Application execution method and device
By encrypting the code collection of applications in the server and utilizing container technology, the problems of application back-end code security and execution efficiency are solved, and security improvement and execution efficiency are achieved.
Patent Information
- Application Number
- CN202510437840.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-25
AI Technical Summary
The back-end code applied in the prior art is arranged in the server, and there are security risks of leakage or tampering. How to improve the security and execution efficiency of the back-end code applied in the server.
Multiple code sets applied are encrypted and deployed in the server, and only the code sets corresponding to the target function that accesses requests access are decrypted and executed. Through encryption algorithms such as DES, AES, RSA, etc., container technology is used to achieve isolation and security protection of code sets.
Reduces the risk of application code leaks or tampering, improves application code security, and improves execution efficiency, ensuring that only content accessing target functions is displayed correctly.
Smart Images

Figure CN120372600A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technologies, and in particular, to technical fields such as application security and application execution. Background Art
[0002] In the prior art, the backend code of an application is usually arranged in plaintext on a server, and the access requests from a client are executed through the plaintext backend code. In this way, there may be security risks such as leakage or tampering of the backend code of the application. Therefore, how to improve the security of the backend code of an application in a server has become a technical problem to be solved. Summary of the Invention
[0003] The present disclosure provides a method and a server for application execution.
[0004] According to one aspect of the present disclosure, there is provided a method for application execution, which is applied to a server and includes:
[0005] Responding to an access request received from a client, determining a target function accessed by the access request, where the target function is one of multiple functions of a first application;
[0006] Determining, in a plurality of encrypted code sets of the first application, an encrypted target code set corresponding to the target function;
[0007] Decrypting the encrypted target code set corresponding to the target function to obtain a decrypted target code set corresponding to the target function;
[0008] Executing the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, where the execution result of the decrypted target code set is used to display, on the client, content corresponding to the target function;
[0009] Sending the execution result of the decrypted target code set to the client.
[0010] According to one aspect of the present disclosure, there is provided an application execution device, including:
[0011] A function determination module, configured to respond to an access request received from a client and determine a target function accessed by the access request, where the target function is one of multiple functions of a first application;
[0012] A code set determination module, configured to determine, in a plurality of encrypted code sets of the first application, an encrypted target code set corresponding to the target function;
[0013] A decryption module, configured to decrypt the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function;
[0014] A code set execution module, configured to execute the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, where the execution result of the decrypted target code set is used to display the content corresponding to the target function on the client;
[0015] A communication module, configured to send the execution result of the decrypted target code set to the client.
[0016] By adopting the above implementation manner, among the multiple encrypted code sets of the first application, the encrypted target code set corresponding to the target function accessed by the access request is determined, where the target function is one of the multiple functions of the first application; after decrypting the encrypted target code set, the decrypted target code set is executed to obtain an execution result of the decrypted target code set; and the execution result of the decrypted target code set is sent to the client, where the execution result of the decrypted target code set is used to display the content corresponding to the target function on the client. In this way, multiple code sets for executing multiple functions of the first application can be encrypted and deployed on the server, reducing the risk of code leakage or tampering of the first application and enhancing the security of the code of the first application. In addition, only by decrypting and executing the code set corresponding to the target function accessed by the access request can the content corresponding to the target function accessed by the client be obtained, further enhancing the execution efficiency of the first application.
[0017] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. Description of the Drawings
[0018] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:
[0019] Figure 1 is a schematic flowchart of a method for application execution according to an embodiment of the present disclosure;
[0020] Figure 2 is a schematic flowchart of a method for application execution according to another embodiment of the present disclosure;
[0021] Figure 3 is a schematic flowchart of a method for application execution according to still another embodiment of the present disclosure;
[0022] Figure 4It is a schematic block diagram of an application execution device according to an embodiment of the present disclosure;
[0023] Figure 5 It is a schematic block diagram of an application execution device according to another embodiment of the present disclosure;
[0024] Figure 6 It is a block diagram of an electronic device for implementing the embodiments of the present disclosure. Detailed implementation manners
[0025] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0026] Figure 1 It is a schematic flowchart of a method for application execution proposed by an embodiment of the present disclosure, including:
[0027] S110. In response to receiving an access request sent by a client, determine a target function accessed by the access request, where the target function is one of multiple functions of a first application.
[0028] S120. In a plurality of encrypted code sets of the first application, determine an encrypted target code set corresponding to the target function.
[0029] S130. Decrypt the encrypted target code set corresponding to the target function to obtain a decrypted target code set corresponding to the target function.
[0030] S140. Execute the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, where the execution result of the decrypted target code set is used to display content corresponding to the target function on the client.
[0031] S150. Send the execution result of the decrypted target code set to the client.
[0032] The method for application execution according to the embodiments of the present disclosure can be executed by a server. The server can be a single physical server or a physical server in a server cluster.
