A program window content protection method and system
Patent Information
- Application Number
- CN202610550851.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-24
- Publication Date
- 2026-09-08
AI Technical Summary
[0004]本发明所要解决的技术问题是:提供一种程序窗口内容保护方法及系统,以解决现有防截屏技术无法在保证稳定可靠的前提下对第三方应用程序窗口进行有效保护的技术问题
[0007]The beneficial effects of this invention are as follows: By creating a dynamic link library (DLL) containing protection logic and loading it into the currently running process (usually the system GUI process) by the main module, this DLL first performs process identification after injection, and only executes subsequent operations when it matches a preset list of target processes. Its core lies in calling the native window attribute setting interface provided by the operating system within the target process's own address space, thereby bypassing process isolation restrictions and achieving anti-screenshot content protection for third-party application windows. This invention combines global hook injection technology with the operating system's native protection API, inheriting the high efficiency and reliability of the native API while breaking through the restriction that the target program must be its own process, achieving universal, stable, and transparent anti-screenshot content protection for any specified third-party program window.
Smart Images

Figure CN122712554A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer security technology, and in particular to a method and system for protecting program window content. Background Technology
[0002] With the development of information technology, sensitive information displayed on computer screens (such as trade secrets and personal privacy) is at risk of being stolen through screenshots and screen recordings. Existing anti-screenshot technologies have significant limitations: methods based on native operating system APIs (such as Windows' SetWindowDisplayAffinity function) cannot be applied to third-party program windows due to process isolation limitations; while graphical interface hooking (API hooking) technology suffers from poor stability, low compatibility, and ease of bypassing; and window overlay technology offers weak protection and negatively impacts user experience.
[0003] Therefore, there is an urgent need for a third-party program window content protection solution that can both overcome process limitations and possess high stability and reliability. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a method and system for protecting the content of program windows, so as to solve the technical problem that existing anti-screenshot technology cannot effectively protect the windows of third-party applications while ensuring stability and reliability.
[0005] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows: A method for protecting the content of a program window, comprising: Create a dynamic link library to protect the program window content, and load the dynamic link library into the currently running process by the main module; The dynamic link library matches the currently running process with a preset list of processes to be protected in the dynamic link library. If a match is successful, the target process is obtained. The target window is obtained based on the target process, and the state of the target window is set to a preset protection state.
[0006] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: A program window content protection system, comprising a main module and a dynamic link library; The main module is used to load the dynamic link library into the currently running process; The dynamic link library is used to match the currently running process with a preset list of processes to be protected in the dynamic link library. If the match is successful, the target process is obtained, the target window is obtained according to the target process, and the state of the target window is set to a preset protection state.
[0007] The beneficial effects of this invention are as follows: By creating a dynamic link library (DLL) containing protection logic and loading it into the currently running process (usually the system GUI process) by the main module, this DLL first performs process identification after injection, and only executes subsequent operations when it matches a preset list of target processes. Its core lies in calling the native window attribute setting interface provided by the operating system within the target process's own address space, thereby bypassing process isolation restrictions and achieving anti-screenshot content protection for third-party application windows. This invention combines global hook injection technology with the operating system's native protection API, inheriting the high efficiency and reliability of the native API while breaking through the restriction that the target program must be its own process, achieving universal, stable, and transparent anti-screenshot content protection for any specified third-party program window. Attached Figure Description
[0008] Figure 1 This is a flowchart of a method for protecting program window content according to an embodiment of the present invention; Figure 2 This is a detailed flowchart of a method for protecting program window content according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the system functional modules of a program window content protection method according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the dynamic link library judgment logic of a program window content protection method according to an embodiment of the present invention; Figure 5 This is an interactive timing diagram of a method for protecting program window content according to an embodiment of the present invention; Figure 6 This is a schematic diagram of a program window content protection system according to an embodiment of the present invention; Label Explanation: 1. A program window content protection system; 2. Main module; 3. Dynamic link library. Detailed Implementation
[0009] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.
