Image encryption and decryption system, method and device and medium
By designing an image encryption and decryption system, the target key stream is generated using the key module, algorithm module and data processing module, which solves the problems of limited security and inefficiency of image encryption in the prior art, and achieves an efficient and secure image encryption and decryption effect.
Patent Information
- Application Number
- CN202510386355.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art has problems of limited security and low efficiency in image encryption, especially in the transmission of massive image data, which is difficult to effectively ensure the security and encryption speed of data.
An image encryption and decryption system is designed to generate a target key stream and perform image encryption/decryption processing through the collaborative work of the key module, algorithm module and data processing module. This system improves the security of image encryption by expanding the key space, and reduces blocking processing through the streaming cipher structure, thereby improving the efficiency of image encryption and decryption.
It realizes improving security and efficiency in the image encryption process, can effectively resist statistical analysis attacks, and maintain high encryption speed on resource-constrained devices.
Smart Images

Figure CN120151452A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of image encryption, and in particular to an image encryption and decryption system, method, device and medium. Background Art
[0002] With the rapid development of computer and Internet technologies, the application of big data is becoming more and more extensive. The transmission of these massive amounts of image data over the Internet has brought many security problems. Therefore, it is necessary to encrypt these image data to improve the security of transmission.
[0003] In related technologies, the pixel value scrambling method or the AES (Advanced Encryption Standard) algorithm is usually used to encrypt images. Among them, the image encryption method of pixel value scrambling realizes image encryption by rearranging the pixel positions, which is relatively simple and has low computational complexity, but the security is limited. The image encryption method of the AES algorithm realizes encryption by rearranging the pixel positions, but due to the relatively cumbersome process, the encryption speed is limited and the computational overhead of key expansion is large.
[0004] In view of this, there is a need for an image encryption and decryption system with strong security and high efficiency. Summary of the Invention
[0005] In view of this, the present invention provides an image encryption and decryption system to improve the security of image data transmission.
[0006] In a first aspect, the present invention provides an image encryption and decryption system, which includes: a key module for transmitting initial information to an algorithm module; the initial information includes key information and an initial vector; the initial vector represents an auxiliary parameter in encryption; an algorithm module for detecting the image data to be processed and converting the initial information into a target key stream with a corresponding length based on the data length of the image data to be processed; a data processing module for encrypting / decrypting the image data to be processed according to the target key stream to obtain an encrypted / decrypted image.
[0007] In this embodiment, the system includes a key module, an algorithm module, and a data processing module. The key module transmits initial information including key information and an initial vector to the algorithm module. The algorithm module converts the received initial information into a target key stream of a corresponding length based on the length of the image data to be processed. The data processing module then encrypts / decrypts the image data to be processed according to the target key stream to obtain an encrypted / decrypted image. Through the above solution, by converting the initial information including key information and an initial vector into a target key stream of a corresponding length, the key space can be expanded, thereby improving the security of image encryption. Moreover, the target key stream is in a stream cipher structure. Compared with block ciphers, there is no need to block-process the image data to be processed, which can improve the efficiency of image encryption and decryption.
[0008] In an alternative embodiment, the algorithm module includes: a key expansion unit for receiving the initial information and expanding the initial information to obtain expansion parameters; the expansion parameters are used to initialize the register unit; the register unit is used to generate a target key stream based on a preset timing and the expansion parameters.
[0009] In this embodiment, the algorithm module includes a key expansion unit and a register unit. Among them, the key expansion unit can expand the initial information to enhance the length and complexity of the key; the register unit can quickly generate a target key stream based on a preset timing and the expansion parameters, thereby improving the encryption / decryption efficiency.
[0010] In an alternative embodiment, a pipeline structure is provided in the register unit; the pipeline structure is used to connect the data paths between the registers; several stages of pipelines are included in the pipeline structure; two adjacent stages of pipelines are connected by an arithmetic module; at least one D flip-flop is included in each stage of the pipeline; the first input terminal of each D flip-flop is connected to the output terminal of the upper arithmetic module; the second input terminal of each D flip-flop receives a clock signal; the output terminal of each D flip-flop is connected to the input terminal of the lower arithmetic module; the arithmetic module is used to perform modulo operation on the input signal.
[0011] In this embodiment, a pipeline structure is provided in the register unit, which can divide a path with a long delay to shorten the circuit, improve the throughput of the system, and accelerate the processing speed of image encryption / decryption.
[0012] In an alternative embodiment, the operation module includes a first adder, a second adder, and a multiplexer circuit; the first input terminal and the second input terminal of the first adder are used to connect to the output terminals of different D flip-flops; the output terminal of the first adder is connected to the first selection terminal of the multiplexer circuit; the carry terminal of the first adder is connected to the control terminal of the multiplexer circuit; the output terminal of the first adder is also connected to the third input terminal of the second adder; the fourth input terminal of the second adder is connected to a high level; the output terminal of the second adder is connected to the second selection terminal of the multiplexer circuit; the output terminal of the multiplexer circuit is the output terminal of the operation module.
[0013] In this embodiment, the operation module includes a first adder, a second adder, and a multiplexer circuit. Among them, the two adders can perform parallel operations, thereby reducing the delay of serial processing.
[0014] In an alternative embodiment, the system further includes: a scrambling module, configured to generate a scrambling address based on a preset scrambling algorithm, and sequentially write the target image data into the scrambling address; the target image data is the image data to be processed or the encrypted / decrypted image.
[0015] In this embodiment, the system further includes a scrambling module, which can generate a scrambling address based on a preset scrambling algorithm and sequentially write the target image data into the scrambling address. This can improve the security of the system.
[0016] In an alternative embodiment, the scrambling module includes: a first scrambling unit, configured to obtain the initial address of the target image data; based on the preset scrambling algorithm, perform a positive transformation on the initial address to generate and send the scrambling address to the scrambling control unit; the scrambling control unit is configured to receive the scrambling address and write the target image data into the scrambling address.
[0017] In this embodiment, the scrambling module includes a first scrambling unit and a scrambling control unit. The first scrambling unit can perform a positive transformation on the initial address of the target image data based on the preset scrambling algorithm to generate the scrambling address. This can optimize the image encryption effect.
[0018] In an alternative embodiment, the scrambling module further includes: a first inverse scrambling unit, configured to obtain the initial address of the target image data; based on the preset scrambling algorithm, perform an inverse transformation on the initial address to generate and send the scrambling address to the scrambling control unit.
[0019] In this embodiment, the scrambling module further includes a first inverse scrambling unit, which can perform an inverse transformation on the initial address based on the preset scrambling algorithm to restore the image data to be processed, which can ensure the integrity of the information.
[0020] In a second aspect, the present invention provides an image encryption and decryption method, which includes: generating initial information and generating a target key stream based on the initial information; the initial information includes key information and an initial vector; obtaining an image processing requirement and image data to be processed; the image data to be processed corresponds to the image processing requirement; the image processing requirement includes at least one of image encryption and image decryption; in the case where the image processing requirement includes image encryption, encrypting the image data to be processed based on the target key stream to obtain an encrypted image; in the case where the image processing requirement includes image decryption, decrypting the image data to be processed based on the target key stream to obtain a decrypted image.