[0033] By adopting the above implementation manner, in the multiple encrypted code sets of the first application, determine the encrypted target code set corresponding to the target function accessed by the access request, where the target function is one of the multiple functions of the first application; after decrypting the encrypted target code set, execute the decrypted target code set to obtain the execution result of the decrypted target code set; send the execution result of the decrypted target code set to the client, where the execution result of the decrypted target code set is used to display the content corresponding to the target function on the client. In this way, multiple code sets for executing multiple functions of the first application can be encrypted and deployed on the server, reducing the risk of code leakage or tampering of the first application and enhancing the security of the first application code. In addition, by only decrypting and executing the code set corresponding to the target function accessed by the access request, the content corresponding to the target function accessed by the client can be obtained, further enhancing the execution efficiency of the first application.
[0034] In one implementation manner, before determining the target function accessed by the access request in response to receiving the access request sent by the client, the operations performed on the server side further include: encrypting each of the multiple code sets of the first application to obtain the multiple encrypted code sets of the first application, where different code sets among the multiple code sets correspond to different functions among the multiple functions of the first application.
[0035] The multiple code sets of the first application can be one of the following: multiple code sets of the backend (or called the server side) of a software program, multiple code sets of the backend (or called the server side) of a website; where the code can be one of the following: PHP (Hypertext Preprocessor) code, Python code, Java code, etc., and for the sake of brevity, they are not listed one by one here.
[0036] Taking the i-th code set among the multiple code sets of the first application as an example (i is a positive integer), the fact that different code sets among the multiple code sets correspond to different functions among the multiple functions of the first application can be: the i-th code set of the first application corresponds to the i-th function of the first application, where the i-th function can be one of the following: page display function, user login function, user registration function, API interface function, etc., and for the sake of brevity, they are not listed one by one here.
[0037] Taking the i-th code set among the multiple code sets of the first application as an example, the encrypting of the multiple code sets of the first application respectively to obtain the encrypted multiple code sets of the first application includes: generating a first key corresponding to the i-th code set among the multiple code sets of the first application based on the i-th first key generation algorithm; encrypting the i-th code set based on the i-th first encryption algorithm and the first key corresponding to the i-th code set to obtain the encrypted i-th code set of the first application.
[0038] The i-th first key generation algorithm may be one of the following: symmetric key generation algorithm, asymmetric key generation algorithm. Among them, the symmetric key generation algorithm includes one of the following: DES (Data Encryption Standard) algorithm, 3DES (Triple Data Encryption Standard) algorithm, AES (Advanced Encryption Standard) algorithm, etc. The asymmetric key generation algorithm includes one of the following: RSA algorithm, ECC (Elliptic Curve Cryptography) algorithm, DSA (Digital Signature Algorithm), etc. For the sake of brevity, they will not be elaborated one by one here.
[0039] The i-th first encryption algorithm may be one of the following: in the case where the i-th first key generation algorithm is a symmetric key generation algorithm, the i-th first encryption algorithm is a symmetric encryption algorithm; in the case where the i-th first key generation algorithm is an asymmetric key generation algorithm, the i-th first encryption algorithm is an asymmetric encryption algorithm. Among them, the symmetric encryption algorithm includes one of the following: DES algorithm, 3DES algorithm, AES algorithm, etc. The asymmetric encryption algorithm includes one of the following: RSA algorithm, ECC algorithm, DSA, etc. For the sake of brevity, they will not be elaborated one by one here.
[0040] Optionally, in the case where the i-th first key generation algorithm is a symmetric key generation algorithm, the generating of a first key corresponding to the i-th code set among the multiple code sets of the first application based on the i-th first key generation algorithm may include: generating a symmetric key corresponding to the i-th code set based on the i-th first key generation algorithm; using the symmetric key corresponding to the i-th code set as the first key corresponding to the i-th code set among the multiple code sets of the first application.
[0041] Optionally, when the i-th first key generation algorithm is an asymmetric key generation algorithm, generating the first key corresponding to the i-th code set among the multiple code sets of the first application based on the i-th first key generation algorithm may include: generating a first public key and a first private key corresponding to the i-th code set based on the i-th first key generation algorithm; using the first public key corresponding to the i-th code set as the first key corresponding to the i-th code set. The first private key corresponding to the i-th code set is used to decrypt the encrypted i-th code set.
[0042] The obtaining manner of each code set in the encrypted multiple code sets of the first application is the same as that of the encrypted i-th code set of the first application described above, which will not be elaborated here. It should be emphasized that the first encryption algorithms for encrypting each code set may be the same or different; the first keys for encrypting each code set may be the same or different.
[0043] In this way, encrypting the multiple code sets of the first application respectively to obtain the encrypted multiple code sets of the first application, where different code sets among the multiple code sets correspond to different functions among the multiple functions of the first application. In this way, the code set of each function of the first application can be encrypted separately, and then in the subsequent processing process, only the code set corresponding to the target function accessed by the access request is decrypted and executed, and the content corresponding to the target function accessed by the client can be obtained, thereby improving the execution efficiency of the first application.
[0044] In an implementation manner, after the server side performs encrypting the multiple code sets of the first application respectively to obtain the encrypted multiple code sets of the first application, it further includes: creating a target container based on the encrypted multiple code sets of the first application and the multiple dependency packages corresponding to the multiple code sets of the first application.
