Application program starting method and device, storage medium and electronic equipment
By encrypting the rendering process and main process code of the Electron application, generating encrypted data and using the target engine to start the application, the code leakage problem caused by reverse engineering attacks is solved, and security and startup efficiency are improved.
Patent Information
- Application Number
- CN202410315903.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-19
- Publication Date
- 2025-09-19
AI Technical Summary
Electron applications are vulnerable to reverse engineering attacks, which can lead to source code leakage and tampering, threatening software security and stability.
The rendering process code and main process code of the Electron application are encrypted differently to generate rendering process encrypted data and main process encrypted data. These encrypted data are then executed by the target engine upon receiving a startup instruction to start the application.
It effectively protects the rendering process code and the main process code, reduces the risk of leakage, improves code readability and startup efficiency, and reduces decryption time.
Smart Images

Figure CN120671130A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to an application startup method, device, storage medium, and electronic device. Background Art
[0002] With the continuous advancement of technology, software has become an indispensable part of our lives and work. As a core component of software, source code carries all of its functions and logic. Unauthorized access and modification of source code can have disastrous consequences. This not only compromises the security and stability of the software, but can also lead to user data leaks, malware intrusions, and even system crashes.
[0003] Source code security issues are particularly prominent for desktop applications developed using the Electron framework. Electron is a framework that allows developers to build cross-platform desktop applications using web technologies such as HTML, CSS, and JavaScript. Because Electron applications essentially package web content as native apps, they are vulnerable to reverse engineering attacks. By decompiling Electron applications, attackers can easily obtain their source code, allowing them to analyze the application's logic, steal sensitive information, and even tamper with the application's functionality. Summary of the Invention
[0004] The present invention provides an application startup method, device, storage medium, and electronic device that can provide security protection for the application's source code when the application is started to perform a preset task, thereby reducing the risk of data leakage. The technical solution is as follows:
[0005] In a first aspect, an embodiment of the present application provides a method for starting an application program, the method comprising:
[0006] Performing a first encryption process on the rendering process code corresponding to the application to obtain rendering process encrypted data corresponding to the rendering process code;
[0007] Performing a second encryption process on the main process code corresponding to the application to obtain main process encrypted data corresponding to the main process code;
[0008] When a startup instruction for the application is received, the main process encrypted data is executed by a target engine and the rendering process encrypted data is loaded to start the application.
[0009] In a second aspect, an embodiment of the present application provides a device for launching an application program, the device comprising:
[0010] A first encryption processing module is used to perform a first encryption process on the rendering process code corresponding to the application program to obtain rendering process encrypted data corresponding to the rendering process code;
[0011] a second encryption processing module, configured to perform a second encryption process on the main process code corresponding to the application program to obtain main process encrypted data corresponding to the main process code;
[0012] The application startup module is used to, upon receiving a startup instruction for the application, respond to the startup instruction, execute the main process encrypted data and load the rendering process encrypted data through a target engine to start the application.
[0013] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, wherein the instructions are suitable for being loaded by a processor and executing the above-mentioned method steps.
[0014] In a fourth aspect, an embodiment of the present application provides an electronic device, which may include: a processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the above-mentioned method steps.
[0015] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:
[0016] In the present application, the rendering process code corresponding to the application is subjected to a first encryption process to obtain rendering process encrypted data, and the main process code corresponding to the application is further subjected to a second encryption process to obtain main process encrypted data. In other words, the present application performs different encryption processes on the rendering process code and the main process code corresponding to the application, respectively, and effectively protects the main process code and the rendering process code through two encryption methods, thereby preventing attackers from simultaneously stealing or tampering with the main process code and the rendering process code, and reducing the possibility of code leakage. The code volume is compressed through encryption processing, which improves the readability of the code and facilitates developers to maintain the main process code and rendering process code corresponding to the application. Furthermore, when a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application to perform preset tasks and provide corresponding services to users. Directly executing the encrypted data through the target engine can save the time for decrypting the encrypted data and improve the efficiency of starting the application to perform preset tasks. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0018] Figure 1 This is a scenario diagram of a method for starting an application program provided in an embodiment of the present application;
[0019] Figure 2 This is a flowchart of a method for starting an application program provided in an embodiment of the present application;
[0020] Figure 3 This is a flowchart of a method for starting an application program provided in an embodiment of the present application;
[0021] Figure 4 This is a flowchart of a method for starting an application program provided in an embodiment of the present application;
[0022] Figure 5 This is a schematic diagram of the structure of a main process encrypted data provided by an embodiment of the present application;
[0023] Figure 6 This is a flowchart of a method for starting an application program provided in an embodiment of the present application;
[0024] Figure 7 This is a schematic diagram of the structure of a main process encrypted data provided by an embodiment of the present application;
[0025] Figure 8 This is a structural diagram of an application startup device provided in an embodiment of the present application;
[0026] Figure 9 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0027] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0028] In the description of this application, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and should not be understood to indicate or imply relative importance. In the description of this application, it should be noted that, unless otherwise expressly specified and limited, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to these processes, methods, products or devices. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances. In addition, in the description of this application, unless otherwise specified, "multiple" refers to two or more. "and / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the associated objects before and after are in an "or" relationship.
