Communication method and communication device supporting variable authentication tag length

The ZUC algorithm enhances security and integrity verification for 5G communications by generating flexible authentication tag lengths, addressing key attack risks through iterative key stream calculations and secure initial vector configurations.

CN120320935APending Publication Date: 2025-07-15BEIJING SYLINCOM TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510396505.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

The existing ZUC algorithm has a short key length and a single integrity authentication. It is impossible to use integrity verification of different lengths for messages of different degrees of importance, resulting in an increased risk of key cracking and unable to meet the security requirements of 5G communication.

Method used

The Zu Chong algorithm is used to generate key streams of different lengths, and the target message authentication code of 32-bit, 64-bit or 128-bit is generated through key mixing and iterative calculation. It supports 256-bit initialization key input, and combines the critical path of pipeline structure optimization and integrity verification to improve the data processing rate.

Benefits of technology

It improves the security and collision resistance of the algorithm, supports authentication tags of different lengths, enhances the security protection of 5G mobile communications, and meets the application needs of high speed and low latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120320935A_ABST
    Figure CN120320935A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and a communication device supporting a variable authentication label length, and the method comprises the steps: generating a first key stream and a second key stream according to input data through employing a ZUC algorithm, and carrying out the encryption processing of the input data through employing the first key stream, and obtaining a ciphertext message; a secret key mixing step: performing shift operation on the current secret key and the next secret key in the second secret key stream to obtain secret key mixed data; a first updating step: updating the next secret key as the current secret key, and sequentially repeating the secret key mixing step and the first updating step for at least one time until all secret key mixed data is obtained; calculating a target message authentication code according to the second key stream and all key mixed data; and sending the ciphertext message and the target message authentication code to a communication receiver. The problem that in the prior art, the bit number of integrity verification is too single, and integrity verification of different lengths cannot be adopted for messages of different importance degrees, so that the risk that a secret key is attacked and cracked is increased is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted communication. Specifically, it relates to a communication method supporting variable authentication tag lengths, a communication device supporting variable authentication tag lengths, a computer-readable storage medium, and a computer program product. Background Technique

[0002] From the development history of modern cryptography, it can be seen that compared with the widely used 3DES, AES, etc., the research on ZUC is relatively less, which can be roughly divided into three directions: 1) Improving the algorithm throughput rate. For example, optimizing the processing logic of the hardware framework, inserting a pipeline structure, and optimizing the critical path of encryption / decryption. 2) Resource optimization. Reducing resource utilization by adopting a reconfigurable structure and lightweight design, etc. For example, optimizing parts such as the S-box by using the method of logic reuse, reducing the use of resources. 3) Optimizing the anti-attack ability of the algorithm. For example, focusing on the algorithm itself to improve the security of ZUC. However, the current research has not deeply studied improving the security of hardware circuits. For example, by improving the key length, authentication tag length, etc., it cannot meet the security requirements of current 5G communication. The ZUC algorithm is a commonly used cryptographic algorithm. With the determination of the new generation of mobile communication 5G standard, due to limitations such as relatively short key length, single integrity authentication, and insufficient length, the ZUC-128 algorithm has weak anti-collision ability, increasing the risk of brute-force cracking or other key search attacks. There is also relatively little research on ZUC-256 currently, and the existing ones are only for hardware optimization of the encryption / decryption process, lacking research on integrity authentication. Summary of the Invention

[0003] The main objective of this application is to provide a communication method supporting variable authentication tag lengths, a communication device supporting variable authentication tag lengths, a computer-readable storage medium, and a computer program product, so as to at least solve the problem in the prior art that the number of digits for integrity verification is too single, and different lengths of integrity verification cannot be adopted for messages of different importance levels, resulting in an increased risk of the key being attacked and cracked.

[0004] To achieve the above object, according to one aspect of the present application, a communication method supporting variable authentication tag lengths is provided, including: obtaining input data, generating a first key stream and a second key stream according to the input data by using the Zu Chongzhi algorithm, and encrypting the input data by using the first key stream to obtain a ciphertext message, where the input data includes an initial key, an initial vector, a constant term, and a plaintext message, and the second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream; a key mixing step of performing a shift operation on the current key and the next key in the second key stream to obtain key mixing data corresponding to the current key and the next key, where the current key is the current key participating in the shift operation in the second key stream, the next key is the next key adjacent to the current key in the second key stream, and the length of the key mixing data is 32 bits; a first update step of updating the next key to be the current key, and sequentially repeating the key mixing step and the first update step at least once until all the keys in the second key stream participate in the shift operation to obtain all the key mixing data; iteratively calculating a target message authentication code according to the second key stream and all the key mixing data, where the length of the target message authentication code is 32 bits, or 64 bits, or 128 bits; sending the ciphertext message and the target message authentication code to a communication recipient so that the communication recipient compares a verification message authentication code with the target message authentication code to determine whether the data transmission is correct, where the verification message authentication code is a message authentication code generated by the communication recipient according to the ciphertext message, the initial key, and the initial vector.

[0005] Optionally, before obtaining the input data, the method further includes: in the case where the register value of a configuration register is 1, generating the initial vector by hardware circuit calculation, where the configuration register is a register for determining the configuration method of the initial vector; in the case where the register value of the configuration register is 0, generating the initial vector by a software configuration method, where the software configuration method is a method configured by a random generation algorithm.

[0006] Optionally, a shift operation is performed on the current key and the next key in the second key stream to obtain the key mixing data corresponding to the current key and the next key, including: substituting the current key and the next key in the second key stream into a first formula for calculation to obtain the key mixing data corresponding to the current key and the next key. The first formula is z[i] = c[j / 32] << i || c[j / 32 + 1] >> 31 - i, where z[i] represents the i-th mixing value in the key mixing data, i = 0, 1, 2,..., 31, c[j / 32] represents the current key, c[j / 32 + 1] represents the next key, j = 1, 2, 3... L, L is the number of keys in the second key stream, << i represents a left shift by i bits, and >> represents a right shift.

[0007] Optionally, a target message authentication code is iteratively calculated according to the second key stream and all the key mixing data. The target message authentication code includes a first message authentication code. The length of the first message authentication code is 32 bits and includes at least: an assignment step of taking the first intermediate value of the current iterative compression intermediate data as the first key value in the second key stream. The current iterative compression intermediate data is a data set obtained by performing an exclusive OR operation on all data in the current mixed key data. The current mixed key data is the mixed key data currently undergoing iterative calculation among all the mixed key data. The first intermediate value is the first intermediate value in the current iterative compression intermediate data; a determination step of determining the first intermediate value as the current intermediate value; a first exclusive OR step of, when the value corresponding to the current bit position of the plaintext message is 1, performing an exclusive OR operation on the current intermediate value and the current mixed value in the current key mixing data to obtain an intermediate value corresponding to the current exclusive OR operation. The current bit position is the bit position corresponding to the current mixed value; a jump step of, when the value corresponding to the current bit position of the plaintext message is 0, not performing an exclusive OR operation on the current intermediate value and the current mixed value in the current key mixing data; a second update step of updating the next mixed value as the current mixed value and simultaneously updating the intermediate value corresponding to the current exclusive OR operation as the current intermediate value. The next mixed value is the next mixed value of the current mixed value; a repetition step of sequentially repeating the first exclusive OR step, the jump step, and the second update step at least once until all data in the current mixed key data have completed iterative calculation to obtain the current iterative compression intermediate data. The length of the current iterative compression intermediate data is 32 bits; a third update step of updating the next mixed key data as the current mixed key data. The next mixed key data is the next mixed key data of the current mixed key data; sequentially repeating the assignment step, the determination step, the first exclusive OR step, the jump step, the second update step, the repetition step, and the third update step at least once until all the mixed data have completed calculation to obtain all the iterative compression intermediate data; a second exclusive OR step of sequentially performing an exclusive OR operation on the last intermediate values of all the iterative compression intermediate data to obtain an exclusive OR output result. The length of the exclusive OR output result is 32 bits; performing data processing on the exclusive OR output result according to the plaintext message to obtain the first message authentication code.

[0008] Optionally, data processing is performed on the XOR output result according to the plaintext message to obtain the first message authentication code, including: when the length of the plaintext message is an integer multiple of the bit width, performing the XOR operation on the XOR output result and the last key of the second key stream to calculate the first message authentication code; when the length of the plaintext message is not an integer multiple of the bit width, determining that the first message authentication code is the XOR output result.

[0009] Optionally, the target message authentication code is iteratively calculated according to the second key stream and all the key mixed data. The target message authentication code includes a second message authentication code with a length of 64 bits, and further includes: sequentially repeating the assignment step, the determination step, the first XOR step, the jump step, the second update step, the repetition step, the third update step, and the second XOR step at least once until all the iterative compression intermediate data is calculated to obtain a first XOR output result; performing data processing on the first XOR output result according to the plaintext message to obtain a first tag intermediate value; taking the first intermediate value of the current iterative compression intermediate data as the second key value in the second key stream; sequentially repeating the determination step, the first XOR step, the jump step, the second update step, the repetition step, the third update step, and the second XOR step at least once until all the iterative compression intermediate data is calculated to obtain a second XOR output result; performing data processing on the second XOR output result according to the plaintext message to obtain a second tag intermediate value; sequentially concatenating the first tag intermediate value and the second tag intermediate value to obtain the second message authentication code.

[0010] Optionally, a target message authentication code is iteratively calculated according to the second key stream and all the key mixing data. The target message authentication code includes a third message authentication code, and the third message authentication code is 128 bits. It further includes: sequentially repeating the assignment step, the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step at least once until all the iteratively compressed intermediate data is calculated to obtain a third exclusive-OR output result; performing data processing on the third exclusive-OR output result according to the plaintext message to obtain a third tag intermediate value; taking the first intermediate value of the current iteratively compressed intermediate data as the second key value in the second key stream; sequentially repeating the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step at least once until all the iteratively compressed intermediate data is calculated to obtain a fourth exclusive-OR output result; performing data processing on the fourth exclusive-OR output result according to the plaintext message to obtain a fourth tag intermediate value; taking the first intermediate value of the current iteratively compressed intermediate data as the third key value in the second key stream; sequentially repeating the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step at least once until all the iteratively compressed intermediate data is calculated to obtain a fifth exclusive-OR output result; performing data processing on the fifth exclusive-OR output result according to the plaintext message to obtain a fifth tag intermediate value; taking the first intermediate value of the current iteratively compressed intermediate data as the fourth key value in the second key stream; sequentially repeating the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step at least once until all the iteratively compressed intermediate data is calculated to obtain a sixth exclusive-OR output result; performing data processing on the sixth exclusive-OR output result according to the plaintext message to obtain a sixth tag intermediate value; sequentially concatenating the third tag intermediate value, the fourth tag intermediate value, the fifth tag intermediate value, and the sixth tag intermediate value to obtain the third message authentication code.

