Method and system for safely executing application program of power terminal, equipment and medium

By using differentiated compilation and dynamic stack address adjustment based on the intrinsic fingerprint of power terminal equipment, the problem of low security of power terminal applications in untrusted environments is solved, thereby improving protection capabilities and reducing the difficulty of reverse analysis.

CN121030731APending Publication Date: 2025-11-28CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510954235.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-11-28

AI Technical Summary

Technical Problem

In untrusted physical environments, the security and protection capabilities of power terminal applications are low. Existing software-level program hardening methods are homogeneous and easily reverse engineered, leading to the failure of hardening protection.

Method used

By using an intrinsic fingerprint generated based on the attributes of the power terminal equipment itself, differentiated compilation and dynamic adjustment of stack addresses are performed to improve the security and protection capabilities of the application. This includes the extraction of explicit and implicit interaction features of the device hardware, the setting of compilation parameters, and the custom generation of instruction sets.

Benefits of technology

It increases the difficulty for attackers to reverse engineer, reduces the detectability and exploitability of unknown vulnerabilities, and enhances the security and protection capabilities of power terminal applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121030731A_ABST
    Figure CN121030731A_ABST
Patent Text Reader

Abstract

The invention provides a power terminal application program security execution method and system, equipment and a medium, and relates to the technical field of network communication and information security. The method comprises the following steps: for each target power terminal, compiling a source code of an application program running on the target power terminal based on an extracted device endogenous fingerprint of the target power terminal to obtain an executable file of the application program; executing an executable file of the application program; the device endogenous fingerprint of the target power terminal is generated based on a communication interaction deviation characteristic generated by the device self attribute of the target power terminal; and in the process of executing the executable file, adjusting the stack address of the executable file based on the offset condition between the equipment endogenous fingerprint of the target power terminal and the reference endogenous fingerprint. According to the invention, the problem that the execution security and protection capability of the application program on the power terminal in the untrusted physical environment are relatively low is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of network communication and information security technology, specifically to a method, system, device, and medium for secure execution of power terminal applications. Background Technology

[0002] With the integration of numerous renewable energy power plants into the power system, a large number of distributed renewable energy monitoring terminals from various investment entities have been widely deployed in untrusted physical environments such as the user side and power plant side. These monitoring terminals interact openly with the power master station system within the isolation and protection system, potentially facing cybersecurity risks such as illegal intrusion of renewable energy monitoring terminals, malicious network control interactions, and malicious operation and destruction of the system. These heterogeneous power terminals in untrusted physical environments are difficult to protect with security hardware, and existing software-level program hardening methods are homogeneous. That is, if a program hardening method is reverse-engineered, the hardening protection of all similar programs will fail, resulting in low security and protection capabilities for application execution on such power terminals. Summary of the Invention

[0003] To overcome the problems of low security and protection capabilities of application execution on power terminals in untrusted physical environments, the present invention provides a method, system, device, and medium for secure execution of power terminal applications.

[0004] On one hand, the present invention provides a method for secure execution of a power terminal application, comprising:

[0005] For each target power terminal, the source code of the application running on the target power terminal is compiled based on the extracted device-inherent fingerprint of the target power terminal to obtain the executable file of the application.

[0006] Execute the executable file of the application;

[0007] The device-inherent fingerprint of the target power terminal is generated based on the communication interaction deviation characteristics generated by the device's own attributes. During the execution of the executable file, the stack address of the executable file is adjusted based on the offset between the device-inherent fingerprint of the target power terminal and the reference device-inherent fingerprint. The reference device-inherent fingerprint is the specified device-inherent fingerprint of the target power terminal.

[0008] Optionally, the device-inherent fingerprint of the target power terminal includes explicit hardware features and implicit interaction features, wherein the implicit interaction features include frequency offset features of wireless communication and link delay features of wired communication.

[0009] Optionally, the frequency offset characteristics of the device's wireless communication include the frequency offset characteristics of transient signals and the carrier frequency offset characteristics of steady-state signals; before compiling the source code of the application running on the target power terminal based on the extracted device-inherent fingerprint of the target power terminal to obtain the executable file of the application, the method further includes:

[0010] Based on time-frequency analysis of the transient signal obtained during the wireless communication process of the target power terminal, the time spectrum of the transient signal is extracted as the frequency offset feature of the transient signal;

[0011] Based on autocorrelation processing of the steady-state signal obtained during the wireless communication process of the target power terminal, the carrier frequency offset characteristics of the steady-state signal are obtained.

[0012] Based on link detection of the target power terminal, the link delay characteristics of the wired communication of the device are obtained;

[0013] Based on the explicit hardware characteristics of the device, the frequency offset characteristics of the transient signal, the carrier frequency offset characteristics of the steady-state signal, and the link delay characteristics of the wired communication of the device, the device intrinsic fingerprint of the target power terminal is determined.

[0014] Optionally, the source code of the application running on the target power terminal is compiled based on the extracted device-inherent fingerprint of the target power terminal to obtain an executable file of the application, including:

[0015] The source code of the application running on the target power terminal is compiled based on the device-inherent fingerprint of the target power terminal to obtain the target code;

[0016] The target code is assembled based on the target instruction set to obtain the corresponding target binary file; the target binary file is linked and merged to generate the executable file of the application.

[0017] The target instruction set is generated based on the device-inherent fingerprint of the target power terminal.

[0018] Optionally, the intrinsic device fingerprint of the target power terminal includes explicit hardware features and implicit interaction features; based on the intrinsic device fingerprint of the target power terminal, the source code of the application running on the target power terminal is compiled to obtain target code, including:

[0019] Based on the differences between the explicit hardware features of the device and the corresponding baseline explicit feature quantities, and the differences between the implicit interaction features of the device and the baseline implicit features, the compilation parameters of the source code are determined.

[0020] The application running on the target power terminal is compiled based on the compilation parameters to obtain the target code;

[0021] The benchmark explicit features and benchmark implicit features are the device hardware explicit features and device implicit interaction features in the benchmark endogenous fingerprint.

[0022] Optionally, based on the differences between the explicit hardware features of the device and the corresponding baseline explicit feature quantities, and the differences between the implicit interaction features of the device and the baseline implicit features, the compilation parameters of the source code are determined, including:

[0023] Based on the similarity between the explicit features of the device hardware and the corresponding benchmark explicit features, the explicit differences of the target power terminal are determined.

