Program code protection method and device, electronic equipment and storage medium

By obfuscating and deforming the assembly instructions of the program code and putting them into the dependency library, and replacing the original code with jump instructions, the problem of program code being rejected due to the addition of TEXT segments when it was launched on the Apple App Store, and effective code protection is achieved.

CN120353471APending Publication Date: 2025-07-22BEIJING BANGCLE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410090088.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing program code protection solution was rejected when it was launched on the Apple App Store because of the increase in the number of TEXT segments, resulting in the problem of being unable to upload.

Method used

By obtaining the assembly instructions of the program code for obfuscation and deformation, generating the target assembly instructions and putting them into the dependency library, replacing the program code with a jump instruction, jumping to the dependency library to execute the target assembly instructions, avoiding the addition of additional TEXT segments.

Benefits of technology

Without adding TEXT segments, the program code is effectively protected and static analysis is prevented, which solves the problem that the program code cannot be listed, and improves the protection effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120353471A_ABST
    Figure CN120353471A_ABST
Patent Text Reader

Abstract

The invention discloses a program code protection method and device, electronic equipment and a storage medium, belongs to the technical field of information security, and is used for solving the problem that a client application program processed by a related protection scheme cannot be put on shelf on AppStore. The method comprises the steps of obtaining program codes and an assembly instruction corresponding to a to-be-protected program code in the program codes; performing confusion deformation processing on the assembly instruction to obtain a target assembly instruction, and putting the target assembly instruction into a pre-compiled dependency library; replacing the to-be-protected program code in the program codes with a jump instruction, and generating a corresponding target program code; and when the jump instruction is executed, jumping to the address of the target assembly instruction in the dependency library, and executing the target assembly instruction in the dependency library.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information security technology, and particularly relates to a method, device, electronic device and storage medium for protecting program code. Background Art

[0002] For the customer application programs on the Apple App Store, Apple provides an obfuscation mechanism. However, Apple's own obfuscation mechanism is similar to the category of dynamic encryption and decryption, and can only prevent static analysis. Moreover, since the encryption algorithm is fixed and is an open secret, there is already a corresponding de-obfuscation technology on the Internet. Through this de-obfuscation technology, it is very easy to extract the decrypted original code, resulting in the security mechanism being ineffective.

[0003] For the related code protection scheme for Apple program application files (iPhone Application, IPA), through the instruction obfuscation technology, the original code is inflated. Therefore, the newly generated protected code generates a new TEXT segment (also called the code segment), and the corresponding Mach-O format also increases the number of TEXT segments accordingly. Among them, the Mach-O format is the abbreviation of the Mach Object file format, which is used for the file formats of executable files, object code, dynamic libraries, and kernel dumps.

[0004] However, recently the App Store has modified its listing policy, prohibiting the number of TEXT segments in the Mach-O format of the submitted IPA files from being more than one. This has led to the problem that the application programs with increased TEXT segments will be rejected when submitting a listing request. That is to say, there is a problem that the customer application programs processed by the related protection scheme cannot be listed on the App Store. Summary of the Invention

[0005] The embodiments of this application provide a method, device, electronic device and storage medium for protecting program code, which can solve the problem that the customer application programs processed by the related protection scheme cannot be listed on the App Store.

[0006] In a first aspect, the embodiments of this application provide a method for protecting program code. The method includes: obtaining program code and the assembly instructions corresponding to the program code to be protected in the program code; performing an obfuscation transformation process on the assembly instructions to obtain target assembly instructions, and putting the target assembly instructions into a pre-compiled dependency library; replacing the program code to be protected in the program code with a jump instruction, and generating corresponding target program code; when the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library.

[0007] In a second aspect, an embodiment of the present application provides a protection device for program code. The device includes: an acquisition module for acquiring assembly instructions corresponding to the program code and the program code to be protected in the program code; a processing module for performing obfuscation transformation on the assembly instructions to obtain target assembly instructions, and putting the target assembly instructions into a pre-compiled dependency library; a generation module for replacing the program code to be protected in the program code with a jump instruction and generating corresponding target program code; when the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library.

[0008] In a third aspect, an embodiment of the present application provides an electronic device. The device includes: a processor; and a memory arranged to store computer-executable instructions, the executable instructions being configured to be executed by the processor, and the executable instructions including a method for protecting program code as described in the first aspect.

