Data decryption method and device, electronic equipment, storage medium and program product

By injecting a detection program into the host program to detect the data migration task status and obtain decryption information, the problem of difficult data extraction from mobile devices is solved, and plaintext data display on the target client is realized.

CN122020685APending Publication Date: 2026-05-12SUZHOU LONGXIN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUZHOU LONGXIN INFORMATION TECH CO LTD
Filing Date
2026-01-21
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In existing technologies, data extraction from mobile devices is difficult, especially when there is insufficient device space or no backup tools. The inability to obtain backup keys on the computer means that the data can only be viewed in software and cannot be extracted in plaintext.

Method used

By injecting a detection program into the host program, the status of the data migration task is detected, and the decryption information is obtained after the task is successful. The decryption information is used to decrypt the encrypted data, so as to realize the plaintext display of the data from the mobile terminal to the target client.

Benefits of technology

It successfully retrieves decryption information from the target client, decrypts encrypted data into plaintext, and ensures the visual display of mobile data on the computer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122020685A_ABST
    Figure CN122020685A_ABST
Patent Text Reader

Abstract

The invention discloses a data decryption method and device, electronic equipment, a storage medium and a program product. A specific embodiment comprises: determining a host program; detecting a task state through a detection program; under the condition that the task state indicates that the data migration task is successfully migrated, determining decryption information corresponding to the host program; and obtaining decrypted data based on the decrypted information and the encrypted data. By injecting the detection program into the host program, the task state of the data migration task is detected, the decryption information is obtained from the target client, the encrypted data is decrypted through the decryption information, and the encrypted data in a ciphertext form is decrypted into the decrypted data in a plaintext form. And the data migrated to the target client by the mobile terminal is ensured to be displayed in a plaintext form.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a data decryption method, apparatus, electronic device, storage medium, and program product. Background Technology

[0002] When data extraction is required from software, the preferred methods for extracting data from mobile devices are currently the operating system's built-in tools such as "backup and restore," "cloning," and "migrating." Alternatively, screen recording of the data generated by the mobile device can be used, but this method is time-consuming and labor-intensive, and it is difficult to extract rich text messages such as voice and video.

[0003] If you encounter situations where device storage is insufficient or there are no backup tools available, you would typically consider the backup function on the corresponding computer version of the software. This backup function allows you to back up data generated when using the software on a mobile device to your computer. However, a backup key is required during the extraction process. This key is used to decrypt the backed-up data for direct viewing. But the backup key is only stored on the server or mobile device and cannot be obtained on the computer. This means that data extracted on the computer can only be viewed within the software and cannot be viewed in plaintext. Summary of the Invention

[0004] This invention provides a data decryption method, apparatus, electronic device, storage medium, and program product to complete data migration on mobile devices and realize data extraction and decryption on computers.

[0005] According to one aspect of the present invention, a data decryption method is provided, applied to a target client, the method comprising: The host program is determined, including the program corresponding to the target client; The task status is detected by a detection program. The task status includes the status of a data migration task, which includes a task of migrating target data generated during mobile terminal runtime to encrypted data in the target client. The mobile terminal is connected to the target client. If the task status indicates that the data migration task has been successfully completed, the decryption information corresponding to the host program is determined, and the decryption information includes information generated during the execution of the host program. Based on the decryption information and the encrypted data, the decrypted data is obtained.

[0006] According to another aspect of the present invention, a data decryption apparatus is provided, configured on a target client, comprising: The first determining module is used to determine the host program, wherein the host program includes the program corresponding to the target client; The detection module is used to detect the task status through a detection program. The task status includes the status of a data migration task, which includes a task of migrating target data generated during mobile terminal runtime to encrypted data in the target client. The mobile terminal is connected to the target client. The second determining module is used to determine the decryption information corresponding to the host program when the task status indicates that the data migration task has been successfully migrated. The decryption information includes information generated during the operation of the host program. The decryption module is used to obtain decrypted data based on the decryption information and the encrypted data.

[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data decryption method according to any embodiment of the present invention.

[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the data decryption method according to any embodiment of the present invention.