[0021] In a third aspect, the present invention provides an image encryption and decryption device, which includes: a generation module for generating initial information and generating a target key stream based on the initial information; the initial information includes key information and an initial vector; an acquisition module for obtaining an image processing requirement and image data to be processed; the image data to be processed corresponds to the image processing requirement; the image processing requirement includes at least one of image encryption and image decryption; an encryption module for encrypting the image data to be processed based on the target key stream to obtain an encrypted image in the case where the image processing requirement includes image encryption; a decryption module for decrypting the image data to be processed based on the target key stream to obtain a decrypted image in the case where the image processing requirement includes image decryption.
[0022] In a fourth aspect, the present invention provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the image encryption and decryption method in the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 is a schematic structural diagram of an image encryption and decryption system according to an embodiment of the present invention;
[0025] Figure 2 is a schematic structural diagram of a key module according to an embodiment of the present invention;
[0026] Figure 3 is a schematic diagram of controlling the state transition of an FSM according to an embodiment of the present invention;
[0027] Figure 4 It is a schematic diagram of a pipeline structure according to an embodiment of the present invention;
[0028] Figure 5 It is a schematic diagram of the structure of an operation module according to an embodiment of the present invention;
[0029] Figure 6 It is a schematic diagram of the structure of an algorithm module according to an embodiment of the present invention;
[0030] Figure 7 It is a schematic diagram of the structure of a scrambling module according to an embodiment of the present invention;
[0031] Figure 8 It is a schematic diagram of the structure of a display module according to an embodiment of the present invention;
[0032] Figure 9 It is a schematic diagram of the structure of an image encryption and decryption system according to an embodiment of the present invention;
[0033] Figure 10 It is a schematic flowchart of an image encryption and decryption method according to an embodiment of the present invention;
[0034] Figure 11 It is a structural block diagram of an image encryption and decryption device according to an embodiment of the present invention;
[0035] Figure 12 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. Specific embodiments
[0036] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0037] Since the 21st century, computer and Internet technologies have developed rapidly. People can conveniently achieve functions such as email sending, e-shopping, online transfer, and file transfer through the Internet. With the full popularization of 4G and the steady advancement of 5G, the application scope of big data has become increasingly wide. However, when these massive data are transmitted on the Internet, many security risks are brought, such as the leakage of personal privacy data, the theft of commercial confidential data of companies and enterprises, and the illegal interception of national security data. It can be said that from the personal level to the enterprise level, and then to the national level, the information security issue is becoming increasingly prominent.
[0038] In the related art, the image encryption and decryption methods mainly include two types: image encryption based on pixel value scrambling and image encryption based on the AES algorithm.
[0039] Among them, the image encryption method based on pixel value scrambling includes the following steps:
[0040] 1) Read the image: First, use an image processing library such as the OpenCV (Open Source Computer Vision Library) library in Python to read the image file to be encrypted and convert it into a digital matrix form. Each element of the matrix corresponds to a pixel value of the image. For example, for a grayscale image, the pixel value range is usually 0 - 255, and for a color image in the RGB (Red Green Blue) mode, there are pixel value matrices for three channels.
[0041] 2) Generate a scrambling sequence: Generate a scrambling sequence through a specific algorithm. A common method is to use a chaotic map to generate a chaotic sequence, such as the Logistic chaotic map. Set appropriate parameters, which can include control parameters and initial values, etc., and generate a series of chaotic values through an iterative formula. Then process these chaotic values to make them an integer sequence equal to the number of image pixels and within the valid index range (such as 0 to the total number of image pixels - 1) as the scrambling sequence.
[0042] 3) Pixel value scrambling: Perform a scrambling operation on the pixel values of the image according to the generated scrambling sequence. For each pixel position in the image, swap its pixel value with the pixel value at the corresponding position in the scrambling sequence. For example, if the first element in the scrambling sequence is 5, then swap the first pixel value in the image with the fifth pixel value, and so on, traversing all the pixels of the image to complete the pixel value scrambling, so that the arrangement of the pixel values of the image becomes disordered, achieving a preliminary encryption effect.
[0043] The image encryption scheme based on pixel value scrambling is relatively simple, with a low computational complexity, and can protect the information security of the image to a certain extent. However, its security is relatively limited because simple pixel value scrambling may retain some statistical features of the image, and there may be a risk of being cracked for some attackers with strong analysis capabilities.
[0044] The image encryption method based on the AES algorithm includes the following steps:
[0045] 1) Image preprocessing. Specifically, the image preprocessing includes steps such as image format conversion and data grouping.
[0046] Among them, the steps of image format conversion are as follows: First, convert the image to be encrypted into a suitable format. For a color image, such as in the RGB mode, it is usually decomposed into three channels, namely red, green, and blue, and each channel can be regarded as an independent two-dimensional matrix. For a grayscale image, it is directly regarded as a two-dimensional matrix, and the elements in the matrix represent pixel values.
[0047] The steps of data grouping are as follows: Group the image data matrix according to the data block size requirements of the AES algorithm. Specifically, the AES standard data block is 128 bits, that is, 16 bytes. Taking a grayscale image as an example, if the image width is W pixels and the height is H pixels, then the total number of pixels in this image is WxH. Divide these pixels into groups of 16 in order. If the last group has less than 16 pixels, padding processing can be performed.
[0048] 2) Key generation and management, among which, key generation and management mainly include two steps: key generation, and key storage and transmission.
[0049] Key generation: The AES algorithm supports key lengths of 128 bits, 192 bits, and 256 bits. A key can be obtained through a random number generator or other secure key generation methods. For example, use the secure random number generation function provided by the operating system to generate a key of the specified length.
[0050] Key storage and transmission: The generated key needs to be securely stored and transmitted. In terms of storage, an encrypted key storage device or a secure software storage mechanism can be used. During the transmission process, a key exchange protocol is usually adopted, such as the Diffie-Hellman protocol, etc. Or encrypt the key before transmission, such as using an asymmetric encryption algorithm such as RSA (Rivest-Shamir-Adleman) to encrypt the AES key to ensure the security of the key.
[0051] 3) Encryption of image data blocks: Encrypt each grouped image data block, and the encryption mode can be selected as AES128, AES192, AES256, etc. according to requirements. Among them, AES128, AES192, and AES256 respectively represent the Advanced Encryption Standard with a 128-bit key, the Advanced Encryption Standard with a 192-bit key, and the Advanced Encryption Standard with a 256-bit key.
[0052] 4) Post-encryption processing, among which, post-encryption processing can include two methods: merging data blocks, and saving or transmitting the encrypted image.
[0053] Merge data blocks: After multiple rounds of encryption, the encryption process is completed for all data blocks. These encrypted data blocks are merged in the original order to form the encrypted image data. For the three channels of a color image, the above encryption process is performed separately, and then the three encrypted channels are merged into an encrypted color image.
[0054] Save or transmit the encrypted image: The encrypted image data is saved to a storage device in an appropriate format or transmitted through communication channels such as the network. Since the encrypted image data has been encrypted by the AES algorithm, even if it is intercepted during transmission, without the correct key, it is difficult for an attacker to obtain the original content of the image.