[0011] According to another aspect of the present application, a communication device supporting variable authentication tag lengths is provided. The device includes: an encryption unit configured to obtain input data, generate a first key stream and a second key stream according to the input data by using the ZUC algorithm, and encrypt the input data by using the first key stream to obtain a ciphertext message. The input data includes an initial key, an initial vector, a constant term, and a plaintext message. The second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream; a key mixing unit configured to perform a key mixing step, perform a shift operation on the current key and the next key in the second key stream to obtain key mixing data corresponding to the current key and the next key. The current key is the key currently participating in the shift operation in the second key stream, and the next key is the next key adjacent to the current key in the second key stream. The length of the key mixing data is 32 bits; an updating unit configured to perform a first updating step, update the next key to the current key, and sequentially repeat the key mixing step and the first updating step at least once until all keys in the second key stream participate in the shift operation to obtain all the key mixing data; an iterative calculation unit configured to iteratively calculate a target message authentication code according to the second key stream and all the key mixing data. The length of the target message authentication code is 32 bits, or 64 bits, or 128 bits; a sending unit configured to send the ciphertext message and the target message authentication code to a communication recipient, so that the communication recipient compares a verification message authentication code with the target message authentication code to determine whether data transmission is correct. The verification message authentication code is a message authentication code generated by the communication recipient based on the ciphertext message, the initial key, and the initial vector.

[0012] According to yet another aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium includes a stored program, wherein when the program runs, it controls the device where the computer-readable storage medium is located to execute any one of the methods.

[0013] According to still another aspect of the present application, a computer program product is provided, including computer instructions, which when executed by a processor, implement any one of the methods.

[0014] Applying the technical solution of the present application in a communication method that supports variable authentication tag lengths, first, obtain input data, and use the ZUC algorithm to generate a first key stream and a second key stream based on the above input data, and encrypt the above input data using the above first key stream to obtain a ciphertext message. The above input data includes an initial key, an initial vector, a constant term, and a plaintext message. The above second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream; then, in the key mixing step, perform a shift operation on the current key and the next key in the above second key stream to obtain key mixing data corresponding to the above current key and the above next key. The above current key is the current key participating in the above shift operation in the above second key stream, and the above next key is the next key adjacent to the above current key in the above second key stream. The length of the above key mixing data is 32 bits; after that, in the first update step, update the above next key to the above current key, and sequentially repeat the above key mixing step and the above first update step at least once until all the keys in the above second key stream participate in the above shift operation to obtain all the above key mixing data; after that, iteratively calculate a target message authentication code based on the above second key stream and all the above key mixing data. The length of the above target message authentication code is 32 bits, or 64 bits, or 128 bits; finally, send the above ciphertext message and the above target message authentication code to a communication recipient, so that the above communication recipient compares the verification message authentication code with the above target message authentication code to determine whether the data transmission is correct. The above verification message authentication code is a message authentication code generated by the above communication recipient based on the above ciphertext message, the above initial key, and the above initial vector. The present application supports 256-bit initialization key input, uses the ZUC algorithm for operation to obtain key streams of different lengths, performs integrity verification based on the key streams, generates a target message authentication code (integrity verification tag length) of the corresponding length, supports three configurable integrity verifications (32 bits, 64 bits, 128 bits), and improves the security of the algorithm. It has a 256-bit key length, provides a larger key space, and supports authentication tags of different lengths (32 bits / 64 bits / 128 bits), has higher security and stronger collision resistance, and can be widely applied to the security protection of 5G mobile communication. At the same time, in order to further meet the 5G application goals of high speed and low latency, the present invention adopts a pipeline structure to improve the data processing rate. The present application solves the problem that the number of bits for integrity verification in the prior art is too single, and it is impossible to adopt different lengths of integrity verification for messages of different importance levels, resulting in an increased risk of the key being attacked and cracked. Description of the Drawings

[0015] Figure 1It shows a hardware structure block diagram of a mobile terminal that executes a communication method supporting variable authentication tag lengths according to an embodiment of the present application;

[0016] Figure 2 It shows a schematic flowchart of a communication method supporting variable authentication tag lengths according to an embodiment of the present application;

[0017] Figure 3 It shows a schematic structural diagram of a communication hardware implementation system supporting variable authentication tag lengths according to an embodiment of the present application;

[0018] Figure 4 It shows a schematic diagram of communication data processing supporting variable authentication tag lengths according to an embodiment of the present application;

[0019] Figure 5 It shows a schematic diagram of the generation of an integrity protection data stream according to an embodiment of the present application;

[0020] Figure 6 It shows a structural block diagram of a communication device supporting variable authentication tag lengths according to an embodiment of the present application.

[0021] Among them, the above-mentioned drawings include the following reference numerals:

[0022] 102, a processor; 104, a memory; 106, a transmission device; 108, an input / output device. Detailed implementation manners

[0023] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.

[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] For the convenience of description, some nouns or terms involved in the embodiments of the present application are explained below:

[0027] ZUC algorithm: includes Zu Chongzhi algorithm, encryption algorithm 128-EEA3 and integrity algorithm 128-EIA3.

[0028] As introduced in the background technology, the ZUC-128 algorithm in the prior art has relatively short key length, single integrity authentication, insufficient length and other limitations, and weak anti-collision capability, which increases the risk of brute force cracking or other key search attacks. There are also few existing studies on ZUC-256, and the only ones are hardware optimization for the encryption / decryption process, etc., lacking research on integrity authentication. In order to solve the problem that the number of bits for integrity authentication is too single and it is impossible to adopt different lengths of integrity authentication for messages of different importance, resulting in an increased risk of key being attacked and cracked, the embodiments of the present application provide a communication method supporting variable authentication tag length, a communication device supporting variable authentication tag length, a computer-readable storage medium and a computer program product.

[0029] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the accompanying drawings in the embodiments of the present invention.

[0030] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 FIG. 1 is a hardware structure block diagram of a mobile terminal supporting a communication method with a variable authentication tag length according to an embodiment of the present invention. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1 Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It can be understood by those skilled in the art thatFigure 1 The structure shown is only schematic and does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal may further include more or fewer components than those shown in Figure 1 , or have a configuration different from that shown in Figure 1 .

[0031] The memory 104 can be used to store computer programs. For example, software programs and modules of application software, such as the computer program corresponding to the communication method supporting variable authentication tag lengths in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely provided with respect to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include the wireless network provided by the communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0032] In this embodiment, a communication method supporting variable authentication tag lengths running on a mobile terminal, a computer terminal, or a similar computing device is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0033] Figure 2 is a flowchart of the communication method supporting variable authentication tag lengths according to the embodiments of the present application. As Figure 2 shown, the method includes the following steps:

[0034] Step S201: Obtain the input data, generate a first key stream and a second key stream according to the above input data using the Zu Chongzhi algorithm, and encrypt the above input data using the above first key stream to obtain a ciphertext message. The above input data includes an initial key, an initial vector, a constant term, and a plaintext message. The above second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream.

[0035] Specifically, for the encryption / decryption function: Use the Zu Chongzhi algorithm to generate a first key stream according to the initial key, initial vector, constant term, and plaintext message, and use the first key stream to perform encryption / decryption processing on the input data. For the integrity protection function: Use the Zu Chongzhi algorithm to generate a second key stream according to the initial key, initial vector, constant term, and plaintext message. The second key stream is a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream, and generate 32-bit, 64-bit, and 128-bit tag values respectively. That is, the key stream for obtaining the ciphertext is different from the key stream for the authentication tag. Therefore, the key stream for encryption / decryption is the key stream of L (L = [(l + 31) / 32] + 2×t / 32) when t is 0, rather than one of the 32-bit key stream, 64-bit key stream, and 128-bit key stream; the 32-bit key stream, 64-bit key stream, and 128-bit key stream are the key streams for 32, 64, and 128-bit authentication tags.

[0036] As Figure 3 shown, a ZUC-256 hardware implementation system supporting variable authentication tag lengths is provided, including 5 modules: an initial vector generation module, an encryption / decryption module, an S-box module, an integrity protection module, and a top-level module. Among them, the encryption / decryption module is divided into three parts: a linear feedback shift register module (LFSR), a bit recombination module (BR), and a non-linear function module (F). The initial value of the linear feedback shift register module is composed of the input data. In the first sixty-four rounds of the initialization mode, the padding data is related to the non-linear F function. In the working mode, it does not accept any input and continuously generates data through linear feedback. The register data of the bit recombination module is spliced from the data in the linear feedback shift register. The non-linear function module outputs a non-linearly processed data through operations such as XOR, modulo operation, splicing, and S-box. The S-box is a multiplexing structure, divided into S0 and S1, with eight module instantiations, four for S0 and four for S1. The S-box is a non-linear module and is the basic structure for performing permutation calculations in symmetric key algorithms. It is implemented in the form of ROM, and the switch is controlled by an enable signal to reduce power consumption.

[0037] In the ZUC-256 encryption / decryption algorithm, the linear feedback shift register module (LFSR) and the S-box module adopt a logic multiplexing method. Since the initialization mode and the working mode of the linear feedback shift register module (LFSR) work serially, it is controlled according to the number of calculation rounds to select the input and output data. In the initialization stage, the data W generated by the padding function and the F function is related. The generation of W includes two memory units R1 and R2. The inputs are X0, X1, and X2 from the output of the bit recombination module, and the generated padding data is W. The specific process is as follows:

[0038] W = (X0 ^ R1) + R2;

[0039] W1 = R1 + X1;

[0040] W2 = R2 ^ X2;

[0041] R1 = S((L1(W1L||W2H));

[0042] R2 = S((L2(W2L||W1H));

[0043] Among them, L1 and L2 are linear transformation functions, L1(X) = X ^ (X <<< 2) ^ (X <<< 10) ^ (X <<< 18) ^ (X <<< 24), L2(X) = X ^ (X <<< 8) ^ (X <<< 14) ^ (X <<< 22) ^ (X <<< 30); W1L represents the lower 16 bits of W1, || represents the concatenation symbol, such as W1L||W2H represents the new 32-bit number composed of the lower 16 bits of W1 and the higher 16 bits of W2; S represents the S-box.