[0029] The present application is described in detail below with reference to specific embodiments.
[0030] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the information involved in this specification is obtained with full authorization.
[0031] An application is software designed to run on electronic devices to accomplish one or more predefined tasks. These tasks may include word processing, graphic design, gaming, network communications, data management, and more. An application consists of code that is executed by the device's operating system to accomplish its intended tasks. These applications cover a wide range of areas, including office productivity, social entertainment, gaming, shopping and payment, education and learning, and healthcare, providing users with convenient and efficient services.
[0032] In this application, the application may be a desktop application developed using the Electron framework, a framework that allows developers to build cross-platform desktop applications using web technologies (such as HTML, CSS, and JavaScript). Because Electron applications essentially package web content as native applications, they are vulnerable to reverse engineering attacks. By decompiling an Electron application, an attacker can easily obtain its source code, analyze the application's logic, steal sensitive information, and even tamper with the application's functionality.
[0033] Therefore, this application proposes an application startup method to solve the above problems. Figure 1 As shown, Figure 1 1 is a schematic diagram of a scenario of an application startup method provided by an embodiment of the present application, including a server 101 that executes the application startup method and an electronic device 102 that sends an application startup instruction to the server. It can be understood that Figure 1 The number and types of processing devices 101 and display devices are for illustration only.
[0034] The server 101 is used to execute the application startup method provided in the embodiment of the present application, encrypt the main process code and rendering code corresponding to the application included on the electronic device 102 or the server 101, and start the application to perform the corresponding task according to the startup instruction for the application sent by the electronic device 102.
[0035] The server 101 may be a separate server device, such as a rack-mounted, blade, tower, or cabinet-mounted server device, or a hardware device with strong computing capabilities such as a workstation or a mainframe computer. It may also be a server cluster composed of multiple servers, wherein the servers in the service cluster may be symmetrically arranged, wherein each server has equivalent functions and status in the transaction link, and each server may independently provide services to the outside world. Providing services independently may be understood as not requiring the assistance of another server.
[0036] The above-mentioned multiple servers can be multiple physical servers, which are independent in hardware; or multiple servers can be multiple virtual servers, which are deployed in the same hardware resource pool. The deployment methods of virtual servers include but are not limited to: VMware, Virtual Box and Virtual PC.
[0037] The electronic device 102 is used to send a startup instruction of the application to the server 101 to instruct the server 101 to execute the main process encrypted data of the application through the target engine and load the rendering process encrypted data to start the application. The electronic device 102 can be an electronic device with communication function, and the electronic device includes but is not limited to: wearable devices, handheld devices, personal computers, tablet computers, vehicle-mounted devices, smart phones, computing devices or other processing devices connected to wireless modems, etc. Electronic devices can be called different names in different networks, such as: user equipment, access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, cellular phone, cordless phone, personal digital assistant (PDA), 5G network or electronic device in future evolution network, etc.
[0038] In one or more embodiments of the present specification, a communication connection can be established between the server 101 and the electronic device 102, and data interaction during application startup is completed based on the communication connection. It should be noted that the server 101 and the electronic device 102 establish a communication connection through a network for interactive communication. The network can be a wireless network or a wired network. The wireless network includes but is not limited to a cellular network, a wireless local area network, an infrared network or a Bluetooth network, and the wired network includes but is not limited to an Ethernet, a universal serial bus (USB) or a controller area network. In one or more embodiments of the present specification, technologies and / or formats including Hypertext Markup Language (HTML) and Extensible Markup Language (XML) are used to represent data exchanged over the network (such as a target compressed package). In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies may be used to replace or supplement the above-mentioned data communication technologies.
[0039] In one embodiment, the server 101 includes main process encrypted data corresponding to the main process code of the application and rendering process encrypted data corresponding to the rendering process code. The server 101 is used to receive a startup instruction for the application sent by the electronic device 102, and in response to the startup instruction, execute the main process encrypted data and load the rendering process encrypted data through the target engine to provide the service corresponding to the application to the electronic device 102. In another embodiment, the electronic device 102 includes main process encrypted data corresponding to the main process code of the application and rendering process encrypted data corresponding to the rendering process code downloaded from the server 101. The electronic device 102 obtains the startup instruction for the application, executes the main process encrypted data and loads the rendering process encrypted data through the target engine obtained from the server 101, and starts the application to perform the corresponding service.
[0040] In one embodiment, Figure 2 The figure shows a flow chart of an application startup method proposed in an embodiment of the present application. This method can be implemented by a computer program and can be run on an application startup device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0041] Specifically, the application startup method includes:
[0042] S101: Perform a first encryption process on a rendering process code corresponding to an application program to obtain rendering process encrypted data corresponding to the rendering process code.