[0009] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the data decryption method described in any embodiment of the present invention.

[0010] The technical solution of this invention involves determining a host program; detecting the task status through a detection program; determining the decryption information corresponding to the host program when the task status indicates that the data migration task has been successfully completed; and obtaining decrypted data based on the decryption information and the encrypted data. By injecting a detection program into the host program, the task status of the data migration task is detected, enabling the acquisition of decryption information on the target client, the decryption of encrypted data using the decryption information, and the conversion of ciphertext encrypted data into plaintext decrypted data, ensuring that the data migrated from the mobile device to the target client is displayed in plaintext.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart of a data decryption method provided in Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of a detection procedure provided according to Embodiment 1 of the present invention; Figure 3 This is a schematic diagram of a data file provided according to Embodiment 1 of the present invention; Figure 4 This is a flowchart of a task status detection method provided in Embodiment 2 of the present invention; Figure 5 This is a schematic diagram of the structure of a data decryption device according to Embodiment 3 of the present invention; Figure 6 This is a block diagram of an electronic device provided according to Embodiment 4 of the present invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Example 1 Figure 1 This is a flowchart of a data decryption method according to Embodiment 1 of the present invention. This embodiment is applicable to the decryption of data. The method can be executed by a data decryption device, which can be implemented in hardware and / or software. The data decryption device can be configured in an electronic device, on which a target client can run. Figure 1 As shown, the method includes: S110. Determine the host program.

[0017] The host program includes the program corresponding to the target client.

[0018] In this embodiment, the host program can be understood as the program corresponding to the target client. By running the host program, the target client can be executed. The target client can be understood as a client installed on a computer; the target client is software that can run on a computer.

[0019] Specifically, the host program corresponding to the target client is obtained from the server corresponding to the target client. This can be done by determining the version number of the target client and identifying the host program that matches the version number of the target client from at least one program stored on the server, for example, obtaining the latest version of the host program stored on the server. Then, the host program is initialized, for example, by decompressing the compressed package containing the host program and putting the host program into running mode.

[0020] S120. Detect the task status through the detection program.

[0021] The task status includes the status of the data migration task, which includes the task of migrating target data generated during mobile terminal runtime to encrypted data in the target client, wherein the mobile terminal is connected to the target client.

[0022] In this embodiment, the detection program can be understood as a program used to detect the data migration task. The detection program can be injected into the host program to intercept or allow the execution of the host program. The detection program can output information acquired during the execution of the data migration task. The data migration task can be understood as a task of migrating target data generated by the mobile terminal to encrypted data in the target client. The execution of the data migration task requires that the target client and the mobile terminal are the same software and are in a connected state. The target data can be understood as the data generated when the user uses the mobile terminal, and the encrypted data can be understood as the data obtained after migrating the data from the mobile terminal to the target client; the encrypted data is data in encrypted ciphertext form.

[0023] Specifically, when it's necessary to migrate target data generated during mobile device usage to the target client, a data migration task needs to be executed. Before executing the data migration task, the mobile device and the target client are connected, ensuring they are on the same network. Then, the detection program is injected into the host program, and it is ensured to run correctly within the host program. During the execution of the data migration task, the task status is determined by monitoring the execution status of various functions within the detection program.

[0024] For example, connecting the mobile device and the target client to the same network allows them to log in to the same account. For instance, the mobile device can scan the QR code required for login on the target client, ensuring that the mobile device and the target client are logging into the same account.

[0025] S130. If the task status indicates that the data migration task has been successfully migrated, determine the decryption information corresponding to the host program.

[0026] The decrypted information includes information generated during the execution of the host program.

[0027] In this embodiment, the decryption information can be understood as information obtained during the execution of the data migration task. The decryption information may include information about the accounts corresponding to the mobile terminal and the target client, as well as information used to decrypt encrypted data.

[0028] Specifically, during the data migration task, if the task status indicates successful migration, it means the target data generated by the mobile device has been successfully migrated to the target client's encrypted data. At this point, the decryption information used to decrypt the target client's encrypted data can be exported using functions included in the detection program. Finally, after the task status indicates successful migration, the detection program is uninstalled from the host program.