[0010] Before detailing the embodiments of this application, some related concepts will first be explained: Dynamic Link Library (DLL): A file library containing code and data that can be used by multiple programs simultaneously.
[0011] Application Programming Interface (API): A library of files containing code and data that can be used by multiple programs simultaneously.
[0012] Window handle (HWND): An integer value used by the operating system to uniquely identify a window.
[0013] Data Loss Prevention: A set of strategies and tools designed to ensure that sensitive data is not accessed, misused, or leaked by unauthorized users.
[0014] Graphical User Interface (GUI): A user interface that allows users to interact with electronic devices through graphical icons and visual indicators.
[0015] SetWindowDisplayAffinity: A Windows API function that sets the display properties of a specified window to control whether its content can be captured in a screenshot or remote session.
[0016] Global Hook: A mechanism that can intercept specific types of events (such as window messages) throughout the system.
[0017] Dynamic library injection (DLL injection): a technique that forces an external dynamic link library into the address space of another running process and executes its code.
[0018] Process isolation: a fundamental security feature of the operating system that prevents one process from directly accessing or interfering with the memory space of another process.
[0019] Hook Procedure: A callback function defined by the application that is called by the operating system when an event monitored by the installed hook occurs.
[0020] In existing technologies, using the Windows operating system's native `SetWindowDisplayAffinity` function to set anti-screenshot properties for windows is one of the most stable and effective software anti-screenshot methods. However, this function only allows one process to modify the properties of the windows it creates, adhering to strict process isolation security principles. This makes it unsuitable for directly protecting other standalone software running on the user's machine, such as browsers, office software, and cloud desktop clients. To address this issue, existing technologies often employ highly intrusive API hooking or window overlay techniques that negatively impact user experience. However, these solutions generally suffer from shortcomings in stability, compatibility, or protection capabilities, making it difficult to meet the high reliability and versatility requirements for developing general-purpose data loss prevention (DLP) products.
[0021] To at least solve the above problems, please refer to Figure 1 as well as Figure 2 This invention provides a method for protecting the content of a program window, comprising: Create a dynamic link library to protect the program window content, and load the dynamic link library into the currently running process by the main module; The dynamic link library matches the currently running process with a preset list of processes to be protected in the dynamic link library. If a match is successful, the target process is obtained. The target window is obtained based on the target process, and the state of the target window is set to a preset protection state.
[0022] As described above, the beneficial effects of this invention are as follows: by injecting a dynamic link library (DLL) containing program window content protection logic into the address space of the target process, and calling the operating system's native protection interface (such as SetWindowDisplayAffinity) within the target process, the technical bottleneck of the native API's inability to protect third-party program windows due to process isolation is solved. This solution retains the efficiency and reliability of the operating system's underlying protection while breaking through process limitations, achieving stable and transparent protection for any specified third-party application window.
[0023] Furthermore, a dynamic link library for protecting the program window content is created, including: Obtain the process identifier of the preset process to be protected; Create a list of processes to be protected that stores the process identifiers.
[0024] As described above, by pre-setting a list of processes to be protected, the protection scheme only applies to the processes in the list, avoiding interference with all GUI processes in the system and improving the accuracy and system compatibility of the scheme.
[0025] Furthermore, the dynamic link library for creating program window content protection also includes: Create a first program, which is used to obtain the identifier of the currently running process and match the identifier of the currently running process with the list of processes to be protected; Create a second program, which is used to set the target window to a preset protected state. The first program and the second program are encapsulated into a dynamic link library.
[0026] As described above, the first program is responsible for process identification and filtering, ensuring that the protection logic is activated only in the process to be protected; the second program encapsulates the core protection API call functions. This separation design facilitates subsequent adjustments and upgrades based on different operating system versions or protection requirements.
[0027] Furthermore, the main module loads the dynamic link library into the currently running process, including: The main module sets a global hook, which loads the dynamic link library into the address space of a process with a message loop mechanism in the operating system.
