Application reinforcement method, apparatus, device, and medium

By decompressing, extracting index information, and generating binary files, the decompressed files are then replaced and integrated into a package, solving the problem of low loading efficiency in existing technologies and improving the efficiency of application hardening and hardware performance.

CN121209949BActive Publication Date: 2026-02-24SHENZHEN YEAHKA TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511755823.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-02-24
Estimated Expiration
2045-11-27

AI Technical Summary

Technical Problem

The application of hardening methods in existing technologies results in low loading efficiency and causes significant damage to hardware performance, thus affecting user experience.

Method used

By receiving reinforcement instructions, the application to be reinforced is decompressed, the target reinforcement information and index information are extracted, a binary file is generated, and the content of the decompressed file is replaced according to the replacement strategy. Finally, the application is integrated and packaged to obtain the target application.

Benefits of technology

It improves the loading efficiency of the hardened application, reduces hardware performance loss, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121209949B_ABST
    Figure CN121209949B_ABST
Patent Text Reader

Abstract

The application discloses an application reinforcement method, device, equipment and medium, and the method comprises the following steps: receiving an input reinforcement instruction, decompressing a to-be-reinforced application corresponding to the reinforcement instruction to obtain a decompressed file; extracting corresponding target reinforcement information from the decompressed file according to an extraction rule; extracting corresponding index information from the target reinforcement information; generating a binary file corresponding to the target reinforcement information according to a preset reinforcement strategy and the index information; and replacing the content of the decompressed file according to a replacement strategy, the index information and the target reinforcement information, obtaining a corresponding replacement file, integrating the binary file and the index file, and packing to obtain a corresponding target application. The application reinforcement method extracts index information, generates a binary file based on the extracted target reinforcement information, replaces the content of the decompressed file, and finally packs to obtain a target application, so that the loading efficiency of the reinforced application is greatly improved by processing the key information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to an application hardening method, apparatus, device, and medium. Background Technology

[0002] To prevent malicious attacks from affecting application stability during loading and execution, critical files within the application can be hardened. However, current hardening methods encrypt all critical files, requiring centralized decryption at startup. This leads to application loading delays and significant performance overhead on hardware, impacting user experience. Therefore, existing methods suffer from low loading efficiency during application hardening. Summary of the Invention

[0003] To overcome the shortcomings of existing technical solutions, embodiments of the present invention provide an application reinforcement method, apparatus, equipment and medium, aiming to solve the problem of low loading efficiency in the application reinforcement process of existing technical methods.

[0004] The technical solution adopted by this invention to solve its technical problem is:

[0005] In a first aspect, embodiments of the present invention provide an application reinforcement method, the method comprising:

[0006] Receive the input reinforcement command, and decompress the application to be reinforced corresponding to the reinforcement command to obtain the decompressed file;

[0007] The corresponding target reinforcement information is extracted from the decompressed file according to the preset extraction rules;

[0008] The corresponding index information is extracted from the target reinforcement information;

[0009] Generate a binary file corresponding to the target reinforcement information based on the preset reinforcement strategy and the index information;

[0010] The content of the decompressed file is replaced according to the preset replacement strategy, the index information, and the target reinforcement information to obtain the corresponding replacement file;

[0011] The replacement file, the binary file, and the decompressed file are integrated and packaged to obtain the corresponding target application.

[0012] Secondly, embodiments of the present invention provide an application reinforcement device, the device comprising:

[0013] The decompression unit is used to receive the input reinforcement command and decompress the application to be reinforced corresponding to the reinforcement command to obtain a decompressed file;

[0014] The first extraction unit is used to extract the corresponding target reinforcement information from the decompressed file according to the preset extraction rules;

[0015] The second extraction unit is used to extract the corresponding index information from the target reinforcement information;

[0016] The file generation unit is used to generate a binary file corresponding to the target reinforcement information according to the preset reinforcement strategy and the index information;

[0017] The content replacement unit is used to replace the content of the decompressed file according to the preset replacement strategy, the index information and the target reinforcement information, so as to obtain the corresponding replacement file;

[0018] The integration and packaging unit is used to integrate and package the replacement file, the binary file, and the decompressed file to obtain the corresponding target application.

[0019] Thirdly, embodiments of the present invention also provide a computer device, the device including a processor, a network interface, a memory and a communication bus, wherein the processor, the network interface and the memory communicate with each other through the communication bus;

[0020] Memory, used to store computer programs;

[0021] When a processor executes a program stored in memory, it implements the steps of any of the above-described application hardening methods.