[0029] S140. Based on the decryption information and the encrypted data, decrypted data is obtained.

[0030] In this embodiment, decrypted data can be understood as data obtained after decrypting encrypted data; decrypted data is data in plaintext form after decryption.

[0031] Specifically, the encrypted data is retrieved from the database based on the basic information contained in the decrypted information. This basic information can be understood as the account information corresponding to the target client. The encrypted data is then decrypted using the database password, and the decrypted data is filtered and analyzed to obtain the decrypted data. The database password, which can be understood as the information used to decrypt the encrypted data, can be set by functions included in the host program. Finally, the host program and installation package corresponding to the target client are cleaned up.

[0032] For example, since the host program is connected to the network during the data migration task, new data may be downloaded from the network environment to the target client. Therefore, it is necessary to remove this non-migrated data. Based on the basic information contained in the decrypted information, the database containing the encrypted data is located. After decrypting the encrypted data using the database password, the mobile migration data is extracted from the database using fields related to the data source. The extracted data is then parsed, where create_time is the time, message_content is the content, local_type is the data type, and real_sender_id is used to distinguish between sending and receiving. Based on the parsed content, the data is filtered to obtain the decrypted data.

[0033] The technical solution of this invention involves determining a host program; detecting the task status through a detection program; determining the decryption information corresponding to the host program when the task status indicates that the data migration task has been successfully completed; and obtaining decrypted data based on the decryption information and the encrypted data. By injecting a detection program into the host program, the task status of the data migration task is detected, enabling the acquisition of decryption information on the target client, the decryption of encrypted data using the decryption information, and the conversion of ciphertext encrypted data into plaintext decrypted data, ensuring that the data migrated from the mobile device to the target client is displayed in plaintext.

[0034] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.

[0035] In one embodiment, the detection program includes a jump function corresponding to a task function, the task function including an information initialization function, a password determination function, and a migration function, the jump function corresponding to the password determination function being a function used by the host program to set a database password related to the encrypted data, and determining the decryption information corresponding to the host program including: When the task status is "initialization complete", obtain the basic information corresponding to the target client recorded by the jump function corresponding to the information initialization function; When the task status is "password acquisition complete", the database password is determined based on the input parameters of the jump function corresponding to the password determination function. If the task status indicates that the data migration task has been successfully completed, the basic information and the database password are used as the decryption information corresponding to the host program through the jump function corresponding to the migration function.

[0036] In this embodiment, task functions can be understood as functions contained in the host program, specifically functions required during the data migration task. Task functions include an information initialization function, a password determination function, and a migration function. A jump-board function can be understood as a function with the same functionality as the task functions; it is a function contained in the detection program. The jump-board function corresponding to the information initialization function can be used to obtain information about the target client's account, i.e., the basic information contained in the decrypted information. The jump-board function corresponding to the password determination function can be understood as a function used to set the database password related to the encrypted data. The jump-board function corresponding to the migration function can be used to determine whether the data migration task's status is "migration successful."

[0037] Specifically, before executing the data migration task, a jump function with the same functionality as the task function is set up in the detection program. Therefore, when the host program calls the task function, it can jump to the jump function. After implementing the jump function, the information corresponding to the jump function can be determined, and the task status of the data migration task can be updated. When executing the data migration task, firstly, the information initialization function included in the task function is called, which jumps to the corresponding jump function. The jump function records the basic information of the target client and updates the task status to "initialization complete." Next, the password determination function included in the task function is called, which jumps to the corresponding jump function. The jump function records the database password and updates the task status to "password retrieval complete." The database password is determined by the input parameter of the jump function corresponding to the password determination function. Then, the migration function included in the task function is called, which jumps to the corresponding jump function. The jump function records the task status as "migration successful" and determines the basic information and database password as the decryption information corresponding to the host program.

