Improved AES (Advanced Encryption Standard) encryption method and system with side channel attack resistance attribute

By introducing the exclusive OR operation of variable-length random number matrix and intermediate matrix into the AES encryption algorithm, the problem of low security and susceptibility to side channel attacks is solved, and higher data security and attack resistance are achieved.

CN119995837APending Publication Date: 2025-05-13SICHUAN VOCATIONAL & TECHN COLLEGE OF COMM
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510368179.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing AES encryption algorithms are less secure and are susceptible to time-side channel and power-side channel attacks.

Method used

During the encryption process, variable-length random numbers are generated to form a random number matrix, and an intermediate matrix is ​​formed with the data in the S box, a round key is generated, and a round key addition operation is performed on the AES standard encrypted data.

Benefits of technology

By introducing the XOR operation of the random number matrix and the intermediate matrix, the anti-side channel attack capability of AES encryption is improved, data security is enhanced, and encryption performance is not significantly reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995837A_ABST
    Figure CN119995837A_ABST
Patent Text Reader

Abstract

The invention discloses an improved AES (Advanced Encryption Standard) encryption method and an improved AES encryption system with a side channel attack resistance attribute, namely, an encryption key is used for carrying out AES encryption on the same plaintext data for multiple times, and a ciphertext generated by each time of encryption is randomly changed and has a certain side channel attack resistance attribute. According to the principle, a variable-length random number mechanism is introduced on the basis of a standard AES encryption algorithm, so that time and power consumed by each AES encryption have certain variability, and the capability of resisting time side channel attack and power consumption side channel attack is improved; a random number matrix and an S-box intermediate matrix are introduced to obtain a reinforced round key, and finally, the round key is used for carrying out round key addition operation on an AES standard ciphertext, so that when the same encryption key is used for carrying out AES encryption on the same data, the ciphertext result after each encryption is randomized, the effect similar to that of RSA public key encryption is achieved, and the encryption efficiency is improved. The security of the data ciphertext is improved, and the encryption and decryption performance is far faster than that of the RSA algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to an improved AES encryption and decryption method and system, belonging to the technical field of data security. Background Art

[0002] The AES encryption algorithm is a very popular encryption algorithm internationally. It is a symmetric encryption algorithm. The same key is used for encryption and decryption. Data is encrypted in groups of 16 bytes. The AES encryption algorithm supports three key lengths: 16 bytes, 24 bytes, and 32 bytes. The corresponding encryption algorithms can be subdivided into AES-128, AES-192, and AES-256 encryption algorithms. AES uses complex operations such as byte-based replacement, row shift, column confusion, and round key addition. These operations are performed in each round of encryption. The number of rounds depends on the key length. AES-128 iterates 10 rounds, AES-192 iterates 12 rounds, and AES-256 iterates 14 rounds. The AES algorithm has been widely used both internationally and domestically.

[0003] Block cipher technology represented by AES has many advantages such as fast encryption and decryption speed, simple implementation, high efficiency and stability. It plays an important role in the field of data security, but also has some hidden dangers and challenges.

[0004] On the one hand, AES encryption is a symmetric encryption algorithm. For fixed data and keys, the output result of each encryption is the same. As processor performance improves, there are certain security risks. On the other hand, in the standard AES encryption algorithm, the calculation time and power of each step are basically fixed. For data and keys of fixed length, the total encryption time and power consumption of each encryption are very close, which makes it vulnerable to side channel attacks such as time side channel attacks and power consumption side channel attacks.

[0005] In view of the above problems, this application proposes a solution. Summary of the invention

[0006] The purpose of this application is to provide an improved AES encryption method to solve the problem that the existing AES encryption algorithm has low security and is susceptible to time side channel and power consumption side channel attacks.

[0007] The technical problem to be solved by this application is: how to provide an AES encryption method that has the property of resisting side-channel attacks and can improve data security.