[0022] Fourthly, embodiments of the present invention further provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the application hardening method described in any of the preceding claims.

[0023] This invention discloses an application hardening method, apparatus, device, and medium. The method includes: receiving an input hardening command; decompressing the application to be hardened corresponding to the hardening command to obtain a decompressed file; extracting corresponding target hardening information from the decompressed file according to extraction rules; extracting corresponding index information from the target hardening information; generating a binary file corresponding to the target hardening information according to a preset hardening strategy and index information; replacing the content of the decompressed file according to a replacement strategy, index information, and target hardening information to obtain a corresponding replacement file, and integrating and packaging it with the binary file and index file to obtain the corresponding target application. This application hardening method, by extracting index information and generating a binary file based on the extracted target hardening information, replacing the content of the decompressed file, and finally packaging it to obtain the target application, significantly improves the loading efficiency of the hardened application by extracting key information for application hardening. Attached Figure Description

[0024] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a flowchart of the application reinforcement method provided in the embodiments of the present invention;

[0026] Figure 2 This is a schematic block diagram of the application reinforcement device provided in the embodiments of the present invention;

[0027] Figure 3 This is a schematic block diagram of a computer device according to an embodiment of the present invention. Detailed Implementation

[0028] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] It should be understood that, when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0030] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0031] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0032] This invention application provides an application hardening method, which is applied to a terminal device. The terminal device executes a stored software program to implement the application hardening method. The terminal device can be a laptop, desktop computer, tablet computer, or mobile phone, or it can be a server terminal such as a cluster server or enterprise server.

[0033] like Figure 1 As shown, the method includes steps S110 to S160.

[0034] S110. Receive the input reinforcement command, and decompress the application to be reinforced corresponding to the reinforcement command to obtain a decompressed file.

[0035] Users can input reinforcement commands into the terminal device, which will then reinforce the application according to the received commands. The reinforcement command specifies the application's storage path and name, allowing the device to retrieve the application stored in the corresponding location on the device as the application to be reinforced. If the application to be reinforced is a packaged program, it can be decompressed to obtain compressed files, which include a folder and code files stored within that folder.

[0036] S120. Extract the corresponding target reinforcement information from the decompressed file according to the preset extraction rules.

[0037] The terminal device is pre-configured with multiple extraction rules, each corresponding to an application framework. The hardening instruction also includes basic application information such as the operating platform, application type, and application version. Extraction rules corresponding to the application framework matching this basic information can be obtained and used. Based on the extraction rules corresponding to the application to be hardened, the target hardening information is extracted from the decompressed file.

[0038] In a specific embodiment, step S120 includes the following sub-steps: extracting the class definitions of the core files in the decompressed files; filtering the classes contained in each core file according to the filtering conditions in the extraction rules and the class definitions to obtain candidate classes; obtaining the method bytecode of each candidate class; extracting the instructions in the method bytecode of the candidate classes and storing them (storing them to a DexCode object) to obtain the corresponding target hardening information.

[0039] The core files in the decompressed file can be obtained. For example, for an application running on the "Android" platform that needs to be hardened, its core file is usually a Dex file. All class definitions in the Dex file can be obtained from the decompressed file. The class definitions contain the metadata of each class.

[0040] The classes contained in the core file are further filtered based on the filtering conditions and class definitions in the extraction rules. If the class definition corresponding to a certain class meets the filtering conditions, the class is determined as a candidate class and retained; if the class definition corresponding to a certain class does not meet the filtering conditions, the class is excluded. Specifically, it can be determined whether the data identifier in the class definition corresponding to the class is zero. If the data identifier (such as class_data_off) is zero, the class is determined not to meet the filtering conditions; if the data identifier is not zero, the class is determined to meet the filtering conditions.

[0041] Further, the bytecode of the selected candidate classes is obtained. Each class contains direct methods and virtual methods. For each direct and virtual method, the method bytecode (CodeItem) can be extracted by calling the `extractMethod` method. The instructions in the bytecode of the candidate classes are then extracted and stored to obtain the corresponding target hardening information.