[0024] Based on the Manhattan distance between the latent features of each feature dimension in the device's latent interaction features and the corresponding baseline latent features, the latent differences of each feature dimension are determined.

[0025] The compilation parameters for the source code compilation process are obtained by fusing the explicit differences of the target power terminal and the implicit differences of each feature dimension.

[0026] Optionally, the compilation parameters include compilation parameters for at least one type of compilation operation: control flow flattening, logic transformation strategy, and redundant operation insertion.

[0027] Optionally, before assembling the target code based on the target instruction set to obtain the corresponding target binary file, the method further includes:

[0028] Based on the device-inherent fingerprint of the target power terminal, the original instruction set corresponding to the hardware device of the target power terminal is remapped to generate the target instruction set.

[0029] Optionally, the process of executing the executable file of the application includes:

[0030] The fingerprint offset of the target power terminal is determined based on the Mahalanobis distance between the device-generated fingerprint of the target power terminal and the reference device-generated fingerprint.

[0031] The stack base address of the executable file is adjusted based on the fingerprint offset of the target power terminal.

[0032] On the other hand, the present invention also provides a system for secure execution of a power terminal application, comprising:

[0033] The compilation module is used to compile the source code of the application running on the target power terminal based on the extracted device intrinsic fingerprint of the target power terminal for each target power terminal, so as to obtain the executable file of the application.

[0034] An execution module is used to execute the executable file of the application.

[0035] The device-inherent fingerprint of the target power terminal is generated based on the communication interaction deviation characteristics generated by the device's own attributes. During the execution of the executable file, the stack address of the executable file is adjusted based on the offset between the device-inherent fingerprint of the target power terminal and the reference device-inherent fingerprint. The reference device-inherent fingerprint is the specified device-inherent fingerprint of the target power terminal.

[0036] Optionally, the device-inherent fingerprint of the target power terminal includes explicit hardware features and implicit interaction features, wherein the implicit interaction features include frequency offset features of wireless communication and link delay features of wired communication.

[0037] Optionally, the frequency offset characteristics of the device's wireless communication include the frequency offset characteristics of transient signals and the carrier frequency offset characteristics of steady-state signals; it also includes: a fingerprint extraction module, the fingerprint extraction module comprising:

[0038] The transient fingerprint extraction submodule is used to perform time-frequency analysis on the transient signal acquired during the wireless communication process of the target power terminal, and extract the time spectrum of the transient signal as the frequency offset feature of the transient signal.

[0039] The steady-state fingerprint extraction submodule is used to obtain the carrier frequency offset characteristics of the steady-state signal by performing autocorrelation processing on the acquired steady-state signal during the wireless communication process of the target power terminal.

[0040] The delay feature extraction submodule is used to obtain the link delay features of the wired communication of the device based on link detection of the target power terminal;

[0041] The fingerprint generation submodule is used to determine the device-inherent fingerprint of the target power terminal based on the explicit hardware features of the device, the frequency offset features of the transient signal, the carrier frequency offset features of the steady-state signal, and the link delay features of the wired communication of the device.

[0042] Optionally, the compilation module includes:

[0043] The compilation submodule is used to compile the source code of the application running on the target power terminal based on the device-inherent fingerprint of the target power terminal to obtain the target code;

[0044] The assembly submodule is used to assemble the target code based on the target instruction set to obtain the corresponding target binary file; and to link and merge the target binary file to generate the executable file of the application.

[0045] The target instruction set is generated based on the device-inherent fingerprint of the target power terminal.

[0046] Optionally, the intrinsic fingerprint of the target power terminal includes explicit hardware features and implicit interaction features; the compilation submodule includes:

[0047] The compilation parameter calculation subunit is used to determine the compilation parameters of the source code based on the difference between the explicit hardware features of the device and the corresponding baseline explicit feature quantity and the difference between the implicit interaction features of the device and the baseline implicit features.

[0048] The compilation subunit is used to compile the application running on the target power terminal based on the compilation parameters to obtain target code;

[0049] The benchmark explicit features and benchmark implicit features are the device hardware explicit features and device implicit interaction features in the benchmark endogenous fingerprint.

[0050] Optionally, the compilation parameter calculation subunit is specifically used for:

[0051] Based on the similarity between the explicit features of the device hardware and the corresponding benchmark explicit features, the explicit differences of the target power terminal are determined.

[0052] Based on the Manhattan distance between the latent features of each feature dimension in the device's latent interaction features and the corresponding baseline latent features, the latent differences of each feature dimension are determined.

[0053] The compilation parameters for the source code compilation process are obtained by fusing the explicit differences of the target power terminal and the implicit differences of each feature dimension.

[0054] Optionally, the compilation parameters include compilation parameters for at least one type of compilation operation: control flow flattening, logic transformation strategy, and redundant operation insertion.

[0055] Optionally, the compilation module further includes:

[0056] The instruction set generation submodule is used to remap the original instruction set corresponding to the hardware device of the target power terminal based on the device-inherent fingerprint of the target power terminal, and generate the target instruction set.

[0057] Optionally, the execution module includes:

[0058] The offset calculation submodule is used to determine the fingerprint offset of the target power terminal based on the Mahalanobis distance between the device-generated fingerprint of the target power terminal and the reference endogenous fingerprint.

[0059] The address adjustment submodule is used to adjust the stack base address of the executable file based on the fingerprint offset of the target power terminal.

[0060] On the other hand, the present invention also provides an electronic device, comprising: at least one processor and a memory; the memory and the processor are connected via a bus;

[0061] The memory is used to store one or more programs;

[0062] When the one or more programs are executed by the at least one processor, the method described in any of the foregoing is implemented.

[0063] On the other hand, the present invention also provides a readable storage medium having an executable program stored thereon, wherein when the executable program is executed, it implements the method described in any one of the above.

[0064] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0065] This invention provides a method and system for secure execution of applications on power terminals. By generating an intrinsic fingerprint of the target power terminal based on communication interaction deviation characteristics generated by the device's own attributes, the source code of the application running on the target power terminal is compiled to obtain an executable file. This method enables differentiated compilation of application code based on device attributes, ensuring unpredictability even when compiling the same code on different power terminals. This increases the difficulty for attackers to reverse engineer the program code through static or dynamic analysis, thereby enhancing the security and protection capabilities of application execution on the target power terminal.