[0038] For example, Figure 2 This is a schematic diagram of a detection procedure provided according to Embodiment 1 of the present invention. Figure 2As shown, the core dynamic link library in the host program contains the information initialization function `globalcfg`, the password determination function `sqlite3_key`, and the migration function `loc_migrate_suc`. In the detection program, jump functions with the same functionality as the task functions are set up. These jump functions include: the jump function `globalcfg_hook` corresponding to the information initialization function, the jump function `sqlite3_key_hook` corresponding to the password determination function, and the jump function `loc_migrate_suc_hook` corresponding to the migration function.

[0039] In one embodiment, obtaining decrypted data based on the decryption information and the encrypted data includes: Determine the data directory corresponding to the host program, wherein the data directory indicates the storage location of the host program; Based on the basic information contained in the data directory and the decryption information, the target file containing the encrypted data is located in the data contained in the host program. The target file includes at least one page of target encrypted data. For each page of target encrypted data, the target encrypted data is decrypted according to the database password contained in the decryption information to obtain the target decrypted data; By combining the target encrypted data and the target decrypted data corresponding to each of the target encrypted data, the decrypted data is obtained.

[0040] In this embodiment, the data directory can be understood as a directory indicating the storage location of the host program, and the data directory can be obtained from the database corresponding to the host program. The target file can be understood as the file containing the encrypted data, and the target file can consist of at least one page of target encrypted data. The target encrypted data can be understood as one page of encrypted data in the target file. The target decrypted data can be understood as the data obtained after decrypting the target encrypted data.

[0041] Specifically, the data directory is traversed based on the basic information contained in the decryption information to determine the target file containing the encrypted data. At least one page of target encrypted data is read from the target file, byte by byte, and the page number of each page is determined. For each page of target encrypted data, the target encrypted data is decrypted using the database password contained in the decryption information to obtain the target decrypted data. Finally, based on the page numbers corresponding to the target encrypted data, the target decrypted data is combined sequentially to obtain the decrypted data.

[0042] For example, the target file may include a data file and a log file. Each page of the target encrypted data is read in units of the set bytes DEFAULT_PAGESIZE (4096), and the page number is recorded as pageno. When pageno = 1 in the data file, the file signature of the target file is determined. Based on the page number corresponding to the target encrypted data, when combining the target decrypted data sequentially, a unit space of the set bytes DEFAULT_SIZE (4096) is allocated. When pageno = 1, the file signature of the target file and the target decrypted data data are written sequentially into the unit space; for other pagenos, the target decrypted data data is directly written into the corresponding unit space. Combining the target decrypted data in each unit space yields the decrypted data.

[0043] Optionally, the step of decrypting the target encrypted data based on the database password contained in the decryption information to obtain the target decrypted data includes: Based on the database password contained in the decryption information, generate a decryption key and a verification key; Using the verification key as a parameter, a first hash authentication code is formed by the target encrypted data and the page number corresponding to the target encrypted data; Determine the second hash authentication code contained in the page containing the target encrypted data; If the first hash authentication code and the second hash authentication code are consistent, the target encrypted data is decrypted using the decryption key and the decryption vector contained in the page containing the target encrypted data as parameters to obtain the target decrypted data.

[0044] In this embodiment, the decryption key can be understood as a security key generated based on the database password. The verification key can be understood as a security key generated based on the decryption key. The first hash authentication code can be understood as an authentication code generated from the target encrypted data and the page number, used to identify the page number of the target encrypted data. The second hash authentication code can be understood as the authentication code contained in the page containing the target encrypted data. The decryption vector can be understood as a vector contained in the page containing the target encrypted data, used to decrypt the target encrypted data.

[0045] For example, based on the data file contained in the target file, a decryption key (key) and a verification key (mac_key) are generated according to the database password contained in the decryption information. Figure 3 This is a schematic diagram of a data file provided according to Embodiment 1 of the present invention. Figure 3As shown, for the data files contained in the target file, the read position of the target encrypted data on each page is denoted as offset (16 when page number is 1, 0 for other pages), and the reserved space size is 80 bytes. Using the verification key mac_key and EVP_sha512() as parameters, a first hash authentication code hash_mac_tmp is generated from the target encrypted data edata of size DEFAULTT_SIZE and the page number pageno of the page containing the target encrypted data. This hash_mac_tmp is compared with the second hash authentication code hash_mac in the page containing the target encrypted data. If the first and second hash authentication codes match, the target encrypted data is decrypted using the decryption key key and the decryption vector IV contained in the page containing the target encrypted data, through the aes_256_cbc algorithm, to obtain the target decrypted data. For the log files contained in the target file, each page of target encrypted data is denoted as Frame. Combined with the page number page_no, the decryption key key, and the verification key mac_key, the data is decrypted using the same method as the data files described above, and the decrypted target data is recorded as page.