[0008] The purpose of this application can be achieved through the following technical solutions:

[0009] Based on the standard AES encryption method, variable-length random numbers are generated during the encryption process to form a random number matrix. The data in the S-box is used to form an intermediate matrix, which is used together with the random number matrix to generate round keys. Finally, the round key addition operation is performed on the AES standard encrypted data.

[0010] The specific technical solution of the improved AES encryption method with anti-side channel attack properties includes:

[0011] 1. Initialization operation, performed once before AES encryption, includes the following 4 operations:

[0012] (1) Set the random number length n, the value of n is not greater than 16;

[0013] (2) Set the maximum random number length to , k is an integer and is set to a larger value;

[0014] (3) Optionally, set a strategy for selecting a 4th-order intermediate matrix from the S-box; if not set, the first 4 rows and 4 columns in the S-box are selected by default to form a 4th-order intermediate matrix;

[0015] (4) Optionally, set a combination strategy of AES ciphertext and random number output with ciphertext. The random number output with ciphertext can be set to be placed after the AES reinforced ciphertext, or it can be set to be inserted into the AES reinforced ciphertext. If not set, the default strategy is 16 bytes of AES reinforced ciphertext + n bytes of random number output with ciphertext.

[0016] 2. Generate a random number of variable length, and select a random value m according to the random number length n set during initialization , generate a random number with actual length m.

[0017] 3. Form a 4th-order initial random number matrix. If the random number length m is not less than 16, directly select the first 16 bytes of random numbers to form a 4th-order initial random number matrix R init ; If the random number length m is less than 16, the m random numbers are filled from front to back to form 16 bytes, and a 4-order initial random number matrix R is formed init .

[0018] 4. Generate the final random number matrix of order 4, including 2 steps:

[0019] (1) According to the selection strategy during initialization, select 4 rows and 4 columns of data from the 16-order S-box matrix to form a 4-order intermediate matrix S mid ;

[0020] (2) The 4th-order initial random number matrix R init and the 4th-order intermediate matrix S midXOR by element position to get the final random number matrix of order 4 , R final As a reinforcement wheel key.

[0021] 5. From the 4th order final random number matrix R final In the sequence from top to bottom and from left to right, n elements are selected to form the random number output along with the ciphertext.

[0022] 6. The 4th-order ciphertext matrix C that completes the last round of standard AES encryption operation std And the 4th-order final random number matrix R final XOR by element position to get AES reinforced ciphertext ; Further, for the AES-128 encryption algorithm, C std Refers to the result after completing 10 rounds of key addition operations; for the AES-192 encryption algorithm, C std Refers to the result after completing 12 rounds of key addition operations; for the AES-256 encryption algorithm, C std Refers to the result after completing 14 rounds of key addition operations.

[0023] 7. Based on the strategy set in the initialization, the AES reinforcement ciphertext and the random number output with the ciphertext are combined to finally obtain the AES output ciphertext; wherein the combination method can be the reinforcement ciphertext concatenated with the random number output with the ciphertext C1C2C3C4C5C6C7C8C9C 10 C 11 C 12 C 13 C 14 C 15 C 16 R1…R n , or you can convert n-byte random number elements R1…R n Insert into the reinforced ciphertext C1C2C3C4C5C6C7C8C9C respectively 10 C 11 C 12 C 13 C 14 C 15 C 16 The specified position in .

[0024] 8. Perform a restore operation on the random number output with the ciphertext of n bytes to obtain the final random number matrix of order 4, including three steps:

[0025] (1) Construct a 4th-order matrix R whose elements are initially all 0 init , fill n bytes with the ciphertext output random number in bytes, from top to bottom and from left to right into R init In the above example, we get the 4th-order temporary random number matrix R. tmp;

[0026] (2) The 4th-order temporary random number matrix R tmp and the 4th-order intermediate matrix S mid XOR by element position to get a 4th-order intermediate random number matrix ;

[0027] (3) From top to bottom and from left to right, from the 4th-order intermediate random number matrix R mid Extract the first n elements from the matrix and add these n elements to the remaining 16-n positions in a circular insertion manner. After the circular insertion is completed, the final random number matrix R of order 4 is obtained. final .