[0066] This invention adjusts the stack address of the executable file based on the offset between the device-generated fingerprint of the target power terminal and the reference device-generated fingerprint. By dynamically adjusting the stack address of the power terminal application during runtime, the security and protection capabilities of code execution are further improved, and the detectability and exploitability of unknown vulnerabilities in the power terminal application are reduced. Attached Figure Description

[0067] Figure 1 This is a flowchart illustrating a secure execution method for a power terminal application according to the present invention.

[0068] Figure 2 Typical waveform diagram of transient / steady-state signal as an example of the present invention;

[0069] Figure 3 A characteristic curve of link delay of different terminals in the frequency domain space, which is an example of the present invention;

[0070] Figure 4 The characteristic curve of link delay in the frequency domain space for the same terminal using different signals, as an example of the present invention;

[0071] Figure 5 This is a block diagram of an electronic device according to the present invention. Detailed Implementation

[0072] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0073] Example 1

[0074] This invention provides a method for secure execution of a power terminal application, the schematic diagram of which is shown below. Figure 1 As shown, the method includes:

[0075] Step S110: For each target power terminal, the source code of the application running on the target power terminal is compiled based on the extracted device-inherent fingerprint of the target power terminal to obtain the executable file of the application.

[0076] Step S120: Execute the executable file of the application.

[0077] The device-inherent fingerprint of the target power terminal is generated based on the communication interaction deviation characteristics generated by the device's own attributes. During the execution of the executable file, the stack address of the executable file is adjusted based on the offset between the device-inherent fingerprint of the target power terminal and the reference device-inherent fingerprint.

[0078] In this example implementation, the target power terminal refers to an uncontrolled power terminal in the power system, that is, a power terminal device that is not directly controlled by the central control system during operation. These devices are typically deployed in untrusted physical environments such as the user side or power station side, and can interact openly with the power master station system. For example, the target power terminal may include heterogeneous intelligent terminals such as user-side inverters and intelligent monitoring equipment (e.g., intelligent monitoring terminals for distributed renewable energy). The device's inherent attributes may include inherent characteristics generated during the manufacturing process of its internal components; for example, the device's inherent attributes may be the free manufacturing tolerances of the communication components within the terminal device. Communication interaction deviation characteristics may include wireless communication deviation characteristics and wired communication deviation characteristics. The device's inherent attributes may also include various hardware attributes, such as the device's processor, memory, cache, etc. Exemplarily, the intrinsic fingerprint of the target power terminal includes explicit hardware characteristics and implicit interaction characteristics. Explicit hardware characteristics of a device can include readily obtainable information such as processor model, cache size, memory address distribution, and network interface MAC address; however, this information is susceptible to tampering. Implicit interaction characteristics are those arising from the inherent manufacturing tolerances of the terminal device's internal communication components, forming a unique identifier for the device. These implicit interaction characteristics include the frequency offset characteristics of the device's wireless communication and the link delay characteristics of its wired communication. The application program on the terminal is compiled based on the fingerprint set of the target power terminal's intrinsic device fingerprint, improving code polymorphism and instruction randomization capabilities. The reference intrinsic fingerprint is the intrinsic fingerprint of the specified target power terminal; for example, it could be the intrinsic fingerprint of a specific uncontrolled power terminal used as a reference. Based on the differences in intrinsic fingerprints between different devices, the stack address of the terminal application during runtime is dynamically adjusted, improving code execution security and protection capabilities, and further reducing the detectability and exploitability of unknown vulnerabilities in the terminal application.

[0079] In some example implementations, before compiling the source code of an application running on the target power terminal based on the extracted device-in-device fingerprint of the target power terminal to obtain an executable file of the application, the method further includes:

[0080] Based on time-frequency analysis of the transient signal obtained during the wireless communication process of the target power terminal, the time spectrum of the transient signal is extracted as the frequency offset feature of the transient signal;

[0081] Based on autocorrelation processing of the steady-state signal obtained during the wireless communication process of the target power terminal, the carrier frequency offset characteristics of the steady-state signal are obtained.

[0082] Based on link detection of the target power terminal, the link delay characteristics of the wired communication of the device are obtained;

[0083] Based on the explicit hardware characteristics of the device, the frequency offset characteristics of the transient signal, the carrier frequency offset characteristics of the steady-state signal, and the link delay characteristics of the wired communication of the device, the device intrinsic fingerprint of the target power terminal is determined.

[0084] In this example embodiment, the frequency offset characteristics of the device's wireless communication include the frequency offset characteristics of transient signals and the carrier frequency offset characteristics of steady-state signals. The transient signal during the target power terminal's wireless communication process can be the transmitted signal when the terminal is turned on or off. During wireless communication, when the terminal is turned on or off, its RF transmitter's power amplifier, oscillator, and modulator undergo a brief non-steady-state process, resulting in the terminal's transmitted signal having device-specific transient envelope characteristics. The steady-state signal during the target power terminal's wireless communication process can be the transmitted signal during stable operation of the terminal. In a stable operating state, the terminal needs to frequently transmit steady-state preamble signals for synchronization. Due to the inaccuracy of the terminal's RF front-end oscillator, the preamble signal has a frequency deviation, thus reflecting the terminal's unique steady-state frequency offset characteristic. Typical waveforms of the target power terminal's transient and steady-state signals are as follows: Figure 2 As shown in the figure, the horizontal axis represents time, and the vertical axis represents signal amplitude. It can be seen from the figure that transient and steady-state signals have different waveform characteristics. The transient and steady-state signals of the terminal can be acquired through the USRP (Universal Software Radio Peripheral). Frequency offset features are extracted from the transient and steady-state signals respectively. For example, short-time Fourier transform is used to perform time-frequency analysis on the transient signal, which can effectively extract transient features.

[0085]

[0086] Where X(f,t) is the time-frequency spectrum function, x(τ) is the transient signal, f is the frequency of the transient signal, w is the sliding window function, mainly used to smooth the signal and avoid spectral leakage, j is the imaginary unit, and τ and t represent time, respectively. After the short-time Fourier transform, the resulting time-frequency spectrum can clearly show the physical characteristics of the terminal, such as modulation characteristics and frequency shift.