[0044] Using the generated value of W and calculating according to the following formula, the padding data S16 is obtained: S16 = (V + W >> 1) mod (2 31 - 1), where V = 2 15 S15 + 2 17 S13 + 2 21 S10 + 2 20 S4 + (1 + 2 8 )S0 mod (2 31 - 1); (a + b) mod (2 31 - 1) represents taking the modulus of the sum of a + b with respect to 2 31 - 1; >> represents right shift.

[0045] In the working mode, no input is accepted and it is continuously generated by linear feedback. The linear feedback function is: S16 = 2 15 S15 + 2 17 S13 + 2 21 S10 + 2 20 S4 + (1 + 2 8)S0 mod(2 31 -1).

[0046] The S-box is the basic structure for performing permutation calculations in symmetric key algorithms and is a non-linear component. The S-box here consists of 4 juxtaposed 8×8 S-boxes, totaling 32×32, forming S0 and S1. Then it is reused to form 4 S-boxes, spliced into 32 bits, i.e., S = (S0, S1, S2, S3), where S0 = S2 and S1 = S3. This module is divided into two parts, namely S0 and S1. In the ZUC-256 encryption / decryption module, since both R1 and R2 use the S-box, a total of 8 are instantiated. The key stream input by the integrity protection module is generated by the encryption / decryption module. The number of generated keys (i.e., the number of keys in the second key stream) is: L = [(l + 31) / 32] + 2×t / 32, where l is the length of the plaintext message, [] represents rounding up, and t is the integrity protection tag length (optional 32 bits, 64 bits, 128 bits).

[0047] It should also be noted that the encryption / decryption part first generates a key stream based on the configured initial key and initial vector, and then XORs the key stream with the plaintext to obtain the ciphertext, or XORs the key stream with the ciphertext to obtain the plaintext, thus realizing the encryption / decryption function with a 256-bit key length. Moreover, before performing the method of the present invention, the communication sender and the communication receiver exchange keys through methods such as key negotiation, so as to have a consistent initial key; the initial vector may be attached before the ciphertext and sent by the communication sender to the communication receiver together (explicit sharing), or the communication sender and the communication receiver generate the corresponding initial vector in a pre-agreed manner (through agreed rules). Therefore, after encrypting the above input data with the above first key stream to obtain the ciphertext message, the above ciphertext message is sent to the communication receiver, so that the above communication receiver first calculates its own decryption key stream based on the initial key and the initial vector, and then decrypts the above ciphertext message according to the decryption key stream.

[0048] Step S202, the key mixing step, performs a shift operation on the current key and the next key in the above second key stream to obtain the key mixing data corresponding to the above current key and the above next key. The above current key is the current key participating in the above shift operation in the above second key stream, and the above next key is the next key adjacent to the above current key in the above second key stream. The length of the above key mixing data is 32 bits.

[0049] Specifically, as Figure 4 shown, the key stream generated by the encryption / decryption module is input into the integrity protection module. The entire data flow process of integrity protection includes the following processes: initialization, key generation, key mixing, iterative compression, and output processing. Specifically, see Figure 5Among them, the pipeline structure of the integrity protection module consists of three steps: key mixing, iterative compression, and output processing. Initialization and key generation are completed by the encryption / decryption module and input into the integrity protection module in the form of a stream cipher. The key stream input into the integrity protection module enters the next step for key mixing, using the key of the current state and the key of the next state, and performing operations such as concatenation to obtain the intermediate data after key mixing (i.e., the above-mentioned key mixed data), a total of 32 pieces.

[0050] Step S203, the first update step, updates the above-mentioned next key to the above-mentioned current key, and sequentially repeats the above-mentioned key mixing step and the above-mentioned first update step at least once until all the keys in the above-mentioned second key stream participate in the above-mentioned shift operation to obtain all the above-mentioned key mixed data.

[0051] Specifically, repeat the above-mentioned key mixing step and the above-mentioned first update step. As Figure 5 shown, after the key 0 and the key 1 are mixed to generate 32-bit key mixed data, update the key 1 to the current key, and remix the key 1 and the key 2 to generate 32-bit key mixed data, and so on until all the keys complete the above-mentioned shift operation to obtain all the key mixed data.

[0052] Step S204, iteratively calculate the target message authentication code based on the above-mentioned second key stream and all the above-mentioned key mixed data. The length of the above-mentioned target message authentication code is 32 bits, or 64 bits, or 128 bits.

[0053] Specifically, when all the keys in the second key stream have participated in the processing of the key mixing step, according to the valid bit positions of the plaintext message, use the key mixed data (z[i]) to perform an exclusive OR operation with the message data to generate compressed intermediate data. Then, further processing is performed according to the message length and the key stream length, which may include an exclusive OR operation with a specific key, and finally generate a 32-bit, 64-bit, or 128-bit target message authentication code (MAC).

[0054] Step S205, send the above-mentioned ciphertext and the above-mentioned target message authentication code to the communication recipient, so that the communication recipient compares the verification message authentication code with the above-mentioned target message authentication code to determine whether the data transmission is correct. The above-mentioned verification message authentication code is the message authentication code generated by the communication recipient based on the above-mentioned ciphertext message, the above-mentioned initial key, and the above-mentioned initial vector.

[0055] Specifically, the ciphertext message and the target message authentication code (MAC) are sent to the communication recipient. The recipient will recalculate the MAC (verify the message authentication code) using the same key stream and the plaintext message, and then compare it with the received MAC to determine whether the message has been tampered with during data transmission. The integrity protection of the data is achieved, ensuring that any modification of the message content can be detected by the recipient during data transmission. The comparison of the MAC provides a data verification function, enhances the security of communication, and prevents man-in-the-middle attacks and data tampering.

[0056] The present invention provides a ZUC-256 hardware implementation system and a communication method that support variable authentication tag lengths, and have a pipeline structure. It supports the encryption / decryption and integrity authentication functions of messages of any length, supports the input of a 256-bit initialization key, and supports three configurable integrity verifications (32 bits, 64 bits, 128 bits), improving the security of the algorithm. By adopting a pipeline structure and optimizing the critical path of integrity verification, the data processing rate is increased, further meeting the 5G application goals of high rate and low latency. Therefore, the implementation of this design enables ZUC-256 to be widely applied in the security protection scenarios of 5G mobile communications.

[0057] In this embodiment, first, input data is obtained, and the First Key Stream and the Second Key Stream are generated according to the above input data by using the Zu Chongzhi algorithm, and the above input data is encrypted by using the above First Key Stream to obtain a ciphertext message. The above input data includes an initial key, an initial vector, a constant term, and a plaintext message. The above Second Key Stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream. Then, in the key mixing step, a shift operation is performed on the current key and the next key in the above Second Key Stream to obtain key mixing data corresponding to the above current key and the above next key. The above current key is the key currently participating in the above shift operation in the above Second Key Stream, and the above next key is the next key adjacent to the above current key in the above Second Key Stream. The length of the above key mixing data is 32 bits. After that, in the first update step, the above next key is updated to the above current key, and the above key mixing step and the above first update step are sequentially repeated at least once until all the keys in the above Second Key Stream participate in the above shift operation to obtain all the above key mixing data. After that, the target message authentication code is iteratively calculated according to the above Second Key Stream and all the above key mixing data. The length of the above target message authentication code is 32 bits, or 64 bits, or 128 bits. Finally, the above ciphertext message and the above target message authentication code are sent to the communication receiver, so that the communication receiver compares the verification message authentication code with the above target message authentication code to determine whether the data transmission is correct. The above verification message authentication code is a message authentication code generated by the communication receiver based on the above ciphertext message, the above initial key, and the above initial vector. This application supports the input of a 256-bit initialization key, uses the Zu Chongzhi algorithm for operation to obtain key streams of different lengths, performs integrity verification according to the key streams, generates a target message authentication code (integrity verification tag length) of the corresponding length, supports three configurable integrity verifications (32 bits, 64 bits, 128 bits), and improves the security of the algorithm. It has a 256-bit key length, provides a larger key space, and supports authentication tags of different lengths (32 bits / 64 bits / 128 bits), has higher security and stronger collision resistance, and can be widely applied to the security protection of 5G mobile communication. At the same time, in order to further meet the 5G application goals of high speed and low latency, the present invention adopts a pipeline structure to improve the data processing rate. This application solves the problem that the number of bits of integrity verification in the prior art is too single, and different lengths of integrity verification cannot be adopted for messages of different importance levels, resulting in an increased risk of the key being attacked and cracked.

[0058] In order to enable those skilled in the art to more clearly understand the technical solution of this application, the implementation process of the communication method supporting variable authentication tag lengths of this application will be described in detail below with reference to specific embodiments.

[0059] To ensure the effectiveness and reliability of the generated initial vector in different scenarios, in an alternative implementation, before the above step S201, the method further includes:

[0060] Step S301, when the register value of the configuration register is 1, calculate and generate the above initial vector through a hardware circuit, where the configuration register is a register for determining the configuration method of the above initial vector;

[0061] Step S302, when the above register value of the above configuration register is 0, generate the above initial vector through a software configuration method, where the software configuration method is a method configured through a random generation algorithm.

[0062] In the above embodiment, as Figure 4 shown, the initial vector generation module includes two configuration methods, and can adopt hardware configuration or software configuration. One of the two is selected through a register, that is, the above configuration register. When the value of the configuration register is 1, it is implemented by hardware circuit. The hardware implementation method is in accordance with the standard of the ZUC stream cipher algorithm. The input data are 32-bit counter parameters, 5-bit bearer layer identification parameters, and 1-bit transmission direction identification parameters, and the corresponding initial vector is generated through the hardware circuit. When the value of the configuration register is 0, it is implemented by software. At this time, the initial vector is directly assigned values by software. The software implementation method is to randomly input the initial vector by software.