[0009] In a fourth aspect, an embodiment of the present application provides a storage medium for storing computer-executable instructions, and the computer-executable instructions cause a computer to execute the method for protecting program code as described in the first aspect.

[0010] In the embodiment of the present application, by acquiring assembly instructions corresponding to the program code and the program code to be protected in the program code, performing obfuscation transformation on the assembly instructions to obtain target assembly instructions, then putting the target assembly instructions into a pre-compiled dependency library, replacing the program code to be protected in the program code with a jump instruction, and generating corresponding target program code, when the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library. Compared with the method of inflating the original code, the newly generated protected code is added to the program code in the form of a newly added TEXT segment (also called a code segment). In this solution, a jump instruction is used to replace the program code to be protected in the program code, and the generated target program code does not include the program code to be protected, preventing the program code to be protected from being statically analyzed. Also, the target assembly instructions obtained by performing obfuscation transformation on the assembly instructions corresponding to the program code to be protected are put into the dependency library. When the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library, which can achieve the purpose of protecting the program code to be protected without adding an extra TEXT segment, solve the problem that the customer application program after being processed by the relevant protection scheme cannot be put on the App Store. Moreover, the target assembly instructions stored in the dependency library are obtained by performing obfuscation transformation on the assembly instructions corresponding to the program code to be protected, further improving the protection effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 It is a schematic flowchart of a method for protecting program code provided by an embodiment of the present application;

[0012] Figure 2 It is a schematic flowchart of another method for protecting program code provided by an embodiment of the present application;

[0013] Figure 3 It is a schematic structural diagram of a device for protecting program code provided by an embodiment of the present application;

[0014] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0015] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0016] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, rather than to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second", etc. are generally of the same type and do not limit the number of objects. For example, the first object can be one or multiple. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the associated objects before and after.

[0017] Next, the method, device, electronic device, and storage medium for protecting program code provided by the embodiments of the present application will be described in detail with reference to the accompanying drawings, specific embodiments, and their application scenarios.

[0018] Figure 1 A method for protecting program code provided by an embodiment of the present invention is shown. This method can be executed by an electronic device, which can include: a server and / or a terminal device, where the terminal device can be, for example, an in-vehicle terminal or a mobile phone terminal, etc. In other words, this method can be executed by software or hardware installed in the electronic device. The method includes the following steps:

[0019] S102: Obtain the program code and the assembly instructions corresponding to the program code to be protected in the program code.

[0020] Specifically, the assembly instructions corresponding to the program code to be protected can be one or more assembly instructions. Among them, the assembly instructions are, for example, MOV X0, SP; for example, ADD X16, X28, X17, etc.

[0021] S104: Perform obfuscation transformation on the assembly instructions to obtain target assembly instructions, and put the target assembly instructions into a pre-compiled dependency library.

[0022] Perform obfuscation transformation on the assembly instructions corresponding to the program code to be protected. For example, the assembly instructions can be replaced by a group of instructions with the same function, the strings used in the assembly instructions can be encrypted to prevent the key words from being located by static analysis tools such as IDA in reverse engineering; the class names, method names, and property names in the assembly instructions can be replaced with meaningless symbols to increase the difficulty of code reverse engineering; the logical structures of multiple assembly instructions can be scrambled to reduce readability. The obfuscation transformation can be performed in one or a combination of the above ways.

[0023] The dependency library can be a library generated corresponding to a framework project developed by the software development framework.NET Framework. The dependency library can be a dynamic library or a static library.

[0024] S106: Replace the program code to be protected in the program code with a jump instruction, and generate the corresponding target program code; when the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library.

[0025] Specifically, the jump instruction can include multiple assembly instructions. The program code to be protected in the program code occupies a certain amount of memory space. After being modified into a jump instruction, there may be remaining memory space, and this remaining memory space is filled with 0.

[0026] Replace the program code to be protected in the program code of the application with a jump instruction, and generate the target program code of the corresponding application.