[0042] In a specific embodiment, the target hardening information includes a list of file objects and file objects. The step of extracting and storing the instructions from the method bytecode of the candidate classes to obtain the corresponding target hardening information includes: creating a file object corresponding to each core file in the decompressed file; obtaining the instructions from the method bytecode contained in the core file and storing them in the file object of the core file; obtaining the basic information of the file object and generating a corresponding file object list.

[0043] Specifically, the target hardening information includes a list of file objects and file objects themselves. The process of obtaining this information is as follows: First, a file object is created for each core file in the decompressed file (e.g., a DexCode object is created for each Dex core file). Each file object corresponds to one core file. Next, the instructions in the bytecode of the methods within the core files are obtained. Each method bytecode contains one or more instructions, so the instructions corresponding to each core file are retrieved and stored in the file object for that core file. A corresponding list of file objects is generated based on the basic information of the file objects. This list stores the basic information of each core file, including the filename, file size, number of methods, and number of instructions.

[0044] S130. Extract the corresponding index information from the target reinforcement information.

[0045] Furthermore, the corresponding index information is extracted from the target hardening information. The index information is the information used to record the relevant index content of the instructions in the target hardening information.

[0046] In a specific embodiment, step S130 includes the following sub-steps: obtaining the basic parameters of the core file from the configuration information of the decompressed file; obtaining the number of bytes occupied by the basic parameters and the corresponding configured file offset parameters; obtaining the starting position of the core file in the decompressed file and storing it in a preset position list; traversing the instructions in the target reinforcement information and obtaining traversal statistics to update the file offset parameters and the position list; after the traversal is completed, combining the obtained position list with the file offset parameters to obtain the corresponding index information.

[0047] The basic parameters of the core file are obtained from the configuration information in the unzipped file. The unzipped file contains configuration information for configuring the overall application program files. This configuration information can be information contained in an XML configuration file. The basic parameters of the core file include the application version number of the application to be hardened. Based on the number of bytes occupied by the basic parameters, combined with the configuration file offset parameters (such as fileOffset) corresponding to the preset number of files, the file offset parameters obtained in the initial configuration are set according to the application version number and the number of bytes corresponding to the preset number of files.

[0048] The system retrieves the starting positions of each core file within the decompressed file and stores these positions in a pre-defined location list (e.g., the `dexCodeIndex` list). It then iterates through the instructions contained in the target hardening information and obtains traversal statistics; based on these statistics, it updates the file offset parameters and the location list. Finally, it iterates through each instruction in the target hardening information to obtain its offset, method index, and instruction data size within the decrypted file; based on the application version number, the starting position of the core file, and the instruction's method index and data size, it updates the information stored in the location list to achieve this update.

[0049] The offset value is calculated based on the instruction's offset and method index, and then updated using this offset value and the number of core files counted during the current traversal. Specifically, the starting offset of the class definition corresponding to the method of the instruction and the offset of the method to which the instruction belongs can be obtained from the instruction's method index; the instruction's offset is also the offset of the instruction set pointing to the corresponding method; therefore, the instruction's offset value = starting offset + offset of the method to which the instruction belongs + ordinal number of the method to which the instruction belongs × 4 (each element occupies 4 bytes) + instruction's offset, which finally yields a hexadecimal value as the offset value, such as "0x157" for a certain instruction. That is, an offset value can be calculated for each instruction, and the file offset parameter is updated once based on the number of core files counted during the current traversal, so the file offset parameter includes the offset values ​​of each instruction.

[0050] After traversing the instructions in the target hardening information, the final updated position list can be combined with the file offset parameter to obtain the corresponding index information.

[0051] S140. Generate a binary file corresponding to the target reinforcement information according to the preset reinforcement strategy and the index information.

[0052] Furthermore, based on the reinforcement strategy and the obtained index information, a binary file corresponding to the target reinforcement information is generated, that is, the binary file is obtained by reinforcement processing the target reinforcement information.

[0053] In a specific embodiment, step S140 includes the following sub-steps: obtaining the file header from the file offset parameter of the index information and writing it into a preset initial file; obtaining the starting position of the core file from the position list of the index information and writing it into the initial file; obtaining the method information in the target reinforcement information according to the file object list in the target reinforcement information and writing it into the initial file one by one; obtaining the instructions in the file objects of the target reinforcement information and the instruction-related information in the index information and writing them into the initial file; encrypting the initial file according to the reinforcement strategy and the index information to obtain the corresponding binary file.

