Method and apparatus for processing data, device, and storage medium

By dynamically replacing the encryption and decryption algorithm with Java agent when the target program is started, the automatic replacement of weak encryption and decryption algorithms in open source components is solved, the efficiency and effect of encryption and decryption algorithm replacement is improved, and the risk of data leakage is reduced.

WO2025139568A1PCT designated stage expired Publication Date: 2025-07-03CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/135038
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-11-27
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In the prior art, the encryption and decryption algorithm used by open source components is easily cracked, resulting in the risk of data leakage. The code scanning method has high missed and false alarm rates, low replacement efficiency, and high labor costs.

Method used

By determining the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm, the Java agent is used to dynamically modify the bytecode in the encryption and decryption algorithm declaration when the target program is started, the weak encryption and decryption algorithm is replaced with the strong encryption and decryption algorithm, and the probe Java agent is used to determine the encryption and decryption algorithm of the target program and automatically replace it.

Benefits of technology

It realizes efficient and accurate encryption and decryption algorithm replacement, improves replacement efficiency, reduces labor costs, and enhances data security and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024135038_03072025_PF_FP_ABST
    Figure CN2024135038_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a method and apparatus for processing data, a device, and a storage medium, which are used for enhancing the replacement efficiency of an encryption / decryption algorithm and improving the replacement effect. The method comprises: determining a correspondence relationship between a first encryption / decryption algorithm and a second encryption / decryption algorithm, the encryption / decryption strength of the first encryption / decryption algorithm being smaller than that of the second encryption / decryption algorithm; when a target program is started, using a probe Java agent to determine a third encryption / decryption algorithm used in an encryption / decryption algorithm declaration corresponding to the target program; and if the third encryption / decryption algorithm is the first encryption / decryption algorithm, invoking the Java agent to, on the basis of the correspondence relationship, modify a third byte code corresponding to the third encryption / decryption algorithm used in the encryption / decryption algorithm declaration into a second byte code corresponding to the second encryption / decryption algorithm, so that the target program is enabled to invoke the second encryption / decryption algorithm on the basis of the second byte code.
Need to check novelty before this filing date? Find Prior Art

Description

Data processing method, device, equipment and storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on December 26, 2023, with application number 202311801425.8 and application name "A data processing method, device, equipment and storage medium", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of computer technology, and in particular to a data processing method, apparatus, device and storage medium. Background Art

[0004] Currently, most programs integrate a large number of open source components. If the encryption and decryption algorithms used by these open source components are outdated or easily cracked, there will be a huge risk of data leakage. To reduce security risks, weak encryption and decryption algorithms need to be replaced with strong ones. In related technologies, code keyword scanning can be used to determine the weak encryption and decryption algorithms that need to be replaced. However, this method has the following drawbacks: First, the code scanning has a high rate of missed and false positives, resulting in poor replacement results; second, technicians are required to modify all detected weak encryption and decryption algorithms one by one, resulting in low replacement efficiency and high labor costs. Summary of the Invention

[0005] The embodiments of the present application provide a data processing method, apparatus, device and storage medium for improving the replacement efficiency of encryption and decryption algorithms and enhancing the replacement effect.

[0006] In a first aspect, an embodiment of the present application provides a data processing method, the method comprising:

[0007] Determining a correspondence between a first encryption and decryption algorithm and a second encryption and decryption algorithm; the encryption and decryption strength of the first encryption and decryption algorithm is less than the encryption and decryption strength of the second encryption and decryption algorithm;

[0008] When the target program is started, the probe Java agent is used to determine the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program;

[0009] If the third encryption and decryption algorithm is the first encryption and decryption algorithm, the Java agent is called to modify the third bytecode corresponding to the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration to the second bytecode corresponding to the second encryption and decryption algorithm based on the correspondence, so that the target program calls the second encryption and decryption algorithm based on the second bytecode.

[0010] In this solution, the first encryption and decryption algorithm has a corresponding relationship with the second encryption and decryption algorithm, and the encryption and decryption strength of the first encryption and decryption algorithm is less than the encryption and decryption strength of the second encryption and decryption algorithm, which is equivalent to the first encryption and decryption algorithm being a weak encryption and decryption algorithm and the second encryption and decryption algorithm being a strong encryption and decryption algorithm; the Java agent is used to determine the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program. When the third encryption and decryption algorithm is determined to be the first encryption and decryption algorithm, that is, when the encryption and decryption algorithm strength in the target program is weak, based on the corresponding relationship, the Java agent can quickly modify the third bytecode corresponding to the third encryption and decryption algorithm to the second bytecode corresponding to the second encryption and decryption algorithm, without the need for manual replacement, and the replacement efficiency is high. In addition, since the corresponding relationship between the weak encryption and decryption algorithm and the strong decryption algorithm is set, the Java agent can achieve accurate replacement and good replacement effect.