[0045] Creating a target container based on the encrypted multiple code sets of the first application and the multiple dependency packages corresponding to the multiple code sets of the first application includes: obtaining an image of the running environment required by the first application; adding the encrypted multiple code sets of the first application, the second key corresponding to each code set in the encrypted multiple code sets of the first application, the multiple dependency packages corresponding to the multiple code sets of the first application, and the second application to the image of the running environment required by the first application to obtain a target image; creating the target container based on the target image.
[0046] The image of the operating environment required for the first application may include one of the following: a Windows system environment image, a Linux system environment image, or other system environment images. For the sake of brevity, they will not be elaborated one by one here.
[0047] The specific method for obtaining the image of the operating environment required for the first application is not limited in this application. For example, it can be obtained from other servers or pre-created in the server.
[0048] The dependency package is at least one of the following: tools, components, files on which multiple code sets of the first application depend for execution, etc. For the sake of brevity, they will not be elaborated one by one here.
[0049] The second application is used to perform at least one of the following: receiving an access request from a client to access the target function of the first application; sending the access request to the first application; receiving the execution result of the decrypted target code set sent by the first application; sending the execution result of the decrypted target code set to the client. Among them, the second application can be one of the following: an Nginx (reverse proxy service) application, an HAProxy (High Availability Proxy) application, etc. The second application can also be other applications with proxy functions, which will not be enumerated here.
[0050] Taking the i-th code set among the multiple code sets of the first application as an example, the second key corresponding to each code set in the encrypted multiple code sets of the first application is described as follows: when the i-th first key generation algorithm is a symmetric key generation algorithm, the second key corresponding to the i-th code set is the same as the first key corresponding to the i-th code set; when the i-th key generation algorithm is an asymmetric key generation algorithm, the second key corresponding to the i-th code set is the first private key corresponding to the i-th code set.
[0051] Among them, the second key corresponding to each code set may be stored in the security protection area of the target container, and this complete protection area only allows the first application to access, or only allows the first application and the target container to access.
[0052] The target container can be one of the following: Docker container, Podman (Portable Docker Machine), LXC (Linux Containers), Kubernetes container, etc. For the sake of brevity, they are not listed one by one here. Among them, the container can achieve system isolation. For example, multiple containers can run on a physical server, and each container has an independent system. The systems between the containers are isolated from each other, and the systems of the containers are isolated from the system of the physical server where the containers are located.
[0053] The specific manner of creating the target container based on the target image is not limited in this application. Taking the target container as a Docker container as an example, the target image may include startup instructions. Based on the target image, creating the target container may be: executing the startup instructions in the target image to create a target container on the server. In this way, the target image can run in the target container, thereby realizing the deployment of the first application in the target container of the server.
[0054] It can be understood that the target container may at least include: multiple encrypted code sets of the first application, a second key corresponding to each code set in the multiple encrypted code sets of the first application, multiple dependency packages corresponding to the multiple code sets of the first application, the operating environment required by the first application, and a second application.
[0055] On the server side, the manner of receiving an access request sent by the client may include: the first application receives the access request sent by the client through the second application in the target container.
[0056] On the server side, the first application receiving the access request sent by the client through the second application in the target container may include: the server receives the access request sent by the client; the server sends the access request to the second application of the target container; the second application receives the access request; the second application sends the access request to the first application.
[0057] Correspondingly, the operations performed on the client side include: in response to a trigger operation, sending an access request to the server to access the target function of the first application, where the access request includes at least one of the following: the access path of the target function of the first application, the identifier of the target function of the first application.
[0058] In the scenario where the first application is the backend code of a website, the triggering operation includes one of the following: the user enters the access path of the target function of the first application in the browser; the user clicks the button of the target function of the first application on the current web page in the browser. Among them, the access path may be a URL (Uniform Resource Locator) path.
[0059] In the scenario where the first application is the backend code of a software program, the triggering operation includes: clicking the button of the target function of the first application in the graphical user interface of the client.
[0060] In this way, by forwarding the access request of the client through the second application in the target container, the direct access of the client to the first application in the target container can be restricted, further enhancing the security of the first application.
[0061] On the server side, determining the target function accessed by the access request may include: the server controls the first application in the target container to determine the target function accessed by the access request based on the access path of the target function in the access request and / or the identifier of the target function.
[0062] On the server side, among the multiple encrypted code sets of the first application, determining the encrypted target code set corresponding to the target function may include: the server controls the first application in the target container to execute based on the correspondence between each code set in the multiple encrypted code sets of the first application and the target function, and determine the encrypted target code set corresponding to the target function. Among them, the correspondence between each code set and the target function can be set according to the actual situation, and this application does not limit it.
[0063] On the server side, taking the target code combination as the i-th code set among the multiple code sets as an example, decrypting the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function may include: the server controls the first application in the target container to execute based on the i-th decryption algorithm and the second key corresponding to the target code set, and decrypt the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function. Among them, the i-th first decryption algorithm is the same algorithm as the above-mentioned i-th first encryption algorithm, and the difference is that the i-th first encryption algorithm is used to encrypt the code set, and the i-th first decryption algorithm is used to decrypt the code set.
[0064] On the server side, executing the target code set corresponding to the decryption of the target function to obtain the execution result of the decrypted target code set includes: executing the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set.
[0065] The executing the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set may include: the server controlling the first application in the target container to execute the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set.