[0054] Specifically, the file header can be obtained from the file offset parameter of the index information and written to a pre-set initial file, which is an empty file. The application version number and the number of core files in the file offset parameter are combined and written as the file header to ensure that the data is written in little-endian order.

[0055] The starting positions of each core file are obtained from the location list in the index information and written sequentially to the initial file. Method information in the target hardening information is obtained from the file object list in the target hardening information. Specifically, the number of methods in each core file in the target hardening information is obtained as method information and written to the initial file one by one. Instructions in the file objects of the target hardening information are obtained and written to the initial file in combination with instruction-related information from the index information. Instruction-related information includes the method index, offset value, and instruction data size.

[0056] Based on the hardening strategy and index information, the initial file after data writing is encrypted to obtain the corresponding binary file.

[0057] In a specific embodiment, encrypting the initial file according to the hardening strategy and the index information to obtain the corresponding binary file includes: generating an encryption key corresponding to the index information according to the key generation rules in the hardening strategy; encrypting the initial file according to the encryption algorithm in the hardening strategy and the encryption key to obtain the corresponding encrypted file; and converting the encrypted file to a different number system to obtain the corresponding binary file.

[0058] Specifically, an encrypted key corresponding to the index information can be generated according to the key generation rules in the hardening strategy. The key generation rules include string combination templates, which can be used to combine information contained in the index information to obtain a combined string. For example, the offset values ​​of each instruction in the index information are obtained, and the remainder is calculated by taking the modulo of the offset value of the instruction based on the data size of the instruction in the index information. Each instruction can then have a corresponding remainder. The calculation process can be expressed as: Remainder = Instruction offset value % Instruction data size. The remainders of each instruction are accumulated to obtain the accumulated remainder value. Further, the version number, the starting position of each core file, and the accumulated remainder value in the index information are sequentially concatenated according to the string combination template to obtain the corresponding combined string.

[0059] The combined string is transformed according to the transformation function in the key generation rules to obtain the encryption key. The transformation function can be a hash function or an elliptic curve cryptography (ECC) function. The hash function performs a hash operation on the combined string to obtain a corresponding digest, which serves as the encryption key. For information of any length (in bits), the hash function (SHA256, Secure Hash Algorithm 256) will generate a 32-byte data set, which can be used as the encryption private key. Similarly, using the combined string as the public key, an elliptic curve cryptography function is used to generate a private key that matches the public key; this private key can then be used as the encryption private key.

[0060] When the combined string is fixed, the encryption key obtained through the conversion function will also be the same. If the values ​​in the combined string change, the encryption key obtained through the conversion function will also change accordingly. Therefore, during the decryption process of an encrypted file, if a string identical to the combined string used for encryption can be obtained, it indicates that the file content used in the decryption process is complete and unaltered. This means that the encrypted file can be successfully decrypted using the key corresponding to that string, yielding accurate decryption information. The initial file is encrypted using the encryption algorithm and encryption key in the hardening strategy to obtain the corresponding encrypted file. The encryption algorithm can be asymmetric encryption algorithms such as the SM2 national cryptographic algorithm or elliptic curve signature algorithm. Since the encryption process typically involves obtaining a hexadecimal encryption private key and converting the initial file to hexadecimal, the resulting encrypted file is a hexadecimal representation. This hexadecimal file information can then be converted to binary file information to obtain a binary file.

[0061] S150. The content of the decompressed file is replaced according to the preset replacement strategy, the index information and the target reinforcement information to obtain the corresponding replacement file.

[0062] The decompressed file is replaced with its contents based on the replacement strategy, index information, and target hardening information, resulting in a replaced file with the replaced contents.

[0063] In a specific embodiment, step S150 includes the following sub-steps: determining the content to be replaced in the decompressed file based on the target hardening information; generating a corresponding replacement sequence based on the replacement strategy and the index information; and sequentially replacing the content to be replaced in the decompressed file based on the index information and the replacement sequence to obtain a corresponding replacement file.

[0064] Specifically, based on the instructions contained in the target hardening information, the code content corresponding to the instructions in the core file of the decompressed file can be identified as the content to be replaced. Further, a corresponding replacement sequence is generated based on the replacement strategy and index information. The replacement strategy includes the replacement character, and the index information includes the data size of the instruction. The data size of the instruction and the replacement character generate a replacement sequence corresponding to the data size. For example, if the replacement character is "R", then the corresponding replacement sequence "RR…R" can be generated.