[0011] Optionally, determining the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes: determining the computing resources required for each encryption and decryption algorithm in a pre-stored encryption and decryption algorithm set; the encryption and decryption strength of any encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set is greater than the encryption and decryption strength of the first encryption and decryption algorithm; according to preset conditions, determining the encryption and decryption algorithm that meets the preset conditions from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm; the preset conditions include that the computing resources required for the encryption and decryption algorithm are less than the idle computing resources of the server where the target program is located; and establishing a correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm.

[0012] Through this method, different encryption and decryption algorithms require different computing resources. An encryption and decryption algorithm whose required computing resources are less than the idle computing resources of the server where the target program is located is selected from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm, so that the server will not be overloaded and the second encryption and decryption algorithm can be run normally, thereby improving the reliability of the solution.

[0013] Optionally, the determining, according to a preset condition, from the pre-stored encryption and decryption algorithm set, an encryption and decryption algorithm that meets the preset condition as the second encryption and decryption algorithm includes: prioritizing the encryption and decryption algorithms in the pre-stored encryption and decryption algorithm set in descending order of the encryption and decryption strength of each encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set; and determining, in descending order of priority, an encryption and decryption algorithm that meets the preset condition from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm.

[0014] Through this method, on the premise that the computing resources required by the selected second encryption and decryption algorithm are less than the idle computing resources of the server where the target program is located, the encryption and decryption algorithm with the strongest encryption and decryption strength is selected from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm, thereby improving the practicality of the solution and further improving the security of the encrypted and decrypted data.

[0015] Optionally, after determining that the third encryption and decryption algorithm is the first encryption and decryption algorithm, the method further includes: determining, based on stack information of the target program during the execution of the third encryption and decryption algorithm, the method name of at least one method called by the target program during the execution of the third encryption and decryption algorithm and the class name of each method call; determining, based on the method name of the at least one method and the class name of each method call, multiple open source components included in the target program; determining a suspicious program on the server where the target program is located, the suspicious program including more than a preset number of open source components among the multiple open source components; and sending an alarm message to the technician's equipment, the alarm message including the suspicious program, and the alarm message being used to instruct a check on whether the suspicious program includes the third encryption and decryption algorithm.

[0016] Through this method, the open source components included are similar, and the encryption and decryption algorithms called in different programs may also be similar. By determining the open source components included in the target program, the suspicious program on the server where the target program is located is determined. The open source components included in the suspicious program are similar to the open source components included in the target program, so the suspicious program may also include the third encryption and decryption algorithm. An alarm message is sent to the technician's equipment to enable the technician to check whether the suspicious program includes the third encryption and decryption algorithm. This improves the practicality of the solution and improves the reliability and stability of other programs.

[0017] Optionally, the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to multiple second encryption and decryption algorithms.

[0018] In a second aspect, an embodiment of the present application provides a data processing device, which includes a module / unit / technical means for executing the method in the above-mentioned first aspect or any optional implementation method of the first aspect.

[0019] Exemplarily, the device may include:

[0020] a determination module, configured to determine a correspondence between a first encryption and decryption algorithm and a second encryption and decryption algorithm; the encryption and decryption strength of the first encryption and decryption algorithm is less than the encryption and decryption strength of the second encryption and decryption algorithm;

[0021] A processing module is used to use a probe Java agent to determine the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program when the target program is started; if the third encryption and decryption algorithm is the first encryption and decryption algorithm, call the Java agent to modify the third bytecode corresponding to the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration to the second bytecode corresponding to the second encryption and decryption algorithm based on the corresponding relationship, so that the target program calls the second encryption and decryption algorithm based on the second bytecode.

[0022] Optionally, when determining the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm, the determination module is specifically used to: determine the computing resources required for each encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set; the encryption and decryption strength of any encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set is greater than the encryption and decryption strength of the first encryption and decryption algorithm; according to preset conditions, determine the encryption and decryption algorithm that meets the preset conditions from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm; the preset conditions include that the computing resources required for the encryption and decryption algorithm are less than the idle computing resources of the server where the target program is located; and establish a correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm.