[0055] However, the image encryption scheme of the AES algorithm also has some disadvantages. As follows:
[0056] 1) Speed limitation due to data block division and round operations: The AES algorithm is a block cipher algorithm. When encrypting an image, the image data needs to be divided into data blocks of a fixed size. For large images, especially high-resolution and large-data-volume images, this block division operation will generate a large number of data blocks, and multiple rounds of encryption need to be performed on each data block in turn. For example, the AES128 standard encryption process includes 10 rounds of encryption operations, AES192 includes 12 rounds, and AES256 includes 14 rounds. Each round contains complex steps such as byte substitution, row shift, column mixing, and round key addition, which makes the encryption process relatively cumbersome and results in a decrease in encryption speed. On resource-constrained devices (such as embedded systems or mobile devices), this efficiency problem is more obvious. These devices have limited computing power and storage resources, and frequent data block processing and multiple rounds of encryption operations will consume a large amount of CPU (Central Processing Unit) time and memory resources, which may affect other functions of the device and even cause the system to freeze.
[0057] 2) Computational overhead of the key expansion process: The key expansion process of the AES algorithm also requires certain computing resources. According to different key lengths (128 bits, 192 bits, or 256 bits), the round keys required for each round of encryption are derived from the initial key through a series of non-linear transformations and circular shift operations. This process involves complex operations, and for a large number of image encryption scenarios, the computational overhead of key expansion will accumulate, further reducing the encryption efficiency.
[0058] 3) Key storage and management risks: AES is a symmetric encryption algorithm, and the same key is used for both encryption and decryption. This requires that the key must be strictly confidential during storage and transmission. If the key is leaked, the encrypted image can be easily decrypted. In practical applications, the storage of the key may be threatened by physical attacks (such as theft of hard drives) or software vulnerabilities (such as hacking of the database storing the key). During the key transmission process, it may also be intercepted by a man-in-the-middle. Although security can be enhanced through methods such as key exchange protocols, there are still risks.
[0059] 4) Possible attack points in the round function operations: The round function of AES includes operations such as row shift, column mixing, and round key addition. The interrelationships between these operations may be exploited by attackers. For example, in certain specific situations, attackers may infer partial information about the key in the previous and subsequent rounds or the original image data by analyzing the output of the round function in the intermediate rounds. Although this type of attack is currently difficult both theoretically and practically, with the development of cryptanalysis techniques, it remains a potential security risk.
[0060] To meet the needs of the popularization of 5G (the 5th Generation Mobile Communication Technology) wireless communication, in related technologies, the ZUC-256 (ZUC stream cipher with 256-bit, the 256-bit Zu Chongzhi stream cipher algorithm) encryption algorithm has been proposed, aiming to provide security for data in the 5G application environment. Moreover, the ZUC-256 encryption algorithm successfully became an ISO / IEC (International Organization for Standardization / International Electrotechnical Commission) international standard in 2020.
[0061] The ZUC-256 encryption algorithm belongs to a type of symmetric encryption algorithm. Compared with block symmetric encryption algorithms such as AES and SM4 (ShangMi Algorithm 4), the ZUC-256 algorithm has a faster encryption speed and can use fewer hardware resources during implementation, making it particularly suitable for high-speed encryption and decryption of data in resource-constrained scenarios. In addition, due to its excellent internal linear feedback register design, the ZUC-256 encryption algorithm has extremely high security characteristics. Currently, the results of security analysis at home and abroad both show that the ZUC-256 algorithm has sufficient security. And in related technologies, there is no hardware implementation method for the ZUC-256 algorithm.
[0062] An embodiment of the present invention provides an image encryption and decryption system, which includes a key module, an algorithm module, and a data processing module. The key module transmits initial information including key information and an initial vector to the algorithm module. The algorithm module converts the received initial information into a target key stream of a corresponding length based on the length of the image data to be processed. The data processing module then encrypts / decrypts the image data to be processed according to the target key stream to obtain an encrypted / decrypted image. Through the above solution, by converting the initial information including key information and an initial vector into a target key stream of a corresponding length, the key space can be expanded, thereby improving the security of image encryption. And the target key stream is in a stream cipher structure. Compared with block ciphers, it is not necessary to block-process the image data to be processed, which can improve the efficiency of image encryption and decryption.
[0063] In this embodiment, an image encryption and decryption system is provided. Figure 1 It is a schematic structural diagram of the image encryption and decryption system according to the embodiment of the present invention, as Figure 1 shown. The system includes the following modules:
[0064] A key module for transmitting initial information to the algorithm module; the initial information includes key information and an initial vector; the initial vector represents an auxiliary parameter in encryption.
[0065] When transmitting an image, operations of encrypting or decrypting the image data are usually performed to improve the security of image data transmission. Before encrypting or decrypting the image data, it is necessary to first determine the encryption and decryption algorithms and configure the encryption and decryption parameters to encrypt and decrypt the image data.
[0066] Among them, the initial information includes key information and an initial vector. The length of the key information can be determined according to the requirements of the encryption algorithm and the security level. In a specific implementation, the initial vector can be generated using a random number generator, and the length of the initial vector can be determined according to the requirements of the encryption algorithm. The settings of the initial vector and the key information can be independent of each other to ensure the security of the encryption algorithm.
[0067] An algorithm module for detecting the image data to be processed and converting the initial information into a target key stream of a corresponding length based on the data length of the image data to be processed;
[0068] After receiving the initial information, it can be stored in the internal memory of a preset algorithm to initialize the preset encryption algorithm. Then, according to the byte stream length of the image data to be processed, the initial information is converted into a target key stream of a corresponding length. In a specific implementation, the length of the target key stream is the same as the byte stream length of the image data to be processed.
[0069] A data processing module for encrypting / decrypting the image data to be processed according to the target key stream to obtain an encrypted / decrypted image.
[0070] Specifically, each byte in the image data to be processed can be operated on with the byte at the corresponding position in the target key stream to obtain the encrypted / decrypted result of the corresponding byte, thereby obtaining the encrypted / decrypted image.
[0071] In a specific implementation, when encrypting the image to be processed, each byte in the byte stream of the image to be processed is operated on with the byte at the corresponding position in the target key stream to obtain encrypted image data, and by performing format conversion on the encrypted image data, the encrypted image can be obtained.
[0072] When decrypting the image to be processed, by operating on the encrypted image, that is, each byte in the byte stream of the image to be processed with the byte at the corresponding position in the target key stream, the result of the decryption process can be obtained, and by performing format conversion on the result of the decryption process, the decrypted image can be obtained.
[0073] The system includes a key module, an algorithm module, and a data processing module. The key module transmits initial information including key information and an initial vector to the algorithm module. The algorithm module converts the received initial information into a target key stream of a corresponding length based on the length of the image data to be processed. The data processing module then encrypts / decrypts the image data to be processed according to the target key stream to obtain an encrypted / decrypted image. Through the above solution, by converting the initial information including key information and an initial vector into a target key stream of a corresponding length, the key space can be expanded, thereby improving the security of image encryption. And the target key stream is in a stream cipher structure. Compared with block ciphers, there is no need to block-process the image data to be processed, which can improve the efficiency of image encryption and decryption.
[0074] In this embodiment, an image encryption and decryption system is provided, and the system includes the following modules:
[0075] A key module for transmitting initial information to the algorithm module; the initial information includes key information and an initial vector; the initial vector represents an auxiliary parameter in encryption;
[0076] For details, please refer to Figure 1 the key module in the illustrated embodiment, which will not be elaborated here.
