Flash encryption method for security chip, security chip and electronic equipment
By using two flash encryption modules in parallel cascaded in the security chip, encrypting using Feistel structure and different wheel functions and S-boxes, and enhancing ciphertext protection through address scrambling, the problems of flash encryption delay, low encryption strength, and high software and hardware communication costs in the existing technology are solved, and efficient encryption and secure storage are achieved.
Patent Information
- Application Number
- CN202510305428.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-06
AI Technical Summary
In the prior art, flash encryption has a long delay, low encryption strength, and high software and hardware communication costs, making it difficult to meet the requirements of high-speed security chips for delay and encryption strength.
Two flash encryption modules in parallel cascade are adopted. Each module uses a Feistel structure to encrypt and decrypt the target data. By dividing and grouping and encrypting with different wheel functions and S-boxes, the encryption strength is increased, and ciphertext protection is enhanced through address scrambling.
It shortens the delay of critical paths, increases the maximum operating frequency of the security chip, enhances encryption strength, reduces the cost of software and hardware communication, and improves the security of flash storage.
Smart Images

Figure CN120105501A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of digital security technology, and in particular to a flash encryption method for a security chip, a security chip and an electronic device. Background Art
[0002] With the development of attack methods and attack devices, the flash data inside the chip has also become unsafe. The flash of most chips stores sensitive information of the chip. Flash data leakage may cause the chip to not work properly and cause security problems. Therefore, the security of flash storage has become a research focus of digital security chips. Plain text storage data may be read out for analysis, tampered with and written to the flash, affecting data security. In order to enhance the application security of SoC (System on Chip) chips, SoC chips usually support data storage in flash for encryption. Specifically, for interface circuits that support encryption and decryption, in the flash write operation, the data is first encrypted and the encryption result is written to the flash; in the flash read operation, the read data is decrypted and sent out.
[0003] The existing flash encryption scheme usually uses a fixed key for encryption. In order to solve the problem of all 1s being read out after the flash is erased, a two-stage serial cascade scheme is used for two encryptions. However, the structure of the serial cascade will increase the delay of the critical path, which is not suitable for the delay requirements of the current high-speed security chip. The critical path refers to the longest path of the signal propagation delay, which determines the highest operating frequency of the chip. Specifically, the Flash is placed closer to the edge of the chip. The flash itself occupies a large area. The control logic will be placed and wound in the remaining space after the flash is placed. Generally, there is a certain distance from the data port of the flash. The structure of two identical encryption and decryption modules is serially cascaded, which makes the encryption delay twice that of a single encryption, which is not conducive to the convergence of the timing. Secondly, the existing technology uses two fixed keys for encryption and decryption, the encryption strength is not enough, and the data is easy to be cracked. Finally, in the existing technology, an indication signal is added to indicate that the data currently read out of the flash is all "1". For the software to determine whether the erasure is successful, it is necessary to check this flag first, which increases the communication cost of software and hardware and causes inconvenience to software implementation.
[0004] Therefore, there is an urgent need for a flash encryption method for a security chip to solve the problems of long delay, low encryption strength, and high software and hardware communication costs in the prior art. Summary of the invention
[0005] The present invention provides a flash encryption method for a security chip, a security chip and an electronic device, which are used to solve the defects of long flash encryption delay, low encryption strength and high software and hardware communication cost in the prior art.
[0006] The present invention provides a flash encryption method for a security chip, wherein the security chip comprises two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data whose values are all "1", and the second flash encryption module is used to encrypt and decrypt other target data; the method comprises: Each of the flash encryption modules uses a Feistel structure to encrypt and decrypt the target data; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each of the round functions uses a different S-box for nonlinear transformation; Each of the flash encryption modules scrambles the address based on a preset scrambling formula, and after obtaining the target address, stores the encrypted ciphertext based on the target address.