[0066] The dependency package corresponding to the target code set may be one or more dependency packages corresponding to the target code set among the multiple dependency packages corresponding to the multiple code sets of the first application. Among them, the corresponding relationship between the target code set and one or more dependency packages among the multiple dependency packages may be set according to the actual situation, and this application does not limit it.
[0067] The server controlling the first application in the target container to execute the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set may include: the server controlling the first application in the target container to execute the decrypted target code set corresponding to the target function; during the process of the first application in the target container executing the decrypted target code set corresponding to the target function, the first application in the target container calls or loads the dependency package corresponding to the target code set; when the first application in the target container finishes executing the decrypted target code set corresponding to the target function, the execution result of the decrypted target code set is obtained.
[0068] Among them, during the process of the first application in the target container executing the decrypted target code set corresponding to the target function, the specific manner in which the first application in the target container calls or loads the dependency package corresponding to the target code set may be set according to the actual situation, and this application does not limit it.
[0069] The execution result of the decrypted target code set may be: the code for the client to display the content corresponding to the target function. Among them, the code for the content corresponding to the target function may be one of the following: HTML (HyperText Markup Language) code, XML (eXtensible Markup Language) code, etc., which will not be listed one by one here.
[0070] In this way, based on the dependency package corresponding to the target code set, execute the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set. In this way, the executability of the target code set can be guaranteed.
[0071] On the server side, sending the execution result of the decrypted target code set to the client includes: the first application in the target container sending the execution result of the decrypted target code set to the client through the second application in the target container.
[0072] The first application in the target container sending the execution result of the decrypted target code set to the client through the second application in the target container includes: the first application in the target container sending the execution result of the decrypted target code set to the second application; the second application receiving the execution result of the decrypted target code set; the second application sending the execution result of the decrypted target code set to the server; the server receiving the execution result of the decrypted target code set; the server sending the execution result of the decrypted target code set to the client.
[0073] Correspondingly, the operations performed on the client side include: receiving the execution result of the decrypted target code set sent by the server; and displaying the content corresponding to the target function based on the execution result of the decrypted target code set.
[0074] Based on the execution result of the decrypted target code set, presenting the content corresponding to the target function can be set according to the actual situation, and this application does not limit it. For example: in the scenario where the first application is the backend code of a website, presenting the content corresponding to the target function based on the execution result of the decrypted target code set can be: after the browser compiles the execution result of the decrypted target code set, presenting the content corresponding to the target function in the browser. Another example: in the scenario where the first application is the backend code of a software program, presenting the content corresponding to the target function based on the execution result of the decrypted target code set can be: after the client compiles the execution result of the decrypted target code set, presenting the content corresponding to the target function in the graphical user interface of the client.
[0075] In one implementation, for the method executed by the server, before determining the target function accessed by the access request in response to receiving the access request sent by the client, it further includes: encrypting multiple dependency packages corresponding to multiple code sets of the first application respectively to obtain multiple encrypted dependency packages corresponding to the multiple code sets.
[0076] Taking the jth dependency package in the multiple dependency packages as an example (j is a positive integer), the encrypting multiple dependency packages corresponding to multiple code sets of the first application respectively to obtain multiple encrypted dependency packages corresponding to the multiple code sets may include: generating a third key corresponding to the jth dependency package in the multiple dependency packages corresponding to multiple code sets of the first application based on the jth second key generation algorithm; encrypting the jth dependency package based on the jth second encryption algorithm and the third key corresponding to the jth dependency package to obtain the jth encrypted dependency package corresponding to the multiple code sets.
[0077] Among them, the jth second key generation algorithm may be one of the following: symmetric key generation algorithm, asymmetric key generation algorithm. The symmetric key generation algorithm and the asymmetric key generation algorithm are the same as those in the above implementation, and will not be elaborated here.
[0078] The jth second encryption algorithm may include one of the following: when the jth second key generation algorithm is a symmetric key generation algorithm, the jth second encryption algorithm is a symmetric encryption algorithm; when the jth second key generation algorithm is an asymmetric key generation algorithm, the jth second encryption algorithm is an asymmetric encryption algorithm, where the symmetric encryption algorithm and the asymmetric encryption algorithm are the same as those in the above implementation, and will not be elaborated here.
[0079] Optionally, when the j-th second key generation algorithm is a symmetric key generation algorithm, generating the third key corresponding to the j-th dependent package among the multiple dependent packages corresponding to the multiple code sets of the first application based on the j-th key generation algorithm includes: generating a symmetric key corresponding to the j-th dependent package among the multiple dependent packages corresponding to the multiple code sets of the first application based on the j-th key generation algorithm; and using the symmetric key corresponding to the j-th dependent package as the third key corresponding to the j-th dependent package.
[0080] Optionally, when the j-th second key generation algorithm is an asymmetric key generation algorithm, generating the third key corresponding to the j-th dependent package among the multiple dependent packages corresponding to the multiple code sets of the first application based on the j-th second key generation algorithm includes: generating a second public key and a second private key corresponding to the j-th dependent package among the multiple dependent packages corresponding to the multiple code sets of the first application based on the j-th second key generation algorithm; and using the second public key corresponding to the j-th dependent package as the third key corresponding to the j-th dependent package. The second private key corresponding to the j-th dependent package is used to decrypt the j-th dependent package.