[0027] The protection method for program code provided by the embodiments of the present invention obtains the program code and the assembly instructions corresponding to the program code to be protected in the program code, performs obfuscation transformation on the assembly instructions to obtain target assembly instructions, then places the target assembly instructions into a pre-compiled dependency library, replaces the program code to be protected in the program code with a jump instruction, and generates corresponding target program code. When the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library. Compared with the method of inflating the original code, the newly generated protected code is added to the program code in the form of a newly added TEXT segment (also known as the code segment). In this solution, the jump instruction is used to replace the program code to be protected in the program code, and the generated target program code does not include the program code to be protected, preventing the program code to be protected from being statically analyzed. Moreover, the target assembly instructions obtained by obfuscating and transforming the assembly instructions corresponding to the program code to be protected are placed in the dependency library. When the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library, which can achieve the purpose of protecting the program code to be protected without adding an extra TEXT segment, solve the problem that the customer application program after being processed by the relevant protection scheme cannot be put on the App Store. And the target assembly instructions stored in the dependency library are obtained by obfuscating and transforming the assembly instructions corresponding to the program code to be protected, further improving the protection effect.

[0028] In one implementation, the jump instruction includes the offset address of the target assembly instruction; the pre-compiled dependency library includes a pre-compiled load method, and the load method code is used to preferentially find the memory base address of the target assembly instruction in the dependency library.

[0029] When the application corresponding to the above target program code is running, the above method can also execute the following steps A1 to A2:

[0030] Step A1, execute the load method code in the dependency library to obtain the memory base address of the target assembly instruction.

[0031] Specifically, the language for compiling the load method code includes but is not limited to the ObjectC language. When the application corresponding to the target program code runs, the load method will be preferentially executed and then return to the main process.

[0032] The execution logic of the load method can be as follows: find the target module included in the target assembly instruction in the dependency library; determine whether the found target module is the main program; if the target module found this time is not the main program, then find the next target module and continue to determine whether the next target module is the main program until all the target modules included in the target assembly instruction are traversed; if the found target module is the main program, then write the base address of the target module into the data segment of the main process; wait; determine whether the target module is called; if it is not called, then wait and determine whether the target module is called according to a preset frequency; if it is called, then execute the target module in the target assembly instruction.

[0033] Step A2: Based on the jump instruction and the memory base address, jump to execute the target assembly instruction.

[0034] The memory base address (Base Address) of the target assembly instruction represents the starting address when the target assembly instruction is loaded into memory, which is an absolute address. The offset address (Offset Address) is the address difference relative to the memory base address, representing the relative address of the target module in the target assembly instruction relative to the memory base address. By adding the offset address to the memory base address, the true physical address or virtual address of the target module in the target assembly instruction can be obtained.

[0035] Exemplarily, after obtaining the memory base address, through the data processing instruction LDR...; the memory base address is transmitted to the destination register, and the jump instruction includes this destination register, and the jump instruction includes the offset address of the target assembly instruction. Then, after adding the offset address of the target assembly instruction to the memory base address, the true address of the target assembly instruction can be obtained. Therefore, when the jump instruction is executed, it can jump to the address of the target assembly instruction in the dependency library.

[0036] In this embodiment, by setting the offset address of the target assembly instruction in the jump instruction and setting the pre-compiled load method (the load method code is used to preferentially find the memory base address of the target assembly instruction in the dependency library) in the pre-compiled dependency library, the memory base address of the target assembly instruction is obtained. Finally, the jump instruction and the memory base address are used to realize the jump execution of the target assembly instruction in the dependency library. Compared with the related technology, the jump instruction is a piece of position-independent code. To access symbols outside the current file, the compiler needs to generate a GOT global offset table. Then the system writes the true memory offset address of the external symbol into this GOT table. Finally, the true target address of the external symbol is taken out from the GOT table in a way similar to reading a variable to complete the access to symbols outside the current file, resulting in a relatively high modification cost. This solution can complete the access outside the current file without increasing the number of GOT table entries, and can protect the code to be protected with a relatively small modification cost.

[0037] In one implementation, after replacing the program code to be protected in the program code with a jump instruction and generating the corresponding target program code (i.e., S106), the following step B1 can also be executed:

[0038] Step B1: Increase the number of fields in the Load Commands field of the Mach-O format corresponding to the program code by one.

[0039] In one implementation, for the obfuscation transformation process of the assembly instructions to obtain the target assembly instructions (step S104), the following step C1 can be specifically executed:

[0040] Step C1: Replace the assembly instructions with the target assembly instructions.