[0046] Optionally, generating a decryption key and a verification key based on the database password contained in the decryption information includes: Determine the encryption parameters, which include the parameters corresponding to the target file; Perform an XOR operation on the encryption parameters to obtain the XOR encryption parameters; A decryption key is generated using the database password contained in the decryption information and the encryption parameters as parameters; A verification key is generated using the decryption key and the XOR encryption parameters.

[0047] In this embodiment, encryption parameters can be understood as parameters stored in the data files contained in the target file, and these encryption parameters can be stored on the first page of the data file containing the target encrypted data. XOR encryption parameters can be understood as parameters obtained by performing an XOR operation on the encryption parameters.

[0048] For example, such as Figure 3As shown, in the data file contained in the target file, when pageno=1, offset bytes (16 bytes) are read from the beginning as the encryption parameter salt. An XOR operation is performed on the encryption parameter salt, and the result is denoted as the XOR encryption parameter mac_salt. Using the database password, encryption parameter salt, iteration count 256000, and sha512() hash parameter contained in the decryption information as parameters, a security key is generated using the PKCS5_PBKDF2_HMAC function, denoted as the decryption key key. Using the decryption key key, XOR encryption parameter mac_salt, iteration count 2, and sha512() hash parameter as parameters, a security key is generated again using the PKCS5_PBKDF2_HMAC function, denoted as the verification key mac_key.

[0049] Example 2 Figure 4 This is a flowchart of a task status detection method according to Embodiment 2 of the present invention. This embodiment focuses on the task status detection described in the above embodiment. Figure 4 As shown, the method includes: S210. Determine the host program.

[0050] S220. Determine the program identifier corresponding to the host program.

[0051] The program identifier includes the unique identifier of the host program.

[0052] In this embodiment, the program identifier can be understood as a unique non-negative integer identifier used to identify the host program, and the program identifier can indicate the location where the detection program is injected into the host program.

[0053] Specifically, a computer can assign a unique non-negative integer identifier to each running process. Based on the host program's process name and command-line arguments, the identifier of the host program corresponding to the target client is determined and used as the program identifier.

[0054] S230. Inject a detection program at the location indicated by the program identifier, so that the detection program runs in the host program and detects the task status through the detection program.

[0055] Specifically, at the location indicated by the program identifier, a remote injection method is used to attach the detection program to the host program for execution. During the data migration task, the detection program monitors the task status.

[0056] Optionally, detecting the task status through the detection program includes: Identify the task functions related to the data migration task, and the function offset addresses of the task functions, wherein the function offset addresses indicate the position of the task functions in the host program; Determine the actual running address corresponding to the function offset address, and set the jump function corresponding to the task function at the position indicated by the actual running address. The actual running address indicates the position of the jump function in the detection program, and the task function and the jump function have the same function. During the execution of the data migration task, the execution status of the jumper function in the detection program is obtained; The execution status is determined as the task status of the data migration task.

[0057] In this embodiment, the function offset address can be understood as the location of the task function within the host program. The actual execution address can be understood as the location of the jump function within the detection program.

[0058] For example, such as Figure 3 As shown, the task functions related to the data migration task are determined, including an information initialization function, a password determination function, and a migration function. The function offset addresses of each task function are determined. The actual execution address corresponding to the function offset address is determined, and the corresponding jumper function is set at the location indicated by the actual execution address. For example, for the information initialization function `globalcfg`, the actual execution address in the detection program is calculated based on the function offset address of `globalcfg` in the host program, and the jumper function `globalcfg_hook` for `globalcfg` is set at the location indicated by the actual execution address. During the execution of the data migration task, the jumper functions corresponding to the information initialization function, password determination function, and migration function are implemented sequentially, and the execution status of the jumper functions in the detection program is obtained. Finally, the execution status is determined as the task status of the data migration task.

