APK Hardening Build and Runtime Lifecycle

加固不是给原 APK 外面套一层 ZIP:它会改写构建产物、启动入口、类加载路径和运行时完整性逻辑

APK hardening build and runtime lifecycle A release artifact passes through compiler optimization, selective protection, package rewriting, alignment and signing, then executes through a shell loader, integrity gates, payload loading, protected logic, and server attestation. PHASE A / CI, HARDENING SERVICE AND RELEASE PIPELINE PHASE B / ANDROID PROCESS STARTUP AND PROTECTED EXECUTION policy-controlled response 1. Release BuildKotlin/Java + NDK + resourcesdebuggable off / symbols archivedproduce APK or AAB input 2. Optimize and SelectR8 shrink / optimize / obfuscatemark high-value methods and assetspreserve mapping and keep rules 3. Harden and Rewriteencrypt / extract / VMP / RASP injectstub entry + loader + integrity policyoutput is a different package 4. Verify and Alignmanifest / ABI / resources / splitszipalign before modern APK signingrun smoke and compatibility tests 5. Sign and PublishAPK v2/v3 or AAB upload keyverify cert / provenance / rolloutno post-sign byte rewriting 6. Package InstallPackage Manager verifies signerOS identity and update continuitynot an anti-reversing check 7. Stub Starts EarlyApplication / Provider / native bootstrapinitialize shell before business codestartup order is compatibility-critical 8. Local Integrity Gatescertificate / files / memory / runtimedebug, hook, root and emulator signalslocal checks remain patchable 9. Materialize Semanticsdecrypt/load class or dispatch VM codeART/JNI executes an equivalent meaningthis is the unavoidable observation point 10. Bind Server Actionattestation + install handle + requestbackend verifies freshness and policyauthorization leaves the client RUNTIME RESPONSE POLICY Report, degrade, challenge, delay or stop according to feature value and confidence; a universal process exit turns false positives into outages. RELEASE GATES THAT MATTER MORE THAN A FEATURE CHECKBOX COMPATIBILITYABI / API / OEM / split / framework PERFORMANCEcold start / memory / battery / jank OBSERVABILITYmapping / symbols / crash attribution PROVENANCEhash / cert / SBOM / reproducibility ENFORCEMENTshadow mode / tiers / rollback

顺序不能乱

  • 现代 APK 通常先加固、对齐,再使用发布密钥签名
  • AAB 需遵守加固厂商与 Play App Signing 的专用流程
  • 签名后任何字节改写都会破坏 v2/v3 完整性

明文不一定落盘

  • 现代方案可采用内存类加载、方法抽取或 VM 调度
  • 但处理器最终必须执行与原逻辑等价的语义
  • 保护目标是缩短窗口并打散稳定锚点

上线门槛不只是能启动

  • 需要覆盖冷启动、崩溃、ANR、耗电和机型分布
  • 保留 mapping、符号、构建哈希和回滚产物
  • 处置策略先观察,再逐级增加摩擦