[0028] Restoring the AES hardened ciphertext to obtain the AES standard ciphertext includes two steps:

[0029] (1) Insert the 16-byte AES hardened ciphertext into a 4-order matrix from top to bottom and from left to right to form a 4-order AES hardened ciphertext matrix C. safe ;

[0030] (2) The 4th-order AES reinforced ciphertext matrix C safe And the 4th-order final random number matrix R final XOR by element position to get the 4th order AES standard ciphertext .

[0031] Supplementary explanation: The technical solutions described in

[0011] -

[0023] are applicable to AES encryption, and the technical solutions described in

[0024] -

[0030] are applicable to AES decryption.

[0032] The advantages of this application include the following two aspects:

[0033] 1. Introduce random number matrix R init and the S-box intermediate matrix S mid , R init and S mid Get the reinforcement round key R by XORing the element position final , using R final By performing round-by-round key addition operations on the data after the last round of standard AES key addition operations, it is possible to use the same encryption key to perform AES encryption on the same data. The ciphertext result will change after each encryption, which has a similar effect to RSA public key encryption. It improves the security of the data ciphertext itself, and at the same time, the encryption performance is not significantly reduced, which is much faster than RSA public key encryption.

[0034] 2. When generating random numbers, a variable-length random number mechanism is introduced to make the time and power consumed by each AES encryption have a certain degree of variability, thereby improving the ability to resist time side channel attacks and power consumption side channel attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0036] Figure 1 Schematic diagram of the overall process of the improved AES encryption algorithm implemented in this application;

[0037] Figure 2 A detailed flowchart of the improved AES encryption algorithm implemented in this application;

[0038] Figure 3 Schematic diagram of the overall decryption process of the improved AES encryption algorithm implemented in this application;

[0039] Figure 4 Detailed decryption flow chart of the improved AES encryption algorithm implemented in this application. DETAILED DESCRIPTION

[0040] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present invention.

[0041] like Figure 2 As shown, the specific process of improved AES encryption includes the following steps:

[0042] Step P1, perform an initialization operation before using AES encryption, including setting the random number length n, the value of n is not greater than 16; setting the maximum random number length generated to , k is an integer; set the strategy for selecting a 4th-order intermediate matrix from the S-box. If not set, the first 4 rows and 4 columns in the S-box are selected by default to form a 4th-order intermediate matrix; set the combination strategy of AES ciphertext and random number output with ciphertext. If not set, the default strategy is 16 bytes of AES reinforced ciphertext + n bytes of random number output with ciphertext;

[0043] Step P2, perform the round key addition operation in the standard AES algorithm, expand the AES encryption key into the round key, group the input plaintext into 16-byte units, encrypt each group into a 4-order matrix, and then perform byte-by-byte XOR with the elements in the round key; if the CBC encryption mode is used, convert the initial vector IV and the group into a 4-order matrix respectively, perform element-by-element position XOR with the elements in the round key in byte units, and then perform byte-by-byte XOR with the elements in the round key; the output result of the operation in step P2 is used as input for step P3;

[0044] Step P3, perform the byte substitution operation in the standard AES algorithm, pass the input 4-order matrix through the S box, and perform byte transformation; the output result of the step P3 operation is used as input for step P4;

[0045] Step P4, perform the row shift operation in the standard AES algorithm, keep the first row of the input 4-order matrix unchanged, circularly shift the second row to the left by 1 byte, circularly shift the third row to the left by 2 bytes, and circularly shift the fourth row to the left by 3 bytes; the output result of the operation in step P4 is used as input for step P5;

[0046] Step P5, performing a column mixing operation in the standard AES algorithm, multiplying the input 4th-order matrix with the given 4th-order positive matrix to confuse the original data; the output result of the operation in step P5 is used as input for step P6;