[0023] Optionally, when the determination module determines, based on preset conditions, that the encryption and decryption algorithm that meets the preset conditions is the second encryption and decryption algorithm from the pre-stored encryption and decryption algorithm set, it is specifically used to: prioritize the encryption and decryption algorithms in the pre-stored encryption and decryption algorithm set in descending order of the encryption and decryption strength of each encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set; and determine, in descending order of priority, that the encryption and decryption algorithm that meets the preset conditions is the second encryption and decryption algorithm from the pre-stored encryption and decryption algorithm set.

[0024] Optionally, after the determination module determines that the third encryption and decryption algorithm is the first encryption and decryption algorithm, the processing module is further used to: determine the method name of at least one method called by the target program in the process of executing the third encryption and decryption algorithm and the class name of each method call based on the stack information of the target program in the process of executing the third encryption and decryption algorithm; determine the multiple open source components included in the target program based on the method name of the at least one method and the class name of each method call; determine the suspicious program on the server where the target program is located, and the suspicious program includes more than a preset number of open source components among the multiple open source components; send an alarm message to the technician's equipment, the alarm message includes the suspicious program, and the alarm message is used to indicate to check whether the suspicious program includes the third encryption and decryption algorithm.

[0025] Optionally, the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to multiple second encryption and decryption algorithms.

[0026] In a third aspect, an embodiment of the present application provides an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the at least one processor executes the instructions stored in the memory, thereby enabling the at least one processor to perform the steps of the data processing method described in the first aspect above.

[0027] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the steps of the data processing method described in the first aspect above.

[0028] In addition, other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or may be understood by practicing the present application. The objectives and other advantages of the present application can be realized and obtained through the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0030] FIG1 is a flow chart of a data processing method provided in an embodiment of the present application;

[0031] FIG2 is a schematic diagram of a method for obtaining a corresponding relationship provided in an embodiment of the present application;

[0032] FIG3 is a structural diagram of a data processing device provided in an embodiment of the present application;

[0033] FIG4 is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0034] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application. Unless there is a conflict, the embodiments in the present application and the features in the embodiments can be combined with each other in any way. In addition, although a logical order is shown in the flow chart, in some cases, the steps shown or described can be performed in a different order than here.

[0035] The terms "first" and "second" in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of its variations are intended to cover non-exclusive protection. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. "Multiple" in this application can mean at least two, for example, two, three or more, and the embodiments of this application are not limited thereto.

[0036] In addition, the term "and / or" in this article is simply a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the characters "three" in this article, unless otherwise specified, generally indicate that the related objects are in an "or" relationship.

[0037] Most current programs integrate numerous open source components. Whether each open source component includes encryption and decryption, as well as the encryption, decryption, and signing methods used, is difficult to predict in advance. Weak encryption and decryption algorithms are those that are vulnerable to attack or have already been successfully attacked. If a program uses an open source component that uses a weak encryption and decryption algorithm, there is a significant risk of data leakage. This issue is often addressed by scanning the code for keywords to identify the weak encryption and decryption algorithms that need to be replaced. However, this approach has the following drawbacks: 1. Code scanning has a high rate of missed and false positives, resulting in poor replacement effectiveness; 2. Technical personnel are required to modify each detected weak encryption and decryption algorithm one by one, resulting in low replacement efficiency and high labor costs.

[0038] In view of this, a technical solution is provided in accordance with an embodiment of the present application to improve the replacement efficiency of encryption and decryption algorithms and enhance the replacement effect.

[0039] In view of the above scenario, the data processing method provided by the present invention is described in detail below with reference to the accompanying drawings.

[0040] It should be noted that in the embodiment of the present application, the number of the first encryption and decryption algorithm, the second encryption and decryption algorithm, and the third encryption and decryption algorithm can be one or more. The "first", "second", and "third" in this application are only used to distinguish encryption and decryption algorithms with different strengths, and do not limit the number of the first encryption and decryption algorithm, the second encryption and decryption algorithm, and the third encryption and decryption algorithm.

[0041] Referring to FIG1 , a flow chart of a data processing method according to an embodiment of the present application is provided. The method can be executed by a computer device, such as a laptop computer, a desktop computer, or a server, and can also be applied to various devices with computing capabilities. The above devices are merely illustrative and are not intended to limit the present embodiment.

[0042] The following takes the method executed by a server as an example. The server has a target program. The method includes:

[0043] S101: Determine a correspondence between a first encryption / decryption algorithm and a second encryption / decryption algorithm.

[0044] The encryption and decryption strength of the first encryption and decryption algorithm is less than the encryption and decryption strength of the second encryption and decryption algorithm.