[0063] The hardware generation method of the IV (Initialization Vector, abbreviated as IV) can provide faster generation speed and higher security. Since the hardware circuit directly participates in the calculation, it can avoid the delay in software generation and possible software-level security vulnerabilities. Hardware generation can usually ensure the randomness and unpredictability of the IV, which is crucial for the security of cryptographic algorithms (such as ZUC-256). In addition, hardware generation can also reduce the burden of software calculation and improve the operating efficiency of the entire system. The software configuration method is usually more useful in scenarios where hardware resources are limited or flexibility is required. Although software generation may not be as fast as hardware generation, it provides a means to generate IV under different conditions, especially when hardware conditions do not allow or software-level control is required.

[0064] Overall, by using the configuration register to determine the generation method of the IV, ZUC-256 realizes the flexible combination of hardware generation and software generation. The high efficiency and security of the hardware generation method, as well as the flexibility and wide adaptability of the software generation method, jointly ensure the effectiveness and reliability of the generated initial vector in different scenarios.

[0065] To enhance the randomness and security of the key stream, in an alternative implementation, the above step S202 includes:

[0066] Step S2021, substitute the current key and the next key in the above second key stream into the first formula for calculation to obtain the key mixing data corresponding to the current key and the next key. The first formula is z[i] = c[j / 32] << i || c[j / 32 + 1] >> 31 - i, where z[i] represents the i-th mixing value in the key mixing data, i = 0, 1, 2, …, 31, c[j / 32] represents the current key, c[j / 32 + 1] represents the next key, j = 1, 2, 3…L, L is the number of keys in the second key stream, << i represents a left shift of i bits, and >> represents a right shift.

[0067] In the above embodiment, the ZUC-256 integrity protection module logic multiplexes the key mixing part, uses the same processed data in parallel, simultaneously realizes parallel control of the integrity protection part, and pipelines other data that needs to be aligned. Specifically, see Figure 3 . The formula for processing the key is: z[i] = c[j / 32] << i || c[j / 32 + 1] >> 31 - i. For example, Figure 3 , the key 0 and the key 1 are subjected to key mixing processing to obtain a z[i] (the above key mixing data), the key 1 and the key 2 are subjected to key mixing processing, and another z[i] will be obtained, and so on. Each key and the next key will obtain a z[i].

[0068] By performing left shift and right shift operations on partial bits of the current key and the next key, and then splicing them together to generate z[i], this operation method increases the complexity and unpredictability of the key stream, thereby improving the security of the algorithm. Since the generation of the key stream depends on the number of bits of the key and specific bit operations, even if an attacker knows part of the key stream, it is difficult to reverse-derive the original key. Through the operations of left shifting i bits and right shifting 31 - i bits, the number of bits of the current key and the next key is extended and reorganized to generate a 32-bit mixing value (z[i]). This bit extension and reorganization ensure that each value of the key stream contains bits from two keys, further enhancing the randomness and security of the key stream.

[0069] In order to calculate a 32-bit message authentication code to ensure that the message is not tampered with during transmission, in an optional implementation manner, the above step S204 at least includes:

[0070] S20401, Assignment Step: Take the first intermediate value of the current iteration-compressed intermediate data as the first key value in the second key stream. The current iteration-compressed intermediate data is the data set obtained by performing an exclusive OR operation on all the data in the current mixed key data. The current mixed key data is the mixed key data currently undergoing iterative calculation among all the mixed key data. The first intermediate value is the first intermediate value in the current iteration-compressed intermediate data;

[0071] S20401, Determination Step: Determine the current intermediate value as the first intermediate value;

[0072] S20402, First Exclusive OR Step: When the value corresponding to the current bit position of the plaintext message is 1, perform an exclusive OR operation on the current intermediate value and the current mixed value in the current key mixed data to obtain the intermediate value corresponding to the current exclusive OR operation. The current bit position is the bit position corresponding to the current mixed value;

[0073] S20403, Skip Step: When the value corresponding to the current bit position of the plaintext message is 0, do not perform an exclusive OR operation on the current intermediate value and the current mixed value in the current key mixed data;

[0074] S20404, Second Update Step: Update the next mixed value as the current mixed value, and at the same time update the intermediate value corresponding to the current exclusive OR operation as the current intermediate value. The next mixed value is the next mixed value of the current mixed value;

[0075] S20405, Repeat Step: Repeat the above first exclusive OR step, the above skip step, and the above second update step at least once until all the data in the current mixed key data have completed iterative calculation to obtain the current iteration-compressed intermediate data. The length of the current iteration-compressed intermediate data is 32 bits;

[0076] S20406, Third Update Step: Update the next mixed key data as the current mixed key data. The next mixed key data is the next mixed key data of the current mixed key data;

[0077] S20407, Repeat successively the above assignment step, the above determination step, the above first exclusive OR step, the above skip step, the above second update step, the above repeat step, and the above third update step at least once until all the above mixed data have completed calculation to obtain all the iteration-compressed intermediate data;

[0078] S20408, the second exclusive OR step, performs sequential consecutive exclusive OR operations on the last intermediate values of all the above iterative compression intermediate data to obtain an exclusive OR output result, where the length of the above exclusive OR output result is 32 bits;

[0079] S20409, performs data processing on the above exclusive OR output result according to the above plaintext message to obtain the above first message authentication code.

[0080] In the above embodiment, if a 32-bit message authentication code needs to be generated, for each input data, first set the first intermediate value as the first key value T[0]=c[0]. For i = 0, 1, 2,..., 31, if the plaintext message M[i]=1 at the corresponding bit, then T=T⊕z[i], that is, sequentially exclusive OR the current intermediate value T with z[i] corresponding to the current bit position. Subsequently, the last (i.e., the 32nd) intermediate value generated is exclusive ORed with the last intermediate value of each subsequent input to complete the iterative compression. Specifically, at the start of each round of iteration, first assign the first intermediate value (T[0]) the value of the first key (c[0]) in the second key stream. Then, determine the first intermediate value (T[0]) as the current intermediate value (T), which is the current state of the iterative calculation. When the current bit position of the plaintext message (M[i]) is 1, perform an exclusive OR operation on the current intermediate value (T) and the current mixing value (z[i]) in the current key mixing data. When the current bit position of the plaintext message (M[i]) is 0, no operation is performed, that is, no exclusive OR operation is performed between the current intermediate value (T) and the current mixing value (z[i]). Regardless of whether the exclusive OR operation is performed, the next mixing value (z[i+1]) is updated to the current mixing value (z[i]), and the current intermediate value (T) is updated to the result of the previous step. By selectively fusing the information of the current plaintext message bit with the key stream data through the exclusive OR operation, a new intermediate value (T) is generated. This series of operations ensures that the generation of the MAC takes into account both the dynamic characteristics of the key stream and fully reflects the bit information of the plaintext message. The skip step improves the flexibility of the algorithm, allowing no operation on some bit positions, which may be beneficial for reducing resource consumption and improving efficiency. The update operation ensures the iterativeness and coherence of the algorithm. After completing one round of iterative calculation, update the next mixed key data to the current mixed key data until all the mixed key data is calculated to obtain all the iterative compression intermediate data. Through repeated iteration, the entire key stream and plaintext message are processed, generating a series of 32-bit intermediate values, providing a basis for the subsequent MAC generation. Perform sequential consecutive exclusive OR operations on the last intermediate values of all the iterative compression intermediate data to generate an exclusive OR output result with a length of 32 bits, as Figure 5As shown, all intermediate values 31 are XORed to obtain the final XOR output result. According to the length and integrity requirements of the plaintext message, final data processing is performed on the XOR output result obtained in the previous step, which usually involves XORing with the last key, and finally the first message authentication code (MAC) is obtained. The final MAC is generated to verify the authenticity and integrity of the message, ensuring that the message has not been tampered with during transmission. The length of the MAC (32 bits, 64 bits, or 128 bits) depends on the data importance and security requirements. The longer the length, the stronger the anti-attack ability of the MAC and the higher the security.

[0081] To ensure flexibility in adapting to various message lengths and improve the security of message authentication code generation, in an optional implementation, the above step S20409 includes:

[0082] S204091, when the length of the above plaintext message is an integer multiple of the bit width, perform the above XOR operation on the above XOR output result and the last key of the above second key stream to calculate the above first message authentication code;

[0083] S204092, when the length of the above plaintext message is not an integer multiple of the above bit width, determine the above first message authentication code as the above XOR output result.

[0084] In the above embodiment, when the length of the plaintext message is an integer multiple of the bit width, it indicates that the message length can be divided evenly by 32 bits (or the set bit width), which means that the last complete 32-bit width of the message has been processed. The above XOR output result is XORed with the last key of the second key stream. When the length of the plaintext message is not an integer multiple of the bit width, that is, the last processing unit of the message is incomplete and does not reach the length of 32 bits. At this time, the integrity protection module will directly use the XOR output result as the first message authentication code (MAC), that is, the part of the second key stream that is not an integer bit width is XORed bit by bit to obtain the above first message authentication code. This processing method ensures that the algorithm can flexibly adapt to various message lengths, including those that are not integer multiples of the bit width. For shorter or irregularly lengthed messages, additional key operations are avoided, improving the efficiency of MAC generation. It ensures that the ZUC-256 algorithm is both flexible and highly secure in the integrity protection function, can adapt to messages of different lengths, and provides a reliable data verification mechanism.

[0085] To calculate a 64-bit message authentication code and increase the flexibility and security of message authentication code generation, in an optional implementation, the above step S204 includes:

[0086] S20410. Repeat the above assignment step, the above determination step, the above first exclusive OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive OR step in sequence at least once until all the above iterative compression intermediate data is calculated to obtain a first exclusive OR output result;

[0087] S20411. Perform data processing on the above first exclusive OR output result according to the above plaintext message to obtain a first tag intermediate value;

[0088] S20412. Take the first intermediate value of the above current iterative compression intermediate data as the second key value in the above second key stream;

[0089] S20413. Repeat the above determination step, the above first exclusive OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive OR step in sequence at least once until all the above iterative compression intermediate data is calculated to obtain a second exclusive OR output result;

[0090] S20414. Perform data processing on the above second exclusive OR output result according to the above plaintext message to obtain a second tag intermediate value;

[0091] S20415. Concatenate the above first tag intermediate value and the above second tag intermediate value in order to obtain the above second message authentication code.