[0081] The obtaining method of each dependent package among the multiple dependent packages is the same as that of the j-th dependent package described above, which will not be elaborated here. It should be emphasized that the second encryption algorithms for encrypting each dependent package may be the same or different; the third keys for encrypting each dependent package may be the same or different.
[0082] In this way, the multiple dependent packages corresponding to the multiple code sets of the first application are encrypted respectively to obtain the encrypted multiple dependent packages corresponding to the multiple code sets. In this way, the security of the first application can be further improved.
[0083] In this embodiment, after the server side encrypts the multiple dependent packages corresponding to the multiple code sets of the first application respectively to obtain the encrypted multiple dependent packages corresponding to the multiple code sets, it further includes: creating a target container based on the encrypted multiple code sets of the first application and the encrypted multiple dependent packages corresponding to the multiple code sets.
[0084] Creating a target container based on the multiple encrypted code sets of the first application and the multiple encrypted dependency packages corresponding to the multiple code sets includes: obtaining an image of the operating environment required by the first application; adding the multiple encrypted code sets of the first application, the second key corresponding to each code set in the multiple encrypted code sets of the first application, the multiple encrypted dependency packages corresponding to the multiple code sets, the fourth key corresponding to each dependency package in the multiple dependency packages, and the second application to the image of the operating environment required by the first application to obtain a target image; creating the target container based on the target image.
[0085] Among them, the method for obtaining the image of the operating environment required by the first application is the same as that in the above embodiment and will not be elaborated here. The method for obtaining the multiple encrypted code sets of the first application and the second key corresponding to each code set in the multiple encrypted code sets of the first application is the same as that in the above embodiment and will not be elaborated here. The method for creating the target container based on the target image is the same as that in the above embodiment and will not be elaborated here.
[0086] It can be understood that the target container may at least include: the multiple encrypted code sets of the first application, the second key corresponding to each code set in the multiple encrypted code sets of the first application, the multiple encrypted dependency packages corresponding to the multiple code sets, the fourth key corresponding to each dependency package in the multiple dependency packages, the operating environment required by the first application, and the second application.
[0087] Taking the j-th dependency package in the multiple dependency packages as an example, the fourth key corresponding to each dependency package in the multiple dependency packages is described as follows: when the j-th second key generation algorithm is a symmetric key generation algorithm, the third key corresponding to the j-th dependency package is the same as the fourth key corresponding to the j-th dependency package; when the j-th second key generation algorithm is an asymmetric key generation algorithm, the second private key corresponding to the j-th dependency package is the fourth key corresponding to the j-th dependency package.
[0088] Among them, the fourth key corresponding to each dependency package in the multiple dependency packages can be stored in the secure protection area of the target container, and the secure protection area only allows the first application to access, or the secure protection area only allows the first application and the target container to access.
[0089] In this embodiment, the method for receiving an access request sent by a client is the same as that in the above embodiment, and will not be elaborated herein. The method for determining the target function accessed by the access request is the same as that in the above embodiment, and will not be elaborated herein. In the multiple encrypted code sets of the first application, determining the encrypted target code set corresponding to the target function is the same as that in the above embodiment, and will not be elaborated herein. Decrypting the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function is the same as that in the above embodiment, and will not be elaborated herein.
[0090] In this embodiment, on the server side, executing the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set includes: obtaining the decrypted dependency package corresponding to the target code set; based on the decrypted dependency package corresponding to the target code set, executing the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set.
[0091] The obtaining of the decrypted dependency package corresponding to the target code set includes one of the following: when the decrypted dependency package corresponding to the target code set does not exist in the cache, decrypting the encrypted dependency package corresponding to the target code set to obtain the decrypted dependency package corresponding to the target code set; when the decrypted dependency package corresponding to the target code set exists in the cache, obtaining the decrypted dependency package corresponding to the target code set from the cache.
[0092] When the decrypted dependency package corresponding to the target code set does not exist in the cache, decrypting the encrypted dependency package corresponding to the target code set to obtain the decrypted dependency package corresponding to the target code set may include: the server controlling the first application in the target container to determine whether the decrypted dependency package corresponding to the target code set exists in the cache of the target container; when the decrypted dependency package corresponding to the target code set does not exist in the cache of the target container, the first application in the target container decrypts the encrypted dependency package corresponding to the target code set to obtain the decrypted dependency package corresponding to the target code set.
[0093] Taking the encrypted dependency package corresponding to the target code set as the j-th dependency package among the multiple encrypted dependency packages, the server controls the first application in the target container to decrypt the encrypted dependency package corresponding to the target code set, and obtain the decrypted dependency package corresponding to the target code set, including: the server controls the first application in the target container to decrypt the encrypted dependency package corresponding to the target code set based on the j-th second decryption algorithm and the fourth key corresponding to the encrypted dependency package corresponding to the target code set, so as to obtain the decrypted dependency package corresponding to the target code set. Wherein, the j-th second decryption algorithm is the same as the j-th second encryption algorithm, the difference being that the j-th second encryption algorithm is used to encrypt the dependency package, and the j-th second decryption algorithm is used to decrypt the dependency package.