[0043] The renderer process code corresponding to an application represents the application's renderer process. The renderer process is primarily responsible for presenting page content, receiving user input, and responding. In a web browser, a renderer process specifically refers to one of the browser's four main processes, responsible for parsing resources such as HTML, JavaScript, CSS, and images downloaded from the network into a displayable and interactive page. For example, when a user opens a new tab or enters a URL, a renderer process is loaded to display the page.
[0044] In Electron applications, the renderer process plays a similar role. Electron applications consist of a main process and at least one renderer process. In other words, an Electron application includes a main process code and at least one renderer process code.
[0045] It is understood that an application can correspond to multiple rendering processes, each of which controls a window. In other words, loading a rendering process code can display a window, and each window runs in its own rendering process code without interfering with each other.
[0046] In this embodiment, a first encryption process is performed on the rendering process code corresponding to the application to obtain rendering process encrypted data corresponding to the rendering process code. The first encryption process is used to protect the rendering process code from being easily read, copied, or tampered with. In other words, the rendering process encrypted data is data obtained by the first encryption process of the rendering process code. It contains information about the rendering process code, but is less likely to be leaked than the rendering process code.
[0047] The first encryption process can be code obfuscation (changing the structure, variable names, function names, etc. of the code, for example, using meaningless variable names, deleting comments and spaces, control flow obfuscation, etc.), code encryption (using encryption algorithms to encrypt the code), code signing (using digital signatures to verify the source and integrity of the code to ensure that the code has not been tampered with during transmission), code compression (using compression algorithms to reduce the size of the code, thereby speeding up the loading and execution of the code), bytecode compilation (compiling the source code into intermediate bytecodes, and then interpreting and executing these bytecodes at runtime, for example, Java uses Java bytecode, and Python uses Python bytecode), code packaging (packaging the code and other resources into an encrypted file or container, which can only be accessed and extracted using specific tools or keys), dynamic code generation (dynamically generating and executing code at runtime, rather than statically compiling and distributing the code), and other encryption processes, or a combination of the above-mentioned multiple encryption processes.
[0048] S102: Perform a second encryption process on the main process code corresponding to the application program to obtain main process encrypted data corresponding to the main process code.
[0049] An application's main process is its core process, responsible for controlling and managing the application's entire lifecycle, displaying its interface, interacting with the operating system, and loading and executing rendering processes. For example, executing the main process code enables operations such as launching the application and performing cleanup upon application shutdown. Main process code also enables interface display and control operations, such as creating and managing the application's graphical user interface (GUI), including windows, menus, and toolbars. Main process code also enables interactive operations with the operating system, such as reading and writing files, communicating over the network, and accessing hardware.
[0050] In an Electron application, the main process is responsible for creating and managing renderer processes. A renderer process is responsible for presenting the webpage or application interface and executing JavaScript code related to that interface. In other words, the main process executes code and loads at least one renderer process as needed. Each renderer process renders a window or tab.
[0051] In this embodiment, the main process code corresponding to the application is subjected to a secondary encryption process to obtain main process encrypted data corresponding to the main process code. The secondary encryption process is used to protect the main process code from being easily read, copied, or tampered with. In other words, the main process encrypted data is the data obtained by the secondary encryption process on the main process code, including information about the main process code, but is less susceptible to leakage than the main process code.
[0052] The second encryption process can be encryption processes such as code obfuscation, code encryption, code signing, code compression, bytecode compilation, code packaging, dynamic code generation, or a combination of the above-mentioned multiple encryption processes.
[0053] In one embodiment, the first encryption process and the second encryption process are different. For example, the first encryption process is code signing, and the second encryption process is bytecode compilation. In this embodiment, the different first and second encryption processes reduce the possibility of simultaneous leakage of the main process code and the rendering process code.
[0054] S103: When a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application.
[0055] The target engines that execute the main process's encrypted data are software components capable of parsing and executing specific types of code (such as bytecode, machine code, or scripts). These engines are typically embedded in the operating system that launches the application. Examples of target engines include the V8 engine, SpiderMonkey engine, JavaScriptCore engine, Python interpreter, Java Virtual Machine (JVM), .NET runtime (Common Language Runtime, CLR), and Lua interpreter. These engines or interpreters all play the role of converting the main process's encrypted data and renderer process's encrypted data corresponding to the main process's code and renderer process's code into executable instructions and provide the necessary runtime support during execution.
[0056] In this embodiment, upon receiving a startup instruction for an application, the target engine corresponding to the second encryption process executes the main process encrypted data and loads the rendering process encrypted data to start the application. For example, if the second encryption process is a bytecode compilation process, the target engine is an engine that can execute the bytecode corresponding to the second encryption process. For example, if the second encryption process is Java bytecode compilation, that is, converting the main process code into main process encrypted data of Java bytecode, the target engine is a Java virtual machine. For another example, if the second encryption process is V8 bytecode compilation, that is, converting the main process code into main process encrypted data of V8 bytecode, the target engine is a V8 engine.