[0028] As described above, utilizing global hooks is a key and standard technique for cross-process DLL injection. By calling system APIs to install global hooks, the operating system automatically loads the specified DLL into all relevant GUI processes. This method provides a reliable and controllable injection approach, laying the foundation for subsequent code execution within the target process.
[0029] Further, obtaining the target window based on the target process includes: When the global hook receives a window activation message from the target process, it determines the target window based on the window handle in the window activation message; Also includes: The target window is periodically searched in the target process, and the handle of the target window is obtained.
[0030] As described above, using window activation events to trigger window capture is an efficient and real-time event-driven approach. When a target process's window is activated, the hook process can immediately obtain the window's handle, allowing protection settings to be applied immediately, ensuring the timeliness and accuracy of protection. For windows not presented through standard activation events, or dynamically created child windows, the polling mechanism ensures that all target windows requiring protection are eventually discovered and protected, enhancing the robustness and completeness of the solution.
[0031] Furthermore, using the dynamic link library to set the target window to a preset protected state includes: Upon receiving an event notification indicating that the target window has been activated, obtain the handle of the target window based on the parameters of the event notification; The handle of the target window is entered into the second program of the dynamic link library, and the state of the target window is set to a preset protected state.
[0032] As described above, after detecting the activation of the target window, the hook procedure function extracts the window handle and passes it to the encapsulated protection function (the second program). This protection function, within the context of the target process, legally calls the operating system API to complete the protection settings. The process from the hook procedure function's detection to the invocation of the system API for protection is tightly linked and logically clear, forming a complete protection chain.
[0033] Further, obtaining the handle of the target window includes: Determine whether the handle of the target window is valid. If so, set the target window to a preset protected state through the second program in the dynamic link library.
[0034] As described above, adding handle validity verification before calling the protection API improves code robustness. This avoids API call failures or unexpected errors due to window destruction, invalid handles, or NULL values, ensuring stable execution of the protection logic and overall system stability.
[0035] Furthermore, it also includes: When uninstalling the global hook, all dynamic link libraries in the currently running process are also uninstalled.
[0036] As described above, this step provides a complete lifecycle management and resource cleanup mechanism. When the main module (such as the protection management program) needs to stop protection, the global hook is uninstalled via UnhookWindowsHookEx, and the operating system automatically uninstalls DLLs from all related processes. This ensures that the protection function can exit cleanly and completely, releasing system resources and restoring the system to its state before protection, demonstrating minimal and controllable impact on the system.
[0037] Please refer to Figure 6 Another embodiment of the present invention provides a program window content protection system, including a main module and a dynamic link library. The main module is used to load the dynamic link library into the currently running process. The dynamic link library is used to match the currently running process with a preset list of processes to be protected in the dynamic link library. If the match is successful, the matched target process is obtained, the target window is obtained according to the target process, and the state of the target window is set to a preset protection state.
[0038] The above-described method and system for protecting program window content are applicable to scenarios requiring protection against the leakage of sensitive information through screenshots or screen recordings. They are particularly suitable as data loss prevention (DLP) products for protecting the window content of running third-party applications (such as cloud desktop clients, financial trading software, engineering design software, online conferencing software, etc.). The following detailed implementation methods illustrate these methods: Please refer to Figure 1 as well as Figure 2 One embodiment of the present invention is as follows: A method for protecting the content of a program window, comprising: S1. Create a dynamic link library for protecting the program window content, including: S11. Obtain the process identifier of the preset process to be protected; Specifically, let's take protecting the window of the third-party application "CloudDesktop.exe" in the Windows operating system as an example.
[0039] The process identifier of the preset process to be protected is "CloudDesktop.exe".
[0040] S12. Establish a list of processes to be protected that stores the process identifiers; Specifically, the aforementioned process identifiers are stored as configuration items in a string array inside the DLL, forming an array of processes to be protected.
[0041] S13. Create a first program, which is used to obtain the identifier of the currently running process and match the identifier of the currently running process with the list of processes to be protected; S14. Create a second program, which is used to set the state of the target window to a preset protected state. S15. Encapsulate the first program and the second program into a dynamic link library.
