the target assembly instruction into a preset protection library, and the preset protection library is a library with the function of protecting code; sets the jump instruction corresponding to the target assembly instruction based on the program to be protected; when receiving a call instruction for calling the program to be protected, performs an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected, and can solve the problem that the existing so file protection method is prone to cracking of the so file.

[0038] In one implementation manner, the step of obtaining the program to be protected in the so dynamic library and determining the target assembly instruction based on the program to be protected (step 102) may execute steps A1 - A2:

[0039] Step A1: Perform disassembly processing on the program to be protected in the so dynamic library to determine the first assembly instruction;

[0040] When obtaining the program to be protected in the so dynamic library and converting the binary machine code language in the so dynamic library into assembly language, it is possible to perform disassembly processing on the program to be protected to determine the first assembly instruction corresponding to the program to be protected.

[0041] Specifically, when obtaining the program to be protected in the so dynamic library, it is possible to first decompress the APK installation package, extract the program to be protected in the so dynamic library, then use the acquisition tool to obtain the function name, address, and size of the so dynamic library, and then use the disassembly tool to extract the function assembly instructions in the text code segment. Among them, the acquisition tool can be the greadelf tool or other tools for obtaining the program to be protected, and the disassembly tool is the objdump tool or other disassembly tools.

[0042] Step A2: Perform obfuscation transformation processing on the first assembly instruction to obtain the target assembly instruction.

[0043] After determining the first assembly instruction, it is possible to perform obfuscation transformation on the first assembly instruction, and then determine the target assembly instruction corresponding to the first assembly instruction. Among them, the obfuscation transformation is to perform transformation on the first assembly instruction. The obtained target assembly instruction has the same function as the first assembly instruction, but the instruction content is different. Specifically, the first assembly instruction can be replaced with a group of assembly instructions with the same function to generate the target assembly instruction. The generated target assembly instruction has the same function as the first assembly instruction, but the content of the two is different.

[0044] Figure 2 is a schematic flowchart of the second code protection method provided by an embodiment of the present application. As Figure 2 shown, the schematic diagram includes:

[0045] Step 202: Obtain the program to be protected in the so dynamic library, and perform disassembly processing based on the program to be protected in the so dynamic library to determine the first assembly instruction;

[0046] Step 204: Perform obfuscation transformation on the first assembly instruction to obtain the target assembly instruction;

[0047] Step 206: Input the target assembly instruction into a preset protection library;

[0048] Among them, the preset protection library is a library with the function of protecting code.

[0049] Step 208: Set a jump instruction corresponding to the target assembly instruction based on the program to be protected;

[0050] Step 210: When receiving a call instruction to call the program to be protected, perform an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected.

[0051] In this embodiment, the first assembly instruction is obtained by performing disassembly processing on the program to be protected, and the target assembly instruction is determined by performing obfuscation transformation on the first assembly instruction. Then, code protection operations are performed on the target assembly instruction, which can increase the difficulty of deciphering the source code of the so dynamic library and enhance the security of the code.

[0052] In one implementation, before the step of inputting the target assembly instruction into the preset protection library (step 104), steps B1 - B2 can also be executed:

[0053] Step B1: Create the protection library and establish a protection function;

[0054] Among them, the protection function is used to save the target assembly instruction.

[0055] Create a shared library with a protection function as the protection library. This protection library can protect the target assembly instructions. After creating the protection library, reserve an empty function in the protection library as the protection function. The role of the empty function is to store the target assembly instructions. That is to say, the target assembly instructions protected in the protection library can be executed, but the data in the protection library cannot be obtained, so that the protection library can protect the target assembly instructions.

[0056] Specifically, create a shared library project named libCodeProtect.so through the Android NDK. Reserve an empty function with a size of 10 megabytes in this shared library project. The name of the empty function can be RestoreCode. When inputting the target assembly instructions into the preset protection library, the target assembly instructions smaller than 10 megabytes can be written into the RestoreCode address of libCodeProtect.so.

[0057] Step B2: Create an initialization instruction.

[0058] Among them, the initialization instruction is used to find the base address of the protection library, and the base address is used to determine the address information of the target assembly instructions.

[0059] After creating the protection library and the protection function, create an initialization instruction. This initialization instruction is used to find the base address of the so protection library and save the found base address. After obtaining the base address information, the address information of the target assembly program can be determined according to the base address information. Furthermore, when receiving a call instruction to call the program to be protected, the target assembly instructions can be determined according to the address information and the target assembly instructions can be executed.