[0092] In the above embodiments, if a 64-bit message authentication code needs to be generated, the generation is split to produce two 32-bit intermediate tag values, which are then concatenated to obtain the 64-bit message authentication code. For each input data, the generation process of the first 32-bit intermediate tag value is the same as that of the 32-bit message authentication code. For the second 32-bit intermediate tag value, first set the second intermediate value as the second key value T[0]=c[1]. For i = 0, 1, 2, …, 31, if the plaintext message M[i] input at the corresponding bit position is 1, then T=T⊕z[i], that is, starting from T[0], perform exclusive OR with z[i] step by step. For each 32-bit intermediate tag value, finally, exclusive OR of the last intermediate value is performed between each data entry to complete the iterative compression. Finally, the two intermediate tag values are concatenated. Specifically, in the process of generating the 64-bit MAC, first repeat the iterative calculation according to the process of generating the 32-bit MAC until all the intermediate data of the iterative compression is calculated to obtain the first exclusive OR output result. Through repeated iteration, it is ensured that the generation of the first 32-bit MAC is based on the complete second key stream and plaintext message data. The first exclusive OR output result is the intermediate result of generating the first 32-bit MAC, providing a basis for generating a longer MAC subsequently. Perform final data processing on the first exclusive OR output result according to the plaintext message to obtain the first intermediate tag value. This processing may include exclusive OR operations or other operations with specific key values to ensure that the final MAC is generated based on the complete message data and key stream. Take the first intermediate value (T[0]) of the current iterative compression intermediate data as the second key value (c[1]) in the second key stream. This marks the start of the generation of the second 32-bit MAC, and the second key value of the second key stream will be used as the starting point. Initialize the calculation process for generating the second 32-bit MAC to ensure that calculations are performed with different starting key values to generate different MAC intermediate values. This step provides a starting value for generating the second 32-bit MAC intermediate value, increasing the complexity of the finally generated 64 bits. Repeat the above determination step, the above first exclusive OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive OR step at least once until all the above iterative compression intermediate data is calculated, but use the second key value (c[1]) of the second key stream as the starting point for calculation until all the iterative compression intermediate data is calculated to obtain the second exclusive OR output result. Perform data processing on the second exclusive OR output result according to the plaintext message to obtain the second intermediate tag value. Concatenate the first intermediate tag value and the second intermediate tag value in order to obtain the 64-bit MAC value. By concatenating two 32-bit MAC intermediate values, a 64-bit MAC value is generated, enhancing the anti-attack ability of the MAC.

[0093] The ZUC-256 algorithm can generate message authentication codes of different lengths, which can be flexibly selected according to the importance and security requirements of the data. This design increases the flexibility and security of MAC generation, ensuring that the algorithm can adapt to different communication security requirements. Especially in high-speed communication systems such as 5G, it provides stronger protection for the integrity and authenticity of data. At the same time, the method of splicing multiple 32-bit MAC intermediate values also improves the anti-attack ability of the algorithm, making ZUC-256 applicable to communication security in the post-quantum era.

[0094] In order to calculate a 128-bit message authentication code and increase the flexibility and security of message authentication code generation, in an optional implementation manner, step S204 described above includes:

[0095] S20416, repeat the above assignment step, the above determination step, the above first exclusive OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive OR step at least once in sequence until all the above iterative compression intermediate data is calculated to obtain a third exclusive OR output result;

[0096] S20417, perform data processing on the above third exclusive OR output result according to the above plaintext message to obtain a third tag intermediate value;

[0097] S20418, take the first intermediate value of the above current iterative compression intermediate data as the second key value in the above second key stream;

[0098] S20419, repeat the above determination step, the above first exclusive OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive OR step at least once in sequence until all the above iterative compression intermediate data is calculated to obtain a fourth exclusive OR output result;

[0099] S20420, perform data processing on the above fourth exclusive OR output result according to the above plaintext message to obtain a fourth tag intermediate value;

[0100] S20421, take the first intermediate value of the above current iterative compression intermediate data as the third key value in the above second key stream;

[0101] S20422, repeat the above determination step, the above first exclusive OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive OR step at least once in sequence until all the above iterative compression intermediate data is calculated to obtain a fifth exclusive OR output result;

[0102] S20423, perform data processing on the above fifth exclusive OR output result according to the above plaintext message to obtain a fifth tag intermediate value;

[0103] S20424, take the first intermediate value of the currently iteratively compressed intermediate data as the fourth key value in the second key stream above;

[0104] S20425, repeat the above determination step, the above first XOR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second XOR step at least once in sequence until all the above iteratively compressed intermediate data is calculated to obtain the sixth XOR output result;

[0105] S20426, perform data processing on the sixth XOR output result according to the above plaintext message to obtain the sixth tag intermediate value;

[0106] S20427, splice the above third tag intermediate value, the above fourth tag intermediate value, the above fifth tag intermediate value, and the above sixth tag intermediate value in sequence to obtain the above third message authentication code.

[0107] In the above embodiment, if a 128-bit MAC needs to be generated, the generation processes of the first two 32-bit tag intermediate values are exactly the same as that of the 64-bit message authentication code. For the third 32-bit tag intermediate value, first set T[0] = c[2]. For i = 0, 1, 2, …, 31, if the plaintext message M[i] input at the corresponding bit position is 1, then starting from T[0], perform XOR with z[i] level by level, that is, T = T ⊕ zi. For the fourth 32-bit tag intermediate value, first set T[0] = c[3]. For i = 0, 1, 2, …, 31, if the plaintext message M[i] input at the corresponding bit position is 1, then starting from T[0], perform XOR with z[i] level by level, that is, T = T ⊕ zi. For each 32-bit tag intermediate value, finally, XOR the last intermediate value between each entry to complete the iterative compression, that is, mac = Ti ⊕ Ti-1. Specifically, if a 128-bit MAC needs to be generated, use the third and fourth key values of the second key stream as the starting values respectively to generate the third tag intermediate value and the fourth tag intermediate value, and then splice them in order. By splicing multiple 32-bit MAC intermediate values, a longer MAC value is generated, enhancing the anti-attack ability of the MAC. A longer MAC means a larger collision space, making the difficulty of brute-force cracking or key search attacks increase significantly, improving the verification standard for data integrity and authenticity. It is applicable to scenarios with higher security requirements, such as the transmission of sensitive data. A longer MAC can provide additional protection to ensure the security of data during transmission.

[0108] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. And, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0109] The embodiments of the present application also provide a communication device supporting variable authentication tag lengths. It should be noted that the communication device supporting variable authentication tag lengths in the embodiments of the present application can be used to execute the communication method for supporting variable authentication tag lengths provided by the embodiments of the present application. The device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used below, the term "module" can be a combination of software and / or hardware that can implement a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0110] The following introduces the communication device supporting variable authentication tag lengths provided by the embodiments of the present application.

[0111] Figure 6 is a structural block diagram of a communication device supporting variable authentication tag lengths according to an embodiment of the present application. As Figure 6 shown, the device includes:

[0112] An encryption unit 10, configured to obtain input data, generate a first key stream and a second key stream according to the input data by using the ZUC algorithm, and encrypt the input data by using the first key stream to obtain a ciphertext message. The input data includes an initial key, an initial vector, a constant term, and a plaintext message. The second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream.

[0113] Specifically, for encryption / decryption functions: use the ZUC algorithm to generate a first key stream according to the initial key, initial vector, constant term, and plaintext message, and use the first key stream to perform encryption / decryption processing on the input data. For integrity protection functions: use the ZUC algorithm to generate a second key stream according to the initial key, initial vector, constant term, and plaintext message. The second key stream is a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream, and generate 32-bit, 64-bit, and 128-bit tag values respectively. That is, the key stream when obtaining the ciphertext is different from the key stream of the authentication tag. Therefore, the key stream during encryption / decryption is the key stream of L when t is 0, rather than one of the 32-bit key stream, 64-bit key stream, and 128-bit key stream; the 32-bit key stream, 64-bit key stream, and 128-bit key stream are the key streams of 32-bit, 64-bit, and 128-bit authentication tags.

[0114] As Figure 3As shown, a ZUC-256 hardware implementation system that supports variable authentication tag lengths is provided, including five modules: an initial vector generation module, an encryption / decryption module, an S-box module, an integrity protection module, and a top-level module. Among them, the encryption / decryption module is divided into three parts: a linear feedback shift register module (LFSR), a bit recombination module (BR), and a non-linear function module (F). The initial value of the linear feedback shift register module is composed of input data. In the first sixty-four rounds of the initialization mode, the padding data is related to the non-linear F function. In the working mode, it does not accept any input and continuously generates data through linear feedback. The register data of the bit recombination module is spliced from the data in the linear feedback shift register. The non-linear function module outputs a non-linearly processed data through operations such as XOR, modulo 32, splicing, and S-box. The S-box is a multiplexing structure, divided into S0 and S1, with eight module instantiations, four for S0 and four for S1. The S-box is a non-linear module and is the basic structure for performing permutation calculations in symmetric key algorithms. It is implemented in the form of ROM, and the switch is controlled by an enable signal to reduce power consumption.

[0115] In the ZUC-256 encryption / decryption algorithm, the linear feedback shift register module (LFSR) and the S-box module adopt the method of logical multiplexing. Since the initialization mode and the working mode of the linear feedback shift register module (LFSR) work serially, it is controlled according to the number of calculation rounds to select the input and output data. In the initialization stage, the padding function is related to the data W generated by the F function. The generation of W includes two memory units R1 and R2, and the inputs are X0, X1, and X2 from the output of the bit recombination module. The generated padding data is W, and the specific process is as follows:

[0116] W = (X0 ^ R1) + R2;

[0117] W1 = R1 + X1;

[0118] W2 = R2 ^ X2;

[0119] R1 = S((L1(W1L || W2H));

[0120] R2 = S((L2(W2L || W1H));

[0121] Among them, L1 and L2 are linear transformation functions, L1(X) = X ^ (X <<< 2) ^ (X <<< 10) ^ (X <<< 18) ^ (X <<< 24), L2(X) = X ^ (X <<< 8) ^ (X <<< 14) ^ (X <<< 22) ^ (X <<< 30); W1L represents the lower 16 bits of W1, || represents the concatenation symbol, such as W1L || W2H represents a new 32-bit number composed of the lower 16 bits of W1 and the higher 16 bits of W2; S represents the S-box.