[0041] Among them, the target assembly instructions are different from the assembly instructions, but have the same execution result.

[0042] Specifically, all the assembly instructions in the assembly instructions can be replaced with the target assembly instructions, and the assembly instructions can be replaced with the target assembly instructions that are different from the assembly instructions but have the same function; part of the assembly instructions in the assembly instructions can also be replaced with the assembly instructions that are different from the part of the assembly instructions but have the same function, and after replacement, it is the target assembly instruction, so as to increase the difficulty of understanding the target assembly instructions obtained after decompiling the program code in the dependent library.

[0043] In one implementation, to obtain the assembly instructions corresponding to the program code and the program code to be protected in the program code (i.e., S102), the following steps D1 to D3 can be specifically executed:

[0044] Step D1: Based on IPA, determine the main program name.

[0045] IPA is the abbreviation of the Apple program application file iPhoneApplication, which is essentially a compressed package. After decompressing it, the CFBundleExecutable field in the decompressed Info.plist file can be parsed to obtain the main program name. Among them, the Info.plist file is a file of the extensible markup language (XML) for storing application-related information, and the CFBundleExecutable field specifies the main program name.

[0046] Step D2: Based on the main program name, obtain the Mach-O format of the program code, and determine the function name, function address, and function size in the program code and the program code.

[0047] It is possible to write code to parse the Mach-O format of the main program more quickly with the help of third-party libraries such as the Python macholib library. After that, the function names, function addresses, and function sizes in the LC_FUNCTION_STARTS segment are parsed through the unsigned integer, variable-length encoding or decoding format (unsigned Little Endian Base128, uleb128) to determine the function names, function addresses, and function sizes in the program code. Among them, the LC_FUNCTION_STARTS segment defines the function start address table.

[0048] Step D3: Based on the program code and the function names, function addresses, and function sizes in the program code, obtain the program code to be protected and the corresponding assembly instructions of the program code to be protected.

[0049] Among them, the function assembly instructions in the text code segment of the program code can be extracted through disassembly tools such as objdump. Of course, disassembly tools include but are not limited to objdump.

[0050] After obtaining the above target program code, it is also necessary to package the target program code and the corresponding files of the dependent library into a new IPA. Exemplarily, in the case where the dependent library is a framework library, create a Frameworks directory and a CodeProtect.framework subdirectory, add the CodeProtect module to the main directory of the IPA, and package it into a new IPA, where CodeProtect is the name of the framework project. In addition, the new IPA also needs to be signed through the codesign tool used to create and manage certificates to obtain the final application program.

[0051] In one implementation, the above dependent library is a framework library; putting the target assembly instructions into the pre-compiled dependent library (i.e., S104) can be specifically performed as the following steps E1:

[0052] Step E1: Put the target assembly instructions into the empty function preset in the framework library.

[0053] An empty function is a complete function that has a function body but no statements in the function body.

[0054] In one implementation, based on the program code and the function names, function addresses, and function sizes in the program code, obtaining the program code to be protected and the corresponding assembly instructions of the program code to be protected (step D3) can be specifically performed as the following steps F1 to F3:

[0055] Step F1: Based on the function names and function addresses in the program code, determine the function code.

[0056] The function code can be one or more, and a function and its function content constitute one function code.

[0057] Step F2: Disassemble the function code using a disassembler to obtain the assembly code.

[0058] Disassemble the binary function code into assembly code.

[0059] Step F3: Based on the preset storage space size of the empty function and the function size, determine the program code to be protected and the assembly instructions corresponding to the program code to be protected in the assembly code.

[0060] Step F4: Obtain the program code to be protected and the assembly instructions.

[0061] Only when the function size of the program code to be protected is less than the preset storage space size of the empty function, it is possible to make the size of the target assembly instructions of the program code to be protected less than the preset storage space size of the empty function. Based on this, determining the assembly instructions can reduce the possibility of wasting resources when, due to limited memory, the target assembly instructions after obfuscation and transformation of the assembly instructions cannot be stored in the preset empty function.

[0062] Figure 2 It is a flowchart showing another method for protecting program code provided by an embodiment of the present application. As Figure 2 shown, the method includes:

[0063] Step 202: Based on IPA, determine the main program name.

[0064] Step 204: Based on the main program name, obtain the Mach-O format of the program code, and determine the function name, function address, and function size in the program code and the program code.