[0094] On the server side, after the target container decrypts the encrypted dependency package corresponding to the target code set and obtains the decrypted dependency package corresponding to the target code set, the method further includes: the target container saves the decrypted dependency package corresponding to the target code set in the cache of the target container.
[0095] On the server side, after the target container saves the decrypted dependency package corresponding to the target code set in the cache of the target container, it further includes: when the specified duration is reached, the target container deletes the decrypted dependency package corresponding to the target code set saved in the cache. Wherein, the specified duration can be set according to the actual situation, which is not limited in this application. For example, it can be 10 minutes, 20 minutes, 30 minutes, or longer or shorter.
[0096] In addition, when the decrypted dependency package corresponding to the target code set exists in the cache of the target container, obtain the decrypted dependency package corresponding to the target code set from the cache of the target container.
[0097] The manner of executing the decrypted target code set corresponding to the target function based on the decrypted dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set is the same as the above-mentioned manner of executing the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set, and will not be elaborated here.
[0098] In this way, it is determined whether there is a decrypted dependency package corresponding to the target code set in the cache; in the case of non-existence, the encrypted dependency package corresponding to the target code set is decrypted; in the case of existence, the decrypted dependency package corresponding to the target code set is obtained from the cache. In this way, the operation of decrypting the dependency package can be avoided from being repeatedly executed, and the execution efficiency of the first application is improved. Further, after obtaining the decrypted dependency package corresponding to the target code set, based on the decrypted dependency package corresponding to the target code set, the decrypted target code set corresponding to the target function is executed to obtain the execution result of the decrypted target code set, provided that the executability of the target code set can be ensured.
[0099] In this embodiment, the manner of sending the execution result of the decrypted target code set to the client is the same as that in the above embodiment, and will not be elaborated here.
[0100] In this embodiment, the operations performed on the client side are the same as those performed by the client in the above embodiment, and will not be elaborated here.
[0101] Combined Figure 2 An exemplary description of the method for executing the above application is as follows:
[0102] S201, on the client side, in response to a trigger operation, send an access request to the server to access the target function of the first application.
[0103] Figure 2 S202 to S207 in
[0104] S202, the server receives the access request sent by the client; the server sends the access request to the second application in the target container; the second application receives the access request; the second application sends the access request to the first application.
[0105] S203, the first application determines the target function accessed by the access request based on the access path of the target function and / or the identifier of the target function in the access request.
[0106] S204, the first application decrypts the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function.
[0107] S205, the first application executes the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set.
[0108] Optionally, when the target container includes multiple dependency packages corresponding to multiple code sets of the first application, the first application executes the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set, including: the first application executes the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set.
[0109] Optionally, when the target container includes multiple encrypted dependency packages corresponding to the multiple code sets, the first application executes the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set, including: the first application obtains the decrypted dependency package corresponding to the target code set; and executes the decrypted target code set corresponding to the target function based on the decrypted dependency package corresponding to the target code set to obtain the execution result of the decrypted target code set.
[0110] S206. The first application sends the execution result of the decrypted target code set to the second application.
[0111] S207. The second application receives the execution result of the decrypted target code set; the second application sends the execution result of the decrypted target code set to the server; the server receives the execution result of the decrypted target code set; the server sends the execution result of the decrypted target code set to the client.
[0112] S208. On the client side, receive the execution result of the decrypted target code set sent by the server; and display the content corresponding to the target function based on the execution result of the decrypted target code set.
[0113] In one example, the operations performed on the server side may further include: the second application records the access log of the first application, where the access log of the first application includes at least one of the following: relevant information of each access request in one or more access requests, and relevant information of each execution result in one or more execution results.
[0114] The one or more access requests include the access request sent by the client described above. The one or more execution results include the execution result of the decrypted target code set described above.
[0115] The relevant information of each access request includes at least one of the following: the reception time of each access request, the transmission time of each access request, the IP (Internet Protocol) address of the client corresponding to each access request, and the parameters of each access request. Among them, the parameters of each access request can be set according to the actual situation, and this application does not limit it. For example, the parameters of each access request can include: the access port of each access request, the identifier and / or path of the function accessed by each access request, and so on.
[0116] The relevant information of each execution result includes at least one of the following: the reception time of each execution result, the transmission time of each execution result, the parameters of each execution result, and so on. Among them, the parameters of each execution result can be set according to the actual situation, and this application does not limit it. For example, the parameters of any one execution result can include: access success, or access failure, or login success, or login failure, and so on.
[0117] In one example, the operations performed on the server side may further include: the second application analyzes the access logs of the first application; in the case where the analysis result of the access logs of the first application includes abnormal access behaviors, an abnormal alarm notification is sent to the administrator. Among them, the abnormal access behaviors at least include: frequently invalid access behaviors, brute-force cracking behaviors, and so on.