[0122] Using the generated W value and calculating according to the following formula, the padding data S16 is obtained: S16 = (V + W >> 1) mod (231 - 1), where V = 215S15 + 217S13 + 221S10 + 220S4 + (1 + 28)S0 mod (231 - 1); (a + b) mod (231 - 1) represents taking the modulus of the sum of a + b with respect to 231 - 1; >> represents right shift.

[0123] In the working mode, no input is accepted and it is continuously generated by linear feedback. The linear feedback function is: S16 = 215S15 + 217S13 + 221S10 + 220S4 + (1 + 28)S0 mod (231 - 1).

[0124] The S-box is the basic structure for performing permutation calculations in symmetric key algorithms and is a non-linear component. The S-box here consists of 4 juxtaposed 8×8 S-boxes, totaling 32×32, forming S0 and S1. Then it is multiplexed to form 4 S-boxes, concatenated into 32 bits, i.e., S = (S0, S1, S2, S3), where S0 = S2, S1 = S3. This module is divided into two parts, namely S0 and S1. In the ZUC-256 encryption / decryption module, since both R1 and R2 use the S-box, a total of 8 are instantiated. The key stream input to the integrity protection module is generated by the encryption / decryption module. The number of generated keys (i.e., the number of keys in the second key stream) is: L = [(l + 31) / 32] + 2×t / 32, where l is the length of the plaintext message, [] represents rounding up, and t is the integrity protection tag length (optional 32 bits, 64 bits, 128 bits).

[0125] The key mixing unit 20 is used to perform the key mixing step, perform a shift operation on the current key and the next key in the above-mentioned second key stream to obtain the key mixing data corresponding to the current key and the above-mentioned next key. The current key is the current key participating in the above-mentioned shift operation in the second key stream, the next key is the next key adjacent to the current key in the second key stream, and the length of the key mixing data is 32 bits.

[0126] Specifically, as Figure 4 shown, the key stream generated by the encryption / decryption module is input to the integrity protection module. The entire data stream process of integrity protection includes the following processes: initialization, key generation, key mixing, iterative compression, and output processing. Specifically, see Figure 5Among them, the pipeline structure of the integrity protection module consists of three steps: key mixing, iterative compression, and output processing. Initialization and key generation are completed by the encryption / decryption module and input into the integrity protection module in the form of a stream cipher. The key stream input into the integrity protection module enters the next step for key mixing, using the key of the current state and the key of the next state, and performing operations such as concatenation to obtain the intermediate data after key mixing (i.e., the above-mentioned key mixed data), a total of 32.

[0127] The update unit 30 is used to execute the first update step to update the above-mentioned next key to the above-mentioned current key, and sequentially repeat the above-mentioned key mixing step and the above-mentioned first update step at least once until all the keys in the above-mentioned second key stream participate in the above-mentioned shift operation to obtain all the above-mentioned key mixed data.

[0128] Specifically, repeat the above-mentioned key mixing step and the above-mentioned first update step. As Figure 5 shown, after key mixing between key 0 and key 1 to generate 32-bit key mixed data, update key 1 to the current key, and re-perform key mixing between key 1 and key 2 to generate 32-bit key mixed data, and so on, until all keys complete the above-mentioned shift operation to obtain all key mixed data.

[0129] The iterative calculation unit 40 is used to iteratively calculate the target message authentication code based on the above-mentioned second key stream and all the above-mentioned key mixed data. The length of the above-mentioned target message authentication code is 32 bits, or 64 bits, or 128 bits.

[0130] Specifically, when all the keys in the second key stream have participated in the processing of the key mixing step, according to the valid bit positions of the plaintext message, perform an exclusive OR operation on the key mixed data (z[i]) and the message data to generate compressed intermediate data. Then, further process according to the message length and the key stream length, which may include an exclusive OR operation with a specific key, and finally generate a 32-bit, 64-bit, or 128-bit target message authentication code (MAC).

[0131] The sending unit 50 is used to send the above-mentioned ciphertext message and the above-mentioned target message authentication code to the communication recipient, so that the communication recipient compares the verification message authentication code with the above-mentioned target message authentication code to determine whether the data transmission is correct. The above-mentioned verification message authentication code is the message authentication code generated by the communication recipient based on the above-mentioned ciphertext message, the above-mentioned initial key, and the above-mentioned initial vector.

[0132] Specifically, the plaintext message (M), the second key stream (ZUC key stream), and the target message authentication code (MAC) are sent to the communication recipient. The recipient will recalculate the MAC (verify the message authentication code) using the same key stream and the plaintext message, and then compare it with the received MAC to determine whether the message has been tampered with during the data transmission process. This achieves data integrity protection, ensuring that any modification to the message content can be detected by the recipient during the data transmission process. The comparison of the MAC provides a data verification function, enhances the security of communication, and prevents man-in-the-middle attacks and data tampering.

[0133] In this embodiment, an encryption unit is configured to obtain input data, generate a first key stream and a second key stream according to the input data by using the Zu Chongzhi algorithm, and encrypt the input data by using the first key stream to obtain a ciphertext message. The input data includes an initial key, an initial vector, a constant term, and a plaintext message. The second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream. A key mixing unit is configured to perform a key mixing step, perform a shift operation on the current key and the next key in the second key stream to obtain key mixing data corresponding to the current key and the next key. The current key is the current key participating in the shift operation in the second key stream, and the next key is the next key adjacent to the current key in the second key stream. The length of the key mixing data is 32 bits. An updating unit is configured to perform a first updating step, update the next key to the current key, and sequentially repeat the key mixing step and the first updating step at least once until all the keys in the second key stream participate in the shift operation to obtain all the key mixing data. An iterative calculation unit is configured to iteratively calculate a target message authentication code according to the second key stream and all the key mixing data. The length of the target message authentication code is 32 bits, or 64 bits, or 128 bits. A sending unit is configured to send the ciphertext message and the target message authentication code to a communication receiver, so that the communication receiver compares a verification message authentication code with the target message authentication code to determine whether data transmission is correct. The verification message authentication code is a message authentication code generated by the communication receiver based on the ciphertext message, the initial key, and the initial vector. This application supports the input of a 256-bit initialization key, uses the Zu Chongzhi algorithm to perform operations to obtain key streams of different lengths, performs integrity verification according to the key streams, generates target message authentication codes (integrity verification label lengths) of corresponding lengths, supports three configurable integrity verifications (32 bits, 64 bits, 128 bits), and improves the security of the algorithm. It has a 256-bit key length, provides a larger key space, and supports authentication labels of different lengths (32 bits / 64 bits / 128 bits), has higher security and stronger collision resistance, and can be widely applied to the security protection of 5G mobile communication. At the same time, in order to further meet the 5G application goals of high speed and low latency, the present invention adopts a pipeline structure, which improves the data processing rate. This application solves the problem that the number of bits of integrity verification in the prior art is too single, and different lengths of integrity verification cannot be adopted for messages of different importance levels, resulting in an increased risk of the key being attacked and cracked.

[0134] In order to ensure the effectiveness and reliability of the generated initial vector in different scenarios, in an optional embodiment, the device further includes:

[0135] A first generation unit, configured to calculate and generate the above-mentioned initial vector through a hardware circuit when the register value of a configuration register is 1 before obtaining input data, where the configuration register is a register for determining the configuration method of the above-mentioned initial vector;

[0136] A second generation unit, configured to generate the above-mentioned initial vector through a software configuration method when the register value of the above-mentioned configuration register is 0, where the software configuration method is a method configured through a random generation algorithm.

[0137] In the above embodiment, as Figure 4 shown, the initial vector generation module includes two configuration methods, and can adopt hardware configuration or software configuration. A register is used to configure the one - of - two selection, that is, the above - mentioned configuration register. When the value of the configuration register is 1, it is implemented by a hardware circuit. The hardware implementation method is in accordance with the standard of the ZUC stream cipher algorithm. The input data is a 32 - bit counter parameter, a 5 - bit bearer layer identification parameter, and a 1 - bit transmission direction identification parameter, and the corresponding initial vector is generated through the hardware circuit. When the value of the configuration register is 0, it is implemented by software. At this time, the initial vector is directly assigned a value by software, and the software implementation method is to randomly input the initial vector by software.

[0138] The hardware generation of the IV (Initialization Vector, abbreviated as IV) can provide a faster generation speed and higher security. Since the hardware circuit directly participates in the calculation, it can avoid the delay in software generation and possible software - level security vulnerabilities. Hardware generation can usually ensure the randomness and unpredictability of the IV, which is crucial for the security of cryptographic algorithms (such as ZUC - 256). In addition, hardware generation can also reduce the burden of software calculation and improve the operating efficiency of the entire system. The software configuration method is usually more useful in scenarios where hardware resources are limited or flexibility is required. Although software generation may not be as fast as hardware generation, it provides a means to generate the IV under different conditions, especially when hardware conditions do not allow or software - level control is required.

[0139] Overall, by using the configuration register to determine the generation method of the IV, ZUC - 256 realizes the flexible combination of hardware generation and software generation. The high efficiency and security of the hardware generation method, as well as the flexibility and wide adaptability of the software generation method, jointly ensure the effectiveness and reliability of the generated initial vector in different scenarios.

[0140] In order to enhance the randomness and security of the key stream, in an optional embodiment, the above - mentioned key mixing unit includes:

[0141] A calculation module is used to substitute the current key and the next key in the above-mentioned second key stream into the first formula for calculation to obtain the key mixing data corresponding to the current key and the next key. The first formula is z[i] = c[j / 32] << i || c[j / 32 + 1] >> 31 - i, where z[i] represents the i-th mixing value in the key mixing data, i = 0, 1, 2, …, 31, c[j / 32] represents the current key, c[j / 32 + 1] represents the next key, j = 1, 2, 3…L, L is the number of keys in the second key stream, << i represents a left shift of i bits, and >> represents a right shift.

