Method, device, medium and program product for constructing initial vector based on combination counter

By constructing the initial vector through a combination of counters, and combining the cycle counter and the communication counter, the problems of initial vector reuse risk and shortened device life in the wireless system are solved, and secure communication and extended device life are achieved.

CN119519963BActive Publication Date: 2025-09-23NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411660381.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-20
Publication Date
2025-09-23
Estimated Expiration
2044-11-20

AI Technical Summary

Technical Problem

When constructing initial vectors in existing technologies, the random factor method has the risk of reuse, and the one-way factor method frequently erases the device's non-volatile memory, resulting in a shortened device lifespan. This makes it difficult to ensure system security and device lifespan in resource-constrained wireless systems.

Method used

A combination counter is used to construct an initial vector, which is combined with a cycle counter and a communication counter. The combination counter is transmitted through a channel to reduce communication resource usage and to erase and write non-volatile memory at specific times to extend the life of the device.

Benefits of technology

Without increasing the communication resource usage and device erasure frequency, the uniqueness and security of system information transmission are guaranteed, thus extending the service life of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119519963B_ABST
    Figure CN119519963B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of information security technology and provides a method, device, medium, and program product for constructing an initialization vector (IV) based on a combination counter. The method comprises: two communicating parties agreeing in advance on a padding number; and using the combination counter and the padding number to jointly construct an initialization vector (IV) for encryption and decryption. The method proposed in the present invention is a special method based on multiple combination digital counters, such as a cycle counter and a communication counter. In combination with channel transmission resource requirements, the cycle counter and the communication counter are represented by reasonable calculations. This method ensures one-time, one-key system information transmission and meets system security communication requirements while utilizing fewer communication resources and without compromising system lifespan. The method has broad application prospects, particularly in wireless system applications where channel transmission resources are relatively limited.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a method, device, medium and program product for constructing an initialization vector based on a combination counter. Background Art

[0002] In 1949, Shannon proved that the "one-time pad" cryptosystem is theoretically unbreakable. To ensure system security, the initial state used by the key generator each time it generates a key sequence during the key rotation cycle (i.e., the initial state vector (IV), which can be transmitted along with the ciphertext over the channel) must meet uniqueness requirements or specific randomness requirements within the system's acceptable reuse limits. Based on current scientific and technological conditions, there are two main methods for constructing the initialization vector (IV): random factor construction and one-way factor construction.

[0003] When using random factors to construct the initialization vector, the randomness of the data inevitably leads to the possibility of data reuse, making it impossible to ensure complete data uniqueness, which poses a certain security risk to the system. While increasing the length of the random number can reduce the probability of reuse, it also increases the amount of data required to be transmitted over the channel to the recipient, making it less suitable for wireless systems with limited channel resources.

[0004] When using a one-way factor to construct an initialization vector, if there is one-way increasing or decreasing information in the system that can strictly guarantee one-way non-repetition, such as time reference, angle change, spatial position, etc., or based on a pure digital counter, it can all be used as a one-way factor to construct and generate the initialization vector. However, the used initialization vector needs to be recorded during each encryption, and the device's non-volatile memory needs to be frequently erased, which may cause the device to fail and shorten its service life. Summary of the Invention

[0005] Building on traditional methods for constructing initialization vectors (IVs) for stream ciphers, this invention proposes a method, device, medium, and program product for constructing IVs based on combinational counters, specifically for generating one-way factors. This method utilizes a unique method based on multiple digital counters, such as cycle counters and communication counters. By rationally representing these counters using calculations, and taking into account channel transmission resource requirements, it ensures one-time padding for system information transmission and meets system security requirements, while minimizing communication resource usage and preserving system lifespan. This method holds great promise for widespread application in wireless systems, particularly where channel transmission resources are limited.

[0006] The present invention provides a method for constructing an initialization vector based on a combination counter, comprising:

[0007] The communicating parties agree on the number of padding in advance;

[0008] The combined counter and padding number are used to form the initial vector IV in the encryption and decryption process.

[0009] In some embodiments, the combined counter consists of a communication counter and a cycle counter.

[0010] In some embodiments, the cycle counter is stored in a non-volatile memory and the communication counter is stored in a volatile memory.

[0011] In some embodiments, both the cycle counter and the communication counter are initially set to zero.

[0012] In some embodiments, only the combination counter is transmitted in the channel during communication.