[0077] In a specific implementation, the structural schematic diagram of the key module is as shown in Figure 2As shown, the key module transmits the initial information required by the algorithm module to the algorithm module and provides a trigger signal "trigger" to enable the algorithm module to start iteration. The key module includes a frequency division and baud rate adaptation unit, an instruction receiving unit, a key receiving unit, a key cache and instruction parsing unit, a control FSM (Finite State Machine) state machine, and a key conversion and sending unit.
[0078] Among them, the frequency division and baud rate adaptation unit is used for clock frequency division and baud rate adjustment, which can be used to adapt to different interface transmission rates and has strong adaptability. The baud rate is adjusted by configuring instruction information before the operation starts. The frequency division and baud rate adaptation unit receives a clock signal (Clk) and a reset signal (Rst_n), and resets the key module based on the compound signal and performs clock frequency division based on the clock signal.
[0079] The instruction receiving unit receives and parses instructions, including but not limited to baud rate configuration, key bit width, key sending bit width, initial vector bit width, initial vector sending bit width, etc. Among them, the baud rate configuration is used to adjust the baud rate, and the baud rate configuration information (Cmd_po) can be directly sent to the allocation and baud rate adaptation unit. The key bit width and the key sending bit width are used to indicate the bit width of key reception and the bit width of sending after processing, and the key information (Cmd_data) containing the key bit width and the key sending bit width can be directly sent to the key cache and instruction parsing unit. The initial vector bit width and the initial vector sending bit width are used to indicate the bit width of initial vector reception and the bit width of sending after processing, and the initial key information (Cmd_k) containing the initial vector bit width and the initial vector sending bit width can be directly sent to the key receiving unit. In a specific implementation, the minimum key bit width can be 1 bit, that is, the lowest significant bit of the key that can be received is 1, and the maximum supported key bit width is 32 bits.
[0080] After receiving the initial key information (Cmd_k) sent by the instruction receiving unit, the key receiving unit sends the corresponding key data (Key_data) and key enable signal (Key_en) to the key cache and instruction parsing unit.
[0081] The key cache and instruction parsing unit is used to cache the key information and initial vector from the previous stage, and parse the instruction trigger signal to trigger the next-level control FSM state machine to perform a state transition. In a specific implementation, the key cache and instruction parsing unit receives the baud rate of the baud rate adjustment unit sent by the allocation and baud rate adaptation unit. It receives the key information (Cmd_data) sent by the instruction receiving unit, the key data (Key_data) and key enable signal (Key_en) sent by the key receiving unit. After caching the key information and key data internally, it sends signals to the next-level control FSM state machine. Among them, the signals can include Cmd0, empty, valid, and Data_fsm. Among them, Cmd0 represents the command numbered 0 and is used to drive the FSM state machine; the empty signal represents whether there is key data written. When the empty signal is pulled low to 0, it means that there is key data written. When the empty signal is 1, it means that there is no key data written; the valid signal represents whether the data is valid; the Data_fsm signal represents the data finite state machine and is used to control the state machine to perform conversions between different states such as data reception, processing, and storage.
[0082] The control FSM state machine is used to splice the key information and initial vector according to the previous-stage instruction parsing, and send the key information, initial vector, and trigger signal to the algorithm module. In the normal mode, it sends 256-bit key information (Key[255:0]) and 184-bit initial vector (iv[183:0]). In the Debug (debug) mode, it sends the key information and initial vector to the key conversion and sending unit, and the key conversion and sending unit sends x-bit key information (Debug mode: Key[x - 1:0]) and initial vector (Debug mode: iv[x - 1:0]) to the algorithm module. Among them, x can be set according to the actual situation.
[0083] In some alternative embodiments, the control FSM state operation diagram is as Figure 3 shown. Taking the normal mode (outputting 256-bit key and 184-bit initial vector) as an example, the state transition process is described as follows:
[0084] When the Rst_n (reset signal) is at a low level, the control FSM state machine is reset. When reset, all signals except the flag signal are set to zero. At this time, the control FSM state machine is in the S0_idle waiting state. When the flag signal is high, it proves that there is no data returned to the host computer at this time, and the empty signal of the FIFO (First In, First Out) is at a high level, which proves that there is no data written to the FIFO.
[0085] The initial key is sent to the key receiving unit. When the initial key is input, the write request of the KEY_FIFO (Key First-In-First-Out) module is pulled high, and the initial key is written into the KEY_FIFO module. At the same time, the empty signal is pulled low to 0, indicating that there is key data written.
[0086] When the KEY_FSM (Key Finite State Machine) module receives that the empty signal is at a low level, it pulls high the read request of the KEY_FIFO module, and at the same time, the state machine jumps to the S1 state. That is, empty = 0, State = S1, Rd_en = 1.
[0087] When the read request of the KEY_FIFO module is pulled high, the valid (valid) signal will be pulled high after one clock cycle. At this time, the 32-bit output data data_fsm in the control FSM state machine is written into the register of the KEY_FSM module. When the counter counts to the configured value, the counter is cleared, and key splicing is performed. After the splicing is completed, the state machine jumps to the S2 state. That is, cnt = configured value, State = S2, cnt = 0.
[0088] The initial vector is sent to the key receiving unit. When the write request for data input to the IV_FIFO (Initial Vector First-In-First-Out) module is pulled high, the initial vector data is written into the IV_FIFO module. At the same time, the empty signal is pulled low to 0, indicating that there is data written. When the KEY_FSM module receives that the empty signal in the IV_FIFO module is 0 again, it will jump to the S3 state. That is, empty = 0, State = S3, Rd_en = 0.
[0089] Since the initial vector is 184 bits, the control logic reads the data in the IV_FIFO module. When the counter counts to the configured value, the counter is cleared, and vector splicing is performed. After the splicing is completed, it enters the S4 state. That is, cnt = configured value, State = S4, cnt = 0.
[0090] In the S4 state, the trigger signal is pulled high (the trigger signal is active high) to trigger the algorithm module, and the initial key and the initial vector are sent to the algorithm module to generate the target key stream, and it jumps to the S5 state at the next clock.
[0091] In the S5 state, the flag signal is pulled low. When the information is sent, the flag signal is pulled high again, and the state machine jumps back to the S0 state. That is, State = S0, flag = 1.
[0092] The algorithm module is used to detect the image data to be processed and convert the initial information into the target key stream of the corresponding length based on the data length of the image data to be processed;
[0093] For details, please refer to Figure 1The algorithm modules of the illustrated embodiments will not be elaborated herein.
[0094] In some alternative embodiments, the above algorithm modules include:
[0095] A key expansion unit, configured to receive initial information and expand the initial information to obtain expansion parameters; the expansion parameters are used to initialize the register unit.
[0096] Among them, the key expansion unit, after receiving the initial information, can, according to the actual situation, perform format conversion on the initial information and fill it into the target register, and then, based on a preset algorithm, iteratively generate a parameter sequence, and splice the iteratively generated parameter sequence to obtain the expansion parameters.
[0097] A register unit, configured to generate a target key stream based on a preset timing sequence and expansion parameters.
[0098] Among them, the preset timing sequence can be the internal clock timing of the system to ensure that subsequent encryption / decryption operations can be executed according to the normal clock cycle. In each clock cycle, bits are extracted from a specific position in the memory unit and operated on according to a preset encryption algorithm to generate a target key stream.