[0007] According to a flash encryption method for a security chip provided by the present invention, the target data is a 32-bit word, and the flash encryption module encrypts the target data based on the following steps: Divide the target data into four groups to obtain four data to be encrypted, each of which has a length of one byte; For the mth group of data to be encrypted, the mth group of data to be encrypted is evenly divided into a left half and a right half; wherein m is a positive integer For the i-th round, based on the i-th round subkey and the right half, encrypt using the round function corresponding to the m-th group, perform an XOR operation on the encryption result and the left half to obtain the right half of the i+1-th round, and use the right half as the left half of the i+1-th round; wherein i is a positive integer; After iterating for n rounds, the left half of the n+1th round is exchanged with the right half of the n+1th round, and then they are concatenated in left-right order to obtain the ciphertext corresponding to the mth group of data to be encrypted; The ciphertexts corresponding to the four data to be encrypted are concatenated in order to obtain the ciphertext corresponding to the target data.
[0008] According to a flash encryption method for a security chip provided by the present invention, a subkey used in each round is different, and the subkey is generated based on a master key, and the master key is generated based on the following steps: Based on a preset operation method, the fixed key value is operated with the address to obtain a master key.
[0009] According to a flash encryption method for a security chip provided by the present invention, the round function encrypts the right half of the i-th round of the m-th group of data to be encrypted based on the following steps: Add one bit to the highest bit and the lowest bit of the right half to obtain a 6-bit extended value; Perform an XOR operation on the extended value and the subkey of the i-th round to obtain a 6-bit XOR operation result; Using the S-box corresponding to the m-th group of data to be encrypted to perform a nonlinear transformation on the XOR operation result to obtain a 4-bit transformation result; The transformation result is bit-swapped to obtain an encryption result.
[0010] According to a flash encryption method for a security chip provided by the present invention, the S-box is a lookup table of 4 rows and 16 columns. For any of the S-boxes, a nonlinear transformation is performed on the XOR result based on the following steps: Concatenate the highest bit and the lowest bit of the XOR result to obtain the target number of rows; Using the middle four bits of the XOR result as the target column number; Based on the target number of rows and the target number of columns, a transformation result is obtained by querying from the S-box.
[0011] According to a flash encryption method for a security chip provided by the present invention, the target address is determined based on the following steps: XOR operation result: performing an XOR operation on the address and the scrambling code to obtain an XOR operation result; Based on the XOR operation result, a target address is determined.
[0012] According to a flash encryption method for a security chip provided by the present invention, the input data in the encryption direction and the input data in the decryption direction in the first flash encryption module are fixed values, and the fixed values are all "1"; the ciphertext obtained after decrypting the data is determined based on the following steps: Comparing the output data of the encryption direction in the first flash encryption module with the input data of the decryption direction in the second flash encryption module; If the two are equal, it is determined that the decrypted plaintext is the output data in the decryption direction of the first flash encryption module; If the two do not equal, it is determined that the decrypted plain text is the output data of the decryption direction in the second flash encryption module.
[0013] According to a flash encryption method for a security chip provided by the present invention, a ciphertext obtained after encrypting data is determined based on the following steps: Comparing the output data of the first flash encryption module in the decryption direction with the input data of the second flash encryption module in the encryption direction; If the two are equal, it is determined that the encrypted ciphertext is the output data in the encryption direction of the first flash encryption module; If the two do not want to be equal, the encrypted ciphertext is determined to be the output data of the encryption direction in the second flash encryption module.
[0014] The present invention also provides a security chip, which includes two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data with values of all "1", and the second flash encryption module is used to encrypt and decrypt other target data. The security chip applies any of the flash encryption methods for security chips described above.
[0015] The present invention also provides an electronic device, comprising the security chip as described above, or configured to apply any one of the flash encryption methods for security chips as described above.