[0047] Step P6, performing the round key addition operation in the standard AES algorithm, performing byte-wise XOR of the input 4th-order matrix and the elements in the round key;

[0048] Loop through the byte substitution operation of step P3, the row shift operation of step P4, the column mixing operation of step P5, and the round key addition operation of step P6, and count the number of loops c; if it is the AES-128 algorithm and c is 9, execute step P7, otherwise jump to step P3 to continue the loop; if it is the AES-192 algorithm and c is 11, execute step P7, otherwise jump to step P3 to continue the loop; if it is the AES-256 algorithm and c is 13, execute step P7, otherwise jump to step P3 to continue the loop;

[0049] Step P7, execute the last round of byte substitution operation in the standard AES algorithm, pass the input 4-order matrix through the S box, and perform byte transformation; the output result of the operation in step P7 is used as input for step P8;

[0050] Step P8, performing the last round of row shift operation in the standard AES algorithm, keeping the first row of the input 4-order matrix unchanged, cyclically shifting the second row to the left by 1 byte, cyclically shifting the third row to the left by 2 bytes, and cyclically shifting the fourth row to the left by 3 bytes; the output result of the operation in step P8 is used as input for step P9;

[0051] Step P9, perform the last round key addition operation in the standard AES algorithm, and perform byte-wise XOR on the input 4th-order matrix and the elements in the round key; the output result of step P9 operation is the AES standard ciphertext: the 4th-order ciphertext matrix C std , which is used as input for step P14;

[0052] Step P10, generate a random number of variable length, and select a random value m according to the random number length n set during initialization , generate a random number with an actual length of m and use it as input for step P11;

[0053] Step P11, forming a 4th order initial random number matrix. If the random number length m is not less than 16, directly select the first 16 bytes of random numbers to form a 4th order initial random number matrix R init ; If the random number length m is less than 16, the m random numbers are filled from front to back to form 16 bytes, and a 4-order initial random number matrix R is formed init , and use it as input for step P13;

[0054] Step P12, first, according to the selection strategy during initialization, select 4 rows and 4 columns of data from the 16-order S-box matrix to form a 4-order intermediate matrix S mid , and use it as input for step P13;

[0055] Step P13, generate a 4th order final random number matrix, and replace the 4th order initial random number matrix R generated in step P11 with init and the 4th-order intermediate matrix S generated in step P12 mid XOR by element position to get the final random number matrix of order 4 , which is used as input for steps P14 and P15;

[0056] Step P14, from the 4th order final random number matrix R final In the sequence from top to bottom and from left to right, n elements are selected to form a random number output along with the ciphertext, and the random number is used as input for step P16;

[0057] Step P15, R final As the reinforcement round key, the 4-order ciphertext matrix C generated in step P9 is std and the fourth-order final random number matrix R generated in step P13final XOR by element position to get AES reinforced ciphertext , and use it as input for step P16;

[0058] Step P16, based on the strategy set initially, combines the random number output along with the ciphertext generated in step P14 and the AES reinforced ciphertext generated in step P15 to obtain the final AES ciphertext for output.

[0059] At this point, all steps of the improved AES encryption have been completed; before encryption, the plaintext is grouped in units of 16 bytes, and then encrypted in units of groups; after encryption, the output ciphertext length of each group is 16+n, where n is the length of the random number output with the ciphertext.

[0060] like Figure 4 As shown, the specific process of improved AES decryption includes the following steps:

[0061] Step S1, decompose the ciphertext into groups, each group size is 16+n, and parse the groups according to the rules set in the initialization;

[0062] Step S2, by parsing, obtain a 16-byte AES reinforced ciphertext and an n-byte random number output along with the ciphertext;

[0063] Step S3: construct a 4th-order matrix R whose elements are all 0 initially. init , fill n bytes with the ciphertext output random number in bytes, from top to bottom and from left to right into R init In the above example, we get the 4th-order temporary random number matrix R. tmp ;