[0087] Furthermore, by extracting the autocorrelation of the steady-state signal, the carrier frequency offset characteristics associated with the steady-state signal can be obtained:

[0088]

[0089] in, For carrier frequency offset estimation, T is the period of the steady-state signal, y is the steady-state signal, and y is the carrier frequency offset. *It is the conjugate function of the steady-state signal, where n is the index of the steady-state signal sampling point and N is the number of steady-state signal sampling points.

[0090] For the wired communication process of the terminals, link delay characteristics are extracted. Considering the link delay characteristics between different terminals in a distributed renewable energy scenario, a random modulation active probing method is first adopted. The master station sends a known probe signal to the power terminal to perform link probing and obtain link characteristic information. Specifically, assuming the system uses a modulated signal x(t) as the probe signal, this signal is transmitted through link h(t), and the response signal recorded at the receiving end (target power terminal) is y(t). Due to the link delay characteristics, y(t) is affected by equipment characteristics and environmental changes. The link delay characteristics can be estimated using discrete Fourier transform:

[0091]

[0092] Where X[k] is the Discrete Fourier Transform of the modulated signal x(t) after sampling, k is the sequence index corresponding to the Discrete Fourier Transform, and Y[k] is the Discrete Fourier Transform of the response signal y(t) after sampling. Link delay characteristics can be used to analyze the stability and dynamic changes of signal transmission paths. This example considers that due to factors such as manufacturing processes, materials, and environment, the actual output frequency of the crystal oscillator in a device will have a unique inherent deviation, which will lead to different processing delays for different devices. Even devices with equivalent positions in the same network topology will exhibit different link delay characteristics due to differences in crystal oscillator tolerances. Therefore, the uniqueness of crystal oscillator tolerances can be used to construct a unique link fingerprint for a device, thereby achieving accurate identification and differentiation of devices. Malicious external devices may impersonate the traffic behavior of legitimate devices, but the link delay characteristics are difficult to forge, such as... Figure 3 As shown in the figure, the yellow and blue curves represent the characteristic curves of the link delay RTT (Round Trip Time) of two different power terminals in the frequency domain. The horizontal axis represents amplitude, and the vertical axis represents amplitude. From Figure 3 It can be seen that the response signals of different terminals differ significantly, therefore, random modulation detection can effectively distinguish between different devices. The characteristic curves (amplitude A and amplitude B) of link delay in the frequency domain for the same terminal using different signals are shown below. Figure 4 As shown in the figure, the horizontal axis represents amplitude, and the vertical axis represents amplitude. From Figure 4 It can be seen that the envelope (shape) of the link delay of the same terminal is similar, that is, the link delay characteristics of the same terminal are similar, which can be used as a unique fingerprint of the terminal. Finally, the directly obtainable explicit information such as processor model, cache size, memory address distribution, network interface MAC address, and X(f,t) are combined with the other information. Latent interaction features combine to form a corresponding device-native fingerprint, i.e., a fingerprint set F = {f1, f2, ..., f...}. s}, f s Let s be the s-th fingerprint feature.

[0093] In some implementations, S110 compiles the source code of the application running on the target power terminal based on the extracted device-inherent fingerprint of the target power terminal to obtain an executable file of the application, including:

[0094] The source code of the application running on the target power terminal is compiled based on the device-inherent fingerprint of the target power terminal to obtain the target code;

[0095] The target code is assembled based on the target instruction set to obtain the corresponding target binary file; the target binary file is then linked and merged to generate the executable file of the application.

[0096] In this example implementation, compiling the source code of the application on the target power terminal can be a process where a compiler translates the source code or preprocessed code into assembly code. For example, the compilation process may include compiling the source code into intermediate code, and then optimizing the intermediate code to form the target code. Compilation parameters related to the above compilation process can be generated based on the device's intrinsic fingerprint. The compilation process is completed based on these parameters, giving the target code unique intrinsic fingerprint characteristics of the device, thus avoiding the problem of reverse engineering and extraction of the source code in an open environment. The target instruction set is generated based on the device's intrinsic fingerprint. The target code is assembled using the target instruction set carrying the device's intrinsic fingerprint to obtain the corresponding target binary file, increasing the difficulty of code decompilation and improving code security.

[0097] For example, the source code of the application running on the target power terminal is compiled based on the device-inherent fingerprint of the target power terminal to obtain target code, including:

[0098] Based on the differences between different explicit feature quantities in the explicit features of the device hardware and their corresponding baseline explicit feature quantities, and the differences between different dimensions of implicit features in the implicit interaction features of the device and their corresponding baseline implicit features, the compilation parameters of the source code are determined.

[0099] The application running on the target power terminal is compiled based on the compilation parameters to obtain the target code.

[0100] In this example implementation, the baseline explicit features and baseline implicit features are the device hardware explicit features and device implicit interaction features in the baseline endogenous fingerprint, which are the corresponding features of the specified target power terminal (i.e., the baseline terminal). Compilation parameters can be various parameters during the compilation process; for example, compilation parameters can be parameters from the code optimization process. To address the problem that binary programs of heterogeneous power and new energy monitoring terminals are easily reverse-engineered and extracted in an open environment, a program vulnerability obfuscation protection method based on diversified compilation is designed. For example, at least one of three compilation options—control flow flattening, logic transformation strategy, and redundant operation insertion—is used to design program vulnerability obfuscation protection, ensuring that compiling the same code on different terminals still maintains unpredictability, increasing the difficulty for attackers to reverse engineer the code through static or dynamic analysis. Accordingly, the compilation parameters include compilation parameters for at least one of the compilation operations: control flow flattening, logic transformation strategy, and redundant operation insertion. The compilation parameters of the source code can be determined based on the differences between different explicit feature quantities in the explicit features of the device hardware and the corresponding baseline explicit feature quantities, and the differences between different dimensions of the implicit interaction features of the device and the corresponding baseline implicit features. In other words, the compilation parameters are determined based on the fingerprint differences between the current terminal and the baseline terminal, so that the compilation result has the characteristics of the device's intrinsic fingerprint.

[0101] For example, the compilation parameters of the source code are determined based on the differences between the explicit hardware features of the device and the corresponding baseline explicit feature quantities, and the differences between the implicit interaction features of the device and the baseline implicit features, including:

[0102] Based on the similarity between the explicit features of the device hardware and the corresponding benchmark explicit features, the explicit differences of the target power terminal are determined.

[0103] Based on the Manhattan distance between the latent features of each feature dimension in the device's latent interaction features and the corresponding baseline latent features, the latent differences of each feature dimension are determined.