[0016] The present invention provides a flash encryption method for a security chip, a security chip and an electronic device. The security chip comprises two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data whose values are all "1", and the second flash encryption module is used to encrypt and decrypt other target data; each of the flash encryption modules uses a Feistel structure to encrypt and decrypt the target data; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each of the round functions uses a different S box for nonlinear transformation; each of the flash encryption modules scrambles the address based on a preset scrambling formula, and after obtaining the target address, the encrypted ciphertext is stored based on the target address. The present invention cascades two flash encryption modules through a parallel structure, and the delay is half of that of the serial cascade, which shortens the delay of the critical path, facilitates the convergence of the system timing, and improves the maximum operating frequency of the security chip; in the encryption and decryption process, different round functions are used to encrypt and decrypt the packet data, and each round function uses a different S box to increase the encryption strength and effectively protect the target data. In addition, by scrambling the address, the protection of the ciphertext is strengthened, and the security of the flash storage is further enhanced; the first flash encryption module performs special processing on the all-"1" data, and it is no longer necessary to indicate the flag bit for the all-"1" after erasure. The encryption and decryption behavior is not perceived by the software. The software only needs to determine whether the read data is all "1" after erasure, thereby reducing the communication cost of software and hardware and facilitating the development of software to realize functions such as erasing and writing. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0018] Figure 1 It is a flow chart of a flash encryption method for a security chip provided by the present invention; Figure 2 It is a schematic diagram of the flash encryption architecture provided by the present invention; Figure 3 It is a schematic diagram of the Feistel encryption structure provided by the present invention; Figure 4 It is a structural schematic diagram of the flash encryption module provided by the present invention; Figure 5It is a schematic diagram of the address scrambling structure provided by the present invention. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0020] It should be noted that in the description of the embodiments of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "include one..." do not exclude the existence of other identical elements in the process, method, article or device including the elements. The orientation or position relationship indicated by the terms "upper", "lower" and the like is based on the orientation or position relationship shown in the drawings, which is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention. Unless otherwise clearly specified and limited, the terms "installed", "connected" and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, or it can be a connection between two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0021] The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.
[0022] Figure 1 It is a flow chart of a flash encryption method for a security chip provided by the present invention; Figure 2 It is a schematic diagram of the flash encryption architecture provided by the present invention; like Figure 1 and Figure 2 As shown, the security chip includes two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data with values of all "1", and the second flash encryption module is used to encrypt and decrypt other target data; the method includes the following: S110, each flash encryption module encrypts and decrypts the target data using a Feistel structure; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each round function uses a different S-box to perform nonlinear transformation; S120, each flash encryption module scrambles the address based on a preset scrambling formula, and after obtaining the target address, stores the encrypted ciphertext based on the target address.
[0023] It is understandable that there is no strict timing restriction between S110 and S120.
[0024] Here, the first flash encryption module is as follows Figure 2 As shown in Flash_Cipher1, the second flash encryption module is as follows Figure 2 As shown in Flash_Cipher2, two flash encryption modules are connected in parallel; among them, i_plaim_wdata is the input data in the encryption direction, o_cipher_wdata is the output data in the encryption direction, i_cipher_rdata is the input data in the decryption direction, and o_plain_rdata is the output data in the decryption direction.
[0025] Here, the Feistel structure is a framework for designing a block cipher, which divides the input plaintext into two equal-length parts (usually a left half and a right half), and then transforms it through a series of round functions. In each round, a subkey is used to process half of the data and the result is XORed with the other half of the data.
[0026] The embodiment of the present invention provides a flash encryption method for a security chip, wherein the security chip includes two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data with values of all "1", and the second flash encryption module is used to encrypt and decrypt other target data; each of the flash encryption modules uses a Feistel structure to encrypt and decrypt the target data; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each of the round functions uses a different S box for nonlinear transformation; each of the flash encryption modules scrambles the address based on a preset scrambling formula, and after obtaining the target address, the encrypted ciphertext is stored based on the target address. The present invention cascades two flash encryption modules through a parallel structure, and the delay is half of that of the serial cascade, which shortens the delay of the critical path, facilitates the convergence of the system timing, and improves the maximum operating frequency of the security chip; in the encryption and decryption process, different round functions are used to encrypt and decrypt the packet data, and each round function uses a different S box to increase the encryption strength and effectively protect the target data. In addition, by scrambling the address, the protection of the ciphertext is strengthened, and the security of the flash storage is further enhanced; the first flash encryption module performs special processing on the all-"1" data, and it is no longer necessary to indicate the flag bit for the all-"1" after erasure. The encryption and decryption behavior is not perceived by the software. The software only needs to determine whether the read data is all "1" after erasure, thereby reducing the communication cost of software and hardware and facilitating the development of software to realize functions such as erasing and writing.