[0059] S240. If the task status indicates that the data migration task has been successfully migrated, determine the decryption information corresponding to the host program.

[0060] S250. Based on the decryption information and the encrypted data, the decrypted data is obtained.

[0061] The technical solution of this invention involves determining the program identifier corresponding to the host program; injecting a detection program at the location indicated by the program identifier, causing the detection program to run in the host program, and detecting the task status through the detection program. By injecting the detection program into the host program using the program identifier corresponding to the host program, the task status of the data migration task is detected. If the data migration task is successful, decryption information is obtained on the target client, and the decryption information is output.

[0062] Example 3 Figure 5 This is a schematic diagram of a data decryption device according to Embodiment 3 of the present invention. Figure 5 As shown, the device includes: The first determining module 310 is used to determine the host program, wherein the host program includes the program corresponding to the target client; Detection module 320 is used to detect the task status through a detection program. The task status includes the status of a data migration task, which includes a task of migrating target data generated during mobile terminal runtime to encrypted data in the target client. The mobile terminal is connected to the target client. The second determining module 330 is used to determine the decryption information corresponding to the host program when the task status indicates that the data migration task has been successfully migrated. The decryption information includes information generated during the operation of the host program. The decryption module 340 is used to obtain decrypted data based on the decryption information and the encrypted data.

[0063] The data decryption device provided in this embodiment of the invention determines the host program through a first determining module; detects the task status through a detection module using a detection program; determines the decryption information corresponding to the host program through a second determining module when the task status indicates that the data migration task has been successfully migrated; and obtains decrypted data based on the decryption information and the encrypted data through a decryption module. Through the cooperation of these modules, a detection program is injected into the host program, completing the detection of the task status of the data migration task. This enables the acquisition of decryption information on the target client, the decryption of encrypted data using the decryption information, and the conversion of ciphertext encrypted data into plaintext decrypted data, ensuring that data migrated from the mobile device to the target client is displayed in plaintext.

[0064] In one embodiment, the detection module 320 includes: The first determining unit is used to determine the program identifier corresponding to the host program, wherein the program identifier includes the unique identifier of the host program; The detection unit is used to inject a detection program at the location indicated by the program identifier, so that the detection program runs in the host program and detects the task status through the detection program.

[0065] In one embodiment, the detection unit is specifically used for: Identify the task functions related to the data migration task, and the function offset addresses of the task functions, wherein the function offset addresses indicate the position of the task functions in the host program; Determine the actual running address corresponding to the function offset address, and set the jump function corresponding to the task function at the position indicated by the actual running address. The actual running address indicates the position of the jump function in the detection program, and the task function and the jump function have the same function. During the execution of the data migration task, the execution status of the jumper function in the detection program is obtained; The execution status is determined as the task status of the data migration task.

[0066] In one embodiment, the detection program includes a jump function corresponding to a task function, the task function including an information initialization function, a password determination function, and a migration function, and the jump function corresponding to the password determination function is a function used by the host program to set a database password related to the encrypted data. The second determination module 330 is specifically used for: When the task status is "initialization complete", obtain the basic information corresponding to the target client recorded by the jump function corresponding to the information initialization function; When the task status is "password acquisition complete", the database password is determined based on the input parameters of the jump function corresponding to the password determination function. If the task status indicates that the data migration task has been successfully completed, the basic information and the database password are used as the decryption information corresponding to the host program through the jump function corresponding to the migration function.

[0067] In one embodiment, the decryption module 340 includes: The second determining unit is used to determine the data directory corresponding to the host program, wherein the data directory indicates the storage location of the host program; The search unit is used to search for the target file containing the encrypted data in the data contained in the host program based on the basic information contained in the data directory and the decryption information, wherein the target file includes at least one page of target encrypted data; The decryption unit is used to decrypt the target encrypted data for each page according to the database password contained in the decryption information, so as to obtain the target decrypted data. The combination unit is used to combine the target encrypted data and the target decryption data corresponding to each of the target encrypted data to obtain decrypted data.