[0060] Specifically, after creating the protection function, add an init initialization instruction. The function of this instruction is to find and save the content base address of the so dynamic library program. This initialization instruction can be executed after the so dynamic library program is repackaged and installed, so as to obtain the base address of the so dynamic library main program after installation.

[0061] In one implementation, for setting the jump instruction corresponding to the target assembly instruction based on the program to be protected (step 106), steps C1 - C2 can be executed:

[0062] Step C1: Obtain the offset address of the target assembly instruction and determine the jump instruction based on the offset address;

[0063] When setting a jump instruction corresponding to a target assembly instruction based on a program to be protected, the offset address of the target assembly instruction can be obtained and the jump instruction can be determined based on the offset address. Among them, the offset address of the target assembly instruction can be included in the generated jump instruction.

[0064] Specifically, determine the offset address of the RestoreCode area of the target assembly instruction, and determine the jump instruction according to the offset address. The offset address offset of the RestoreCode area can be included in the jump instruction.

[0065] Step C2: Modify the program to be protected into the jump instruction.

[0066] After determining the jump instruction, the head of the program to be protected can be modified into the jump instruction, or the entire program to be protected can be modified into the jump instruction. Preferably, the entire program to be protected can be modified into the jump instruction. In this way, when receiving an instruction to execute the program to be protected, the modified jump instruction can be executed, so as to determine the target assembly instruction corresponding to the program to be protected and perform an execution operation on the target assembly instruction. Moreover, the modified program to be protected only has the content of the jump instruction and no other data, which can better protect the program to be protected.

[0067] Specifically, when modifying the entire program to be protected into the jump instruction, the beginning of the program to be protected can be changed into the jump instruction, and then other instructions in the program to be protected can be replaced with 0, so that there is only one jump instruction in the program to be protected. Or other instructions in the program to be protected can be replaced with other information irrelevant to the program to be protected, which is not specifically limited here.

[0068] In one implementation manner, before performing an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected when receiving a call instruction for calling the program to be protected (step 108), steps D1-D2 can also be executed:

[0069] Step D1: Perform a dependency processing on the protection library and the so dynamic library, and perform a packaging operation based on the directories where the protection library and the so dynamic library are located to determine an installation package;

[0070] After creating an initialization instruction for the protection library, perform a dependency processing on the protection library and the so dynamic library, so that when receiving a call instruction for calling a program to be protected in the so dynamic library, the target assembly instruction can be determined from the protection library according to the call instruction. That is to say, associate the protection library and the dynamic library in the so program, so as to implement the jump function in the jump instruction, that is, the target assembly instruction corresponding to the program to be protected can be determined from the protection library according to the jump instruction.

[0071] After performing dependency processing on the protected library and the so dynamic library, package the directory where the processed protected library and so dynamic library are located, and determine the installation package after packaging. Among them, when performing the packaging process, the protected library and the so dynamic library are in the same directory. After the packaging process, the packaged APK can be signed to prevent others from decrypting the installation package and obtaining the program to be protected, which can increase the difficulty of obtaining the program to be protected.

[0072] Specifically, modify the ELF format of the so dynamic library program, and add a shared library dependency named libCodeProtect.so (i.e., the protected library) after the last shared library. After performing the dependency processing, add the libCodeProtect.so shared library to the so directory of the APK and package it into a new installation package. Among them, when packaging it into a new installation package, it can be signed and packaged through signapk.jar.

[0073] Figure 3 It is a schematic diagram of the main program file format provided by an embodiment of the present application. Figure 3 (a) shows the situation of the so dynamic library when the code to be protected is not protected. It can be seen from the directory that there are 5 shared libraries in the directory when the program to be protected is not protected, but these 5 shared libraries cannot perform protection operations on the programs among them. Figure 3 (b) shows the situation of the so dynamic library after the code to be protected is protected. It can be seen from the directory that after the program to be protected is protected, there are 6 shared libraries in the directory, that is, a shared library named libCodeProtect.so (i.e., the protected library) is added. This protected library can perform protection operations on the stored data (i.e., the target assembly instructions). When the code to be protected is protected, when receiving a call instruction to call the program to be protected in the shared library without protection function, it can determine the target assembly instruction corresponding to the program to be protected from the shared library with protection function according to the modified jump instruction, and perform an execution operation on the target assembly instruction.