[0027] In an optional embodiment, the target data is a 32-bit word, and the flash encryption module encrypts the target data based on the following steps: Divide the target data into four groups to obtain four data to be encrypted, each of which has a length of one byte; For the mth group of data to be encrypted, the mth group of data to be encrypted is evenly divided into a left half and a right half; wherein m is a positive integer For the i-th round, based on the i-th round subkey and the right half, encrypt using the round function corresponding to the m-th group, perform an XOR operation on the encryption result and the left half to obtain the right half of the i+1-th round, and use the right half as the left half of the i+1-th round; wherein i is a positive integer; After iterating for n rounds, the left half of the n+1th round is exchanged with the right half of the n+1th round, and then they are concatenated in left-right order to obtain the ciphertext corresponding to the mth group of data to be encrypted; The ciphertexts corresponding to the four data to be encrypted are concatenated in order to obtain the ciphertext corresponding to the target data.
[0028] In the embodiment of the present invention, the flash encryption module groups the data and performs encryption operation on the groups. The number of encryption rounds is determined according to the encryption strength requirement. The more encryption rounds, the better the encryption effect and the longer the encryption time.
[0029] In the embodiment of the present invention, flash encryption is performed by a hardware circuit, and the encryption action needs to be completed in one clock cycle. To ensure the encryption strength, a different wheel key is used in each round.
[0030] Flash storage is written in word units, i.e. 4 bytes, 32 bits. In the embodiment of the present invention, the data is divided into 4 groups and encrypted in bytes. To ensure the encryption strength, the F function of each group is different. In addition, the chip performs mixed layout and wiring of the encryption circuit, which ensures the encryption strength under the condition of low latency.
[0031] Figure 3 is a schematic diagram of the Feistel encryption structure provided by the present invention, such as Figure 3 As shown, encryption is performed byte by byte, and after encryption, the word is formed. Taking 4 rounds as an example, specifically: The 4-byte target data is divided into four groups, each group is one byte of data to be encrypted; For any byte of data to be encrypted, divide the byte into two groups evenly by bit, the left half L 0 and the right half R 0 ; The right half R 0 Directly assign to the left half of the second round L 1 , that is, L 1 =R 0 ; Select the first round subkey K 1 With the right half R 0 Input to the round function F for operation, and get the encryption result F(R 0 , K 1 ); The left half L 0 And the encryption result F(R 0 , K 1 ) is XORed to get the right half R of the second round 1 , that is, R 1 =L 0 ⊕F(R 0 , K 1 ); In the second, third and fourth rounds, subkeys are selected again and the operation of the first round is repeated to obtain L 4 and R 4 ; To ensure that the encryption and decryption structures are the same, swap the left and right parts to obtain the ciphertext L 5 and R 5 ; L 5 , R 5 Concatenate the ciphertexts of the other three data to be encrypted in sequence to obtain the ciphertext corresponding to the final target data.
[0032] The flash encryption method for a security chip provided by an embodiment of the present invention divides the input plaintext into two equal-length parts, transforms them through a series of round functions, and performs an XOR operation on the result and the other half of the data. The encryption and decryption processes are almost the same, which simplifies the hardware and software implementation, and each step is reversible, and the decryption can accurately restore the original data.
[0033] In an optional embodiment, each round uses a different subkey, the subkey is generated based on a master key, and the master key is generated based on the following steps: Based on a preset operation method, the fixed key value is operated with the address to obtain a master key.