[0104] The compilation parameters for the source code compilation process are obtained by fusing the explicit differences of the target power terminal and the implicit differences of each feature dimension.

[0105] In this example implementation, the device hardware explicit features and the corresponding baseline explicit features are each vectors composed of multiple explicit feature quantities. The explicit differences are determined by calculating the similarity between the two vectors. For example, if the baseline endogenous fingerprint set of the baseline terminal is F... base For explicit information in the endogenous fingerprint set, cosine similarity can be used to calculate terminal differences:

[0106]

[0107] Among them, f θ For cosine similarity, f is the baseline dominant eigenvector of the baseline terminal. i 显性 Let ||·|| be the explicit feature vector of the device hardware of terminal i, and ||·|| be the norm. The explicit difference of the target power terminal (terminal i) is 1-f. θ Its range is [-1, 1];

[0108] For latent features, the Manhattan distance is used to calculate the dissimilarity:

[0109]

[0110] Among them, D 隐性 For the implicit differences of terminal i, The m-th dimension of the implicit interaction features of the benchmark terminal is the implicit feature of the device. Let M be the m-th dimension of the baseline latent feature of terminal i, where M is the number of dimensions corresponding to the latent feature fingerprint.

[0111] After obtaining the implicit and explicit differences, they are concatenated and merged, and the result is normalized to obtain the compilation parameters for the source code compilation process. For example, the compilation parameters are the values ​​of mllvm-split_num, mllvm-sub_loop, and mllvm-bcf_loop in the ollvm obfuscation. Considering compilation and execution efficiency, the values ​​of these parameters generally do not exceed 5. Therefore, the concatenation and merging result can be normalized to the range [1,5], and the integer part is the value of the parameter.

[0112] For example, the compilation parameters include compilation parameters for at least one type of compilation operation: control flow flattening, logic transformation strategy, and redundant operation insertion.

[0113] In this example implementation, control flow flattening transforms the hierarchical control logic in the code into a flattened form, increasing the difficulty of code analysis. The originally linear conditional branch structure is converted into a non-linear flow based on state machine transitions, requiring the code execution path to track multiple jumps of state variables within loops, significantly increasing the difficulty of reverse engineering. Specifically, mllvm-fla can be used to activate the control flow flattening option; simultaneously, mllvm-split can be used to activate basic block splitting, further enhancing the code obfuscation effect; based on the characteristics of the device's intrinsic fingerprint set, the parameter mllvm-split_num = L, where L is the value of the previously calculated editing parameter. The logic transformation strategy is based on the principles of Boolean algebra, performing equivalent transformations on the logical operations in the code. While this transformation does not change the final functionality of the code, it makes the logical structure more complex, making it difficult for attackers to understand the transformed logical relationships during reverse engineering. Specifically, mllvm-sub can be used to activate instruction replacement, setting mllvm-sub_loop = L, where L is the value of the previously calculated editing parameter. Redundant operation insertion involves inserting meaningless instructions into the code without affecting its original functionality, thus interfering with an attacker's analysis of the core code's capabilities. Typically, arithmetic or logical operation instructions that do not change the actual data value are inserted, disrupting the attacker's understanding of the core computational logic. Specifically, mllvm-bcf is used to activate spurious control flow injection, filling it with randomly selected useless instructions, and setting mllvm-bcf_loop = L, where L is a previously calculated edit parameter value. Through this multi-layered, multi-strategy code diversification compilation method, the polymorphism and anti-analysis capabilities of heterogeneous monitoring terminal application code can be effectively improved, thereby reducing the possibility of attackers performing reverse engineering through static disassembly, dynamic debugging, and other methods, achieving code security protection for terminal devices.

[0114] In some implementations, before assembling the target code based on the target instruction set to obtain the corresponding target binary file, the following steps are also included:

[0115] Based on the device-inherent fingerprint of the target power terminal, the original instruction set corresponding to the hardware device of the target power terminal is remapped to generate the target instruction set.

[0116] In this example implementation, the device fingerprint set is set as F = {f1, f2, ..., f...} s Each fingerprint feature can be used as a random seed input into the compiler's custom instruction set generation logic. During instruction encoding randomization, the instruction encoding mode is dynamically adjusted based on the device fingerprint, so that the same function corresponds to different instruction sequences on different devices. Specifically, for instruction encoding, a random mapping function M′ is defined as the core mapping rule for converting device fingerprints to the target instruction set, i.e.

[0117] M′:F×I orig →I custom (6)

[0118] Among them, I orig This represents the original instruction set, while I... custom This refers to the target instruction set, which is a custom instruction set generated based on the device fingerprint. For example, the mapping function can be implemented using instruction remapping based on a hash function, ensuring that the instruction sequences generated by different devices are significantly different at the binary level. Even if an attacker obtains executable code on one device, they still cannot execute the same instruction sequence on another device. This increases the polymorphism and reverse engineering resistance of the code. For example, the implementation leverages the modularity and virtual instruction execution strategy of the LLVM compiler. First, new instruction set rules need to be defined, using the device's intrinsic fingerprint and the original instruction set to generate the target instruction set to support the parsing and mapping of custom instructions. During instruction selection, LLVM uses a pattern matching method to determine the conversion from code to target instructions.

[0119] In some implementations, the process of executing the executable file of the application in S120 includes:

[0120] The fingerprint offset of the target power terminal is determined based on the Mahalanobis distance between the device-generated fingerprint of the target power terminal and the reference device-generated fingerprint.

[0121] The stack base address of the executable file is adjusted based on the fingerprint offset of the target power terminal.

[0122] In this example implementation, the basic idea of ​​dynamic stack address adjustment is to dynamically modify the program's stack layout based on the terminal's intrinsic fingerprint, so that the stack address changes when the same function call is executed on different devices. Let the executable file's stack base address be SP, and the adjustment process can be represented as:

[0123] SP′=SP+Δ(F) (7)

[0124] Where SP′ is the adjusted stack address, and Δ(F) represents the terminal's fingerprint offset. Dynamic adjustment of the stack address ensures that even when running in the same software environment, the program's stack address will change due to different device fingerprints, thus increasing the difficulty for attackers to reconstruct the code logic through static analysis and dynamic debugging. The calculation of Δ(F) can use Mahalanobis distance. The linear correlation between vectors in the fingerprint set is modeled using the covariance matrix Σ between the target terminal device's intrinsic fingerprint set and the baseline intrinsic fingerprint set. The data is then transformed into a decorrelation space before calculating the distance.