[0057] The launch command is used to launch an application. It can be obtained based on the trigger conditions of the display adjustment command. The trigger conditions can be set according to actual needs. The trigger conditions can be time conditions, service type conditions, or operation type conditions. For example, the launch command can be triggered at a specified time; when a specified service type is executed; or when a specified operation type is detected.
[0058] like Figure 3 As shown, Figure 3 2 is a flow chart of an application startup method provided by an embodiment of the present application. Application 200 includes main process code 2011 and rendering process code 2012. Rendering process code 2012 is processed using a first encryption process to obtain rendering process encrypted data 2022. Main process code 2011 is processed using a second encryption process to obtain main process encrypted data 2021.
[0059] Furthermore, when a start instruction 203 for the application 200 is received, in response to the move instruction 203, the main process encrypted data 2021 is executed through the target engine 204 and the rendering process encrypted data 202 is loaded to start the application 200 and perform corresponding tasks or provide corresponding services.
[0060] It is understandable that in Figure 3 In the embodiment, the number of rendering process codes 2012 is one. In other embodiments, the number of rendering process codes 2012 corresponding to the application 200 is multiple. The multiple rendering process codes 2012 are processed separately through multiple first encryption processes to obtain the rendering process encrypted data 202 corresponding to each rendering process code 2012.
[0061] In the present application, the rendering process code corresponding to the application is subjected to a first encryption process to obtain rendering process encrypted data, and the main process code corresponding to the application is further subjected to a second encryption process to obtain main process encrypted data. In other words, the present application performs different encryption processes on the rendering process code and the main process code corresponding to the application, respectively, and effectively protects the main process code and the rendering process code through two encryption methods, thereby preventing attackers from simultaneously stealing or tampering with the main process code and the rendering process code, and reducing the possibility of code leakage. The code volume is compressed through encryption processing, which improves the readability of the code and facilitates developers to maintain the main process code and rendering process code corresponding to the application. Furthermore, when a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application to perform preset tasks and provide corresponding services to users. Directly executing the encrypted data through the target engine can save the time for decrypting the encrypted data and improve the efficiency of starting the application to perform preset tasks.
[0062] In one embodiment, Figure 4 The figure shows a flow chart of an application startup method proposed in an embodiment of the present application. This method can be implemented by a computer program and can be run on an application startup device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0063] Specifically, the application startup method includes:
[0064] S201: Perform a first encryption process on a rendering process code corresponding to an application program to obtain rendering process encrypted data corresponding to the rendering process code.
[0065] See the above S101, which will not be repeated here.
[0066] S202: Convert at least one target subcode in the main process code corresponding to the application program to obtain an encrypted subcode corresponding to each target subcode.
[0067] The main process code corresponding to the application program includes multiple subcodes. Subcodes refer to the individual modules, functions, or threads launched and managed within the main process. The subcodes within the main process that require conversion are target subcodes. In this embodiment, the second encryption process involves converting at least one target subcode to obtain the main process encrypted data corresponding to the main process code. This conversion process may involve changing the structure, variable names, function names, etc. of the target subcode, performing encryption calculations on the target subcode using an encryption algorithm to obtain data in another form, or compiling the target subcode through bytecode compilation.
[0068] In one embodiment, at least one target subcode in the main process code corresponding to the application is determined; each target subcode is byte-converted to obtain a target bytecode corresponding to each target subcode as the encrypted subcode corresponding to the target subcode. Bytecode conversion or bytecode compilation generally refers to converting source code into an intermediate representation, namely bytecode. Bytecode is a low-level representation that is independent of a specific hardware platform and can be executed on different operating systems and hardware architectures.
[0069] For example, in this embodiment, each target subcode is subjected to V8 bytecode conversion processing to obtain the V8 bytecode corresponding to each target subcode as the encrypted subcode corresponding to the target subcode.
[0070] In this embodiment, determining at least one target subcode in the main process code corresponding to the application includes: determining a subcode with a degree of disclosure less than a preset degree as the target subcode based on the disclosure status of multiple subcodes in the main process code corresponding to the application; wherein the number of target subcodes is at least one.
[0071] The disclosure status of multiple subcodes within the main process code corresponding to the application. This disclosure status can be understood as the public and private attributes of the subcodes, or the visibility of the subcodes on external entities such as public networks. In this embodiment, subcodes with a disclosure level less than a preset level are identified as target subcodes. For example, among the multiple subcodes included in the main process code, subcodes that are not publicly disclosed are target subcodes that require conversion.
[0072] In this embodiment, only part of the sub-code in the main process code is converted as the target sub-code, rather than the entire main process code. This can improve the efficiency of the second encryption processing of the main process code and save the time of the second encryption processing to obtain the main process encrypted data.
[0073] S203: Embed at least one encrypted sub-code into the main process code to obtain main process encrypted data corresponding to the main process code.