[0034] Figure 4 It is a structural diagram of the flash encryption module provided by the present invention, such as Figure 4 As shown in the figure, Key0 is a fixed key value key, which is calculated with the address i_addr to obtain the new Key1. As the master key, Key1 changes with the address, which increases the strength of flash encryption. In the Key_Gen module, Key0 and i_addr can be operated with lightweight linear operations, such as bit swapping and XOR operation.
[0035] also, Figure 4 The decryption circuit module in the can be reused with the encryption circuit. Feistel's characteristic encryption and decryption use the same process and the same set of hardware circuits to reduce the chip area. The difference is that the wheel key must be input in reverse order, that is, the wheel key of the last round of encryption is used for the first round of decryption.
[0036] In the flash encryption method for a security chip provided by the embodiment of the present invention, the address is involved in the encryption, and even if the data is the same, the encryption result will be different as the address changes, thereby effectively increasing the encryption strength and ensuring data security.
[0037] In an optional embodiment, the round function encrypts the i-th round right half of the m-th group of data to be encrypted based on the following steps: Add one bit to the highest bit and the lowest bit of the right half to obtain a 6-bit extended value; Perform an XOR operation on the extended value and the subkey of the i-th round to obtain a 6-bit XOR operation result; Using the S-box corresponding to the m-th group of data to be encrypted to perform a nonlinear transformation on the XOR operation result to obtain a 4-bit transformation result; The transformation result is bit-swapped to obtain an encryption result.
[0038] Specifically, the right half is the right half byte of the plaintext, which is 4 bits long. One bit is added to the left (highest bit) and the right (lowest bit) of the 4 bits, expanding it from 4 bits to 6 bits. For example, for 0010, a bit with a value of 1 is added to its left and a bit with a value of 0 is added to its right, and the expansion is 100100. Here, the added bit can be a fixed value or a value randomly selected based on a preset rule. The expanded 6 bits and the subkey K of this round i Perform XOR operation, the key is 6 bits, and obtain a 6-bit XOR operation result; The 6-bit XOR operation result is compressed by 6-4 lines. The compression method is to perform nonlinear transformation through S-box to obtain the transformation result. Four different S-boxes are used for four bytes. The design principle of S-box can meet nonlinearity, avalanche and bit independence. The transformation results are bit-swapped to disrupt the original sorting order and obtain F(R0, K1), for example, B3B2B1B0→B1B0B2B3.
[0039] Furthermore, the S-box is a lookup table with 4 rows and 16 columns. For any of the S-boxes, a nonlinear transformation is performed on the XOR result based on the following steps: Concatenate the highest bit and the lowest bit of the XOR result to obtain the target number of rows; Using the middle four bits of the XOR result as the target column number; Based on the target number of rows and the target number of columns, a transformation result is obtained by querying from the S-box.
[0040] Specifically, taking one of the S boxes as an example, the S box has 4 rows and 16 columns, and the result of the 6-bit XOR operation is [B5B4B3B2B1B0]. Then [B5B0] determines the number of rows to be 00, 01, 10, or 11, and [B4B3B2B1] determines the number of columns to be 0000 to 1111. For example, 100100 has 10 rows and 0010 columns, that is, the corresponding value is 2 rows and 2 columns.
[0041] In an optional embodiment, the target address is determined based on the following steps: XOR operation result: performing an XOR operation on the address and the scrambling code to obtain an XOR operation result; Based on the XOR operation result, a target address is determined.
[0042] Figure 5 is a schematic diagram of the address scrambling structure provided by the present invention, such as Figure 5 As shown, the address i_addr is disturbed, and after the address is disturbed, the ciphertext is placed in a disturbed address o_onece_addr according to the value of the scrambling code nonce. The physical address and the logical address are disturbed to protect the ciphertext.
[0043] In the embodiment of the present invention, based on i_addr nonce To determine the target address, the XOR operation result may be directly used as the target address, or the XOR operation result may be further calculated to obtain the target address.
[0044] Here, the scrambling code nonce may be a fixed value or a value randomly generated using a preset method.