[0125]

[0126] Among them, D M The Mahalanobis distance between the device-generated fingerprint and the reference device-generated fingerprint is represented by Σ. -1 Find the inverse of the covariance matrix Σ; F i For terminal i, the device-inherent fingerprint set, F base The set of intrinsic fingerprints serves as the baseline, with the superscript T indicating the transpose operation. Compared to the commonly used Euclidean distance calculation method, the Mahalanobis distance calculation method significantly improves the robustness of the results to outliers and avoids the influence of different types of information in the fingerprint set on the stack offset weights. This example addresses the risks of code analysis and reverse engineering attacks existing in the current execution process by dynamically adjusting the stack address during code execution using the device's intrinsic fingerprint. Through this dynamic adjustment mechanism, it is ensured that the same code produces different stack offsets when executed on different devices, thereby significantly reducing the attack risks during the operation of new energy distributed devices and improving the security and protection capabilities of code execution.

[0127] The new power system strategy will vigorously develop a new energy system represented by wind power and solar power. my country's installed capacity of new energy power generation (including wind power, solar power, and biomass power) is 1.45 billion kilowatts, accounting for 40.7% of the total installed power generation capacity, exceeding that of thermal power, indicating that new energy has become the main force in my country's energy system transformation and upgrading towards a green and low-carbon direction. However, a large number of distributed new energy monitoring terminal devices from different investment entities are widely deployed in untrusted physical environments on the user side and power station side, interacting openly with the power master station system within the isolation and protection system. This exposes the new energy monitoring system outside the power isolation and protection system, making it vulnerable to cybersecurity attacks such as illegal intrusion of new energy monitoring terminals, malicious network control interactions, and malicious operation and destruction of the system. Unlike the closed network and dedicated equipment environment of traditional power business, the large number of heterogeneous intelligent terminals such as user-side inverters and intelligent monitoring equipment widely connected to new energy monitoring are generally deployed in uncontrolled network environments such as residential communities and factories, making them extremely vulnerable to malicious exploitation and control. However, existing hardware-based protection methods cannot be applied to uncontrolled terminals, and existing software-level program hardening methods are homogenized. Once the hardening method of a single program is reverse-engineered, the hardening protection of similar programs will all fail.

[0128] To address the above problems, this invention studies a terminal application protection method that meets resource-constrained conditions, supports differentiated protection for terminal programs, and avoids batch breaches caused by the same attack method. To address the risk of application code being easily reverse-engineered, it proposes diversified compilation and dynamic instruction set generation methods to improve code execution security and protection capabilities, and constructs a polymorphic application protection system bound to the device's intrinsic fingerprint. Specifically, firstly, an intrinsic fingerprint extraction method for uncontrolled power terminals is proposed, constructing an intrinsic fingerprint set containing explicit device information and implicit interaction characteristics; secondly, compilation option parameters are set based on the fingerprint set, and the polymorphism of the code is improved through strategies such as control flow flattening, logic transformation, and redundant operation insertion; subsequently, instruction encoding is randomized based on the intrinsic fingerprint information to generate instruction sets that are tightly bound to the device identity and are distinct from each other; finally, based on the differences in intrinsic fingerprints between different devices, the stack address of the terminal application during runtime is dynamically adjusted to improve code execution security and protection capabilities, further reducing the detectability and exploitability of unknown vulnerabilities in the terminal application.

[0129] This invention proposes a security hardening and protection method for uncontrolled power terminal applications. Compared with existing program hardening methods, it first forms a device-bound intrinsic fingerprint based on the inherent information and physical characteristics (wireless communication characteristics, link communication characteristics) of the terminal device. Then, based on the intrinsic fingerprint, it performs program compilation obfuscation, custom instruction set generation, and dynamic runtime stack adjustment. Because it binds to the device's intrinsic fingerprint information (which has tamper-proof and spoofable characteristics), it can generate a unique and differentiated protection method for each terminal application, resulting in stronger resistance to reverse engineering compared to existing program hardening methods. Furthermore, for clustered terminal devices, it can form differentiated program representations, effectively preventing the lateral spread of malicious attacks on similar terminal devices. In addition, it can also be used to investigate terminals where malicious program leaks occur.

[0130] Example 2

[0131] Based on the same inventive concept, the present invention also provides a secure execution system for power terminal applications, comprising:

[0132] The compilation module is used to compile the source code of the application running on the target power terminal based on the extracted device intrinsic fingerprint of the target power terminal for each target power terminal, so as to obtain the executable file of the application.

[0133] An execution module is used to execute the executable file of the application.

[0134] The device-inherent fingerprint of the target power terminal is generated based on the communication interaction deviation characteristics generated by the device's own attributes. During the execution of the executable file, the stack address of the executable file is adjusted based on the offset between the device-inherent fingerprint of the target power terminal and the reference device-inherent fingerprint. The reference device-inherent fingerprint is the specified device-inherent fingerprint of the target power terminal.

[0135] In one possible implementation, the device-inherent fingerprint of the target power terminal includes explicit hardware features and implicit interaction features, wherein the implicit interaction features include frequency offset features of wireless communication and link delay features of wired communication.

[0136] In one possible implementation, the frequency offset characteristics of the device's wireless communication include the frequency offset characteristics of transient signals and the carrier frequency offset characteristics of steady-state signals; it also includes: a fingerprint extraction module, the fingerprint extraction module comprising:

[0137] The transient fingerprint extraction submodule is used to perform time-frequency analysis on the transient signal acquired during the wireless communication process of the target power terminal, and extract the time spectrum of the transient signal as the frequency offset feature of the transient signal.

[0138] The steady-state fingerprint extraction submodule is used to obtain the carrier frequency offset characteristics of the steady-state signal by performing autocorrelation processing on the acquired steady-state signal during the wireless communication process of the target power terminal.

[0139] The delay feature extraction submodule is used to obtain the link delay features of the wired communication of the device based on link detection of the target power terminal;

[0140] The fingerprint generation submodule is used to determine the device-inherent fingerprint of the target power terminal based on the explicit hardware features of the device, the frequency offset features of the transient signal, the carrier frequency offset features of the steady-state signal, and the link delay features of the wired communication of the device.