[0074] After converting at least one target subcode in the main process code, the encrypted subcode is embedded into the main process code based on the location of the target subcode corresponding to the encrypted subcode in the main process code. This process continues until all the at least one encrypted subcode is embedded into the main process code to obtain main process encrypted data corresponding to the main process code, so that the main process encrypted data can be executed by the target engine and achieve the preset task.
[0075] like Figure 5 As shown, Figure 5 3014, subcode 3015, and subcode 3016.
[0076] According to the publicity of each sub-code, the sub-code with a publicity level lower than the preset level is used as the target sub-code. Figure 5 In the illustrated embodiment, the target subcodes are subcode 3012 , subcode 3014 , and subcode 3015 .
[0077] Furthermore, each target subcode is byte-converted. Specifically, subcode 3012, subcode 3014, and subcode 3015 are byte-converted to obtain encrypted subcode 3021 corresponding to subcode 3012, encrypted subcode 3022 corresponding to subcode 3014, and encrypted subcode 3023 corresponding to subcode 3015, respectively.
[0078] Furthermore, according to the location information of each target subcode in the main process code 301, at least one encrypted subcode is embedded into the main process code 301 to obtain the main process encrypted data 302. Specifically, the main process encrypted data 302 includes the following: Figure 5 The code 3011, encrypted subcode 3021, subcode 3013, encrypted subcode 3022, encrypted subcode 3023, and subcode 3016 are shown in FIG. 3011 , and the positional relationship between the above subcodes and encrypted subcodes is as shown in FIG. Figure 5 shown.
[0079] S204: When a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application.
[0080] See the above S103, which will not be repeated here.
[0081] In the present application, the rendering process code corresponding to the application is subjected to a first encryption process to obtain rendering process encrypted data, and the main process code corresponding to the application is further subjected to a second encryption process to obtain main process encrypted data. In other words, the present application performs different encryption processes on the rendering process code and the main process code corresponding to the application, respectively, and effectively protects the main process code and the rendering process code through two encryption methods, thereby preventing attackers from simultaneously stealing or tampering with the main process code and the rendering process code, and reducing the possibility of code leakage. The code volume is compressed through encryption processing, which improves the readability of the code and facilitates developers to maintain the main process code and rendering process code corresponding to the application. Furthermore, when a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application to perform preset tasks and provide corresponding services to users. Directly executing the encrypted data through the target engine can save the time for decrypting the encrypted data and improve the efficiency of starting the application to perform preset tasks.
[0082] In one embodiment, Figure 6 The figure shows a flow chart of an application startup method proposed in an embodiment of the present application. This method can be implemented by a computer program and can be run on an application startup device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application.
[0083] Specifically, the application startup method includes:
[0084] S301: Compile and package the rendering process code corresponding to the application to obtain a rendering encrypted file corresponding to the rendering process code.
[0085] The rendering process encrypted data includes rendering encrypted files. In other words, in this embodiment, the first encryption process is code packaging, which is to package the rendering process code and other resources into an encrypted file or container, and the content can only be accessed and extracted using specific tools or keys.
[0086] For example, by compiling and packaging the rendering process code into an encrypted ZIP format file, not only the rendering process code can be encrypted, but also the size of the rendering process code can be compressed.
[0087] S302: Store the decryption key corresponding to the rendered encrypted file in the main process code of the application.
[0088] The rendering process encrypted data includes a decryption key. In other words, the rendering process encrypted data includes a decryption key and a rendering encrypted file. The decryption key is used to decrypt the rendering encrypted file to obtain the corresponding rendering process code. Therefore, in this embodiment, not only is the rendering process code compiled and packaged into a rendering encrypted file, but a decryption key is also provided for decrypting the rendering encrypted file. This encryption method prevents an attacker from decrypting the rendering encrypted file, even if they obtain it. This effectively improves the security of the rendering process code and prevents leakage of the rendering process code.
[0089] like Figure 7 As shown, Figure 7 4 is a schematic diagram of the structure of encrypted data for a main process provided in an embodiment of the present application. Rendering process code 401 is compiled and packaged to obtain a rendering encrypted file 402 and a decryption key 403. Furthermore, decryption key 403 is stored in main process code 404, which includes subcode 4041, subcode 4042, subcode 4043, subcode 4044, encryption key 403, subcode 4045, subcode 4046, and the like.
[0090] S303: Convert at least one target subcode in the main process code to obtain an encrypted subcode corresponding to each target subcode.
[0091] See above S202, which will not be described again here.
[0092] It is worth noting that in this embodiment, the decryption key 403 is converted into encrypted sub-code 4043 through bytecode conversion. The main process encrypted data 403 includes the decryption key 403 obtained by first encrypting the rendering process code 401 and then converting it into encrypted sub-code 4053. In other words, this embodiment performs a secondary encryption process on the rendering process code, which can effectively improve the security of the rendering process code and prevent the leakage of the rendering process code.
[0093] S304: Embed at least one encrypted sub-code into the main process code to obtain main process encrypted data corresponding to the main process code.
[0094] See above S203, which will not be described again here.