[0099] In a specific implementation, 4 bits can be extracted in each cycle, and then the bits are reorganized according to a preset combination rule; the target bits obtained by bit reorganization are used as inputs and passed to a non-linear function to obtain an output result, and then the output result and the non-input bits after bit reorganization are subjected to a target operation to generate a target key stream.
[0100] In some alternative embodiments, a pipeline structure is provided in the register unit; the pipeline structure is used to connect the data paths between the registers;
[0101] The pipeline structure includes several levels of pipelines; two levels of pipelines are connected by an arithmetic module; each level of pipeline includes at least one D flip-flop; the first input terminal of each D flip-flop is connected to the output terminal of the upper arithmetic module; the second input terminal of each D flip-flop receives a clock signal; the output terminal of each D flip-flop is connected to the input terminal of the lower arithmetic module; the arithmetic module is used to perform modulo operation on the input signal.
[0102] Among them, the pipeline structure can divide the corresponding combinational logic according to the encryption algorithm to shorten the data paths between the registers in the register unit, thereby improving the operation efficiency of the circuit.
[0103] In some alternative embodiments, the arithmetic module includes a first adder, a second adder, and a multiplexer circuit; the first input terminal and the second input terminal of the first adder are used to connect to the output terminals of different D flip-flops; the output terminal of the first adder is connected to the first selection terminal of the multiplexer circuit; the carry terminal of the first adder is connected to the control terminal of the multiplexer circuit; the output terminal of the first adder is also connected to the third input terminal of the second adder; the fourth input terminal of the second adder is connected to a high level; the output terminal of the second adder is connected to the second selection terminal of the multiplexer circuit; the output terminal of the multiplexer circuit is the output terminal of the arithmetic module.
[0104] In a practical application, the pipeline structure set in the register unit is as Figure 4 shown Figure 4 which is provided with a first-level pipeline and a second-level pipeline. Among them, madder represents the arithmetic module. w>>1 means shifting the binary value stored in the variable w one bit to the right as a whole. Clk represents the clock signal, and D represents the D flip-flop.
[0105] In some alternative embodiments, the expression of the encryption algorithm is as shown in Equation 1:
[0106] s 16 = 2 15 s 15 + 2 17 s 13 + 2 21 s 10 + 2 20 s 4 +(1 + 2 8 )s 0 mod(2 31 - 1) Equation 1
[0107] where s 16 represents the 17th register unit, s 15 represents the 16th register unit, s 13 represents the 14th register unit, s 10 represents the 11th register unit, s 4 represents the 5th register unit, s 0 represents the 1st register unit. Equation 1 can be expressed as follows:
[0108] s 16 = u + 2 15 s 15 + 2 17 s 13 + 2 21 s 10 + 2 20 s 4 +(1 + 2 8 )s 0 mod(231 Equation 2 - 1
[0109] The modulo operation in Equation 2 can be completed by the structure of the operation module as shown in Figure 5 . In this structure, adder is an adder with a bit width of 31 bits, and its output includes the sum and carry of the addition operation. The upper part takes a and b as inputs, and obtains the sum (sum1) and carry signal (carry) of a and b. The lower part takes sum1 and "1" as inputs, and obtains the addition result sum2. The carry signal, sum1, and sum2 are all sent to the Sel module. The Sel module is a data selector. For the Sel module, when the input carry signal carry is 1, the result of sum2 is selected, otherwise the result of sum1 is selected. In this way, the output value is the calculation result of (a + b) mod (231 - 1). The propagation delay of the madder module is the delay of two adders plus the data selection circuit Sel.
[0110] Adjusting and splitting the calculation order of Equation 2 can shorten the data path between registers and improve the operating frequency of the circuit.
[0111] In some alternative embodiments, the schematic diagram of the algorithm module is as shown in Figure 6 . The algorithm module includes a reset Sync (synchronous) unit, an FSM_TOP unit, a ZUC (Zhang - Uniform Cryptographic) linear feedback shift register LFSR (Linear Feedback Shift Register) unit, a bit recombination BR unit, a key expansion Expand EX unit, a Function F unit, and an exclusive - OR Xor unit.
[0112] After power - on reset, the image encryption - decryption system is in the initial state at this time. Except for the FSM_TOP unit, the enables of the other units are reset to 0. At this time, if you want to start the system, the enable signal needs to be pulled high first, and the FSM_TOP unit samples the start signal; the start signal indicates whether the system starts to work. When the rising edge of the start signal is captured, the system starts to work. The enable signal indicates the enable signal. When the enable signal is high, the system works normally. When the enable signal is low, the system pauses. After the enable signal is pulled low and then pulled high again, the system will continue to work in the previous state.
[0113] If the key needs to be re - loaded, the rising edge of the start signal is required again to make the system work again. In any case where the Rst_n signal and the enable signal are both at a high level, the rising edge of the start signal can trigger a new working process of the system.
[0114] The function of the reset Sync unit is to synchronously release the reset signal to improve the stability of the system. After receiving the Rst_n signal, it will send the sync_reset signal to the ZUC linear feedback shift register LFSR unit, the FSM_TOP unit, and the Function F unit.
[0115] The FSM_TOP unit is the controller of the system, which enables each sub-module to work in coordination and also completes the detection of the rising edge of the start signal.
[0116] The working process of the algorithm module can be described as follows:
[0117] After receiving the synchronous reset signal sync_reset, when the reset is over and the enable is valid, the key expansion Expand EX unit will complete the key expansion work according to the key (key information) and iv (initial vector) signals on the current input port, generating the key expansion result, that is, Key[...]. At this time, the FSM_TOP unit can receive the start signal.
[0118] After detecting the rising edge of the start signal, the system is triggered to start. After the FSM_TOP unit detects the rising edge of the start signal and the enable signal is high, it receives 256-bit key information (Keydata[255:0]) and 184-bit initial vector (ivdata[183:0]). Then it controls Lfsr_reset and F_reset to perform an internal system reset on the corresponding units, and controls Lfsr_en, F_en, and Xor_en to enable the corresponding units.
[0119] After the internal system reset, the ZUC linear feedback shift register LFSR unit and the Function F unit will complete the key download and register setting work according to the designed timing. After the ZUC linear feedback shift register LFSR unit completes the key download, it reports to the FSM_TOP unit using the signal load_key_rdy;
[0120] Each unit runs according to the designed timing and enters the initialization stage of the ZUC algorithm. After the initialization stage is completed, the ZUC linear feedback shift register LFSR unit reports to the FSM_TOP unit through the init_rdy signal.
[0121] Each unit operates according to the designed timing sequence, and the system enters the working state of the ZUC algorithm. In this state, the ZUC linear feedback shift register (LFSR) unit needs to first complete the pre-computation preparation work of the pipeline. After completion, it reports to the FSM_TOP unit through the Pipe_rdy signal. Specifically, the ZUC LFSR unit will output a number of bits, such as Figure 6 S0[30:0], S2[30:0], S5[30:0], S7[30:0], S9[30:0], S11[30:0], S14[30:0], and S15[30:0] as shown. Bit Reorganization (BR) unit. It extracts bits from the output of the ZUC LFSR unit and combines them into 4 words according to the preset combination rule to obtain bx0, bx1, bx2, and bx3. Among them, bx0, bx1, and bx2 are passed as inputs to the Function F unit for processing, and two 32-bit words W[31:0] and U[31:0] and the enable signal w_en are output. Among them, the enable signal w_en represents the write enable. Exclusive OR (Xor) unit, which is used to perform an exclusive OR operation on the output of the Function F unit and bx3 to obtain the key stream on the output port Output_z.