[0042] Specifically, the DLL implements two core programs: The first program, within the DLL_PROCESS_ATTACH event handler of the DllMain function, retrieves the full path of the current host process by calling the GetModuleFileName(NULL,...) API, extracts the executable filename (e.g., "CloudDesktop.exe"), and compares it with the list of processes to be protected. The second program, implemented as a function (e.g., SetProtectionStatus), internally calls the Windows SetWindowDisplayAffinity function with the parameter WDA_MONITOR. This sets the display affinity of the specified window to be displayed only on the monitor, thus achieving the effect of preventing screenshot content from being captured.
[0043] S2. The main module loads the dynamic link library into the currently running process, including: Set a global hook to load the dynamic link library into the address space of a process with a message loop mechanism in the operating system.
[0044] Please refer to Figure 3Specifically, after startup, the main module (such as a standalone protection program Helper.exe) performs the following operations: calls LoadLibrary to load the DLL created in step S1; calls GetProcAddress to obtain the address of a hook procedure function (such as CBTProc) in the DLL; calls the SetWindowsHookEx function to set a global computer training hook (WH_CBT), passing the address of the hook procedure function obtained in the previous step and the module handle of the DLL as parameters, with the thread ID parameter set to 0 to indicate a global hook. After this call, the operating system automatically injects the DLL into the address space of all GUI processes with message loops in the system (including "CloudDesktop.exe" and others such as notepad.exe).
[0045] S3. The dynamic link library matches the currently running process with the preset list of processes to be protected in the dynamic link library. If the match is successful, the target process is obtained.
[0046] Please refer to Figure 4 Specifically, when a DLL is injected into the "CloudDesktop.exe" process, its DllMain function is called (with the parameter fdwReason set to DLL_PROCESS_ATTACH). The first program encapsulated in the DLL executes immediately: it obtains the current process name "CloudDesktop.exe," compares it with an item in the list of processes to be protected, and if a match is found, the current process is confirmed as the target process. The DLL remains active in this target process, and its exported hook procedure functions are registered to the system hook chain. For other unrelated processes injected (such as "explorer.exe"), the first program comparison fails, and the DLL will not perform any subsequent operations, thus minimizing the impact on unrelated programs.
[0047] S4. Obtain the target window based on the target process, including: S41. Listen for messages from the global hook. When the global hook receives a message that the target window has been activated, obtain the handle of the target window through the global hook. S42. In the target process, periodically search for the target window belonging to the current target process through a preset function, and obtain the handle of the target window through the preset function; The step of obtaining the handle of the target window includes: determining whether the handle of the target window is valid; if so, setting the state of the target window to a preset protected state through a second program in the dynamic link library.
[0048] Please refer to Figure 5Specifically, within the target process "CloudDesktop.exe", the target window can be obtained through either event-driven or polling methods. Event-driven: The hook procedure function (CBTProc) of the installed WH_CBT global hook listens for system events. When the user clicks or otherwise activates the main window of "CloudDesktop.exe", the system generates an HCBT_ACTIVATE event and calls CBTProc. This function obtains the handle (HWND) of the window to be activated from the wParam parameter. Polling-driven: The DLL can start a low-frequency timer or thread in the target process to periodically call APIs such as EnumWindows or FindWindow to find specific windows belonging to the "CloudDesktop.exe" process (e.g., identified by window class name or title) and obtain their window handles.
[0049] S5. Set the target window to a preset protection state, including: Create a hook procedure function. When the hook procedure function receives an event notification indicating that the target window is activated, obtain the handle of the target window based on the parameters of the event notification. The second program in the dynamic link library sets the target window to a preset protected state.