[0065] Step 206: Based on the program code and the function name, function address, and function size in the program code, obtain the program code to be protected and the assembly instructions corresponding to the program code to be protected.

[0066] Step 208: Perform obfuscation and transformation on the assembly instructions to obtain the target assembly instructions, and place the target assembly instructions in a pre-compiled dependency library; the pre-compiled dependency library includes a pre-compiled load method, and the load method code is used to preferentially find the memory base address of the target assembly instructions in the dependency library.

[0067] Step 210: Replace the program code to be protected in the program code with a jump instruction, and generate the corresponding target program code; the jump instruction includes the offset address of the target assembly instructions.

[0068] And when the application corresponding to the above target program code is running, perform the following steps 212 to 216:

[0069] Step 212, execute the load method code in the dependency library to obtain the memory base address of the target assembly instruction.

[0070] Step 214, based on the jump instruction and the memory base address, jump to execute the target assembly instruction; when the jump instruction is executed, jump to the address of the target assembly instruction in the dependency library and execute the target assembly instruction in the dependency library.

[0071] The program code protection method provided by the embodiments of the present invention obtains the assembly instructions corresponding to the program code and the program code to be protected in the program code, performs obfuscation transformation on the assembly instructions to obtain the target assembly instructions, then puts the target assembly instructions into a pre-compiled dependency library, replaces the program code to be protected in the program code with a jump instruction, and generates the corresponding target program code. When the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library. Compared with the method of inflating the original code, the newly generated protection code is added to the program code in the form of a newly added TEXT segment (also called the code segment). This solution uses a jump instruction to replace the program code to be protected in the program code, and the generated target program code does not include the program code to be protected, preventing the program code to be protected from being statically analyzed. At the same time, the target assembly instructions obtained by obfuscating and transforming the assembly instructions corresponding to the program code to be protected are put into the dependency library. When the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library, which can achieve the purpose of protecting the program code to be protected without adding an extra TEXT segment, solve the problem that the customer application program after being processed by the relevant protection scheme cannot be put on the App Store. Moreover, the target assembly instructions stored in the dependency library are obtained by obfuscating and transforming the assembly instructions corresponding to the program code to be protected, further improving the protection effect.

[0072] Based on the same idea of the program code protection method provided by the above one or more embodiments, one or more embodiments of this specification also provide a program code protection device.

[0073] Corresponding to the program code protection method provided by the above embodiments, based on the same technical concept, the embodiments of the present invention also provide a program code protection device, Figure 3 is a schematic structural diagram of the program code protection device according to the embodiments of the present invention. This program code protection device is used to execute Figures 1 to 2 the described program code protection method, such as Figure 3As shown in the figure, the protection device for program code includes: an acquisition module 310, a processing module 320, and a generation module 330.

[0074] The acquisition module 310 is used to obtain the assembly instructions corresponding to the program code and the program code to be protected in the program code.

[0075] The processing module 320 is used to perform obfuscation transformation on the assembly instructions to obtain target assembly instructions, and put the target assembly instructions into a pre-compiled dependency library.

[0076] The generation module 330 is used to replace the program code to be protected in the program code with jump instructions, and generate corresponding target program code; when the jump instructions are executed, it jumps to the address of the target assembly instructions in the dependency library and executes the target assembly instructions in the dependency library.

[0077] In one implementation, the jump instructions include the offset address of the target assembly instructions; the pre-compiled dependency library includes a pre-compiled load method, and the load method code is used to preferentially find the memory base address of the target assembly instructions in the dependency library; the protection device for the above program code further includes an execution module 340, and when the application corresponding to the above target program code runs, it is specifically used for:

[0078] Execute the load method code in the dependency library to obtain the memory base address of the target assembly instructions;

[0079] Based on the jump instructions and the memory base address, jump to execute the target assembly instructions.

[0080] In one implementation, the generation module 330 is further used for:

[0081] Increase the number of fields in the Load Commands field of the Mach-O format of the executable file corresponding to the program code by one.

[0082] In one implementation, the processing module 320 is specifically used for:

[0083] Replace the assembly instructions with target assembly instructions; the target assembly instructions are different from the assembly instructions but have the same execution result.