[0045] It is understandable that the strength of an encryption and decryption algorithm is related to the key length and the complexity of the encryption and decryption algorithm. The longer the key length, the higher the complexity of the encryption and decryption algorithm, and the stronger the encryption and decryption algorithm. In addition, for different encryption and decryption algorithms, the encryption and decryption strength can also be set by technicians according to actual conditions. For example, the encryption and decryption strength of a currently cracked encryption and decryption algorithm is less than the encryption and decryption strength of an un-cracked encryption and decryption algorithm. Based on this fact, the technician sets a smaller value for the encryption and decryption strength of the cracked encryption and decryption algorithm and a larger value for the encryption and decryption strength of the un-cracked encryption and decryption algorithm. This embodiment of the present application does not impose any restrictions.

[0046] In possible implementations, the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm may be implemented as follows:

[0047] 1. The correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to multiple second encryption and decryption algorithms.

[0048] 2. The correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to one second encryption and decryption algorithm.

[0049] In addition, if there are multiple first encryption and decryption algorithms, the second encryption and decryption algorithms corresponding to different first encryption and decryption algorithms may be the same or different, and this embodiment of the present application does not impose any limitation.

[0050] For example, the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm can be shown in Table 1 below, where the first encryption / decryption algorithm and the second encryption / decryption algorithm in the same row have a correspondence. Each encryption / decryption algorithm in the table is composed of "encryption mode / operating mode corresponding to the encryption mode / padding method corresponding to the encryption mode." For example, in "DES / CBC / PKCS5Padding," DES is the encryption mode, CBC is the operating mode corresponding to DES, and PKCS5Padding is the padding method corresponding to DES.

[0051] Table 1

[0052] The above describes the corresponding relationship. The following describes how to determine the corresponding relationship between the first encryption and decryption algorithm and the second encryption and decryption algorithm.

[0053] In a possible implementation, a correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm is received, which is input by a technician or sent by other equipment.

[0054] For example, referring to Figure 2, the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm is configured in the rule server, and the rule server sends the correspondence to server 1, server 2,..., server n. In the embodiment of the present application, the server where the target program is located can be any server from server 1 to server n, which receives the correspondence sent by the rule server.

[0055] In another possible implementation, the computing resources required for each encryption and decryption algorithm in a pre-stored encryption and decryption algorithm set are determined; the encryption and decryption strength of any encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set is greater than the encryption and decryption strength of the first encryption and decryption algorithm; based on preset conditions, the encryption and decryption algorithm that meets the preset conditions is determined from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm; the preset conditions include that the computing resources required for the encryption and decryption algorithm are less than the idle computing resources of the server where the target program is located; and a correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm is established.

[0056] Optionally, if the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to multiple second encryption and decryption algorithms, if there are multiple encryption and decryption algorithms that meet the preset conditions in the pre-stored encryption and decryption algorithm set, then the multiple encryption and decryption algorithms that meet the preset conditions can be used as multiple second encryption and decryption algorithms; or, if the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to one second encryption and decryption algorithm, then any encryption and decryption algorithm that meets the preset conditions can be used as the second encryption and decryption algorithm corresponding to a first encryption and decryption algorithm.

[0057] It is understandable that the computing resources required for each encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set can be input to the server in advance by technicians based on experimental data, and the embodiments of the present application do not limit this.

[0058] Through this method, different encryption and decryption algorithms require different computing resources. An encryption and decryption algorithm whose required computing resources are less than the idle computing resources of the server where the target program is located is selected from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm, so that the server will not exceed the load when running the second encryption and decryption algorithm, thereby improving the reliability of the solution.

[0059] Furthermore, a second encryption / decryption algorithm that meets a preset condition can be determined from a pre-stored encryption / decryption set based on the strength of the encryption / decryption algorithms. Specifically, the encryption / decryption algorithms in the pre-stored encryption / decryption set are prioritized in descending order of the encryption / decryption strength of each algorithm in the pre-stored encryption / decryption set; and an encryption / decryption algorithm that meets the preset condition is determined from the pre-stored encryption / decryption set as the second encryption / decryption algorithm in descending order of priority.

[0060] Optionally, if the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm includes one first encryption / decryption algorithm corresponding to multiple second encryption / decryption algorithms, then, in descending order of priority, multiple encryption / decryption algorithms that meet preset conditions are determined from a pre-stored encryption / decryption algorithm set as multiple second encryption / decryption algorithms; or, if the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm includes one first encryption / decryption algorithm corresponding to one second encryption / decryption algorithm, then, in descending order of priority, the first encryption / decryption algorithm that meets the preset conditions is used as the second encryption / decryption algorithm corresponding to a first encryption / decryption algorithm.