[0074] Step D2: After performing the installation operation on the installation package, execute the initialization instruction to determine the base address of the protected library and save the base address.

[0075] After determining the installation package and performing the installation process based on the installation package, the initialization instruction is executed to determine the base address of the protection library and save the base address information. That is to say, after the new installation package is installed, the initialization instruction will be preferentially executed to obtain the base address information of the protection library and save the base address information, which is used to determine the address information of the target assembly instruction. That is, after determining the base address information and receiving the call instruction, the address information of the target assembly instruction can be determined according to the base address information and the offset address information in the jump instruction.

[0076] Specifically, after performing the installation operation on the new installation package, the system will preferentially execute the init method in the libCodeProtect.so shared library to complete the code initialization, that is, obtain the base address base of the main program and write it into the address 0x1000A410 in the data segment of the main process. After the init method is executed, the control right returns to the so dynamic library program.

[0077] Figure 4 It is a flowchart of the initialization instruction execution method provided by an embodiment of the present application. As Figure 4 shown, the flowchart includes:

[0078] Step 402: Obtain the base address information and save the base address information;

[0079] The initialization instruction can determine the base address information of the main program after the installation package is installed and save the base address information and write it into the data segment of the main program.

[0080] Step 404: When the program to be protected is called, determine the target assembly instruction by means of the jump instruction and perform the execution operation.

[0081] When the program to be protected is called, the position information of the target assembly instruction can be determined by means of the offset address information in the jump instruction and the base address information obtained in step 402, and the target assembly instruction is executed.

[0082] Figure 5 It is a flowchart of the third code protection method provided by an embodiment of the present application. As Figure 5 shown, the flowchart includes:

[0083] Step 502: Obtain the program to be protected in the so dynamic library and determine the target assembly instruction based on the program to be protected;

[0084] Step 504: Create the protection library and establish the protection function;

[0085] Among them, the protection function is used to save the target assembly instruction.

[0086] Step 506: Create an initialization instruction;

[0087] Among them, the initialization instruction is used to find the base address of the protection library, and the base address is used to determine the address information of the target assembly instruction.

[0088] Step 508: Input the target assembly instruction into a preset protection library;

[0089] Among them, the preset protection library is a library with a protection code function.

[0090] Step 510: Set a jump instruction corresponding to the target assembly instruction based on the program to be protected;

[0091] Step 512: Perform a dependency process on the protection library and the so dynamic library, and perform a packaging operation based on the directories where the protection library and the so dynamic library are located to determine an installation package;

[0092] Step 514: After performing an installation operation on the installation package, execute the initialization instruction to determine the base address of the protection library and save the base address;

[0093] Step 516: When receiving a call instruction for calling the program to be protected, perform an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected.

[0094] In this embodiment, by pre-creating a protection library and establishing a protection function, setting a jump instruction for the program to be protected and storing the target assembly instruction corresponding to the program to be protected in the protection library, when receiving a call instruction for calling the program to be protected, the target assembly instruction corresponding to the program to be protected can be determined from the protection library with a protection function through the jump instruction and an execution operation is performed on the target assembly instruction, increasing the difficulty of code acquisition, so that the so file is more difficult to crack.

[0095] In one implementation manner, when receiving a call instruction for calling the program to be protected, performing an execution operation on the target assembly instruction from the protection library based on the jump instruction (step 108) may execute steps E1 - E2:

[0096] Step E1: When receiving the call instruction, determine the address information of the target assembly instruction based on the jump instruction;

[0097] When receiving a call instruction for calling the program to be protected, determine the address information of the target assembly instruction based on the jump instruction, where the jump instruction can be determined based on the address information of the target assembly instruction. That is to say, the jump instruction is used to jump the call instruction to the target assembly instruction for calling and the jump instruction includes the address information of the target assembly instruction.

[0098] Specifically, after the function space of the program to be protected is modified into a jump instruction, when a call instruction for calling the program to be protected is received, the jump instruction will be executed. When executing the jump instruction, the address information of the target assembly instruction will be determined. Among them, the address information of the target assembly instruction may be included in the call instruction. When the address information of the target assembly instruction is included in the call instruction, the address information of the target assembly instruction can be directly obtained according to the call instruction.

[0099] Step E2: Determine the target assembly instruction based on the address information of the target assembly instruction and perform operation processing on the target assembly instruction.

[0100] After determining the address information of the target assembly instruction, determine the target assembly instruction corresponding to the program to be protected in the protection library according to the address information and perform operation processing on the target assembly instruction.