[0118] Among them, the specific method of analyzing the access logs of the first application can be set according to the actual situation, and this application does not limit it. For example: in the case where the abnormal access behavior is a frequently invalid access behavior, it can be: when there are multiple access requests sent by a certain client in the access logs of the first application and the number of times is greater than the first threshold, and the parameters of the execution results of the code sets corresponding to the functions accessed by these multiple access requests are all access failures, it is determined that there is a frequently invalid access behavior. Another example: in the case where the abnormal access behavior is a brute-force cracking behavior, it can be: when there are multiple access requests sent by a certain client in the access logs of the first application and the number of times is greater than the first threshold, and the parameters of the execution results of the code sets corresponding to the functions accessed by these multiple access requests are all login failures, it is determined that there is a brute-force cracking behavior.
[0119] Sending the abnormal alarm notification to the administrator can be: sending an alarm email or an alarm text message to the client held by the administrator. The administrator can be the operation and maintenance personnel of the server.
[0120] In one example, after sending an exception alarm notification to the administrator, the operations performed on the server side may further include: the second application rejecting an access request sent by the client corresponding to the abnormal access behavior. Specifically, it may be rejecting an access request sent from the IP address of the client corresponding to the abnormal access behavior.
[0121] In this way, by monitoring the access logs of the first application through the second application, abnormal access behaviors can be discovered and blocked in a timely manner, improving the security protection ability of the first application.
[0122] Combined with Figure 3 An exemplary description of the method executed by the above application is as follows:
[0123] S301, on the server side, encrypting multiple code sets of the first application respectively to obtain multiple encrypted code sets of the first application. S301 may further include: encrypting multiple dependency packages corresponding to the multiple code sets of the first application respectively to obtain multiple encrypted dependency packages corresponding to the multiple code sets.
[0124] S302, creating a target container.
[0125] Optionally, the creating of the target container may include: creating a target container based on the multiple encrypted code sets of the first application and the multiple dependency packages corresponding to the multiple code sets of the first application.
[0126] Optionally, the creating of the target container may include: creating a target container based on the multiple encrypted code sets of the first application and the multiple encrypted dependency packages corresponding to the multiple code sets.
[0127] S303, on the client side, in response to a trigger operation, sending an access request to access the target function of the first application to the server.
[0128] S304, on the server side, the first application receives the access request sent by the client through the second application.
[0129] S305, on the server side, the first application determines the target function accessed by the access request based on the access path of the target function in the access request and / or the identifier of the target function.
[0130] S306, on the server side, the first application decrypts the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function.
[0131] S307, on the server side, the first application executes the decrypted target code set corresponding to the target function to obtain the execution result of the decrypted target code set.
[0132] Optionally, when the target container includes a plurality of dependency packages corresponding to a plurality of code sets of the first application, the first application executes the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, including: the first application executes the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set, to obtain the execution result of the decrypted target code set.
[0133] Optionally, when the target container includes a plurality of encrypted dependency packages corresponding to the plurality of code sets, the first application executes the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, including: the first application obtains the decrypted dependency package corresponding to the target code set; and executes the decrypted target code set corresponding to the target function based on the decrypted dependency package corresponding to the target code set, to obtain the execution result of the decrypted target code set.
[0134] S308, on the server side, the first application sends the execution result of the decrypted target code set to the second application.
[0135] S309, on the server side, the second application records the access log of the first application.
[0136] Figure 4 The schematic block diagram of an application execution device provided by an embodiment of the present disclosure is shown. As Figure 4 shown, it includes:
[0137] A function determination module 401, configured to determine a target function accessed by the access request in response to receiving an access request sent by a client, where the target function is one of a plurality of functions of a first application;
[0138] A code set determination module 402, configured to determine an encrypted target code set corresponding to the target function from a plurality of encrypted code sets of the first application;
[0139] A decryption module 403, configured to decrypt the encrypted target code set corresponding to the target function to obtain a decrypted target code set corresponding to the target function;
[0140] A code set execution module 404, configured to execute the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, where the execution result of the decrypted target code set is used to display content corresponding to the target function on the client;
[0141] The communication module 405 is configured to send the execution result of the decrypted target code set to the client.
[0142] The code set execution module is configured to execute the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set, and obtain the execution result of the decrypted target code set.
[0143] The code set execution module is configured to obtain the decrypted dependency package corresponding to the target code set; and execute the decrypted target code set corresponding to the target function based on the decrypted dependency package corresponding to the target code set, to obtain the execution device of the decrypted target code set.
[0144] The code set execution module is configured to perform one of the following: when the decrypted dependency package corresponding to the target code set does not exist in the cache, decrypt the encrypted dependency package corresponding to the target code set to obtain the decrypted dependency package corresponding to the target code set; when the decrypted dependency package corresponding to the target code set exists in the cache, obtain the decrypted dependency package corresponding to the target code set from the cache.
[0145] As Figure 5 shown, the apparatus further includes:
[0146] The encryption module 501 is configured to encrypt each of the multiple code sets of the first application to obtain multiple encrypted code sets of the first application, where different code sets among the multiple code sets correspond to different functions among the multiple functions of the first application.
[0147] The encryption module is configured to encrypt each of the multiple dependency packages corresponding to the multiple code sets of the first application to obtain multiple encrypted dependency packages corresponding to the multiple code sets.
[0148] For the specific functions and examples of the modules and sub-modules of the apparatus according to the embodiments of the present disclosure, reference may be made to the relevant descriptions of the corresponding steps in the above method embodiments, which will not be elaborated here.