[0061] It is understandable that the encryption and decryption strength of each encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set input by the technician can be received, and the embodiment of the present application does not limit this.

[0062] Exemplarily, a first encryption and decryption algorithm corresponds to a second encryption and decryption algorithm, and the pre-stored encryption and decryption algorithm set includes encryption and decryption algorithms 1 to 3. Encryption and decryption algorithms 1 to 3 are prioritized in descending order of encryption and decryption strength. The sorting results are as follows in descending order of priority: encryption and decryption algorithm 2, encryption and decryption algorithm 1, encryption and decryption algorithm 3. First, it is determined whether encryption and decryption algorithm 2 meets the preset conditions. If so, encryption and decryption algorithm 2 is the second encryption and decryption algorithm. If not, the operation of determining whether the encryption and decryption algorithm meets the preset conditions is repeated for encryption and decryption algorithm 1 until an encryption and decryption algorithm that meets the preset conditions is determined as the second encryption and decryption algorithm.

[0063] Through this method, on the premise that the computing resources required by the selected second encryption and decryption algorithm are less than the idle computing resources of the server where the target program is located, the encryption and decryption algorithm with the strongest encryption and decryption strength is selected from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm, thereby improving the practicality of the solution and further improving the security of the encrypted and decrypted data.

[0064] It is understandable that the second encryption and decryption algorithm can also be determined from the encryption and decryption algorithms that meet the preset conditions based on other rules. The embodiments of the present application do not limit this. For example, in order to reduce the load on the server and reduce the power consumption of the server, the second encryption and decryption algorithm is the encryption and decryption algorithm that requires the least computing resources among all encryption and decryption algorithms that meet the preset conditions.

[0065] S102: When the target program is started, the probe Java agent is used to determine the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program.

[0066] The probe (Java Agent) can dynamically modify the bytecode of the loaded class while the program is running, injecting additional functions and behaviors into the application, such as adding logs to methods, implementing aspect-oriented programming (AOP), and performance monitoring.

[0067] When the target program is started, the Java agent is injected into the encryption and decryption algorithm declaration method of the target program. The Java agent determines the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program by monitoring the input parameters and context when declaring the encryption and decryption algorithm.

[0068] The number of third encryption and decryption algorithms can be one or more. The encryption and decryption declaration contains a Cipher object instance, and the target program implements the encryption and decryption algorithm using the Cipher object instance. If there are multiple third encryption and decryption algorithms, a new Cipher instance will replace the old one each time an encryption and decryption algorithm is declared, thus replacing the old and new third encryption and decryption algorithms. In this way, injecting the Java agent once into the target program can obtain all third encryption and decryption algorithms.

[0069] S103: If the third encryption / decryption algorithm is the first encryption / decryption algorithm, the Java agent is called to modify the third bytecode corresponding to the third encryption / decryption algorithm used in the encryption / decryption algorithm declaration to the second bytecode corresponding to the second encryption / decryption algorithm based on the corresponding relationship, so that the target program calls the second encryption / decryption algorithm based on the second bytecode.

[0070] In one possible implementation, if the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm determined in step S101 includes one first encryption and decryption algorithm corresponding to multiple second encryption and decryption algorithms, the Java agent is called to modify the third bytecode corresponding to the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration to the second bytecode corresponding to any second encryption and decryption algorithm in the multiple second encryption and decryption algorithms based on the correspondence; or, if the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm determined in step S101 includes one first encryption and decryption algorithm corresponding to one second encryption and decryption algorithm, the third bytecode corresponding to the third encryption and decryption algorithm is modified to the second bytecode corresponding to the second encryption and decryption algorithm.

[0071] In one possible implementation, in addition to modifying the third encryption and decryption algorithm used in the encryption and decryption declaration, a Java agent may be called to modify the key generation logic and encryption and decryption algorithm logic corresponding to the encryption and decryption declaration.

[0072] For example, see Table 2 below. The original code logic is the code logic used when the target program uses the third encryption and decryption algorithm for encryption. The new code logic is the code logic used when the target program uses the second encryption and decryption algorithm for encryption. In this table, the second line contains the encryption and decryption algorithm declarations, the third line contains the encryption algorithm instance initialization logic, and the fourth line contains the encryption algorithm logic. The code logic used when the target program uses the third encryption and decryption algorithm for decryption and the second encryption and decryption algorithm for decryption is similar to that in the table below, except that "ENCRYPT_MODE" in the third line is changed to "DECRYPT_MODE."