[0084] In one implementation, the acquisition module 310 includes:

[0085] The first determination unit 3101 is used to determine the main program name based on the Apple program application file IPA;

[0086] The second determination unit 3102 is used to obtain the Mach-O format of the program code based on the main program name, and determine the function name, function address and function size in the program code and the program code.

[0087] An obtaining unit 3103, configured to obtain the program code to be protected and the assembly instructions corresponding to the program code to be protected based on the program code, function name, function address, and function size in the program code.

[0088] In one implementation, the dependency library is a framework library; a processing module 320 is specifically configured to:

[0089] Place the target assembly instructions into a preset empty function in the framework library.

[0090] In one implementation, the obtaining unit 3103 is specifically configured to:

[0091] Determine the function code based on the function name and function address in the program code;

[0092] Disassemble the function code through a disassembling tool to obtain the assembly code;

[0093] Based on the preset storage space size of the empty function and the function size, determine the program code to be protected and the assembly instructions corresponding to the program code to be protected in the assembly code;

[0094] Obtain the program code to be protected and the assembly instructions.

[0095] The protection device for program code provided by the embodiments of the present invention obtains the assembly instructions corresponding to the program code to be protected in the program code, performs obfuscation transformation processing on the assembly instructions to obtain target assembly instructions, then places the target assembly instructions into a pre-compiled dependency library, replaces the program code to be protected in the program code with a jump instruction, and generates corresponding target program code. When the jump instruction is executed, it jumps to the address of the target assembly instructions in the dependency library and executes the target assembly instructions in the dependency library. Compared with the original code that has been inflated, the newly generated protection code is added to the program code in the form of a newly added TEXT segment (also known as the code segment). This solution uses a jump instruction to replace the program code to be protected in the program code, and the generated target program code does not include the program code to be protected, preventing the program code to be protected from being statically analyzed. Also, the target assembly instructions obtained by obfuscating and transforming the assembly instructions corresponding to the program code to be protected are placed in the dependency library. When the jump instruction is executed, it jumps to the address of the target assembly instructions in the dependency library and executes the target assembly instructions in the dependency library, which can achieve the purpose of protecting the program code to be protected without adding an extra TEXT segment, solve the problem that the customer application program after being processed by the related protection scheme cannot be put on the App Store, and furthermore, the target assembly instructions stored in the dependency library are obtained by obfuscating and transforming the assembly instructions corresponding to the program code to be protected, further improving the protection effect.

[0096] Those skilled in the art should understand that the protection device for the above program code can be used to implement the protection method of the program code described above. The detailed description should be similar to that in the method part above. To avoid repetition, it will not be elaborated here.

[0097] Based on the same technical concept, the embodiment of the present application also provides an electronic device, which is used to execute the above protection method of the program code. Figure 4 FIG. is a schematic structural diagram of an electronic device for implementing various embodiments of the present application. The electronic device may vary greatly due to different configurations or performances, and may include a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 communicate with each other through the communication bus 440. The processor 410 can call a computer program stored in the memory 430 and executable on the processor 410 to execute the following steps:

[0098] Obtain the program code and the assembly instructions corresponding to the program code to be protected in the program code;

[0099] Perform an obfuscation transformation process on the assembly instructions to obtain target assembly instructions, and put the target assembly instructions into a pre-compiled dependency library;

[0100] Replace the program code to be protected in the program code with a jump instruction, and generate corresponding target program code; when the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library.

[0101] The solution provided by the embodiment of the present invention is through.

[0102] The specific execution steps can refer to the steps of the above embodiment of the protection method of the program code, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.

[0103] It should be noted that the electronic device in the embodiment of the present application includes: a server, a terminal, or other devices other than the terminal.

[0104] The above structure of the electronic device does not limit the electronic device. The electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements. For example, the input unit may include a Graphics Processing Unit (GPU) and a microphone, and the display unit may be configured with a display panel in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit includes at least one of a touch panel and other input devices. The touch panel is also called a touch screen. Other input devices may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, a joystick, which will not be elaborated here.

[0105] The memory can be used to store software programs and various data. The memory mainly includes a first storage area for storing programs or instructions and a second storage area for storing data. Among them, the first storage area can store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory can include volatile memory or non-volatile memory, or the memory can include both volatile and non-volatile memory. Among them, the non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically Erasable PROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synchlink DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM).