[0142] In the above embodiment, the ZUC-256 integrity protection module logic multiplexes the key mixing part, uses the same processed data in parallel, simultaneously realizes the parallel control of the integrity protection part, and pipelines other data that needs to be aligned. Specifically, see Figure 3 . The formula for processing the key is: z[i] = c[j / 32] << i || c[j / 32 + 1] >> 31 - i. For example, Figure 3 , the key 0 and the key 1 are subjected to key mixing processing to obtain a z[i] (the above-mentioned key mixing data), the key 1 and the key 2 are subjected to key mixing processing, and another z[i] will be obtained, and so on. Each key and the next key will obtain a z[i].

[0143] By performing left shift and right shift operations on partial bits of the current key and the next key, and then splicing them together to generate z[i], this operation method increases the complexity and unpredictability of the key stream, thereby improving the security of the algorithm. Since the generation of the key stream depends on the number of bits of the key and specific bit operations, even if an attacker knows part of the key stream, it is difficult to reverse-derive the original key. Through the operations of left shifting i bits and right shifting 31 - i bits, the number of bits of the current key and the next key is extended and reorganized to generate a 32-bit mixing value (z[i]). This bit extension and reorganization ensure that each value of the key stream contains bits from two keys, further enhancing the randomness and security of the key stream.

[0144] In order to calculate a 32-bit message authentication code to ensure that the message is not tampered with during transmission, in an optional implementation manner, the above calculation unit at least includes:

[0145] The first assignment module is used to execute the assignment step, taking the first intermediate value of the current iteration compressed intermediate data as the first key value in the above-mentioned second key stream. The current iteration compressed intermediate data is a data set obtained by performing an exclusive OR operation on all data in the current mixed key data. The current mixed key data is the mixed key data currently undergoing iterative calculation among all the above-mentioned mixed key data. The first intermediate value is the first intermediate value in the current iteration compressed intermediate data;

[0146] The determination module is used to execute the determination step, determining the above-mentioned first intermediate value as the current intermediate value;

[0147] The first exclusive OR module is used to execute the first exclusive OR step. When the value corresponding to the current bit of the above-mentioned plaintext message is 1, an exclusive OR operation is performed on the above-mentioned current intermediate value and the current mixed value in the above-mentioned current key mixed data to obtain the intermediate value corresponding to the current exclusive OR operation. The current bit is the bit corresponding to the above-mentioned current mixed value;

[0148] The jump module is used to execute the jump step. When the value corresponding to the above-mentioned current bit of the above-mentioned plaintext message is 0, the above-mentioned current intermediate value and the current mixed value in the above-mentioned current key mixed data do not perform an exclusive OR operation;

[0149] The first update module is used to execute the second update step, updating the next mixed value to the above-mentioned current mixed value, and at the same time updating the intermediate value corresponding to the above-mentioned current exclusive OR operation to the above-mentioned current intermediate value. The next mixed value is the next mixed value of the above-mentioned current mixed value;

[0150] The first repetition module is used to execute the repetition step, sequentially repeating the above-mentioned first exclusive OR step, the above-mentioned jump step, and the above-mentioned second update step at least once until all data in the above-mentioned current mixed key data have completed iterative calculation, obtaining the above-mentioned current iteration compressed intermediate data. The length of the above-mentioned current iteration compressed intermediate data is 32 bits;

[0151] The second update module is used to execute the third update step, updating the above-mentioned next mixed key data to the above-mentioned current mixed key data. The next mixed key data is the next above-mentioned mixed key data of the above-mentioned current mixed key data;

[0152] The second repetition module is used to execute the step of sequentially repeating the above-mentioned assignment step, the above-mentioned determination step, the above-mentioned first exclusive OR step, the above-mentioned jump step, the above-mentioned second update step, the above-mentioned repetition step, and the above-mentioned third update step at least once until all the above-mentioned mixed data have completed calculation, obtaining all the iteration compressed intermediate data;

[0153] A second exclusive-OR module, configured to perform a second exclusive-OR step of sequentially performing consecutive exclusive-OR operations on the last intermediate values of all the above-mentioned iteratively compressed intermediate data to obtain an exclusive-OR output result, where the length of the above-mentioned exclusive-OR output result is 32 bits;

[0154] A first data processing module, configured to perform data processing on the above-mentioned exclusive-OR output result according to the above-mentioned plaintext message to obtain the above-mentioned first message authentication code.

[0155] In the above embodiment, if a 32-bit message authentication code needs to be generated, for each piece of input data, first set the first intermediate value as the first key value T[0]=c[0]. For i = 0, 1, 2,..., 31, if the plaintext message M[i] corresponding to the bit is 1, then T = T⊕z[i], that is, the current intermediate value T is sequentially exclusive-ORed with z[i] corresponding to the current bit. Subsequently, the last (i.e., the 32nd) intermediate value generated is exclusive-ORed with the last intermediate value of each subsequent piece to complete iterative compression. Specifically, at the beginning of each round of iteration, first assign the first intermediate value (T[0]) to the value of the first key (c[0]) in the second key stream. Then, determine the first intermediate value (T[0]) as the current intermediate value (T), which is the current state of the iterative calculation. When the current bit of the plaintext message (M[i]) is 1, perform an exclusive-OR operation on the current intermediate value (T) and the current mixed value (z[i]) in the current key mixed data. When the current bit of the plaintext message (M[i]) is 0, no operation is performed, that is, the current intermediate value (T) and the current mixed value (z[i]) are not exclusive-ORed. Regardless of whether the exclusive-OR operation is performed, the next mixed value (z[i + 1]) is updated to the current mixed value (z[i]), and the current intermediate value (T) is updated to the result of the previous step. By selectively fusing the information of the current plaintext message bit with the key stream data through the exclusive-OR operation, a new intermediate value (T) is generated. This series of operations ensures that the generation of the MAC takes into account both the dynamic characteristics of the key stream and fully reflects the bit information of the plaintext message. The skip step improves the flexibility of the algorithm, allowing no operation on some bits, which may be beneficial for reducing resource consumption and improving efficiency. The update operation ensures the iterativeness and coherence of the algorithm. After completing a round of iterative calculation, update the next mixed key data to the current mixed key data until all the mixed key data is calculated to obtain all the iteratively compressed intermediate data. Through repeated iteration, the entire key stream and plaintext message are processed, generating a series of 32-bit intermediate values, providing a basis for the subsequent generation of the MAC. Sequentially perform consecutive exclusive-OR operations on the last intermediate values of all the iteratively compressed intermediate data to generate an exclusive-OR output result with a length of 32 bits, as Figure 5As shown, all intermediate values 31 are XORed to obtain the final XOR output result. According to the length and integrity requirements of the plaintext message, the final data processing is performed on the XOR output result obtained in the previous step, which usually involves XORing with the last key, and finally the first Message Authentication Code (MAC) is obtained. The final MAC is generated to verify the authenticity and integrity of the message, ensuring that the message has not been tampered with during transmission. The length of the MAC (32 bits, 64 bits, or 128 bits) depends on the data importance and security requirements. The longer the length, the stronger the anti-attack ability of the MAC and the higher the security.

[0156] In order to ensure flexibility in adapting to various message lengths and improve the security of message authentication code generation, in an optional implementation manner, the above first data processing module includes:

[0157] An XOR sub-module, configured to perform the above XOR operation on the above XOR output result and the last key of the above second key stream when the length of the above plaintext message is an integer multiple of the bit width, and calculate the above first message authentication code;

[0158] A determination sub-module, configured to determine that the above first message authentication code is the above XOR output result when the length of the above plaintext message is not an integer multiple of the above bit width.

[0159] In the above embodiment, when the length of the plaintext message is an integer multiple of the bit width, it indicates that the message length can be divided evenly by 32 bits (or the set bit width), which means that the last complete 32-bit width of the message has been processed. The above XOR output result is XORed with the last key of the second key stream. When the length of the plaintext message is not an integer multiple of the bit width, that is, the last processing unit of the message is incomplete and does not reach the length of 32 bits. At this time, the integrity protection module will directly use the XOR output result as the first message authentication code (MAC). This processing method ensures that the algorithm can flexibly adapt to various message lengths, including those that are not integer multiples of the bit width. For shorter or irregular-length messages, additional key operations are avoided, improving the efficiency of MAC generation. It ensures that the ZUC-256 algorithm has both flexibility and high security in the integrity protection function, can adapt to messages of different lengths, and provides a reliable data verification mechanism.

[0160] In order to calculate a 64-bit message authentication code and increase the flexibility and security of message authentication code generation, in an optional implementation manner, the above calculation unit further includes:

[0161] A third repetition module, configured to repetitively perform the above-mentioned assignment step, determination step, first exclusive-OR step, jump step, second update step, repetition step, third update step, and second exclusive-OR step in sequence at least once until all the above-mentioned iteratively compressed intermediate data is completely computed to obtain a first exclusive-OR output result;

[0162] A second data processing module, configured to perform data processing on the first exclusive-OR output result according to the above-mentioned plaintext message to obtain a first tag intermediate value;

[0163] A second assignment module, configured to set the first intermediate value of the above-mentioned current iteratively compressed intermediate data to the second key value in the above-mentioned second key stream;

[0164] A fourth repetition module, configured to repetitively perform the above-mentioned determination step, first exclusive-OR step, jump step, second update step, repetition step, third update step, and second exclusive-OR step in sequence at least once until all the above-mentioned iteratively compressed intermediate data is completely computed to obtain a second exclusive-OR output result;

[0165] A third data processing module, configured to perform data processing on the second exclusive-OR output result according to the above-mentioned plaintext message to obtain a second tag intermediate value;

[0166] A first splicing module, configured to sequentially splice the above-mentioned first tag intermediate value and the above-mentioned second tag intermediate value to obtain the above-mentioned second message authentication code.