[0095] S305. When a startup instruction for the application is received, the main process encrypted data is executed by the target engine, and the rendering process encrypted data is loaded and decrypted by the decryption key during the execution of the main process encrypted data to start the application.
[0096] like Figure 7As shown, the main process encrypted data 405 is executed by the target engine, and in the process of executing the main process encrypted data 405, the subcode 4041, the encrypted subcode 4051, the subcode 4043, the encrypted subcode 4052 are executed in sequence, and the decryption key 403 is obtained when executing the encrypted subcode 4053, and the rendering encrypted file 402 is further loaded and decrypted to execute the rendering process code 401, and then the encrypted subcode 4053, the encrypted subcode 4054, the subcode 4046, etc. are executed in sequence until the application is started and the preset task is completed.
[0097] In the present application, the rendering process code corresponding to the application is subjected to a first encryption process to obtain rendering process encrypted data, and the main process code corresponding to the application is further subjected to a second encryption process to obtain main process encrypted data. In other words, the present application performs different encryption processes on the rendering process code and the main process code corresponding to the application, respectively, and effectively protects the main process code and the rendering process code through two encryption methods, thereby preventing attackers from simultaneously stealing or tampering with the main process code and the rendering process code, and reducing the possibility of code leakage. The code volume is compressed through encryption processing, which improves the readability of the code and facilitates developers to maintain the main process code and rendering process code corresponding to the application. Furthermore, when a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application to perform preset tasks and provide corresponding services to users. Directly executing the encrypted data through the target engine can save the time for decrypting the encrypted data and improve the efficiency of starting the application to perform preset tasks.
[0098] The following are device embodiments of the present application, which can be used to implement the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.
[0099] See Figure 7 , which shows a schematic diagram of the structure of an application launching device provided by an exemplary embodiment of the present application. The application launching device can be implemented as all or part of a device through software, hardware, or a combination of both. The application launching device includes a first encryption processing module 501, a second encryption module 502, and an application launching module 503.
[0100] A first encryption processing module 501 is configured to perform a first encryption process on the rendering process code corresponding to the application program to obtain rendering process encrypted data corresponding to the rendering process code;
[0101] A second encryption processing module 502 is configured to perform a second encryption process on the main process code corresponding to the application program to obtain main process encrypted data corresponding to the main process code;
[0102] The application startup module 503 is used to, upon receiving a startup instruction for the application, respond to the startup instruction, execute the main process encrypted data and load the rendering process encrypted data through a target engine to start the application.
[0103] In one embodiment, the second encryption processing module 502 includes:
[0104] a conversion processing unit, configured to convert at least one target subcode in the main process code corresponding to the application program to obtain an encrypted subcode corresponding to each target subcode;
[0105] The code embedding unit is used to embed at least one of the encrypted sub-codes into the main process code to obtain the main process encrypted data corresponding to the main process code.
[0106] In one embodiment, the conversion processing unit includes:
[0107] a determination subunit, configured to determine at least one target subcode in a main process code corresponding to the application;
[0108] The conversion sub-unit is used to perform bytecode conversion on each of the target sub-codes to obtain a target bytecode corresponding to each of the target sub-codes as an encrypted sub-code corresponding to the target sub-code.
[0109] In one embodiment, the determination sub-unit is specifically used to determine a sub-code with a disclosure level less than a preset level as a target sub-code based on the disclosure status of multiple sub-codes in the main process code corresponding to the application; wherein the number of the target sub-code is at least one.
[0110] In one embodiment, the first encryption processing module 501 includes:
[0111] The compiling and packaging unit is used to compile and package the rendering process code corresponding to the application to obtain a rendering encrypted file corresponding to the rendering process code; wherein the rendering process encrypted data includes the rendering encrypted file.
[0112] In one embodiment, the first encryption processing module 501 further includes:
[0113] A key storage unit, configured to store a decryption key corresponding to the rendering encrypted file in the main process code of the application; wherein the rendering process encrypted data includes the decryption key;
[0114] The application startup module 503 includes:
[0115] A program startup unit is used to execute the main process encrypted data through a target engine when receiving a startup instruction for the application, and to load and decrypt the rendering encrypted file through the decryption key during the execution of the main process encrypted data to start the application.
[0116] In one embodiment, the application startup module 503 includes:
[0117] An engine startup unit is configured to, upon receiving a startup instruction for the application, execute the main process encrypted data and load the rendering process encrypted data through a target engine corresponding to the second encryption process to start the application.
[0118] In the present application, the rendering process code corresponding to the application is subjected to a first encryption process to obtain rendering process encrypted data, and the main process code corresponding to the application is further subjected to a second encryption process to obtain main process encrypted data. In other words, the present application performs different encryption processes on the rendering process code and the main process code corresponding to the application, respectively, and effectively protects the main process code and the rendering process code through two encryption methods, thereby preventing attackers from simultaneously stealing or tampering with the main process code and the rendering process code, and reducing the possibility of code leakage. The code volume is compressed through encryption processing, which improves the readability of the code and facilitates developers to maintain the main process code and rendering process code corresponding to the application. Furthermore, when a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application to perform preset tasks and provide corresponding services to users. Directly executing the encrypted data through the target engine can save the time for decrypting the encrypted data and improve the efficiency of starting the application to perform preset tasks.