[0045] The flash encryption method for a security chip provided by the embodiment of the present invention remaps the address by scrambling so that the logical address and the physical address are no longer consistent, thereby enhancing the protection function for the storage of ciphertext.
[0046] In an optional embodiment, the input data in the encryption direction and the input data in the decryption direction in the first flash encryption module are fixed values, and the fixed values are all "1"; the ciphertext obtained after decrypting the data is determined based on the following steps: Comparing the output data of the encryption direction in the first flash encryption module with the input data of the decryption direction in the second flash encryption module; If the two are equal, it is determined that the decrypted plaintext is the output data in the decryption direction of the first flash encryption module; If the two do not equal, it is determined that the decrypted plain text is the output data of the decryption direction in the second flash encryption module.
[0047] After the Flash is powered on or erased, the value of the Flash is all "1". According to the normal decryption circuit, such as Figure 2Flash_Cipher2 in will decrypt a value other than "1", so the software cannot determine whether the erasure is successful, so special processing is required for all "1". Before processing, Flash_Cipher2 encrypts FFFF_FFFF to obtain the ciphertext ABAB_ABAB, and ABAB_ABAB is decrypted to obtain FFFF_FFFF. With the same encryption algorithm, CDCD_CDCD encrypts to obtain the ciphertext FFFF_FFFF, and FFFF_FFFF is decrypted to obtain CDCD_CDCD. In this way, it is impossible to distinguish whether FFFF_FFFF is the value after the flash is erased or the value obtained by decrypting ABAB_ABAB. In order to solve this problem, special processing is required for the all-"1" value FFFF_FFFF. After processing, FFFF_FFFF is encrypted and decrypted to obtain FFFF_FFFF. In this way, FFFF_FFFF encrypted ABAB_ABAB needs to correspond to CDCD_CDCD decrypted by FFFF_FFFF, and the remaining other data is not specially processed, that is: Before treatment: FFFF_FFFF<->ABAB_ABAB; CDCD_CDCD<->FFFF_FFFF; After processing: FFFF_FFFF<->FFFF_FFFF; CDCD_CDCD <-> ABAB_ABAB.
[0048] Because the address is involved in encryption, as the address changes, there may be several data that are calculated by the address and key0 to FFFF_FFFF. These plaintext data are not fixed values according to the change of the address. The ciphertext FFFF_FFFF may correspond to several different plaintext values obtained after the operation with the address and key0. For ease of understanding, the following example is given: If the address is 0000_0000 and the data is 0000_0001, and the address is 0000_0001 and the data is 0000_0000, and they are encrypted with key0 only by XOR operation, their results are the same. Non-linear encryption algorithms will also have such a situation where one ciphertext corresponds to several different plaintexts under different data and different addresses. Therefore, you cannot simply read all "1" directly, or write all "1" directly when writing all "1", and then directly correspond ABAB_ABAB and CDCD_CDCD.
[0049] In order to solve the above problem, the first flash encryption module is used to handle the special all-1 situation. In the encryption direction, the input data i_plain_wdata is fixed to FFFF_FFFF. Under a certain address i_addr and Key, the encrypted result is as follows Figure 2 The output data o_cipher_wdata is ABAB_ABAB; in the decryption direction, the input data i_cipher_rdata is FFFF_FFFF. In the case of a certain address and key0, the decrypted result is as follows Figure 2 The output data o_plain_rdata is CDCD_CDCD. Except for i_plain_wdata and i_cipher_rdata, the other configurations and inputs of the first flash encryption module are the same as those of the second flash encryption module, and the encryption and decryption algorithms of the two encryption and decryption modules are the same.
[0050] In the specific implementation process, the input data i_plain_wdata in the encryption direction of the first flash encryption module and the input data i_cipher_rdata in the decryption direction are fixed to all "1", that is, FFFF_FFFF, then o_cipher_wdata = ABAB_ABAB, o_plain_rdata = CDCD_CDCD. ABAB_ABAB is compared with the input data i_cipher_rdata in the decryption direction of the second flash encryption module. If the two are equal, it means that the data read from the flash is ABAB_ABAB, which needs to correspond to CDCD_CDCD, then the actual original data rdata selects CDCD_CDCD; if the two are not equal, the normal decrypted data is selected, that is, the output data o_plain_rdata in the decryption direction of the second flash encryption module.