[0068] In one embodiment, the decryption unit includes: A generation subunit is used to generate a decryption key and a verification key based on the database password contained in the decryption information; The first determining subunit is used to determine the first hash authentication code formed by the target encrypted data and the page number corresponding to the target encrypted data, using the verification key as a parameter; The second determining subunit is used to determine the second hash authentication code contained in the page containing the target encrypted data; The decryption subunit is used to decrypt the target encrypted data by using the decryption key and the decryption vector contained in the page containing the target encrypted data as parameters, when the first hash authentication code and the second hash authentication code are consistent, to obtain the target decrypted data.

[0069] In one embodiment, generating sub-units is specifically used for: Determine the encryption parameters, which include the parameters corresponding to the target file; Perform an XOR operation on the encryption parameters to obtain the XOR encryption parameters; A decryption key is generated using the database password contained in the decryption information and the encryption parameters as parameters; A verification key is generated using the decryption key and the XOR encryption parameters.

[0070] The data decryption device provided in this embodiment of the invention can execute the data decryption method provided in any embodiment of the invention. Through the cooperation and coordination between the modules, the data decryption is completed, and it has the corresponding functional modules and beneficial effects of the execution method.

[0071] Example 4 According to embodiments of the present invention, the present invention also provides an electronic device, a computer-readable storage medium, and a computer program product.

[0072] Figure 6This is a block diagram of an electronic device according to Embodiment 4 of the present invention, which implements the data decryption method described in the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0073] like Figure 6 As shown, the electronic device 410 includes at least one processor 411 and a memory, such as a read-only memory (ROM) 412 or a random access memory (RAM) 413, communicatively connected to the at least one processor 411. The memory stores computer programs executable by the at least one processor. The processor 411 can perform various appropriate actions and processes based on the computer program stored in the ROM 412 or loaded from storage unit 418 into the RAM 413. The RAM 413 may also store various programs and data required for the operation of the electronic device 410. The processor 411, ROM 412, and RAM 413 are interconnected via a bus 414. An input / output (I / O) interface 415 is also connected to the bus 414.

[0074] Multiple components in the electronic device are connected to the I / O interface 415, including: an input unit 416, such as a keyboard, mouse, etc.; an output unit 417, such as various types of displays, speakers, etc.; a storage unit 418, such as a disk, optical disk, etc.; and a communication unit 419, such as a network card, modem, wireless transceiver, etc. The communication unit 419 allows the electronic device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0075] Processor 411 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 411 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 411 performs the various methods and processes described above, such as data decryption methods.

[0076] In some embodiments, the data decryption method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 418. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 410 via ROM 412 and / or communication unit 419. When the computer program is loaded into RAM 413 and executed by processor 411, one or more steps of the data decryption method described above may be performed. Alternatively, in other embodiments, processor 411 may be configured to perform the data decryption method by any other suitable means (e.g., by means of firmware).

[0077] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0078] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0079] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0080] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0081] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0082] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0083] In some embodiments, the computer program product includes a computer program that, when executed by a processor, implements the data decryption method provided in the embodiments of the present invention.

[0084] The technical solution of this invention provides a data decryption method, apparatus, electronic device, storage medium, and program product. It involves: determining a host program; detecting the task status through a detection program; determining the decryption information corresponding to the host program if the task status indicates successful data migration; and obtaining decrypted data based on the decryption information and the encrypted data. By injecting a detection program into the host program, the task status of the data migration task is detected, enabling the acquisition of decryption information on the target client, the decryption of encrypted data using the decryption information, and the conversion of ciphertext encrypted data into plaintext decrypted data, ensuring that data migrated from the mobile device to the target client is displayed in plaintext.