[0065] Based on the offset value and method index of the instruction in the index information, the content to be replaced in the core file is replaced with the corresponding replacement sequence. After replacing the content to be replaced in the decompressed file in turn, the corresponding replacement file can be obtained.

[0066] S160. Integrate and package the replacement file, the binary file, and the decompressed file to obtain the corresponding target application.

[0067] The replacement file, binary file, and decompressed file are integrated and packaged to obtain the corresponding target application. The binary file is written to a specific directory (such as the assets directory). The replacement file is merged with the shell file of the application to be hardened to obtain a merged file. The configuration information is updated based on the stored binary file and the merged file to obtain new configuration information. The configuration information, the merged file, and the stored binary file are integrated with other files in the decompressed file (excluding configuration information and core files), and the integrated file is compressed to obtain a compressed application package, which can be used as the target application.

[0068] If the target application can be transmitted over a network (e.g., the target application is available for download by the user), the terminal device receiving the target application can restore the target application and load and run the restored application file.

[0069] Specifically, the terminal device can decompress the target application according to the above method, extract the replacement information corresponding to the substitution sequence, extract the index information based on the replacement information, and generate an encryption key corresponding to the index information according to the same key generation rules as the above steps. If the target application file is received completely and is not tampered with during transmission, the same encryption key as in step S140 above can be obtained, thereby successfully decrypting the binary file and finally restoring the original application; if the application file is not received completely or the information is tampered with during transmission (such as changes in the offset value of the instruction, changes in the data size of the instruction, changes in the application version number, or changes in the order of core files that lead to changes in the starting position, the same encryption private key cannot be obtained, that is, the binary file cannot be successfully decrypted and the correct file content cannot be obtained.

[0070] During the restoration process of a target application, the terminal device can create separate child and parent processes. The child process performs security checks on the application restoration and execution (such as checking if Frida tools are running in memory) and uses ptrace to prevent debugging. Simultaneously, the parent process monitors the child process's running status to ensure its proper functioning and reliable security checks. If the child process exits abnormally, the parent process immediately terminates the application to prevent it from running in an insecure environment. This process separation increases debugging complexity and creates a dual protection mechanism, ensuring that even if an attacker bypasses the protection of one process, the other process can still detect and respond.

[0071] The detection of child processes specifically includes: (1) memory mapping detection (find_in_maps), by reading / proc / <pid>The / maps file checks whether Frida-related shared libraries (such as frida-agent) are loaded in the memory mapping of the current process; its function is to detect whether Frida tools are loaded in the process, and once found, it immediately triggers the application to crash. (2) Thread detection (find_in_threads_list) traverses all threads of the current process to check whether there are suspicious threads related to Frida (such as gmain, gdbus, etc.); its function is to detect whether Frida tools are hidden in the process through specific thread names. If multiple suspicious threads are detected, it is considered that there is a security threat and triggers the application to crash. (3) Detection thread (detectFridaOnThread): The detection logic runs continuously in an independent thread and checks periodically whether there are Frida-related shared libraries or threads; its function is to ensure that the application can detect and respond to the injection and debugging of Frida tools in a timely manner throughout the entire running process.

[0072] The application hardening method disclosed in the above embodiments includes: receiving an input hardening command; decompressing the application to be hardened corresponding to the hardening command to obtain a decompressed file; extracting corresponding target hardening information from the decompressed file according to extraction rules; extracting corresponding index information from the target hardening information; generating a binary file corresponding to the target hardening information according to a preset hardening strategy and index information; replacing the content of the decompressed file according to a replacement strategy, index information, and target hardening information to obtain a corresponding replacement file, and integrating and packaging it with the binary file and index file to obtain the corresponding target application. This application hardening method, by extracting index information and generating a binary file based on the extracted target hardening information, replacing the content of the decompressed file, and finally packaging it to obtain the target application, significantly improves the loading efficiency of the hardened application by extracting key information for application hardening.

[0073] This invention also provides an application hardening device, which can be configured in a terminal device and is used to perform any of the aforementioned application hardening methods. Specifically, please refer to... Figure 2 , Figure 2 This is a schematic block diagram of an application reinforcement device provided in an embodiment of the present invention.

[0074] like Figure 2 As shown, the application reinforcement device 100 includes a decompression unit 110, a first extraction unit 120, a second extraction unit 130, a file generation unit 140, a content replacement unit 150, and an integration and packaging unit 160.