[0101] In one implementation, when receiving the call instruction, based on the jump instruction to determine the address information of the target assembly instruction (step E1), steps F1-F2 can be executed:

[0102] Step F1: Determine the offset address of the target assembly instruction based on the call instruction;

[0103] When receiving the call instruction, determine the offset address of the target assembly instruction based on the call instruction. Among them, the offset address of the target assembly instruction may be included in the jump instruction, so that the offset address of the target assembly instruction can be determined according to the call instruction. That is to say, when determining the address information of the target assembly instruction according to the call instruction, the offset address of the target assembly instruction may be included in the call instruction, and then the address information of the target assembly instruction can be determined according to the offset address.

[0104] Specifically, when receiving a call instruction for calling the program to be protected, the ldr instruction can be used to read the address 0x1000A410 to obtain the base jump instruction, that is, the offset address of the target assembly instruction.

[0105] Step F2: Obtain the base address of the protection library and determine the address information of the target assembly instruction based on the offset address and the base address.

[0106] After determining the offset address of the target assembly instruction, determine the base address of the protection library from a preset protection library and determine the address information of the target assembly instruction based on the offset address of the target assembly instruction and the base address of the protection library. That is to say, the address information of the target assembly instruction is determined according to the offset address and the base address, and the base address information can be obtained according to the initialization instruction (i.e., the code initialization operation performed when the installation package is installed), and the offset address information can be obtained according to the jump instruction.

[0107] Specifically, after determining the base jump instruction, determine the absolute memory address of the target assembly instruction corresponding to the code to be protected in the libCodeProtect.so shared library according to the base address base and the offset address 0x390, so as to perform execution processing on the target assembly instruction.

[0108] Figure 6 It is a flowchart of the fourth code protection method provided by the embodiments of the present application. As Figure 5 shown, the schematic diagram includes:

[0109] Step 602: Obtain the program to be protected in the so dynamic library, and perform disassembly processing based on the program to be protected in the so dynamic library to determine the first assembly instruction;

[0110] Step 604: Perform obfuscation transformation processing on the first assembly instruction to obtain the target assembly instruction;

[0111] Step 606: Create the protection library and establish a protection function;

[0112] Wherein, the protection function is used to save the target assembly instruction.

[0113] Step 608: Create an initialization instruction;

[0114] Wherein, the initialization instruction is used to find the base address of the protection library, and the base address is used to determine the address information of the target assembly instruction.

[0115] Step 610: Input the target assembly instruction into a preset protection library;

[0116] Wherein, the preset protection library is a library with a function of protecting code.

[0117] Step 612: Obtain the offset address of the target assembly instruction and determine the jump instruction based on the offset address;

[0118] Step 614: Modify the program to be protected into the jump instruction;

[0119] Step 616: Perform dependency processing on the protection library and the so dynamic library, and perform a packaging operation based on the directories where the protection library and the so dynamic library are located to determine an installation package;

[0120] Step 618: After performing an installation operation on the installation package, execute an initialization instruction to determine the base address of the protection library and save the base address;

[0121] Step 620: When receiving a call instruction for calling the program to be protected, determine the offset address of the target assembly instruction based on the call instruction;

[0122] Step 622: Obtain the base address of the protection library and determine the address information of the target assembly instruction based on the offset address and the base address;

[0123] Step 624: Determine the target assembly instruction based on the address information of the target assembly instruction and perform operation processing on the target assembly instruction.

[0124] In this embodiment, by obtaining a program to be protected in an so dynamic library and determining a target assembly instruction based on the program to be protected; inputting the target assembly instruction into a preset protection library, where the preset protection library is a library with a protection code function; setting a jump instruction corresponding to the target assembly instruction based on the program to be protected; when receiving a call instruction for calling the program to be protected, performing an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected, it is possible to jump to the preset protection library through the jump instruction without increasing the text code segment and the GOT table, thereby completing the function of the program to be protected, and solving the problem that the existing so file protection method is prone to so file cracking under the condition of making less changes to the ELF format.

[0125] It should be noted that for the code protection method provided in the embodiments of the present application, the execution subject may be a code protection device, or a control module in the code protection device for executing the code protection method. In the embodiments of the present application, the code protection method is executed by the code protection device as an example to illustrate the code protection device provided in the embodiments of the present application.