[0122] After entering the working state, the FSM_TOP unit will receive the valid indication of w_valid sent by the Function F unit, and immediately raise Output_z_valid to indicate that the key stream on the output port Output_z is valid at this time and can be used for data encryption.
[0123] Data processing module, which is used to encrypt / decrypt the image data to be processed according to the target key stream to obtain the encrypted / decrypted image.
[0124] For details, please refer to Figure 1 the data processing module in the embodiments shown, which will not be elaborated here.
[0125] Scrambling module: It is used to generate a scrambling address based on the preset scrambling algorithm and write the target image data into the scrambling address in sequence; the target image data is the image data to be processed or the encrypted / decrypted image.
[0126] In some alternative embodiments, the scrambling module includes:
[0127] The first scrambling unit is used to obtain the initial address of the target image data; based on the preset scrambling algorithm, it makes a positive change to the initial address to generate and send the scrambling address to the scrambling control unit.
[0128] Among them, after obtaining the initial address of the target image data, the first scrambling unit uses a preset scrambling algorithm to generate a mapping sequence, and then uses the mapping sequence as the address transformation sequence.
[0129] The scrambling control unit is used to receive the scrambled address and write the target image data into the scrambled address.
[0130] Among them, the read and write functions of the register can be used to read the target image data and write it into the corresponding scrambled address.
[0131] In a practical application, the preset scrambling algorithm is the Logistic mapping scrambling algorithm. First, the Logistic mapping parameters can be defined to generate a Logistic mapping sequence. Among them, the length of the Logistic mapping sequence is the same as the length of the number of image pixels. Then, the Logistic mapping sequence is sorted, and the sorted indexes are recorded. The sorted indexes are the address transformation sequence. According to the address transformation sequence, the pixel values in the target image data are written into the corresponding scrambled addresses, and the scrambled image can be obtained.
[0132] In some alternative embodiments, the scrambling module further includes:
[0133] The first inverse scrambling unit is used to obtain the initial address of the target image data; based on the preset scrambling algorithm, perform an inverse transformation on the initial address to generate and send the scrambled address to the scrambling control unit.
[0134] Based on the preset scrambling algorithm and parameters, generate a mapping sequence, and convert the mapping sequence into an address transformation sequence, and the scrambled address corresponding to the target image data can be obtained.
[0135] In a practical application, the internal structure schematic diagram of the scrambling module is as Figure 7 shown.
[0136] The scrambling module includes a first scrambling unit (ARNOLD_Z), a first inverse scrambling unit (ARNOLD_N), a scrambling control unit (RAMCTRL), and two storage units RAM1 and RAM2.
[0137] When the Rst_n signal is pulled low, the system is reset, and the image data to be processed is stored in RAM2. After the reset ends, the internal state machine of the scrambling module enters the S0 state. Among them, the S0 state indicates the initial state of the scrambling module. In this state, the scrambling module completes some initialization operations, such as clearing the registers.
[0138] When the scrambling module receives the read signal in the S0 state, that is, after the valid flag signal of generating the key in the algorithm module, the scrambling control unit controls the reading of the image data to be processed and enters the data processing module for encryption and decryption operations on the image data to be processed. At the same time, the flag signal is pulled high, indicating that the read data is valid and available, and the state machine jumps to the next S1 state. Among them, the S1 state represents the data reading state.
[0139] When the scrambling module receives the trigger signal Encry_flg in the S1 state, it is determined to be in the encryption mode and jumps to the S2 state. If it receives the trigger signal Decry_flg, it is determined to be in the decryption mode and jumps to the S3 state. Among them, the S2 state indicates that the scrambling module needs to encrypt the target image data, and the S3 state indicates that the scrambling module needs to decrypt the image data.
[0140] When the scrambling control unit receives the enr signal, first, the write enable of RAM1 is pulled high, and the encrypted and decrypted data (Data_inr) is written into RAM1 using a counter. In the next state, the state machine gives the read address of RAM1, and at the same time, the state machine gives the original address (old_addr) to act on the forward transformation of the first scrambling unit. The first scrambling unit converts the single coordinate address into a double coordinate address, and then converts the address after the coordinate transformation of the double coordinate into a new single coordinate address (New_addr) as the write address of RAM2 to write the data (Data_out) into RAM2. When the preset scrambling times are reached, it returns to the S0 state.
[0141] In the decryption mode, the above process is repeated. The only difference is that the original address old_addr given by the scrambling control unit is input to the first inverse scrambling unit, and a new address (New_addr) is obtained through coordinate transformation inside the first inverse scrambling unit as the write address of RAM2. After the inverse scrambling times are reached, the system operation ends and returns to the S0 state again.
[0142] In some alternative embodiments, the image encryption and decryption system further includes:
[0143] A clock module: used to receive a differential clock signal and process the differential clock using a phase-locked loop to generate a global clock.
[0144] In some alternative embodiments, the reset module also generates a driving clock. Utilizing the characteristics of the phase-locked loop, the generated global clock can effectively eliminate clock offset and jitter problems, ensuring the stability and accuracy of the clock signal. At the same time, the phase-locked loop also generates a stand signal, and the stand signal is a flag indicating clock stability. When the stand signal is at a high level, it indicates that the clock after frequency division processing has reached a stable state and can provide a reliable clock reference for subsequent circuit modules.
[0145] In some alternative embodiments, the image encryption and decryption system further includes:
[0146] A reset module, configured to receive a system reset signal and generate a target reset signal based on the system clock signal.
[0147] Wherein, after receiving the system reset signal, the system reset signal interacts with the system clock signal to generate a target reset signal. In some alternative embodiments, the target reset signal is active low to perform the system reset operation. When the target reset signal is pulled high, it indicates the end of the system reset process.
[0148] In some alternative embodiments, the image encryption and decryption system further includes:
[0149] A display module, configured to display the encrypted / decrypted image.
[0150] Wherein, after the data processing module obtains the encrypted / decrypted image, it sends the image to the display module. After receiving the encrypted / decrypted image, the display module can scan the image in a fixed order and display the image on the display screen.
[0151] In a specific implementation, the schematic structural diagram of the display module is as Figure 8 shown, where LCD_CTRL is the screen control unit and LCD_DISPLAY is the screen display unit.
[0152] Wherein, Clk_cld represents the driving clock signal of the display module, and clk represents the clock signal of the display module, which can be uniformly provided by the system clock module to ensure the stability of the system clock.
[0153] Rst_n represents the reset signal of the display module. After the Rst_n signal is pulled low, the system resets and enters the waiting state. In this state, the internal signals of the screen control module are set to zero, and the screen display module controls the screen to be all black.
[0154] Wr_en represents whether data writing is allowed. When the Wr_en signal is 0, it indicates that data cannot be written. When Wr_en is 1, it indicates that data writing is allowed. Data_in[23:0] represents the data input with a bit width of 24 bits. When data arrives and the Wr_en signal is 1, the screen control module starts to operate.
[0155] In some alternative embodiments, there is a RAM memory inside the display module for storing the data to be displayed. After the data storage is completed, the control module starts to read out the data and at the same time controls the screen display module to start scanning.