[0064] Step S4, according to the selection strategy during initialization, select 4 rows and 4 columns of data from the 16-order S-box matrix to form a 4-order intermediate matrix S mid ;

[0065] Step S5: convert the 4th order temporary random number matrix R tmp and the 4th-order intermediate matrix S mid XOR by element position to get a 4th-order intermediate random number matrix ;

[0066] Step S6, from top to bottom and from left to right, from the 4th order intermediate random number matrix R mid Extract the first n elements from the matrix and add these n elements to the remaining 16-n positions in a circular insertion manner. After the circular insertion is completed, the final random number matrix R of order 4 is obtained. final ;

[0067] Step S7, convert the 16-byte AES reinforced ciphertext into a 4th-order matrix and compare it with the 4th-order final random number matrix R final Perform XOR on the element positions to obtain a 4th-order standard AES ciphertext matrix; the output result of step S7 is used as input for step S8;

[0068] Step S8, perform the standard AES decryption initial operation, expand the key into a round key, and perform the round key addition operation; the output result of the operation in step S8 is used as input for step S9;

[0069] Step S9, performing the inverse shift operation of the standard AES decryption algorithm, and performing byte transformation on the input 4-order matrix through the inverse S-box; the output result of the operation in step S9 is used as input for step S10;

[0070] Step S10, performing the inverse byte substitution operation of the standard AES decryption algorithm, keeping the first row of the input 4-order matrix unchanged, cyclically shifting the second row to the right by 1 byte, cyclically shifting the third row to the right by 2 bytes, and cyclically shifting the fourth row to the right by 3 bytes; the output result of the operation in step S10 is used as input for step S11;

[0071] Step S11, performing round key addition operation of the standard AES decryption algorithm; the output result of the operation in step S11 is used as input for step S12;

[0072] Step S12, performing the inverse column mixing operation of the standard AES decryption algorithm, multiplying the input 4th-order matrix with the given 4th-order inverse matrix to restore the original data; the output result of the operation in step S12 is used as input for step S13;

[0073] Loop through the reverse row shift operation of step S9, the reverse byte substitution operation of step S10, the round key addition operation of step S11, and the reverse column mixing operation of step S12, and count the number of loops c; if it is the AES-128 algorithm and c is 9, execute step P7, otherwise jump to step P3 to continue the loop; if it is the AES-192 algorithm and c is 11, execute step P7, otherwise jump to step P3 to continue the loop; if it is the AES-256 algorithm and c is 13, execute step P7, otherwise jump to step P3 to continue the loop;

[0074] Step S13, performing the last round of inverse byte substitution operation of the standard AES decryption algorithm, keeping the first row of the input 4-order matrix unchanged, cyclically shifting the second row to the right by 1 byte, cyclically shifting the third row to the right by 2 bytes, and cyclically shifting the fourth row to the right by 3 bytes; the output result of the operation in step S13 is used as input for step S14;

[0075] Step S14, performing the last round of reverse shift operation of the standard AES decryption algorithm, and performing byte transformation on the input 4-order matrix through the inverse S-box; the output result of the operation in step S14 is used as input for step S15;

[0076] Step S15, executing the last round of key addition operation of the standard AES decryption algorithm, and obtaining the plain text after the operation is completed.

[0077] At this point, all steps of the improved AES decryption are completed; the improved AES decrypts in groups. Before decryption, the ciphertext length of each group is 16+n, where n is the length of the random number output with the ciphertext; after decryption, the plaintext is obtained in groups of 16 bytes.

[0078] The embodiments disclosed above are only used to help explain the present application. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can better understand and use the present invention. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. An improved AES encryption and decryption method with side-channel attack resistance. The method is characterized in that: include: Initialization operation, generating random numbers of variable length to form an initial random number matrix; Generate the final random number matrix and determine the random number to be output along with the ciphertext; Generate AES reinforcement ciphertext to form AES output ciphertext; Perform a restore operation on the random numbers output with the ciphertext to obtain the final random number matrix; Perform a restore operation on the AES reinforced ciphertext to obtain the AES standard ciphertext.