[0141] In one possible implementation, the compilation module includes:

[0142] The compilation submodule is used to compile the source code of the application running on the target power terminal based on the device-inherent fingerprint of the target power terminal to obtain the target code;

[0143] The assembly submodule is used to assemble the target code based on the target instruction set to obtain the corresponding target binary file; and to link and merge the target binary file to generate the executable file of the application.

[0144] The target instruction set is generated based on the device-inherent fingerprint of the target power terminal.

[0145] In one possible implementation, the intrinsic fingerprint of the target power terminal includes explicit hardware features and implicit interaction features; the compilation submodule includes:

[0146] The compilation parameter calculation subunit is used to determine the compilation parameters of the source code based on the difference between the explicit hardware features of the device and the corresponding baseline explicit feature quantity and the difference between the implicit interaction features of the device and the baseline implicit features.

[0147] The compilation subunit is used to compile the application running on the target power terminal based on the compilation parameters to obtain target code;

[0148] The benchmark explicit features and benchmark implicit features are the device hardware explicit features and device implicit interaction features in the benchmark endogenous fingerprint.

[0149] In one possible implementation, the compiler parameter calculation subunit is specifically used for:

[0150] Based on the similarity between the explicit features of the device hardware and the corresponding benchmark explicit features, the explicit differences of the target power terminal are determined.

[0151] Based on the Manhattan distance between the latent features of each feature dimension in the device's latent interaction features and the corresponding baseline latent features, the latent differences of each feature dimension are determined.

[0152] The compilation parameters for the source code compilation process are obtained by fusing the explicit differences of the target power terminal and the implicit differences of each feature dimension.

[0153] In one possible implementation, the compilation parameters include compilation parameters for at least one type of compilation operation: control flow flattening, logic transformation strategy, and redundant operation insertion.

[0154] In one possible implementation, the compilation module further includes:

[0155] The instruction set generation submodule is used to remap the original instruction set corresponding to the hardware device of the target power terminal based on the device-inherent fingerprint of the target power terminal, and generate the target instruction set.

[0156] In one possible implementation, the execution module includes:

[0157] The offset calculation submodule is used to determine the fingerprint offset of the target power terminal based on the Mahalanobis distance between the device-generated fingerprint of the target power terminal and the reference endogenous fingerprint.

[0158] The address adjustment submodule is used to adjust the stack base address of the executable file based on the fingerprint offset of the target power terminal.

[0159] Example 3

[0160] like Figure 5 As shown, the present invention also provides an electronic device, which may be a computer device, a microcontroller device, a smart mobile device, etc. The electronic device in this embodiment may include a processor, a memory, a transceiver component, etc. The memory, processor, and transceiver component are connected via a bus; the memory can be used to store executable programs, and an exemplary executable program may include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, which can be accessed and / or modified when instructions are executed.

[0161] The processor may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, and it is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of a power terminal application security execution method in the above embodiments.

[0162] Example 4

[0163] Based on the same inventive concept, this invention also provides a readable storage medium, specifically an electronic device readable storage medium (Memory). An electronic device readable storage medium is a memory device within an electronic device used to store programs and data. It is understood that the storage medium here can include both built-in storage media within the electronic device and extended storage media supported by the electronic device. The storage medium provides storage space, which stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more executable programs (including program code). It should be noted that the storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. Loading and executing one or more instructions stored in the storage medium by the processor can implement the steps of the secure execution method for a power terminal application described in the above embodiments.

[0164] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0165] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0166] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0167] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0168] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit its scope of protection. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that after reading the present invention, they can still make various changes, modifications or equivalent substitutions to the specific implementation methods of the application, but these changes, modifications or equivalent substitutions are all within the scope of protection of the claims pending approval.

Claims

1. A method for securely executing a power terminal application, characterized in that, include: For each target power terminal, the source code of the application running on the target power terminal is compiled based on the extracted device-inherent fingerprint of the target power terminal to obtain the executable file of the application. Execute the executable file of the application; The device-inherent fingerprint of the target power terminal is generated based on the communication interaction deviation characteristics generated by the device's own attributes. During the execution of the executable file, the stack address of the executable file is adjusted based on the offset between the device-inherent fingerprint of the target power terminal and the reference device-inherent fingerprint. The reference device-inherent fingerprint is the specified device-inherent fingerprint of the target power terminal.

2. The method according to claim 1, characterized in that, The device-inherent fingerprint of the target power terminal includes explicit hardware features and implicit interaction features. The implicit interaction features include frequency offset features of wireless communication and link delay features of wired communication.

3. The method according to claim 2, characterized in that, The frequency offset characteristics of the device's wireless communication include the frequency offset characteristics of transient signals and the carrier frequency offset characteristics of steady-state signals; before compiling the source code of the application running on the target power terminal based on the extracted device-inherent fingerprint of the target power terminal to obtain the executable file of the application, the method further includes: Based on time-frequency analysis of the transient signal obtained during the wireless communication process of the target power terminal, the time spectrum of the transient signal is extracted as the frequency offset feature of the transient signal; Based on autocorrelation processing of the steady-state signal obtained during the wireless communication process of the target power terminal, the carrier frequency offset characteristics of the steady-state signal are obtained. Based on link detection of the target power terminal, the link delay characteristics of the wired communication of the device are obtained; Based on the explicit hardware characteristics of the device, the frequency offset characteristics of the transient signal, the carrier frequency offset characteristics of the steady-state signal, and the link delay characteristics of the wired communication of the device, the device intrinsic fingerprint of the target power terminal is determined.

4. The method according to claim 1, characterized in that, Based on the extracted device-inherent fingerprint of the target power terminal, the source code of the application running on the target power terminal is compiled to obtain the executable file of the application, including: The source code of the application running on the target power terminal is compiled based on the device-inherent fingerprint of the target power terminal to obtain the target code; The target code is assembled based on the target instruction set to obtain the corresponding target binary file; the target binary file is linked and merged to generate the executable file of the application. The target instruction set is generated based on the device-inherent fingerprint of the target power terminal.