[0156] Rd_en represents the enable signal of the screen display module. When the screen display module receives the enable signal Rd_en sent by the screen control module and the enable signal Rd_en is at a high level, the display module starts scanning. At this time, the internal Lcd_de signal of the display module is pulled high, and at the same time, the Lcd_vsync and Lcd_hsync signals are both pulled high, and scanning is performed according to the previously specified x and y coordinate regions. In each clock cycle of Lcd_dclk, the scanned data is transmitted accordingly. Lcd_dclk represents the display data clock signal, where the Lcd_de signal represents the data enable signal, and the Lcd_vsync and Lcd_hsync signals represent the vertical synchronization signal and the horizontal synchronization signal respectively.
[0157] In some alternative embodiments, two counters x_cnt and y_cnt can be used to record the scanned data. When both counters reach the maximum number of pixels of the image to be displayed at the same time, the Lcd_vsync and Lcd_hsync signals are both pulled low, and the scanning ends. For example, when the size of the image to be displayed is 256*256, when both counters reach 256 at the same time, it means the scanning ends.
[0158] After the scanning ends, the image to be displayed is shown by controlling Lcd_r[7:0], Lcd_g[7:0], and Lcd_b[7:0]. Among them, Lcd_r[7:0], Lcd_g[7:0], and Lcd_b[7:0] represent the eight-bit red data signal, the eight-bit green data signal, and the eight-bit blue data signal respectively.
[0159] In a practical application, the structural schematic diagram of the image encryption and decryption system is as Figure 9 shown. The figure includes: a reset unit, a clock unit, a key processing and transmission unit, a zuc256 algorithm unit, a data post-processing unit, an ARNOLD scrambling unit, and an LCD display unit.
[0160] Among them, the clock unit receives the differential clock signal, and the phase-locked loop in the clock unit processes the input differential clock signal to generate the global clock signal and the driving clock of the LCD display screen. With the characteristics of the phase-locked loop, the generated global clock can effectively eliminate the clock offset and jitter problems, ensuring the stability and accuracy of the clock signal. At the same time, a stand signal is generated as a clock stability flag. When it is at a high level, it proves that the divided clock is stable.
[0161] After the stand signal enters the reset unit, it jointly generates the output Rst_n reset signal with the system reset signal reset. The Rst_n reset signal is effective for resetting when it is at a low level. When Rst_n is pulled high, it indicates the end of the reset, and at this time, the phase-locked loop clock has generated a stable clock, and the preliminary preparation work of the system is completed.
[0162] At the beginning of the system operation, an initial vector and an initial key are first sent to enter the key processing and transmission stage. By splicing, a 256-bit initial key Key data and a 184-bit initial vector Iv data are generated. Then, the trigger signal trigger is pulled high and input into the zuc256 algorithm unit.
[0163] After receiving the trigger signal trigger, the initial vector, and the initial key, the zuc256 algorithm unit starts to run. After the initialization stage iteration, it enters the working stage, continuously generating a high level of zuc_flg to indicate that the zuc_out data is valid. At the same time, the key stream sequence counting starts. When the count reaches the total number of image pixels (pixel_len), the zuc_flg signal is pulled low, and the target key stream stops being generated.
[0164] When the zuc_flg signal is pulled high, the digital image pixels of the original image are read out from the ARNOLD scrambling unit. At the same time, the zuc_flg signal is input into the data post-processing unit data encryption module as the trigger signal of the encryption module. The data post-processing unit encryption module generates a data_en signal, that is, when the encrypted data data_out is validly output, the data_en signal is pulled high. When the data_en level changes from high to low, the encryption ends.
[0165] The data_en signal serves as the write enable of the first register in the scrambling unit in the ARNOLD scrambling unit, and the data generated by the data post-processing unit module is input and written into the first register in the scrambling unit. When the scrambling enable signal (Ar_en) is received, the ARNOLD scrambling unit generates a new address for scrambling, reads out the data stored in the first register in the scrambling unit in ascending address order, and writes it into the second register in the scrambling unit according to the new scrambled address. The following process is repeated until the expected scrambling times are reached, generating an Ar_trigger signal, triggering the zuc256 algorithm unit 2 times again to generate the key stream, and reading out the final scrambled data (Ar_out) for encryption with the key stream.
[0166] The system decryption process is similar to the encryption process. When the decryption trigger signal (de_en) of the data post-processing unit is received, the new address module is the ARNOLD inverse scrambling module, serving as the write address of the two registers. It ends after the inverse scrambling times reach the encryption scrambling times, and triggers the ZUC-256 algorithm again to generate the key and repeat the above process.
[0167] After the scrambling process ends, read out the scrambling result (Ar_out) in the second register of the scrambling unit, and input it into the value data post-processing unit module for secondary encryption and decryption. Then, generate an Lcd signal through the data post-processing unit for the encrypted and decrypted data, and input the Lcd signal into the LCD display module to display the image.
[0168] After the encryption and decryption process, send the data into the LCD display module, and at the same time raise the control signal to start scanning the image in a fixed order for display on the LCD liquid crystal display screen. Among them, Lcd_r, Lcd_g, and Lcd_b respectively represent the red data signal, the green data signal, and the blue data signal, and Lcd_others represents the set of other parameters related to the LCD display module.
[0169] According to an embodiment of the present invention, an embodiment of an image encryption and decryption method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0170] In this embodiment, an image encryption and decryption method is provided. Figure 10 It is a schematic flowchart of the image encryption and decryption method according to an embodiment of the present invention, as Figure 10 shown. The system includes the following modules:
[0171] Step S1001, generate initial information, and generate a target key stream based on the initial information; the initial information includes key information and an initial vector.
[0172] Among them, the initial information includes key information and an initial vector. The lengths of the key information and the initial vector can be set according to the requirements of the encryption algorithm. The key information and the initial vector can be generated according to the actual situation.
[0173] After obtaining the initial information, the preset algorithm can be initialized using the initial information. Then, based on the actual requirements, determine the length of the target key stream to be generated. After generating the target key stream of the corresponding length based on the preset algorithm, subsequent encryption / decryption operations can be executed.
[0174] Step S1002, obtain the image processing requirements and the image data to be processed; the image data to be processed corresponds to the image processing requirements; the image processing requirements include at least one of image encryption and image decryption.
[0175] Among them, the image processing requirements include image encryption and image decryption. When the image processing requirement is to encrypt an image, the image data to be processed is unencrypted image data; when the image processing requirement is to decrypt an image, the image data to be processed is encrypted image data.
[0176] Step S1003, when the image processing requirement includes image encryption, encrypt the image data to be processed based on the target key stream to obtain an encrypted image.
[0177] When the image processing requirement includes image encryption, the image data to be processed can be encrypted through the target key stream to obtain the processed image data. By performing format conversion on the processed image data, an encrypted image can be obtained.
[0178] Step S1004, when the image processing requirement includes image decryption, decrypt the image data to be processed based on the target key stream to obtain a decrypted image.
[0179] When the image processing requirement includes image decryption, the image data to be processed can be processed through the target key stream to obtain the processed image data. By performing format conversion on the processed image data, a decrypted image can be obtained.