[0085] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0086] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A data decryption method, characterized in that, Applied to the target client, the method includes: The host program is determined, including the program corresponding to the target client; The task status is detected by a detection program. The task status includes the status of a data migration task, which includes a task of migrating target data generated during mobile terminal runtime to encrypted data in the target client. The mobile terminal is connected to the target client. If the task status indicates that the data migration task has been successfully completed, the decryption information corresponding to the host program is determined, and the decryption information includes information generated during the execution of the host program. Based on the decryption information and the encrypted data, the decrypted data is obtained.

2. The method according to claim 1, characterized in that, The process of detecting task status through a detection program includes: Determine the program identifier corresponding to the host program, wherein the program identifier includes the unique identifier of the host program; A detection program is injected at the location indicated by the program identifier, causing the detection program to run in the host program and detect the task status.

3. The method according to claim 2, characterized in that, The step of detecting the task status through the detection program includes: Identify the task functions related to the data migration task, and the function offset addresses of the task functions, wherein the function offset addresses indicate the position of the task functions in the host program; Determine the actual running address corresponding to the function offset address, and set the jump function corresponding to the task function at the position indicated by the actual running address. The actual running address indicates the position of the jump function in the detection program, and the task function and the jump function have the same function. During the execution of the data migration task, the execution status of the jumper function in the detection program is obtained; The execution status is determined as the task status of the data migration task.

4. The method according to claim 1, characterized in that, The detection program includes a jump function corresponding to a task function. The task function includes an information initialization function, a password determination function, and a migration function. The jump function corresponding to the password determination function is a function used by the host program to set the database password related to the encrypted data. Determining the decryption information corresponding to the host program includes: When the task status is "initialization complete", obtain the basic information corresponding to the target client recorded by the jump function corresponding to the information initialization function; When the task status is "password acquisition complete", the database password is determined based on the input parameters of the jump function corresponding to the password determination function. If the task status indicates that the data migration task has been successfully completed, the basic information and the database password are used as the decryption information corresponding to the host program through the jump function corresponding to the migration function.

5. The method according to claim 1, characterized in that, The process of obtaining decrypted data based on the decryption information and the encrypted data includes: Determine the data directory corresponding to the host program, wherein the data directory indicates the storage location of the host program; Based on the basic information contained in the data directory and the decryption information, the target file containing the encrypted data is located in the data contained in the host program. The target file includes at least one page of target encrypted data. For each page of target encrypted data, the target encrypted data is decrypted according to the database password contained in the decryption information to obtain the target decrypted data; Combine the target encrypted data with the target decrypted data to obtain the decrypted data.

6. The method according to claim 5, characterized in that, The step of decrypting the target encrypted data based on the database password contained in the decryption information to obtain the target decrypted data includes: Based on the database password contained in the decryption information, generate a decryption key and a verification key; Using the verification key as a parameter, a first hash authentication code is formed by the target encrypted data and the page number corresponding to the target encrypted data; Determine the second hash authentication code contained in the page containing the target encrypted data; If the first hash authentication code and the second hash authentication code are consistent, the target encrypted data is decrypted using the decryption key and the decryption vector contained in the page containing the target encrypted data as parameters to obtain the target decrypted data.

7. The method according to claim 6, characterized in that, The step of generating a decryption key and a verification key based on the database password contained in the decryption information includes: Determine the encryption parameters, which include the parameters corresponding to the target file; Perform an XOR operation on the encryption parameters to obtain the XOR encryption parameters; A decryption key is generated using the database password contained in the decryption information and the encryption parameters as parameters; A verification key is generated using the decryption key and the XOR encryption parameters.

8. A data decryption device, characterized in that, Configuration on the target client includes: The first determining module is used to determine the host program, wherein the host program includes the program corresponding to the target client; The detection module is used to detect the task status through a detection program. The task status includes the status of a data migration task, which includes a task of migrating target data generated during mobile terminal runtime to encrypted data in the target client. The mobile terminal is connected to the target client. The second determining module is used to determine the decryption information corresponding to the host program when the task status indicates that the data migration task has been successfully migrated. The decryption information includes information generated during the operation of the host program. The decryption module is used to obtain decrypted data based on the decryption information and the encrypted data.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data decryption method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the data decryption method of any one of claims 1-7.

11. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the data decryption method according to any one of claims 1-7.