5. The method according to claim 4, characterized in that, The device-inherent fingerprint of the target power terminal includes explicit hardware features and implicit interaction features. Based on the device-inherent fingerprint of the target power terminal, the source code of the application running on the target power terminal is compiled to obtain target code, including: Based on the differences between the explicit hardware features of the device and the corresponding baseline explicit feature quantities, and the differences between the implicit interaction features of the device and the baseline implicit features, the compilation parameters of the source code are determined. The application running on the target power terminal is compiled based on the compilation parameters to obtain the target code; The benchmark explicit features and benchmark implicit features are the device hardware explicit features and device implicit interaction features in the benchmark endogenous fingerprint.

6. The method according to claim 5, characterized in that, Based on the differences between the explicit hardware features of the device and the corresponding baseline explicit features, and the differences between the implicit interaction features of the device and the baseline implicit features, the compilation parameters of the source code are determined, including: Based on the similarity between the explicit features of the device hardware and the corresponding benchmark explicit features, the explicit differences of the target power terminal are determined. Based on the Manhattan distance between the latent features of each feature dimension in the device's latent interaction features and the corresponding baseline latent features, the latent differences of each feature dimension are determined. The compilation parameters for the source code compilation process are obtained by fusing the explicit differences of the target power terminal and the implicit differences of each feature dimension.

7. The method according to claim 5 or 6, characterized in that, The compilation parameters include compilation parameters for at least one of the following compilation operations: control flow flattening, logic transformation strategy, and redundant operation insertion.

8. The method according to claim 4, characterized in that, Before assembling the target code based on the target instruction set to obtain the corresponding target binary file, the process also includes: Based on the device-inherent fingerprint of the target power terminal, the original instruction set corresponding to the hardware device of the target power terminal is remapped to generate the target instruction set.

9. The method according to claim 1, characterized in that, The process of executing the executable file of the application includes: The fingerprint offset of the target power terminal is determined based on the Mahalanobis distance between the device-generated fingerprint of the target power terminal and the reference device-generated fingerprint. The stack base address of the executable file is adjusted based on the fingerprint offset of the target power terminal.

10. A secure execution system for a power terminal application, characterized in that, include: The compilation module is used to compile the source code of the application running on the target power terminal based on the extracted device intrinsic fingerprint of the target power terminal for each target power terminal, so as to obtain the executable file of the application. An execution module is used to execute the executable file of the application. The device-inherent fingerprint of the target power terminal is generated based on the communication interaction deviation characteristics generated by the device's own attributes. During the execution of the executable file, the stack address of the executable file is adjusted based on the offset between the device-inherent fingerprint of the target power terminal and the reference device-inherent fingerprint. The reference device-inherent fingerprint is the specified device-inherent fingerprint of the target power terminal.

11. The system according to claim 10, characterized in that, The device-inherent fingerprint of the target power terminal includes explicit hardware features and implicit interaction features. The implicit interaction features include frequency offset features of wireless communication and link delay features of wired communication.

12. The system according to claim 11, characterized in that, The frequency offset characteristics of the device's wireless communication include the frequency offset characteristics of transient signals and the carrier frequency offset characteristics of steady-state signals; It also includes: a fingerprint extraction module, the fingerprint extraction module comprising: The transient fingerprint extraction submodule is used to perform time-frequency analysis on the transient signal acquired during the wireless communication process of the target power terminal, and extract the time spectrum of the transient signal as the frequency offset feature of the transient signal. The steady-state fingerprint extraction submodule is used to obtain the carrier frequency offset characteristics of the steady-state signal by performing autocorrelation processing on the acquired steady-state signal during the wireless communication process of the target power terminal. The delay feature extraction submodule is used to obtain the link delay features of the wired communication of the device based on link detection of the target power terminal; The fingerprint generation submodule is used to determine the device-inherent fingerprint of the target power terminal based on the explicit hardware features of the device, the frequency offset features of the transient signal, the carrier frequency offset features of the steady-state signal, and the link delay features of the wired communication of the device.

13. The system according to claim 10, characterized in that, The compilation module includes: The compilation submodule is used to compile the source code of the application running on the target power terminal based on the device-inherent fingerprint of the target power terminal to obtain the target code; The assembly submodule is used to assemble the target code based on the target instruction set to obtain the corresponding target binary file; and to link and merge the target binary file to generate the executable file of the application. The target instruction set is generated based on the device-inherent fingerprint of the target power terminal.

14. The system according to claim 13, characterized in that, The intrinsic fingerprint of the target power terminal includes explicit hardware features and implicit interaction features; the compilation submodule includes: The compilation parameter calculation subunit is used to determine the compilation parameters of the source code based on the difference between the explicit hardware features of the device and the corresponding baseline explicit feature quantity and the difference between the implicit interaction features of the device and the baseline implicit features. The compilation subunit is used to compile the application running on the target power terminal based on the compilation parameters to obtain target code; The benchmark explicit features and benchmark implicit features are the device hardware explicit features and device implicit interaction features in the benchmark endogenous fingerprint.

15. The system according to claim 14, characterized in that, The compilation parameter calculation subunit is specifically used for: Based on the similarity between the explicit features of the device hardware and the corresponding benchmark explicit features, the explicit differences of the target power terminal are determined. Based on the Manhattan distance between the latent features of each feature dimension in the device's latent interaction features and the corresponding baseline latent features, the latent differences of each feature dimension are determined. The compilation parameters for the source code compilation process are obtained by fusing the explicit differences of the target power terminal and the implicit differences of each feature dimension.

16. The system according to claim 14 or 15, characterized in that, The compilation parameters include compilation parameters for at least one of the following compilation operations: control flow flattening, logic transformation strategy, and redundant operation insertion.

17. The system according to claim 13, characterized in that, The compilation module also includes: The instruction set generation submodule is used to remap the original instruction set corresponding to the hardware device of the target power terminal based on the device-inherent fingerprint of the target power terminal, and generate the target instruction set.

18. The system according to claim 10, characterized in that, The execution module includes: The offset calculation submodule is used to determine the fingerprint offset of the target power terminal based on the Mahalanobis distance between the device-generated fingerprint of the target power terminal and the reference endogenous fingerprint. The address adjustment submodule is used to adjust the stack base address of the executable file based on the fingerprint offset of the target power terminal.

19. An electronic device, characterized in that, include: At least one processor and memory; The memory and processor are connected via a bus; The memory is used to store one or more programs; When the one or more programs are executed by the at least one processor, the method as described in any one of claims 1 to 9 is implemented.

20. A readable storage medium, characterized in that, It contains an executable program, which, when executed, implements the method as described in any one of claims 1 to 9.