[0075] The decompression unit 110 is used to receive the input reinforcement command and decompress the application to be reinforced corresponding to the reinforcement command to obtain a decompressed file.

[0076] The first extraction unit 120 is used to extract the corresponding target reinforcement information from the decompressed file according to the preset extraction rules.

[0077] The second extraction unit 130 is used to extract the corresponding index information from the target reinforcement information.

[0078] The file generation unit 140 is used to generate a binary file corresponding to the target reinforcement information according to the preset reinforcement strategy and the index information.

[0079] The content replacement unit 150 is used to replace the content of the decompressed file according to the preset replacement strategy, the index information and the target reinforcement information, so as to obtain the corresponding replacement file.

[0080] The integration and packaging unit 160 is used to integrate and package the replacement file, the binary file, and the decompressed file to obtain the corresponding target application.

[0081] The application hardening device provided in this embodiment of the invention applies the above-described application hardening method, receives an input hardening command, decompresses the application to be hardened corresponding to the hardening command to obtain a decompressed file; extracts the corresponding target hardening information from the decompressed file according to extraction rules; extracts the corresponding index information from the target hardening information; generates a binary file corresponding to the target hardening information according to a preset hardening strategy and index information; replaces the content of the decompressed file according to a replacement strategy, index information, and target hardening information to obtain a corresponding replacement file, and integrates and packages it with the binary file and index file to obtain the corresponding target application. The above-described application hardening method, by extracting index information and generating a binary file based on the extracted target hardening information, replacing the content of the decompressed file, and finally packaging it to obtain the target application, significantly improves the loading efficiency of the hardened application by extracting key information for application hardening.

[0082] The aforementioned application ruggedization device can be implemented in the form of a computer program, which can, for example... Figure 3 It runs on the computer device shown.

[0083] Please see Figure 3 , Figure 3 This is a schematic block diagram of a computer device provided in an embodiment of the present invention. The computer device can be a terminal device used to execute application hardening methods to perform application hardening processing.

[0084] See Figure 3 The computer device 500 includes a processor 502, a memory, and a network interface 505 connected via a communication bus 501. The memory may include a storage medium 503 and internal memory 504.

[0085] The storage medium 503 may store an operating system 5031 and a computer program 5032. When the computer program 5032 is executed, it causes the processor 502 to execute an application hardening method. The storage medium 503 may be a volatile storage medium or a non-volatile storage medium.

[0086] The processor 502 provides computing and control capabilities to support the operation of the entire computer device 500.

[0087] The internal memory 504 provides an environment for the execution of the computer program 5032 in the storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can execute the application hardening method.

[0088] This network interface 505 is used for network communication, such as providing data transmission. Those skilled in the art will understand that... Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the computer device 500 to which the present invention is applied. The specific computer device 500 may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0089] The processor 502 is used to run the computer program 5032 stored in the memory to implement the corresponding functions in the application hardening method described above.

[0090] Those skilled in the art will understand that Figure 3 The embodiments of the computer device shown do not constitute a limitation on the specific configuration of the computer device. In other embodiments, the computer device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. For example, in some embodiments, the computer device may include only memory and a processor. In such embodiments, the structure and function of the memory and processor are different from those shown. Figure 3 The embodiments shown are consistent and will not be repeated here.

[0091] It should be understood that, in this embodiment of the invention, the processor 502 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.

[0092] In another embodiment of the invention, a computer-readable storage medium is provided. This computer-readable storage medium may be volatile or non-volatile. The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps included in the application hardening method described above.

[0093] Those skilled in the art will readily understand that, for the sake of convenience and brevity, the specific working processes of the devices, apparatuses, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention.

[0094] In the embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. Units with the same function may be grouped into one unit. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, or it may be an electrical, mechanical, or other form of connection.

[0095] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of the present invention, depending on actual needs.

[0096] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0097] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a computer-readable storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned computer-readable storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks.