[0106] The processor may include one or more processing units; optionally, the processor integrates an application processor and a modem processor. Among them, the application processor mainly processes operations related to the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor may not be integrated into the processor either.

[0107] The embodiments of the present application further provide a storage medium, on which computer-executable instructions are stored. When these computer-executable instructions are executed by a processor, they implement each process of the protection method embodiment of the above program code and can achieve the same technical effects. To avoid repetition, they will not be elaborated here.

[0108] Among them, the processor is the processor in the electronic device described in the above embodiments. The storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disc, etc.

[0109] It should be noted that in this article, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including that element. In addition, it should be pointed out that the methods and devices in the embodiments of the present application are not limited to performing functions in the order shown or discussed, and may also include multitasking and parallel processing according to the functions involved, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0110] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present application.

[0111] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A method for protecting program code, characterized in that, The method includes: Obtaining program code and assembly instructions corresponding to the program code to be protected in the program code; Performing obfuscation transformation on the assembly instructions to obtain target assembly instructions, and putting the target assembly instructions into a pre-compiled dependency library; Replacing the program code to be protected in the program code with a jump instruction, and generating corresponding target program code; when the jump instruction is executed, it jumps to the address of the target assembly instruction in the dependency library and executes the target assembly instruction in the dependency library.

2. The method according to claim 1, characterized in that, The jump instruction includes the offset address of the target assembly instruction; the pre-compiled dependency library includes a pre-compiled load method, and the load method code is used to preferentially find the memory base address of the target assembly instruction in the dependency library; the method further includes: Executing the load method code in the dependency library to obtain the memory base address of the target assembly instruction; Based on the jump instruction and the memory base address, jumping to execute the target assembly instruction.

3. The method according to claim 1, wherein After replacing the program code to be protected in the program code with a jump instruction and generating corresponding target program code, it further includes: Increasing the number of fields in the Load Commands field of the loading information in the Mach-O format of the executable file corresponding to the program code by one.

4. The method according to claim 1, characterized in that The performing obfuscation transformation on the assembly instructions to obtain target assembly instructions includes: Replacing the assembly instructions with the target assembly instructions; the target assembly instructions are different from the assembly instructions but have the same execution result.

5. The method according to claim 1, wherein The obtaining program code and assembly instructions corresponding to the program code to be protected in the program code includes: Based on the Apple program application file IPA, determining the main program name; Based on the main program name, obtaining the Mach-O format of the program code, and determining the function name, function address, and function size in the program code and the program code; Based on the program code and the function name, function address, and function size in the program code, obtaining the program code to be protected and the assembly instructions corresponding to the program code to be protected.

6. The method according to claim 1, characterized in that, The dependency library is a framework library developed by the software development framework.NETFramework; The putting the target assembly instructions into a pre-compiled dependency library includes: Putting the target assembly instructions into a preset empty function in the framework library.

7. The method according to claims 5 and 6, characterized in that, The obtaining the program code to be protected and the assembly instructions corresponding to the program code to be protected based on the program code and the function name, function address, and function size in the program code includes: Based on the function name and function address in the program code, determining the function code; Disassembling the function code through a disassembler to obtain assembly code; Based on the preset storage space size of the empty function and the function size, determining the program code to be protected and the assembly instructions corresponding to the program code to be protected in the assembly code; Obtaining the program code to be protected and the assembly instructions.

8. A protection device for program code, characterized in that, The device includes: An acquisition module, configured to obtain assembly instructions corresponding to program code and the program code to be protected in the program code; A processing module, configured to perform obfuscation transformation on the assembly instructions to obtain target assembly instructions, and place the target assembly instructions into a pre-compiled dependency library; A generation module, configured to replace the program code to be protected in the program code with jump instructions, and generate corresponding target program code; when the jump instructions are executed, they jump to the address of the target assembly instructions in the dependency library and execute the target assembly instructions in the dependency library.

9. An electronic device, characterized in that, The device includes: A processor; and A memory arranged to store computer-executable instructions, the executable instructions being configured to be executed by the processor, the executable instructions including a protection method for executing the program code according to any one of claims 1-7.

10. A storage medium, characterized in that, The storage medium is used to store computer-executable instructions, and the computer-executable instructions cause a computer to execute the protection method of the program code according to any one of claims 1-7.