[0119] It should be noted that the application launch device provided in the above embodiment, when executing the application launch method, only uses the division of the above-mentioned functional modules as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the application launch device provided in the above embodiment and the application launch method embodiment are based on the same concept. The implementation process is detailed in the method embodiment and will not be repeated here.
[0120] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0121] The present application also provides a computer storage medium that can store multiple instructions, which are suitable for being loaded and executed by a processor as described above. Figure 1 - Figure 6The application startup method of the embodiment shown, the specific execution process can be found in Figure 1 - Figure 6 The detailed description of the illustrated embodiment will not be repeated here.
[0122] The present application also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by a processor as described above. Figure 1 - Figure 6 The application startup method of the embodiment shown, the specific execution process can be found in Figure 1 - Figure 6 The detailed description of the illustrated embodiment will not be repeated here.
[0123] See Figure 9 , is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Figure 9 As shown, the electronic device 600 may include: at least one processor 601 , at least one network interface 604 , a user interface 603 , a memory 605 , and at least one communication bus 602 .
[0124] The communication bus 602 is used to implement the connection and communication between these components.
[0125] The user interface 603 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 603 may also include a standard wired interface and a wireless interface.
[0126] The network interface 604 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0127] The processor 601 may include one or more processing cores. The processor 601 utilizes various interfaces and lines to connect various components within the server 600. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 605, and calling data stored in the memory 605, the processor 601 executes various functions of the server 600 and processes data. Optionally, the processor 601 may be implemented in at least one hardware form of a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 601 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; and the modem is used to handle wireless communications. It is understood that the modem may not be integrated into the processor 601 and may be implemented separately on a single chip.
[0128] Among them, the memory 605 may include a random access memory (RAM) or a read-only memory (Read-Only Memory). Optionally, the memory 605 includes a non-transitory computer-readable storage medium. The memory 605 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 605 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 605 may also be optionally at least one storage device located away from the aforementioned processor 601. As Figure 9 As shown, the memory 605 as a computer storage medium may include an operating system, a network communication module, a user interface module, and an application startup application.
[0129] exist Figure 9In the electronic device 600 shown, the user interface 603 is mainly used to provide an input interface for the user and obtain data input by the user; and the processor 601 can be used to call the application program started by the application program stored in the memory 605 and specifically perform the following operations:
[0130] Performing a first encryption process on the rendering process code corresponding to the application to obtain rendering process encrypted data corresponding to the rendering process code;
[0131] Performing a second encryption process on the main process code corresponding to the application to obtain main process encrypted data corresponding to the main process code;
[0132] When a startup instruction for the application is received, the main process encrypted data is executed by a target engine and the rendering process encrypted data is loaded to start the application.
[0133] In one embodiment, the processor 601 performs the second encryption processing on the main process code corresponding to the application to obtain the main process encrypted data corresponding to the main process code, specifically performing:
[0134] Convert at least one target subcode in the main process code corresponding to the application to obtain an encrypted subcode corresponding to each target subcode;
[0135] At least one of the encrypted sub-codes is embedded into the main process code to obtain main process encrypted data corresponding to the main process code.
[0136] In one embodiment, the processor 601 performs the conversion processing of at least one target subcode in the main process code corresponding to the application to obtain the encrypted subcode corresponding to each target subcode, specifically performing:
[0137] Determining at least one target subcode in the main process code corresponding to the application;
[0138] Each target subcode is subjected to bytecode conversion processing to obtain a target bytecode corresponding to each target subcode as an encrypted subcode corresponding to the target subcode.
[0139] In one embodiment, the processor 601 executes the at least one target sub-code in the main process code corresponding to the application, specifically performing:
[0140] According to the disclosure status of multiple subcodes in the main process code corresponding to the application, a subcode with a disclosure level less than a preset level is determined as a target subcode; wherein the number of the target subcode is at least one.
[0141] In one embodiment, the processor 601 performs the first encryption processing on the rendering process code corresponding to the application to obtain the rendering process encrypted data corresponding to the rendering process code, specifically performing:
[0142] Compile and package the rendering process code corresponding to the application to obtain a rendering encrypted file corresponding to the rendering process code; wherein the rendering process encrypted data includes the rendering encrypted file.
[0143] In one embodiment, after the processor 601 compiles and packages the rendering process code corresponding to the application program to obtain the rendering encrypted file corresponding to the rendering process code, it further executes:
[0144] Storing the decryption key corresponding to the rendering encrypted file in the main process code of the application; wherein the rendering process encrypted data includes the decryption key;
[0145] The processor 601 executes the main process encrypted data and loads the rendering process encrypted data through the target engine when receiving the startup instruction for the application to start the application, specifically performing:
[0146] When a startup instruction for the application is received, the main process encrypted data is executed by a target engine, and the rendering encrypted file is loaded and decrypted by the decryption key during the execution of the main process encrypted data to start the application.