[0050] Specifically, after obtaining a valid handle (HWND) of the target window, within the context of the target process "CloudDesktop.exe", the Windows API `SetWindowDisplayAffinity(hWnd, WDA_MONITOR)` is called via a second program (the `SetProtectionStatus` function) encapsulated in the DLL. Since this call occurs within the target process's own address space, it is legal and executes successfully. Upon successful execution, the window is marked by the operating system as being in a default protected state (anti-screenshot state). Any attempt to capture the screen using a regular desktop window manager (DWM) or GDI method (including the PrintScreen key, screenshot tools, screen recording software, etc.) will result in a black or blank image of this window, thus protecting the program window content.
[0051] S6. When uninstalling the global hook, uninstall all dynamic link libraries in the currently running process.
[0052] Specifically, when protection needs to be stopped, the main module calls UnhookWindowsHookEx to uninstall the global hook. The operating system will then uninstall the DLL from all processes, and the protection will be lifted.
[0053] In summary, this embodiment bypasses process isolation restrictions by injecting a DLL into the target process via a global hook and calling the native API (SetWindowDisplayAffinity) within the target process. The entire solution requires no code modification to the target program, is completely transparent to the end user, and utilizes reliable protection mechanisms at the operating system kernel level. This achieves efficient, stable, and universal protection against screenshots for third-party application windows, effectively solving existing technical bottlenecks.
[0054] Please refer to Figure 6 Embodiment two of the present invention is as follows: A program window content protection system includes a main module and a dynamic link library. The main module is used to load the dynamic link library into the currently running process. The dynamic link library is used to match the currently running process with a preset list of processes to be protected in the dynamic link library. If the match is successful, the matched target process is obtained, the target window is obtained according to the target process, and the state of the target window is set to a preset protection state.
[0055] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent modifications made based on the content of the present invention specification and drawings, or direct or indirect applications in related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for protecting the content of a program window, characterized in that, include: Create a dynamic link library to protect the program window content, and load the dynamic link library into the currently running process by the main module; The dynamic link library matches the currently running process with a preset list of processes to be protected in the dynamic link library. If a match is successful, the target process is obtained. The target window is obtained based on the target process, and the state of the target window is set to a preset protection state.
2. The method according to claim 1, characterized in that, Create a dynamic link library for protecting the program window content, including: Obtain the process identifier of the preset process to be protected; Create a list of processes to be protected that stores the process identifiers.
3. The method according to claim 2, characterized in that, The dynamic link library for creating program window content protection also includes: Create a first program, which is used to obtain the identifier of the currently running process and match the identifier of the currently running process with the list of processes to be protected; Create a second program, which is used to set the target window to a preset protected state. The first program and the second program are encapsulated into a dynamic link library.
4. The method according to claim 3, characterized in that, The main module loads the dynamic link library into the currently running process, including: The main module sets a global hook, which loads the dynamic link library into the address space of a process with a message loop mechanism in the operating system.
5. The method according to claim 4, characterized in that, Obtaining the target window based on the target process includes: When the global hook receives a window activation message from the target process, it determines the target window based on the window handle in the window activation message.
6. The method according to claim 1, characterized in that, Obtaining the target window based on the target process also includes: The target window is periodically searched in the target process, and the handle of the target window is obtained.
7. The method according to claim 5, characterized in that, Using the dynamic link library to set the target window to a preset protected state includes: Upon receiving an event notification indicating that the target window has been activated, obtain the handle of the target window based on the parameters of the event notification; The handle of the target window is entered into the second program of the dynamic link library, and the state of the target window is set to a preset protected state.
8. The method according to claim 7, characterized in that, Obtaining the handle of the target window includes: Determine whether the handle of the target window is valid. If so, set the target window to a preset protected state through the second program in the dynamic link library.
9. The method according to claim 4, characterized in that, Also includes: When uninstalling the global hook, all dynamic link libraries in the currently running process are also uninstalled.
10. A program window content protection system, characterized in that, Including the main module and dynamic link libraries: The main module is used to load the dynamic link library into the currently running process; The dynamic link library is used to match the currently running process with a preset list of processes to be protected in the dynamic link library. If the match is successful, the target process is obtained, the target window is obtained according to the target process, and the state of the target window is set to a preset protection state.