[0073] Table 2

[0074] In one possible implementation, after determining that the third encryption and decryption algorithm is the first encryption and decryption algorithm, determine the method name of at least one method called by the target program in the process of executing the third encryption and decryption algorithm and the class name of each method call based on the stack information of the target program in the process of executing the third encryption and decryption algorithm; determine the multiple open source components included in the target program based on the method name of the at least one method and the class name of each method call; determine the suspicious program on the server where the target program is located, and the suspicious program includes more than a preset number of open source components among the multiple open source components; send an alarm message to the technician's equipment, the alarm message includes the suspicious program, and the alarm message is used to indicate whether to check whether the suspicious program includes the third encryption and decryption algorithm.

[0075] Among them, before determining the multiple open source components included in the target program, the correspondence between the combination of specified method names and class names and the open source components can be pre-set. If a certain stack information contains the specified method name and class name, it is determined that the target program includes the open source components corresponding to the specified method name and class name.

[0076] Exemplarily, at least one method called by the target program during execution of the third encryption and decryption algorithm is called in a chain, for example: method 1 calls method 2, method 2 calls method 3, and so on. The stack trace includes the method name of method 1 and the class name called by method 1, the method name of method 2 and the class name called by method 2, and so on. Based on the method name of method 1 and the class name called by method 1, the open source component providing method 1 can be determined. For example, if the stack trace contains "org.springframe.XXXX" during execution of the third encryption and decryption algorithm, it is determined that the target program includes the open source component Spring Security.

[0077] If the open source components included in the program are similar, the encryption and decryption algorithms called may also be similar. By determining the open source components included in the target program, the suspicious program on the server where the target program is located can be determined. The open source components included in the suspicious program are similar to the open source components included in the target program, so the suspicious program may also include a third encryption and decryption algorithm. An alarm message is sent to the technician's equipment to enable the technician to check whether the suspicious program includes the third encryption and decryption algorithm. If the suspicious program includes the third encryption and decryption algorithm, the third encryption and decryption algorithm is replaced with an encryption and decryption algorithm that is stronger than the third encryption and decryption algorithm. This improves the practicality of the solution and improves the reliability and stability of the suspicious program.

[0078] In the above schemes S101 to S103, the first encryption and decryption algorithm has a corresponding relationship with the second encryption and decryption algorithm, and the encryption and decryption strength of the first encryption and decryption algorithm is less than the encryption and decryption strength of the second encryption and decryption algorithm, which is equivalent to the first encryption and decryption algorithm being a weak encryption and decryption algorithm and the second encryption and decryption algorithm being a strong encryption and decryption algorithm; the Java agent is used to determine the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program. When the third encryption and decryption algorithm is determined to be the first encryption and decryption algorithm, that is, when the encryption and decryption algorithm strength in the target program is weak, based on the corresponding relationship, the Java agent can quickly modify the third bytecode corresponding to the third encryption and decryption algorithm to the second bytecode corresponding to the second encryption and decryption algorithm, without the need for manual replacement, and the replacement efficiency is high. In addition, since the corresponding relationship between the weak encryption and decryption algorithm and the strong decryption algorithm is set, the Java agent can achieve accurate replacement and good replacement effect.

[0079] The above describes the method provided by the embodiment of the present application, and the following describes the device provided by the embodiment of the present application.

[0080] 3 , based on the same inventive concept, an embodiment of the present invention provides a data processing device, including:

[0081] Exemplarily, the apparatus 300 includes:

[0082] Determining module 301, configured to determine a correspondence between a first encryption and decryption algorithm and a second encryption and decryption algorithm; the encryption and decryption strength of the first encryption and decryption algorithm is less than the encryption and decryption strength of the second encryption and decryption algorithm;

[0083] Processing module 302 is used to use the probe Java agent to determine the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration corresponding to the target program when the target program is started; if the third encryption and decryption algorithm is the first encryption and decryption algorithm, call the Java agent to modify the third bytecode corresponding to the third encryption and decryption algorithm used in the encryption and decryption algorithm declaration to the second bytecode corresponding to the second encryption and decryption algorithm based on the corresponding relationship, so that the target program calls the second encryption and decryption algorithm based on the second bytecode.

[0084] Optionally, when determining the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm, the determination module 301 is specifically used to: determine the computing resources required for each encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set; the encryption and decryption strength of any encryption and decryption algorithm in the pre-stored encryption and decryption algorithm set is greater than the encryption and decryption strength of the first encryption and decryption algorithm; according to preset conditions, determine the encryption and decryption algorithm that meets the preset conditions from the pre-stored encryption and decryption algorithm set as the second encryption and decryption algorithm; the preset conditions include that the computing resources required for the encryption and decryption algorithm are less than the idle computing resources of the server where the target program is located; and establish a correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm.