2. The improved AES encryption method with side channel attack resistance according to claim 1, characterized in that: Initialization operation generates random numbers of variable length to form an initial random number matrix, including: Set the random number length n, the value of n is not greater than 16; Set the maximum random number length to , k is an integer greater than 1; Set the strategy for selecting a 4-order intermediate matrix from the S-box. By default, the first 4 rows and 4 columns in the S-box are selected to form the intermediate matrix. Set the combination strategy of AES ciphertext and random number output with ciphertext. You can set the random number output with ciphertext to be placed after the AES reinforced ciphertext or insert it into the AES reinforced ciphertext. The default strategy is 16-byte AES reinforced ciphertext + n-byte random number output with ciphertext. According to the random number length n set during initialization, the actual length generated is m A random number; If the random number length m is not less than 16, directly select the first 16 bytes of random numbers to form a 4-order initial random number matrix R init ; If the random number length m is less than 16, the m random numbers are filled from front to back to form 16 bytes, and a 4-order initial random number matrix R is formed init .

3. The improved AES encryption method with side channel attack resistance according to claim 2, characterized in that: Generate the final random number matrix and determine the random number output along with the ciphertext, including: According to the selection strategy during initialization, 4 rows and 4 columns of data are selected from the 16-order S-box matrix to form a 4-order intermediate matrix S mid ; The initial random number matrix R init and the intermediate matrix S mid XOR by element position to get the final random number matrix ; From the final random number matrix R final In the sequence from top to bottom and from left to right, n elements are selected to form the random number output along with the ciphertext.

4. The improved AES encryption method with side channel attack resistance according to claim 3, characterized in that: Generate AES reinforced ciphertext and form AES output ciphertext, including: The 4th-order ciphertext matrix C that will complete the last round of AES encryption operation std And the final random number matrix R final XOR by element position to get AES reinforced ciphertext ; Based on the initialization policy, the AES reinforced ciphertext and the random number output with the ciphertext are combined to obtain the AES output ciphertext.

5. The improved AES encryption method with side channel attack resistance according to claim 4, characterized in that: Perform a restore operation on the random numbers output with the ciphertext to obtain the final random number matrix, including: First construct a 4th-order matrix R whose elements are initially all 0 init Then fill the n random numbers output with the ciphertext into R from top to bottom and from left to right. init In the above example, we get the temporary random number matrix R. tmp ; The temporary random number matrix R tmp With the intermediate matrix S mid XOR by element position to get the intermediate random number matrix ; From top to bottom and from left to right, from the middle random number matrix R mid Extract the first n elements from the random number matrix R, and add these n elements to the remaining 16-n positions in a circular insertion manner. After the circular insertion is completed, the final random number matrix R is obtained. final .

6. The improved AES encryption method with side channel attack resistance according to claim 5, characterized in that: Restore the AES hardened ciphertext to obtain the AES standard ciphertext, including: Insert the AES reinforced ciphertext into the 4th-order matrix from top to bottom and from left to right to form the AES reinforced ciphertext matrix C safe ; The AES reinforced ciphertext matrix C safe And the final random number matrix R final XOR by element position to get AES standard ciphertext .

7. An improved AES encryption and decryption system with side-channel attack resistance, characterized in that: The invention comprises a processor and a memory storing computer program instructions, wherein when the computer program instructions are executed by the processor, the improved AES encryption and decryption method with side channel attack resistance property as claimed in any one of claims 1 to 6 is executed.

Citation Information

Cited By

  • Secure encryption and decryption method and system for resisting side channel attack

    CN120185795A

  • A secure encryption and decryption method and system for resisting side channel attacks

    CN120185795B

  • Meteorological observation data hybrid encryption method and device based on polling key, and medium

    CN121547282A

  • Data security communication method of 6G terahertz communication system

    CN121568099A

  • A data security communication method of a 6G terahertz communication system

    CN121568099B