[0051] The flash encryption method for a security chip provided by an embodiment of the present invention performs special processing on all "1"s through the first flash encryption module, and there is no need to indicate the flag bit for all "1"s after erasure. The software only needs to determine whether the read data is all "1"s after erasure. The effect is the same as that without adding flash encryption, reducing the communication cost between software and hardware, reducing the operation of software erasure check flag bits, and also reducing the probability of errors.
[0052] In an optional embodiment, the ciphertext obtained after encrypting the data is determined based on the following steps: Comparing the output data of the first flash encryption module in the decryption direction with the input data of the second flash encryption module in the encryption direction; If the two are equal, it is determined that the encrypted ciphertext is the output data in the encryption direction of the first flash encryption module; If the two do not want to be equal, the encrypted ciphertext is determined to be the output data of the encryption direction in the second flash encryption module.
[0053] In the specific implementation process, CDCD_CDCD is compared with the input data i_plain_wdata in the encryption direction of the second flash encryption module. If the two are equal, it means that the data written to the flash is CDCD_CDCD, which needs to correspond to ABAB_ABAB, and the data actually written to the flash is strobed as ABAB_ABAB; if the two are not equal, the strobe is the normal encrypted data, that is, the output data o_cipher_wdata in the encryption direction of the second flash encryption module. In summary, the first flash encryption module mainly handles the situation of all "1", and the second flash encryption module is used for encryption and decryption in other situations.
[0054] The flash encryption method for a security chip provided by an embodiment of the present invention performs special processing on all "1"s through the first flash encryption module, and there is no need to indicate the flag bit for all "1"s after erasure. The software only needs to determine whether the read data is all "1"s after erasure. The effect is the same as that without adding flash encryption, reducing the communication cost between software and hardware, reducing the operation of software erasure check flag bits, and also reducing the probability of errors.
[0055] On the other hand, the present invention further provides a security chip, comprising two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data whose values are all "1", and the second flash encryption module is used to encrypt and decrypt other target data, and the security chip applies the flash encryption method for security chip provided by the above methods, the method comprising: each of the flash encryption modules encrypts and decrypts the target data using a Feistel structure; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each of the round functions uses a different S-box for nonlinear transformation; Each of the flash encryption modules scrambles the address based on a preset scrambling formula, and after obtaining the target address, stores the encrypted ciphertext based on the target address.
[0056] On the other hand, the present invention also provides an electronic device, comprising the security chip as described above, wherein the security chip comprises two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data whose values are all "1", and the second flash encryption module is used to encrypt and decrypt other target data, or is configured to apply the flash encryption method for the security chip provided by the above methods, the method comprising: each of the flash encryption modules encrypts and decrypts the target data using a Feistel structure; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each of the round functions uses a different S-box for nonlinear transformation; Each of the flash encryption modules scrambles the address based on a preset scrambling formula, and after obtaining the target address, stores the encrypted ciphertext based on the target address.
[0057] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.
[0058] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0059] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A flash encryption method for a security chip, characterized in that: The security chip includes two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data with values of all "1", and the second flash encryption module is used to encrypt and decrypt other target data; the method includes: Each of the flash encryption modules uses a Feistel structure to encrypt and decrypt the target data; in the step of encrypting and decrypting the target data, the target data is divided into a preset number of groups, each group is encrypted using a different round function, and each of the round functions uses a different S-box for nonlinear transformation; Each of the flash encryption modules scrambles the address based on a preset scrambling formula, and after obtaining the target address, stores the encrypted ciphertext based on the target address.