[0085] Optionally, when the determination module 301 determines, based on a preset condition, that the encryption / decryption algorithm that meets the preset condition is the second encryption / decryption algorithm from the pre-stored encryption / decryption algorithm set, it is specifically used to: prioritize the encryption / decryption algorithms in the pre-stored encryption / decryption algorithm set in descending order of the encryption / decryption strength of each encryption / decryption algorithm in the pre-stored encryption / decryption algorithm set; and determine, based on the order of priority from large to small, that the encryption / decryption algorithm that meets the preset condition is the second encryption / decryption algorithm from the pre-stored encryption / decryption algorithm set.

[0086] Optionally, after the determination module 301 determines that the third encryption and decryption algorithm is the first encryption and decryption algorithm, the processing module 302 is further used to: determine the method name of at least one method called by the target program in the process of executing the third encryption and decryption algorithm and the class name of each method call based on the stack information of the target program in the process of executing the third encryption and decryption algorithm; determine the multiple open source components included in the target program based on the method name of the at least one method and the class name of each method call; determine the suspicious program on the server where the target program is located, and the suspicious program includes more than a preset number of open source components among the multiple open source components; send an alarm message to the technician's equipment, the alarm message includes the suspicious program, and the alarm message is used to indicate to check whether the suspicious program includes the third encryption and decryption algorithm.

[0087] Optionally, the correspondence between the first encryption and decryption algorithm and the second encryption and decryption algorithm includes one first encryption and decryption algorithm corresponding to multiple second encryption and decryption algorithms.

[0088] It should be understood that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.

[0089] As a possible product form of the above-mentioned device, referring to FIG4 , an embodiment of the present application further provides an electronic device 400, including:

[0090] At least one processor 401; and a communication interface 403 communicatively connected to the at least one processor 401; the at least one processor 401 executes instructions stored in the memory 402, so that the electronic device 400 executes the method in the embodiment shown in Figure 1 through the communication interface 403.

[0091] Optionally, the memory 402 is located outside the electronic device 400 .

[0092] Optionally, the electronic device 400 includes the memory 402, which is connected to the at least one processor 401 and stores instructions executable by the at least one processor 401. FIG4 shows with dotted lines that the memory 402 is optional for the electronic device 400.

[0093] The processor 401 and the memory 402 may be coupled via an interface circuit or may be integrated together, which is not limited here.

[0094] The specific connection medium between the processor 401, memory 402, and communication interface 403 is not limited in the embodiments of the present application. In Figure 4, the processor 401, memory 402, and communication interface 403 are connected via bus 404. The bus is represented by a bold line in Figure 4. The connection between other components is only for schematic illustration and is not intended to be limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 4 only uses a single bold line, but this does not mean that there is only one bus or only one type of bus.

[0095] It should be understood that the processors mentioned in the embodiments of the present application can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor that is implemented by reading software code stored in a memory.

[0096] Exemplarily, the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0097] It should be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM).

[0098] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated into the processor.

[0099] It should be noted that the memory described herein is intended to include, but not be limited to, these and any other suitable types of memory.

[0100] As another possible product form, an embodiment of the present application also provides a computer-readable storage medium, which is used to store instructions. When the instructions are executed, the computer executes the method in the embodiment shown in Figure 1.

[0101] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0102] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.

[0103] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0104] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0105] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.

Claims

1. A data processing method, characterized in that, The method includes: Determining the correspondence between a first encryption / decryption algorithm and a second encryption / decryption algorithm; the encryption / decryption strength of the first encryption / decryption algorithm is less than that of the second encryption / decryption algorithm; When the target program starts, using a probe Java agent to determine the third encryption / decryption algorithm used in the encryption / decryption algorithm declaration corresponding to the target program; If the third encryption / decryption algorithm is the first encryption / decryption algorithm, calling the Java agent to modify the third bytecode corresponding to the third encryption / decryption algorithm used in the encryption / decryption algorithm declaration to the second bytecode corresponding to the second encryption / decryption algorithm based on the correspondence, so that the target program calls the second encryption / decryption algorithm based on the second bytecode.