[0149] In the technical solution of the present disclosure, the acquisition, storage, and application of user personal information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0150] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0151] Figure 6FIG. shows a schematic block diagram of an exemplary electronic device 600 that may be used to implement embodiments of the present disclosure. The server is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The server may also represent various forms of mobile devices, such as, personal digital assistants, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only exemplary and are not intended to limit the implementations of the present disclosure described and / or claimed herein.
[0152] As Figure 6 shown, the electronic device 600 includes a computing unit 601 that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0153] Multiple components in the electronic device 600 are connected to the I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a magnetic disk, an optical disk, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows the electronic device 600 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0154] The computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 executes the various methods and processes described above. For example, in some embodiments, the above methods can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded into the RAM 603 and executed by the computing unit 601, at least one step of the methods described above can be executed. Alternatively, in other embodiments, the computing unit 601 can be configured to execute the above methods in any other suitable manner (e.g., by means of firmware).
[0155] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor, receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0156] The program code (or referred to as application code) for implementing the methods of the present disclosure can be written in any combination of at least one programming language. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine and partially on a remote machine as an independent software package, or executed entirely on a remote machine or server.
[0157] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on at least one wire, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0158] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0159] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0160] A computer system can include a client and a server. The client and the server are generally far apart from each other and typically interact through a communication network. The relationship of the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating a blockchain.
[0161] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitations are imposed herein.
[0162] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. A method for application execution, comprising: Responding to an access request sent by a client, determining a target function accessed by the access request, wherein the target function is one of multiple functions of a first application; Determining, in multiple encrypted code sets of the first application, an encrypted target code set corresponding to the target function; Decrypting the encrypted target code set corresponding to the target function to obtain a decrypted target code set corresponding to the target function; Executing the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, wherein the execution result of the decrypted target code set is used to display content corresponding to the target function on the client; Sending the execution result of the decrypted target code set to the client.
2. The method according to claim 1, wherein The executing the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set includes: Based on a dependency package corresponding to the target code set, executing the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set.
3. The method according to claim 1, wherein, The executing the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set includes: Obtaining a decrypted dependency package corresponding to the target code set; Based on the decrypted dependency package corresponding to the target code set, executing the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set.
4. The method according to claim 3, wherein The obtaining the decrypted dependency package corresponding to the target code set includes one of the following: In the case where there is no decrypted dependency package corresponding to the target code set in the cache, decrypting the encrypted dependency package corresponding to the target code set to obtain the decrypted dependency package corresponding to the target code set; In the case where there is a decrypted dependency package corresponding to the target code set in the cache, obtaining the decrypted dependency package corresponding to the target code set from the cache.
5. The method according to any one of claims 1-4, further comprising: Encrypting multiple code sets of the first application respectively to obtain multiple encrypted code sets of the first application, wherein different code sets among the multiple code sets correspond to different functions among multiple functions of the first application.
6. The method according to claim 4, further comprising: Encrypting multiple dependency packages corresponding to multiple code sets of the first application respectively to obtain multiple encrypted dependency packages corresponding to the multiple code sets.
7. An apparatus for application execution, comprising: A function determination module, configured to respond to an access request sent by a client and determine a target function accessed by the access request, wherein the target function is one of multiple functions of a first application; A code set determination module, configured to determine an encrypted target code set corresponding to the target function in multiple encrypted code sets of the first application; A decryption module, configured to decrypt the encrypted target code set corresponding to the target function to obtain the decrypted target code set corresponding to the target function; A code set execution module, configured to execute the decrypted target code set corresponding to the target function to obtain an execution result of the decrypted target code set, wherein the execution result of the decrypted target code set is used to display the content corresponding to the target function on the client; A communication module, configured to send the execution result of the decrypted target code set to the client.
8. The apparatus according to claim 7, wherein, The code set execution module is configured to execute the decrypted target code set corresponding to the target function based on the dependency package corresponding to the target code set to obtain an execution result of the decrypted target code set.
9. The apparatus according to claim 7, wherein The code set execution module is configured to obtain the decrypted dependency package corresponding to the target code set; based on the decrypted dependency package corresponding to the target code set, execute the decrypted target code set corresponding to the target function to obtain an execution device of the decrypted target code set.
10. The device according to claim 9, wherein, The code set execution module is configured to perform one of the following: In the case where the decrypted dependency package corresponding to the target code set does not exist in the cache, decrypt the encrypted dependency package corresponding to the target code set to obtain the decrypted dependency package corresponding to the target code set; In the case where the decrypted dependency package corresponding to the target code set exists in the cache, obtain the decrypted dependency package corresponding to the target code set from the cache.
11. The apparatus according to any one of claims 7-10, further comprising: An encryption module, configured to encrypt multiple code sets of the first application respectively to obtain multiple encrypted code sets of the first application, wherein different code sets among the multiple code sets correspond to different functions among the multiple functions of the first application.
12. The device according to claim 11, wherein, The encryption module is configured to encrypt multiple dependency packages corresponding to the multiple code sets of the first application respectively to obtain multiple encrypted dependency packages corresponding to the multiple code sets.