2. The flash encryption method for a security chip according to claim 1, characterized in that: The target data is a 32-bit word, and the flash encryption module encrypts the target data based on the following steps: Divide the target data into four groups to obtain four data to be encrypted, each of which has a length of one byte; For the mth group of data to be encrypted, the mth group of data to be encrypted is evenly divided into a left half and a right half; wherein m is a positive integer For the i-th round, based on the i-th round subkey and the right half, encrypt using the round function corresponding to the m-th group, perform an XOR operation on the encryption result and the left half to obtain the right half of the i+1-th round, and use the right half as the left half of the i+1-th round; wherein i is a positive integer; After iterating for n rounds, the left half of the n+1th round is exchanged with the right half of the n+1th round, and then they are concatenated in left-right order to obtain the ciphertext corresponding to the mth group of data to be encrypted; The ciphertexts corresponding to the four data to be encrypted are concatenated in order to obtain the ciphertext corresponding to the target data.
3. The flash encryption method for a security chip according to claim 2, characterized in that: Each round uses a different subkey, which is generated based on the master key, which is generated based on the following steps: Based on a preset operation method, the fixed key value is operated with the address to obtain a master key.
4. The flash encryption method for a security chip according to claim 2 or 3, characterized in that: The round function encrypts the right half of the i-th round of the m-th group of data to be encrypted based on the following steps: Add one bit to the highest bit and the lowest bit of the right half to obtain a 6-bit extended value; Perform an XOR operation on the extended value and the subkey of the i-th round to obtain a 6-bit XOR operation result; Using the S-box corresponding to the m-th group of data to be encrypted to perform a nonlinear transformation on the XOR operation result to obtain a 4-bit transformation result; The transformation result is bit-swapped to obtain an encryption result.
5. The flash encryption method for a security chip according to claim 4, characterized in that: The S-box is a lookup table with 4 rows and 16 columns. For any of the S-boxes, a nonlinear transformation is performed on the XOR result based on the following steps: Concatenate the highest bit and the lowest bit of the XOR result to obtain the target number of rows; Using the middle four bits of the XOR result as the target column number; Based on the target number of rows and the target number of columns, a transformation result is obtained by querying from the S-box.
6. The flash encryption method for a security chip according to claim 1, characterized in that: The target address is determined based on the following steps: XOR operation result: performing an XOR operation on the address and the scrambling code to obtain an XOR operation result; Based on the XOR operation result, a target address is determined.
7. The flash encryption method for a security chip according to claim 1, characterized in that: The input data in the encryption direction and the input data in the decryption direction of the first flash encryption module are fixed values, and the fixed values are all "1"; the ciphertext obtained after the data is decrypted is determined based on the following steps: Comparing the output data of the encryption direction in the first flash encryption module with the input data of the decryption direction in the second flash encryption module; If the two are equal, it is determined that the decrypted plaintext is the output data in the decryption direction of the first flash encryption module; If the two do not equal, it is determined that the decrypted plain text is the output data of the decryption direction in the second flash encryption module.
8. The flash encryption method for a security chip according to claim 7, characterized in that: The ciphertext obtained after encrypting the data is determined based on the following steps: Comparing the output data of the first flash encryption module in the decryption direction with the input data of the second flash encryption module in the encryption direction; If the two are equal, it is determined that the encrypted ciphertext is the output data in the encryption direction of the first flash encryption module; If the two do not want to be equal, the encrypted ciphertext is determined to be the output data of the encryption direction in the second flash encryption module.
9. A security chip, characterized in that: The security chip includes two flash encryption modules cascaded in parallel, wherein the first flash encryption module is used to encrypt and decrypt target data with values of all "1", and the second flash encryption module is used to encrypt and decrypt other target data. The security chip applies the flash encryption method for security chip as described in claim 1 to perform flash encryption.
10. An electronic device, characterized in that: The device comprises the security chip as claimed in claim 9, or is configured to apply the flash encryption method for a security chip as claimed in claim 1 to perform flash encryption.
Citation Information
Cited By
Security access control system and method and storage medium
CN122153867A
Secure access control system, method and storage medium
CN122153867B
Data encryption method and decryption method
CN122419994A