2. The method according to claim 1, characterized in that, The determining the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm includes: Determining the computing resources required for each encryption / decryption algorithm in a pre-stored set of encryption / decryption algorithms; the encryption / decryption strength of any encryption / decryption algorithm in the pre-stored set of encryption / decryption algorithms is greater than that of the first encryption / decryption algorithm; According to a preset condition, determining, from the pre-stored set of encryption / decryption algorithms, the encryption / decryption algorithm that meets the preset condition as the second encryption / decryption algorithm; the preset condition includes that the computing resources required by the encryption / decryption algorithm are less than the idle computing resources of the server where the target program is located; Establishing the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm.

3. The method according to claim 2, wherein The determining, according to the preset condition, the encryption / decryption algorithm that meets the preset condition as the second encryption / decryption algorithm from the pre-stored set of encryption / decryption algorithms includes: Sorting the encryption / decryption algorithms in the pre-stored set of encryption / decryption algorithms in descending order of the encryption / decryption strength of each encryption / decryption algorithm in the pre-stored set of encryption / decryption algorithms; Determining, in descending order of priority, the encryption / decryption algorithm that meets the preset condition from the pre-stored set of encryption / decryption algorithms as the second encryption / decryption algorithm.

4. The method according to claim 1, wherein After determining that the third encryption / decryption algorithm is the first encryption / decryption algorithm, the method further includes: According to the stack information during the execution of the third encryption / decryption algorithm by the target program, determining the method name of at least one method called during the execution of the third encryption / decryption algorithm by the target program and the class name of each method call; Determining multiple open-source components included in the target program according to the method name of the at least one method and the class name of each method call; Determining a suspicious program on the server where the target program is located, the suspicious program including more than a preset number of open-source components among the multiple open-source components; Sending an alarm message to the technician's device, the alarm message including the suspicious program, and the alarm message is used to indicate checking whether the suspicious program includes the third encryption / decryption algorithm.

5. The method according to claim 1, characterized in that The correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm includes one first encryption / decryption algorithm corresponding to multiple second encryption / decryption algorithms.

6. A data processing device, characterized in that, The device includes: A determination module, configured to determine the correspondence between a first encryption / decryption algorithm and a second encryption / decryption algorithm; the encryption / decryption intensity of the first encryption / decryption algorithm is less than that of the second encryption / decryption algorithm; A processing module, configured to, when a target program starts, use a probe Java agent to determine a third encryption / decryption algorithm used in the encryption / decryption algorithm declaration corresponding to the target program; if the third encryption / decryption algorithm is the first encryption / decryption algorithm, call the Java agent to modify the third bytecode corresponding to the third encryption / decryption algorithm used in the encryption / decryption algorithm declaration to the second bytecode corresponding to the second encryption / decryption algorithm based on the correspondence, so that the target program calls the second encryption / decryption algorithm based on the second bytecode.

7. The device according to claim 6, characterized in that, When determining the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm, the determination module is specifically configured to: Determine the computing resources required for each encryption / decryption algorithm in a pre-stored set of encryption / decryption algorithms; the encryption / decryption intensity of any encryption / decryption algorithm in the pre-stored set of encryption / decryption algorithms is greater than that of the first encryption / decryption algorithm; According to a preset condition, determine, from the pre-stored set of encryption / decryption algorithms, the encryption / decryption algorithm that meets the preset condition as the second encryption / decryption algorithm; the preset condition includes that the computing resources required for the encryption / decryption algorithm are less than the idle computing resources of the server where the target program is located; Establish the correspondence between the first encryption / decryption algorithm and the second encryption / decryption algorithm.

8. The device according to claim 7, characterized in that, When determining, according to the preset condition, from the pre-stored set of encryption / decryption algorithms, the encryption / decryption algorithm that meets the preset condition as the second encryption / decryption algorithm, the determination module is specifically configured to: Sort the encryption / decryption algorithms in the pre-stored set of encryption / decryption algorithms in descending order of the encryption / decryption intensity of each encryption / decryption algorithm in the pre-stored set of encryption / decryption algorithms; Determine, in descending order of priority, from the pre-stored set of encryption / decryption algorithms, the encryption / decryption algorithm that meets the preset condition as the second encryption / decryption algorithm.

9. An electronic device, characterized in that, Includes: At least one processor; And a memory and a communication interface communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the at least one processor, by executing the instructions stored in the memory, enables the electronic device to execute the method according to any one of claims 1 to 5 through the communication interface.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions run on a computer, enables the computer to execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Encryption software application extension method and device, electronic equipment and storage medium

    CN114676443A

  • Data opening security visual supervision system and method and storage medium

    CN115510433A

  • Data processing method and device, equipment and storage medium

    CN117786624A

  • Method for dynamically transforming the bytecode of JAVA virtual machine bootstrap classes

    US20140075422A1