[0098] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.< / pid>

Claims

1. An application reinforcement method, characterized in that, The method includes: Receive the input reinforcement command, and decompress the application to be reinforced corresponding to the reinforcement command to obtain the decompressed file; The corresponding target reinforcement information is extracted from the decompressed file according to the preset extraction rules; The corresponding index information is extracted from the target reinforcement information; Generate a binary file corresponding to the target reinforcement information based on the preset reinforcement strategy and the index information; The content of the decompressed file is replaced according to the preset replacement strategy, the index information, and the target reinforcement information to obtain the corresponding replacement file; The replacement file, the binary file, and the decompressed file are integrated and packaged to obtain the corresponding target application; The step of extracting the corresponding index information from the target reinforcement information includes: Obtain the basic parameters of the core file from the configuration information of the decompressed file; Obtain the number of bytes occupied by the basic parameters and the corresponding configured file offset parameters; Obtain the starting position of the core file in the decompressed file and store it in a preset position list; The instructions in the target reinforcement information are traversed and the traversal statistics are obtained to update the file offset parameters and the position list; After the traversal is complete, the obtained position list is combined with the file offset parameter to obtain the corresponding index information; The step of generating a binary file corresponding to the target reinforcement information based on the preset reinforcement strategy and the index information includes: The file header is obtained from the file offset parameter of the index information and written to the preset initial file; The starting position of the core file is obtained from the position list of the index information and written into the initial file; The method information in the target hardening information is obtained from the file object list in the target hardening information and written to the initial file one by one; The instructions in the file object containing the target hardening information and the instruction-related information in the index information are written to the initial file; The initial file is encrypted according to the hardening strategy and the index information to obtain the corresponding binary file.

2. The reinforcement method according to claim 1, characterized in that, The step of extracting the corresponding target hardening information from the decompressed file according to preset extraction rules includes: Extract the class definitions of the core files from the decompressed files; The classes contained in each of the core files are filtered according to the filtering conditions in the extraction rules and the class definitions to obtain candidate classes; Obtain the method bytecode for each of the candidate classes; The instructions in the bytecode of the methods of the candidate classes are extracted and stored to obtain the corresponding target hardening information.

3. The reinforcement method according to claim 2, characterized in that, The target hardening information includes a list of file objects and file objects. Extracting and storing the instructions from the bytecode of the methods for the candidate classes to obtain the corresponding target hardening information includes: Create a file object corresponding to each core file in the decompressed file; Obtain the instructions from the method bytecode contained in the core file and store them accordingly into the file object of the core file; Obtain the basic information of the file object and generate a corresponding list of file objects.

4. The reinforcement method according to claim 1, characterized in that, The step of encrypting the initial file according to the hardening strategy and the index information to obtain the corresponding binary file includes: Generate an encryption key corresponding to the index information according to the key generation rules in the hardening strategy; The initial file is encrypted using the encryption algorithm and encryption key in the hardening strategy to obtain the corresponding encrypted file; The encrypted file is converted to its base to obtain the corresponding binary file.

5. The reinforcement method according to claim 1, characterized in that, The step of replacing the content of the decompressed file according to the preset replacement strategy, the index information, and the target hardening information to obtain the corresponding replacement file includes: The content to be replaced in the decompressed file is determined based on the target reinforcement information; Generate a corresponding replacement sequence based on the replacement strategy and the index information; The contents to be replaced in the decompressed file are replaced sequentially according to the index information and the replacement sequence to obtain the corresponding replacement file.

6. An application reinforcement device, characterized in that, The apparatus is used to perform the application hardening method as described in any one of claims 1-5, the apparatus comprising: The decompression unit is used to receive the input reinforcement command and decompress the application to be reinforced corresponding to the reinforcement command to obtain a decompressed file; The first extraction unit is used to extract the corresponding target reinforcement information from the decompressed file according to the preset extraction rules; The second extraction unit is used to extract the corresponding index information from the target reinforcement information; The file generation unit is used to generate a binary file corresponding to the target reinforcement information according to the preset reinforcement strategy and the index information; The content replacement unit is used to replace the content of the decompressed file according to the preset replacement strategy, the index information and the target reinforcement information, so as to obtain the corresponding replacement file; The integration and packaging unit is used to integrate and package the replacement file, the binary file, and the decompressed file to obtain the corresponding target application.

7. A computer device, characterized in that, The device includes a processor, a network interface, a memory, and a communication bus, wherein the processor, network interface, and memory communicate with each other through the communication bus; Memory, used to store computer programs; When a processor executes a program stored in memory, it implements the steps of the application hardening method according to any one of claims 1-5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the application hardening method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Method and device for security reinforcement of mobile application program

    CN107977553A