[0126] Figure 7 It is a schematic structural diagram of a code protection device according to an embodiment of the present invention. As Figure 7 shown, the code protection device includes: a first determination module 702, a first input module 704, a first setting module 706, and a first execution module 708.

[0127] The first determination module 702 is configured to obtain a program to be protected in an so dynamic library and determine a target assembly instruction based on the program to be protected;

[0128] A first input module 704, configured to input the target assembly instruction into a preset protection library, where the preset protection library is a library with a protection code function;

[0129] A first setting module 706, configured to set a jump instruction corresponding to the target assembly instruction based on the program to be protected;

[0130] A first execution module 708, configured to, when receiving a call instruction for calling the program to be protected, perform an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected.

[0131] The code protection device in the embodiments of the present application may be a device, or a component, an integrated circuit, or a chip in a terminal. The device may be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, a vehicle-mounted electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and the non-mobile electronic device may be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine, or a self-service machine, etc. The embodiments of the present application do not make specific limitations.

[0132] The code protection device in the embodiments of the present application may be a device with an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems. The embodiments of the present application do not make specific limitations.

[0133] The code protection device provided in the embodiments of the present application can implement Figures 1 to 6 each process implemented in the method embodiments. To avoid repetition, details are not described here again.

[0134] Based on the same technical concept, the embodiments of the present application further provide an electronic device, which is used to execute the above-mentioned code protection method, Figure 8Schematic diagram of a structure of an electronic device for implementing various embodiments of the present application. The electronic device may vary greatly due to different configurations or performances, and may include a processor 802, a communications interface 804, a memory 806, and a communication bus 808. Among them, the processor 802, the communications interface 804, and the memory 806 complete mutual communication through the communication bus 808. The processor 802 may call a computer program stored in the memory 806 and executable on the processor 802 to perform the following steps:

[0135] Obtain a program to be protected in the so dynamic library, and determine a target assembly instruction based on the program to be protected;

[0136] Input the target assembly instruction into a preset protection library, where the preset protection library is a library with a protection code function;

[0137] Set a jump instruction corresponding to the target assembly instruction based on the program to be protected;

[0138] When a call instruction for calling the program to be protected is received, perform an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected.

[0139] In one implementation, the obtaining the program to be protected in the so dynamic library and determining the target assembly instruction based on the program to be protected includes:

[0140] Perform disassembly processing on the program to be protected in the so dynamic library to determine a first assembly instruction;

[0141] Perform obfuscation transformation processing on the first assembly instruction to obtain the target assembly instruction.

[0142] In one implementation, before inputting the target assembly instruction into the preset protection library, the method further includes:

[0143] Create the protection library and establish a protection function, where the protection function is used to save the target assembly instruction;

[0144] Create an initialization instruction, where the initialization instruction is used to find the base address of the protection library, and the base address is used to determine the address information of the target assembly instruction.

[0145] In one implementation, the setting the jump instruction corresponding to the target assembly instruction based on the program to be protected includes:

[0146] Obtain the offset address of the target assembly instruction and determine the jump instruction based on the offset address;

[0147] Modify the program to be protected into the jump instruction.

[0148] In one implementation, before performing an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected when receiving a call instruction for calling the program to be protected, the method further includes:

[0149] Perform a dependency process on the protection library and the so dynamic library, and based on the directories where the protection library and the so dynamic library are located, perform a packaging operation to determine an installation package;

[0150] After performing an installation operation on the installation package, execute an initialization instruction to determine the base address of the protection library and save the base address.

[0151] In one implementation, when receiving a call instruction for calling the program to be protected, performing an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected includes:

[0152] When receiving the call instruction, determine the address information of the target assembly instruction based on the jump instruction;

[0153] Based on the address information of the target assembly instruction, determine the target assembly instruction and perform an operation process on the target assembly instruction.

[0154] In one implementation, when receiving the call instruction, determining the address information of the target assembly instruction based on the jump instruction includes:

[0155] Determine the offset address of the target assembly instruction based on the call instruction;

[0156] Obtain the base address of the protection library and determine the address information of the target assembly instruction based on the offset address and the base address.

[0157] For the specific execution steps, reference can be made to the steps of the above-mentioned code protection method embodiment, and the same technical effects can be achieved. To avoid repetition, details are not elaborated here.

[0158] It should be noted that the electronic devices in the embodiments of the present application include: servers, terminals, or other devices other than terminals.