[0180] For the image encryption and decryption method provided in this embodiment, the key information in the initial information can be set according to actual requirements. When permitted by the preset encryption algorithm, the longer the length of the key information and the larger the space, the higher the security of image encryption can be enhanced. Moreover, after encrypting the image data to be processed through the target key stream, the statistical characteristics between image pixels can be effectively destroyed to resist statistical analysis attacks.
[0181] In this embodiment, an image encryption and decryption device is further provided. This device is used to implement the above-mentioned embodiment and the preferred implementation manners, and those that have been described will not be elaborated again. As used below, the term "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0182] This embodiment provides an image encryption and decryption device, as Figure 11 shown, including:
[0183] A generation module 1101, configured to generate initial information and generate a target key stream based on the initial information; the initial information includes key information and an initial vector;
[0184] An acquisition module 1102 is configured to acquire an image processing requirement and image data to be processed; the image data to be processed corresponds to the image processing requirement; the image processing requirement includes at least one of image encryption and image decryption;
[0185] An encryption module 1103 is configured to, when the image processing requirement includes image encryption, encrypt the image data to be processed based on a target key stream to obtain an encrypted image;
[0186] A decryption module 1104 is configured to, when the image processing requirement includes image decryption, decrypt the image data to be processed based on the target key stream to obtain a decrypted image.
[0187] The further function descriptions of the above-mentioned various modules and units are the same as those in the corresponding embodiments above, and will not be elaborated here.
[0188] The image encryption and decryption device in this embodiment is presented in the form of functional units. Here, the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and a memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0189] An embodiment of the present invention further provides a computer device having the above Figure 11 shown image encryption and decryption device.
[0190] Please refer to Figure 12 , Figure 12 which is a schematic structural diagram of a computer device provided by an alternative embodiment of the present invention. As shown in Figure 12 , the computer device includes: one or more processors 10, a memory 20, and an interface for connecting each component, including a high-speed interface and a low-speed interface. Each component communicates with each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in the memory or on the memory to display graphical information of a GUI on an external input / output device (such as a display device coupled to the interface). In some alternative embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a set of blade servers, or a multi-processor system). Figure 12 One processor 10 is taken as an example in
[0191] The processor 10 may be a central processing unit, a network processor, or a combination thereof. Among them, the processor 10 may further include a hardware chip. The above-mentioned hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The above-mentioned programmable logic device may be a complex programmable logic device, a field-programmable gate array, a generic array logic, or any combination thereof.
[0192] Among them, the memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiments.
[0193] The memory 20 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some alternative embodiments, the memory 20 may optionally include a memory remotely provided with respect to the processor 10, and these remote memories may be connected to the computer device through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0194] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk, or a solid-state drive; the memory 20 may also include a combination of the above types of memories.
[0195] The computer device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30, and the output device 40 may be connected through a bus or other means. Figure 12 Taking the connection through the bus as an example.
[0196] The input device 30 can receive input digital or character information, and generate key signal inputs related to the user settings and function controls of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (such as an LED), and a tactile feedback device (such as a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light-emitting diode, a display, and a plasma display. In some alternative embodiments, the display device may be a touch screen.
[0197] Embodiments of the present invention also provide a computer-readable storage medium. The method according to the embodiments of the present invention can be implemented in hardware, firmware, or be implemented as computer code that can be recorded on a storage medium, or be implemented as computer code that is originally stored in a remote storage medium or a non-transitory machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored as such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.
[0198] A part of the present invention can be applied as a computer program product, such as computer program instructions, which when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should be able to understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.
[0199] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. An image encryption and decryption system, characterized in that: The system comprises: A key module, used to transmit initial information to the algorithm module; the initial information includes key information and an initial vector; the initial vector represents an auxiliary parameter in encryption; An algorithm module, used for detecting the image data to be processed, and converting the initial information into a target key stream of corresponding length based on the data length of the image data to be processed; The data processing module is used to encrypt / decrypt the image data to be processed according to the target key stream to obtain an encrypted / decrypted image.
2. The system according to claim 1, characterized in that The algorithm module includes: A key expansion unit, used for receiving initial information and expanding the initial information to obtain an expansion parameter; the expansion parameter is used for initializing the register unit; The register unit is used to generate a target key stream based on a preset timing and the extended parameters.
3. The system according to claim 2, characterized in that The register unit is provided with a pipeline structure; the pipeline structure is used to connect the data paths between the registers; The pipeline structure includes several pipeline levels; two pipeline levels are connected by a layer of operation modules; each pipeline level includes at least one D flip-flop; the first input end of each D flip-flop is connected to the output end of the upper layer operation module; the second input end of each D flip-flop is connected to the clock signal; the output end of each D flip-flop is connected to the input end of the lower layer operation module; the operation module is used to take the modulus of the input signal.
4. The system according to claim 3, characterized in that The operation module includes a first adder, a second adder and a number selection circuit; The first input terminal and the second input terminal of the first adder are used to connect to the output terminals of different D flip-flops; the output terminal of the first adder is connected to the first selection terminal of the number selection circuit; the carry terminal of the first adder is connected to the control terminal of the number selection circuit; The output end of the first adder is also connected to the third input end of the second adder; the fourth input end of the second adder is connected to a high level; the output end of the second adder is connected to the second selection end of the number selection circuit; the output end of the number selection circuit is the output end of the operation module.
5. The system according to claim 1, characterized in that The system further comprises: The scrambling module is used to generate a scrambling address based on a preset scrambling algorithm, and write the target image data into the scrambling address in sequence; the target image data is the image data to be processed or the encrypted / decrypted image.
6. The system according to claim 5, characterized in that The scrambling module comprises: A first scrambling unit is used to obtain an initial address of target image data; based on the preset scrambling algorithm, make a positive change to the initial address to generate and send a scrambled address to a scrambling control unit; The scrambling control unit is used to receive the scrambling address and write the target image data into the scrambling address.
7. The system according to claim 6, characterized in that The scrambling module also includes: The first scrambling inverse unit is used to obtain the initial address of the target image data; based on the preset scrambling algorithm, the initial address is reversely changed to generate and send the scrambling address to the scrambling control unit.
8. An image encryption and decryption method, characterized in that: The method comprises: Generate initial information, and generate a target key stream based on the initial information; the initial information includes key information and an initial vector; Acquire image processing requirements and image data to be processed; the image data to be processed corresponds to the image processing requirements; the image processing requirements include at least one of image encryption and image decryption; In the case where the image processing requirement includes image encryption, encrypting the image data to be processed based on the target key stream to obtain an encrypted image; In the case where the image processing requirement includes image decryption, the image data to be processed is decrypted based on the target key stream to obtain a decrypted image.
9. An image encryption and decryption device, characterized in that: The device comprises: A generating module, used to generate initial information, and generate a target key stream based on the initial information; the initial information includes key information and an initial vector; An acquisition module, used for acquiring image processing requirements and image data to be processed; the image data to be processed corresponds to the image processing requirements; the image processing requirements include at least one of image encryption and image decryption; An encryption module, used for, when the image processing requirement includes image encryption, performing encryption processing on the image data to be processed based on the target key stream to obtain an encrypted image; A decryption module is used to decrypt the image data to be processed based on the target key stream to obtain a decrypted image when the image processing requirement includes image decryption.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the image encryption and decryption method according to claim 8.
Citation Information
Cited By
Data processing method and system, chip, electronic equipment, storage medium and computer program product
CN122286850A