[0147] In one embodiment, upon receiving a startup instruction for the application, the processor 601 executes the main process encrypted data and loads the rendering process encrypted data through the target engine to start the application, specifically performing:
[0148] When a startup instruction for the application is received, the target engine corresponding to the second encryption processing executes the main process encrypted data and loads the rendering process encrypted data to start the application.
[0149] In the present application, the rendering process code corresponding to the application is subjected to a first encryption process to obtain rendering process encrypted data, and the main process code corresponding to the application is further subjected to a second encryption process to obtain main process encrypted data. In other words, the present application performs different encryption processes on the rendering process code and the main process code corresponding to the application, respectively, and effectively protects the main process code and the rendering process code through two encryption methods, thereby preventing attackers from simultaneously stealing or tampering with the main process code and the rendering process code, and reducing the possibility of code leakage. The code volume is compressed through encryption processing, which improves the readability of the code and facilitates developers to maintain the main process code and rendering process code corresponding to the application. Furthermore, when a startup instruction for the application is received, the main process encrypted data is executed by the target engine and the rendering process encrypted data is loaded to start the application to perform preset tasks and provide corresponding services to users. Directly executing the encrypted data through the target engine can save the time for decrypting the encrypted data and improve the efficiency of starting the application to perform preset tasks.
[0150] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-readable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory, or a random access memory.
[0151] The above disclosure is only a preferred embodiment of the present application, and certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.
Claims
1. A method for starting an application, characterized in that: The method comprises: Performing a first encryption process on the rendering process code corresponding to the application to obtain rendering process encrypted data corresponding to the rendering process code; Performing a second encryption process on the main process code corresponding to the application to obtain main process encrypted data corresponding to the main process code; When a startup instruction for the application is received, the main process encrypted data is executed by a target engine and the rendering process encrypted data is loaded to start the application.
2. The application startup method according to claim 1, characterized in that: The performing a second encryption process on the main process code corresponding to the application to obtain main process encrypted data corresponding to the main process code includes: Convert at least one target subcode in the main process code corresponding to the application to obtain an encrypted subcode corresponding to each target subcode; At least one of the encrypted sub-codes is embedded into the main process code to obtain main process encrypted data corresponding to the main process code.
3. The application startup method according to claim 2, characterized in that: The converting of at least one target subcode in the main process code corresponding to the application to obtain an encrypted subcode corresponding to each target subcode includes: Determining at least one target subcode in the main process code corresponding to the application; Each target subcode is subjected to bytecode conversion processing to obtain a target bytecode corresponding to each target subcode as an encrypted subcode corresponding to the target subcode.
4. The application startup method according to claim 3, characterized in that: The determining of at least one target subcode in the main process code corresponding to the application comprises: According to the disclosure status of multiple subcodes in the main process code corresponding to the application, a subcode with a disclosure level less than a preset level is determined as a target subcode; wherein the number of the target subcode is at least one.
5. The application startup method according to claim 1, characterized in that: The performing a first encryption process on the rendering process code corresponding to the application to obtain rendering process encrypted data corresponding to the rendering process code includes: Compile and package the rendering process code corresponding to the application to obtain a rendering encrypted file corresponding to the rendering process code; wherein the rendering process encrypted data includes the rendering encrypted file.
6. The application startup method according to claim 5, further comprising: compiling and packaging the rendering process code corresponding to the application to obtain the rendering encrypted file corresponding to the rendering process code; Storing the decryption key corresponding to the rendering encrypted file in the main process code of the application; wherein the rendering process encrypted data includes the decryption key; Upon receiving a startup instruction for the application, executing the main process encrypted data and loading the rendering process encrypted data by a target engine to start the application, including: When a startup instruction for the application is received, the main process encrypted data is executed by a target engine, and the rendering encrypted file is loaded and decrypted by the decryption key during the execution of the main process encrypted data to start the application.
7. The application startup method according to claim 1, characterized in that: Upon receiving a startup instruction for the application, executing the main process encrypted data and loading the rendering process encrypted data by a target engine to start the application, including: When a startup instruction for the application is received, the target engine corresponding to the second encryption processing executes the main process encrypted data and loads the rendering process encrypted data to start the application.
8. An application startup device, characterized in that: The device comprises: A first encryption processing module is used to perform a first encryption process on the rendering process code corresponding to the application program to obtain rendering process encrypted data corresponding to the rendering process code; a second encryption processing module, configured to perform a second encryption process on the main process code corresponding to the application program to obtain main process encrypted data corresponding to the main process code; The application startup module is used to, upon receiving a startup instruction for the application, respond to the startup instruction, execute the main process encrypted data and load the rendering process encrypted data through a target engine to start the application.
9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 7.
10. An electronic device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method steps according to any one of claims 1 to 7.