[0013] In some embodiments, the combination counter operates as follows:

[0014] When the power is turned on, the cycle counter is incremented by 1 and written into the non-volatile memory;

[0015] During communication, each time a device sends a packet of encrypted information through the channel, the communication counter increases by 1, and the cycle counter remains unchanged; when the communication counter reaches the maximum value and rolls over to 0, the cycle counter increases by 1 and is written to the non-volatile memory;

[0016] When shutting down, the communication counter is cleared to 0 and the cycle counter remains unchanged;

[0017] When the key is changed, the cycle counter and the communication counter are both set to 0, and the cycle counter is written to the non-volatile memory.

[0018] The present invention further provides an electronic device, comprising:

[0019] at least one processor; and a memory communicatively coupled to the at least one processor;

[0020] The memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the above method by executing the instructions stored in the memory.

[0021] The present invention also provides a computer-readable storage medium, characterized in that the computer-readable storage medium is used to store instructions, and when the instructions are executed, the above method is implemented.

[0022] The present invention also provides a computer program product, which, when called by a computer, enables the computer to execute the above method.

[0023] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:

[0024] 1. Throughout the device's lifespan, the non-volatile memory recording the cycle counter value only needs to be written and erased when the device is powered on, the key is changed, or the communication counter reaches its maximum value. This significantly reduces the probability of writing and erasing the non-volatile memory, compared to erasing the non-volatile memory to record the counter change value every time a single digital counter changes. Furthermore, during communication, only the combined counter needs to be transmitted over the channel, significantly saving channel transmission space compared to transmitting the entire initialization vector.

[0025] 2. Evaluate the power-on and power-off frequency and packet sending frequency of the information sending device in the system, and reasonably set the representation range (bit length) of the communication counter and cycle counter to ensure that the initial vector is not reused within each key replacement cycle in a system with limited channel transmission resources. At the same time, minimize the number of times the device's non-volatile memory is erased and written, thereby extending the device's service life. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 Schematic diagram of an initialization vector constructed based on a combination counter in an embodiment of the present invention.

[0027] Figure 2 Schematic diagram of the change of the initial vector during the communication process in an embodiment of the present invention.

[0028] Figure 3 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0029] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Generally, the components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0030] Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the invention as claimed, but rather merely represents selected embodiments of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort are intended to fall within the scope of protection of the present invention.

[0031] An embodiment of the present invention provides a method for constructing an initialization vector based on a combination counter, including:

[0032] The communicating parties agree on the number of padding in advance;

[0033] The combined counter and padding number are used to form the initial vector IV in the encryption and decryption process.

[0034] With the initialization vector IV constructed as described above, only the combination counter needs to be transmitted in the channel during communication, thereby reducing the occupation of communication channel resources.

[0035] In the embodiment of the present invention, a single digital counter is abandoned and multiple digital counters are used to form a combination counter. The combination counter and the filler number form the initial vector for use in the cryptographic algorithm. The combination counter can be designed as a communication counter and a cycle counter. Figure 1 As shown, the design rules are: the cycle counter is stored in the non-volatile memory, and the communication counter is stored in the volatile memory; the cycle counter and the communication counter are both initially set to 0.

[0036] like Figure 2 As shown, the working method of the combination counter is as follows:

[0037] (1) When the power is turned on, the cycle counter is incremented by 1 and written into the non-volatile memory.

[0038] (2) During communication, each time a device sends a packet of encrypted information through the channel, the communication counter increases by 1, and the cycle counter remains unchanged; when the communication counter accumulates to the maximum value and rolls over to 0, the cycle counter increases by 1 and is written into the non-volatile memory.

[0039] (3) When shutting down, the communication counter is cleared to 0 and the cycle counter remains unchanged.

[0040] (4) When the key is changed, the cycle counter and communication counter are both set to 0, and the cycle counter is written to the non-volatile memory.

[0041] Based on the same technical concept, an embodiment of the present invention further provides an electronic device that can implement the method flow of constructing an initialization vector based on a combination counter provided in the above embodiment of the present invention. In one embodiment, the electronic device can be a server, or a terminal device or other electronic device. Figure 3 As shown, the electronic device may include:

[0042] At least one processor, and a memory connected to the at least one processor. The embodiment of the present invention does not limit the specific connection medium between the processor and the memory. Figure 3 The example in this article is that the processor and memory are connected via a bus. Figure 3 The connections between the other components are shown in bold lines, which are only for illustration and not intended to be limiting. The bus can be divided into address bus, data bus, control bus, etc. Figure 3 The processor is represented by a single thick line, but this does not mean that there is only one bus or only one type of bus. Alternatively, the processor can also be called a controller, without any limitation on the name.