[0159] The above electronic device structure does not limit the electronic device. The electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements. For example, the input unit may include a Graphics Processing Unit (GPU) and a microphone, and the display unit may be configured with a display panel in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit includes at least one of a touch panel and other input devices. The touch panel is also called a touch screen. Other input devices may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, which will not be elaborated here.

[0160] The memory can be used to store software programs and various data. The memory mainly includes a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area can store an operating system, application programs or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory may include volatile memory or non-volatile memory, or the memory may include both volatile and non-volatile memory. Among them, the non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically Erasable PROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synchlink DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM).

[0161] The processor may include one or more processing units; optionally, the processor integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor may not be integrated into the processor either.

[0162] The embodiment of the present application further provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, it implements each process of the above-mentioned embodiment of the code protection method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0163] Among them, the processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc.

[0164] The embodiment of the present application further provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run a program or instruction to implement each process of the above-mentioned embodiment of the code protection method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0165] It should be understood that the chip mentioned in the embodiment of the present application may also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0166] It should be noted that in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without more limitations, the element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article, or device including that element. In addition, it should be pointed out that the scope of the method and device in the embodiment of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described method may be executed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, the features described with reference to certain examples may be combined in other examples.

[0167] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present application.

[0168] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A code protection method, comprising: Obtaining a program to be protected in the so dynamic library, and determining target assembly instructions based on the program to be protected; Inputting the target assembly instructions into a preset protection library, where the preset protection library is a library with a function of protecting code; Setting a jump instruction corresponding to the target assembly instructions based on the program to be protected; When receiving a call instruction for calling the program to be protected, performing an execution operation on the target assembly instructions from the protection library based on the jump instruction set for the program to be protected.

2. The method according to claim 1, wherein the obtaining a program to be protected in the so dynamic library and determining target assembly instructions based on the program to be protected comprises: Performing disassembly processing on the program to be protected in the so dynamic library to determine first assembly instructions; Performing obfuscation transformation processing on the first assembly instructions to obtain the target assembly instructions.

3. The method according to claim 1, before inputting the target assembly instructions into the preset protection library, the method further comprises: Creating the protection library and establishing a protection function, where the protection function is used to save the target assembly instructions; Creating an initialization instruction, where the initialization instruction is used to find the base address of the protection library, and the base address is used to determine the address information of the target assembly instructions.

4. The method according to claim 1, wherein the setting a jump instruction corresponding to the target assembly instructions based on the program to be protected comprises: Obtaining the offset address of the target assembly instructions and determining the jump instruction based on the offset address; Modifying the program to be protected into the jump instruction.

5. The method according to claim 1, before performing an execution operation on the target assembly instructions from the protection library based on the jump instruction set for the program to be protected when receiving a call instruction for calling the program to be protected, the method further comprises: Performing dependency processing on the protection library and the so dynamic library, and performing a packaging operation based on the directories where the protection library and the so dynamic library are located to determine an installation package; After performing an installation operation on the installation package, executing the initialization instruction to determine the base address of the protection library and saving the base address.

6. The method according to claim 1, wherein the performing an execution operation on the target assembly instructions from the protection library based on the jump instruction set for the program to be protected when receiving a call instruction for calling the program to be protected comprises: When receiving the call instruction, determining the address information of the target assembly instructions based on the jump instruction; Determining the target assembly instructions based on the address information of the target assembly instructions and performing operation processing on the target assembly instructions.

7. The method according to claim 6, wherein the determining the address information of the target assembly instructions based on the jump instruction when receiving the call instruction comprises: Determining the offset address of the target assembly instructions based on the call instruction; Obtaining the base address of the protection library and determining the address information of the target assembly instructions based on the offset address and the base address.

8. A code protection device, comprising: A first determination module, configured to obtain a program to be protected in a so dynamic library, and determine a target assembly instruction based on the program to be protected; A first input module, configured to input the target assembly instruction into a preset protection library, where the preset protection library is a library with a protection code function; A first setting module, configured to set a jump instruction corresponding to the target assembly instruction based on the program to be protected; A first execution module, configured to, when receiving a call instruction for calling the program to be protected, perform an execution operation on the target assembly instruction from the protection library based on the jump instruction set for the program to be protected.

9. A computer device, characterized in that, The device includes: A processor; and A memory arranged to store computer-executable instructions, the executable instructions being configured to be executed by the processor, the executable instructions including steps for performing the method according to any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium is used to store computer-executable instructions, and the executable instructions cause a computer to execute the method according to any one of claims 1 to 7.