[0043] In an embodiment of the present invention, the memory stores instructions that can be executed by at least one processor. The at least one processor can execute the method of constructing an initialization vector based on a combination counter discussed above by executing the instructions stored in the memory. The processor can implement Figure 3 The functions of each module in the device shown.

[0044] Among them, the processor is the control center of the device, which can use various interfaces and lines to connect the various parts of the entire control device, and monitor the device as a whole by running or executing instructions stored in the memory and calling data stored in the memory, the various functions of the device and processing data.

[0045] In an optional design, the processor may include one or more processing units, and the processor may integrate an application processor and a modem processor, wherein the application processor primarily processes the operating system, user interface, and application programs, and the modem processor primarily processes wireless communications. It is understood that the modem processor may not be integrated into the processor. In some embodiments, the processor and memory may be implemented on the same chip, or in some embodiments, they may be implemented on separate chips.

[0046] The processor can be a general-purpose processor, such as a CPU, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method for constructing an initialization vector based on a combinational counter disclosed in the embodiments of the present invention can be directly implemented and executed by a hardware processor, or by a combination of hardware and software modules within the processor.

[0047] As a non-volatile computer-readable storage medium, memory can be used to store non-volatile software programs, non-volatile computer executable programs and modules. Memory can include at least one type of storage medium, for example, can include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, disk, optical disk, etc. Memory is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory in the embodiment of the present invention can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.

[0048] By designing and programming the processor, the code corresponding to the method for constructing an initialization vector based on a combination counter described in the aforementioned embodiment can be embedded into the chip, thereby enabling the chip to perform the steps of the method for constructing an initialization vector based on a combination counter described in the aforementioned embodiment during operation. Designing and programming a processor is well known to those skilled in the art and will not be further described here.

[0049] Based on the same inventive concept, an embodiment of the present invention further provides a storage medium storing computer instructions. When the computer instructions are executed on a computer, the computer executes the method for constructing an initialization vector based on a combination counter discussed above.

[0050] In some optional embodiments, the present invention also provides various aspects of a method for constructing an initialization vector based on a combination counter, which can also be implemented in the form of a program product, which includes program code. When the program product is run on an apparatus, the program code is used to cause the control device to execute the steps of a method for constructing an initialization vector based on a combination counter according to various exemplary embodiments of the present invention described above in this specification.

[0051] It should be noted that although several units or subunits of the device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to an embodiment of the present invention, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of a unit described above can be further divided into multiple units to be embodied. In addition, although the operations of the method of the present invention are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired results. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step, and / or one step can be decomposed into multiple steps.

[0052] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0053] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as a combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a server, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the process in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0054] Program code for performing the operations of the present invention may be written using any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0055] Where a remote computing device is involved, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0056] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0057] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0058] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A method for constructing an initialization vector based on a combination counter, characterized in that: include: The communicating parties agree on the number of padding in advance; The combined counter and padding number are used to form the initial vector IV in the encryption and decryption process; The combination counter is composed of a communication counter and a cycle counter; the working method of the combination counter is as follows: When the power is turned on, the cycle counter is incremented by 1 and written into the non-volatile memory; During communication, each time a device sends a packet of encrypted information through the channel, the communication counter increases by 1, and the cycle counter remains unchanged; When the communication counter reaches the maximum value, it rolls over to 0, the cycle counter increases by 1, and is written into the non-volatile memory; When shutting down, the communication counter is cleared to 0 and the cycle counter remains unchanged; When the key is changed, the cycle counter and the communication counter are both set to 0, and the cycle counter is written to the non-volatile memory.

2. The method for constructing an initialization vector based on a combination counter according to claim 1, characterized in that: The cycle counter is stored in a non-volatile memory, and the communication counter is stored in a volatile memory.

3. The method for constructing an initialization vector based on a combination counter according to claim 2, characterized in that: The cycle counter and communication counter are both initially set to 0.

4. The method for constructing an initialization vector based on a combination counter according to any one of claims 1 to 3, characterized in that: During communication, only the combination counter is transmitted on the channel.

5. An electronic device, characterized in that: include: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the at least one processor executes the method according to any one of claims 1 to 4 by executing the instructions stored in the memory.

6. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store instructions, and when the instructions are executed, the method according to any one of claims 1 to 4 is implemented.

7. A computer program product, characterized in that When the computer program product is called by a computer, the computer is caused to execute the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Synchronizing method of initial vector IV in operating mode of packet cipher

    CN101286832A

  • Encrypting and decrypting methods and equipment

    CN103746814A