[0167] In order to compute a 128-bit message authentication code and increase the flexibility and security of message authentication code generation, in an optional implementation, the above-mentioned computing unit further includes:

[0168] A fifth repetition module, configured to repetitively perform the above-mentioned assignment step, determination step, first exclusive-OR step, jump step, second update step, repetition step, third update step, and second exclusive-OR step in sequence at least once until all the above-mentioned iteratively compressed intermediate data is completely computed to obtain a third exclusive-OR output result;

[0169] A fourth data processing module, configured to perform data processing on the third exclusive-OR output result according to the above-mentioned plaintext message to obtain a third tag intermediate value;

[0170] A third assignment module, configured to set the first intermediate value of the above-mentioned current iteratively compressed intermediate data to the second key value in the above-mentioned second key stream;

[0171] The sixth repetition module is used to repeat the above determination step, the above first exclusive-OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive-OR step at least once in sequence until all the above iterative compression intermediate data is calculated to obtain a fourth exclusive-OR output result;

[0172] The fifth data processing module is used to perform data processing on the above fourth exclusive-OR output result according to the above plaintext message to obtain a fourth tag intermediate value;

[0173] The fourth assignment module is used to take the first intermediate value of the above current iterative compression intermediate data as the third key value in the above second key stream;

[0174] The seventh repetition module is used to repeat the above determination step, the above first exclusive-OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive-OR step at least once in sequence until all the above iterative compression intermediate data is calculated to obtain a fifth exclusive-OR output result;

[0175] The sixth data processing module is used to perform data processing on the above fifth exclusive-OR output result according to the above plaintext message to obtain a fifth tag intermediate value;

[0176] The fifth assignment module is used to take the first intermediate value of the above current iterative compression intermediate data as the fourth key value in the above second key stream;

[0177] The eighth repetition module is used to repeat the above determination step, the above first exclusive-OR step, the above jump step, the above second update step, the above repetition step, the above third update step, and the second exclusive-OR step at least once in sequence until all the above iterative compression intermediate data is calculated to obtain a sixth exclusive-OR output result;

[0178] The seventh data processing module is used to perform data processing on the above sixth exclusive-OR output result according to the above plaintext message to obtain a sixth tag intermediate value;

[0179] The second splicing module is used to splice the above third tag intermediate value, the above fourth tag intermediate value, the above fifth tag intermediate value, and the above sixth tag intermediate value in sequence to obtain the above third message authentication code.

[0180] In the above embodiments, if a 128-bit MAC needs to be generated, the generation process of the middle value of the first two 32-bit tags is exactly the same as that of the 64-bit message authentication code. For the middle value of the third 32-bit tag, first set T[0]=c[2]. For i = 0, 1, 2, …, 31, if the plaintext message M[i] input at the corresponding bit is 1, then starting from T[0], perform exclusive OR with z[i] level by level, that is, T = T⊕zi. For the middle value of the fourth 32-bit tag, first set T[0]=c[3]. For i = 0, 1, 2, …, 31, if the plaintext message M[i] input at the corresponding bit is 1, then starting from T[0], perform exclusive OR with z[i] level by level, that is, T = T⊕zi. For each 32-bit tag middle value, finally, perform exclusive OR of the last intermediate value between each item to complete the iterative compression, that is, mac = Ti⊕Ti-1. Specifically, if a 128-bit MAC needs to be generated, use the third and fourth key values of the second key stream as the starting values respectively to generate the third tag middle value and the fourth tag middle value, and then splice them in order. By splicing multiple 32-bit MAC middle values, a longer MAC value is generated, enhancing the anti-attack ability of the MAC. A longer MAC means a larger collision space, significantly increasing the difficulty of brute-force cracking or key search attacks, and improving the verification standard for data integrity and authenticity. It is applicable to scenarios with higher security requirements, such as the transmission of sensitive data. A longer MAC can provide additional protection to ensure the security of data during transmission.

[0181] The above communication device supporting variable authentication tag lengths includes a processor and a memory. The above encryption unit, key mixing unit, update unit, etc. are all stored in the memory as program units, and the corresponding functions are implemented by the processor executing the above program units stored in the memory. The above modules are all located in the same processor; or, the above each module is located in different processors in any combination form.

[0182] The processor contains a kernel, and the kernel retrieves the corresponding program unit from the memory. One or more kernels can be set. By adjusting the kernel parameters, the problem that the number of bits for integrity verification in the prior art is too single and different lengths of integrity verification cannot be adopted for messages of different importance levels, resulting in an increased risk of key attack and cracking, can be solved.

[0183] The memory may include non-permanent memory in computer-readable media, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory includes at least one storage chip.

[0184] An embodiment of the present invention provides a computer-readable storage medium. The computer-readable storage medium includes a stored program. When the program runs, it controls the device where the computer-readable storage medium is located to execute the communication method supporting variable authentication tag lengths.

[0185] An embodiment of the present invention provides a processor. The processor is used to run a program. When the program runs, it executes the communication method supporting variable authentication tag lengths.

[0186] An embodiment of the present invention provides a communication system supporting variable authentication tag lengths. The communication system supporting variable authentication tag lengths includes a processor, a memory, and a program stored on the memory and executable on the processor. When the processor executes the program, it implements at least the steps of the communication method supporting variable authentication tag lengths:

[0187] This application also provides a computer program product. When executed on a data processing device, it is adapted to execute a program initialized with at least the steps of the communication method supporting variable authentication tag lengths as follows.

[0188] Obviously, those skilled in the art should understand that the above modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.

[0189] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0190] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.

[0191] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0192] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0193] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0194] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0195] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0196] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0197] From the above description, it can be seen that the above embodiments of the present application achieve the following technical effects:

[0198] 1) The communication method of the present application supports variable authentication tag length, supports 256-bit initialization key input, uses Zu Chongzhi's algorithm to calculate to obtain key streams of different lengths, performs integrity verification according to the key stream, generates a target message authentication code of corresponding length (integrity verification tag length), supports three configurable integrity verifications (32 bits, 64 bits, 128 bits), and improves the security of the algorithm. With a key length of 256 bits, a larger key space is provided, and authentication tags of different lengths (32 bits / 64 bits / 128 bits) are supported, which has higher security and stronger collision resistance, and can be widely used in the security protection of 5G mobile communications. At the same time, in order to further meet the high-speed, low-latency 5G application goals, the present invention adopts a pipeline structure to improve the data processing rate. The present application solves the problem that the number of bits of integrity verification in the prior art is too single, and it is impossible to adopt integrity verification of different lengths for messages of different importance, resulting in an increased risk of key being attacked and cracked.

[0199] 2) The communication device of the present application that supports variable authentication tag lengths supports the input of a 256-bit initialization key. It uses the Zu Chongzhi algorithm for operation to obtain key streams of different lengths, performs integrity verification based on the key streams, generates target message authentication codes (integrity verification tag lengths) of corresponding lengths, and supports three configurable integrity verifications (32 bits, 64 bits, 128 bits), improving the security of the algorithm. It has a 256-bit key length, provides a larger key space, and supports authentication tags of different lengths (32 bits / 64 bits / 128 bits), with higher security and stronger collision resistance, and can be widely applied to the security protection of 5G mobile communications. At the same time, in order to further meet the 5G application goals of high speed and low latency, the present invention adopts a pipeline structure, improving the data processing rate. This application solves the problem in the prior art that the number of bits for integrity verification is too single, and different lengths of integrity verification cannot be adopted for messages of different importance levels, resulting in an increased risk of the key being attacked and cracked.

[0200] The foregoing are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A communication method supporting variable authentication tag lengths, characterized in that, Including: Obtain input data, generate a first key stream and a second key stream according to the input data by using the Zu Chongzhi algorithm, and encrypt the input data by using the first key stream to obtain a ciphertext message. The input data includes an initial key, an initial vector, a constant term, and a plaintext message. The second key stream is one of a 32-bit key stream, a 64-bit key stream, and a 128-bit key stream. A key mixing step: perform a shift operation on the current key and the next key in the second key stream to obtain key mixing data corresponding to the current key and the next key. The current key is the key currently participating in the shift operation in the second key stream, and the next key is the next key adjacent to the current key in the second key stream. The length of the key mixing data is 32 bits. A first update step: update the next key to be the current key, and sequentially repeat the key mixing step and the first update step at least once until all the keys in the second key stream participate in the shift operation to obtain all the key mixing data. Iteratively calculate a target message authentication code according to the second key stream and all the key mixing data. The length of the target message authentication code is 32 bits, or 64 bits, or 128 bits. Send the ciphertext message and the target message authentication code to a communication recipient, so that the communication recipient compares a verification message authentication code with the target message authentication code to determine whether data transmission is correct. The verification message authentication code is a message authentication code generated by the communication recipient based on the ciphertext message, the initial key, and the initial vector.

2. The method according to claim 1, characterized in that, Before obtaining the input data, the method further includes: When the register value of a configuration register is 1, calculate and generate the initial vector through a hardware circuit. The configuration register is a register for determining the configuration method of the initial vector. When the register value of the configuration register is 0, generate the initial vector through a software configuration method. The software configuration method is a method configured through a random generation algorithm.

3. The method according to claim 1, wherein Performing a shift operation on the current key and the next key in the second key stream to obtain the key mixing data corresponding to the current key and the next key includes: Substitute the current key and the next key in the second key stream into a first formula for calculation to obtain the key mixing data corresponding to the current key and the next key. The first formula is z[i]=c[j / 32]<<i||c[j / 32 + 1]>>31 - i, where z[i] represents the i-th mixing value in the key mixing data, i = 0, 1, 2,..., 31, c[j / 32] represents the current key, c[j / 32 + 1] represents the next key, j = 1, 2, 3...L, L is the number of keys in the second key stream, <<i represents a left shift of i bits, and >> represents a right shift.

4. The method according to claim 1, characterized in that, The target message authentication code is iteratively calculated based on the second key stream and all the key mixing data. The target message authentication code includes a first message authentication code. The length of the first message authentication code is 32 bits and at least includes: An assignment step of taking the first intermediate value of the current iterative compression intermediate data as the first key value in the second key stream. The current iterative compression intermediate data is a data set obtained by performing an exclusive OR operation on all the data in the current mixed key data. The current mixed key data is the mixed key data that is currently undergoing iterative calculation among all the mixed key data. The first intermediate value is the first intermediate value in the current iterative compression intermediate data; A determination step of determining the first intermediate value as the current intermediate value; A first exclusive OR step of, when the value corresponding to the current bit position of the plaintext message is 1, performing an exclusive OR operation on the current intermediate value and the current mixed value in the current key mixing data to obtain an intermediate value corresponding to the current exclusive OR operation. The current bit position is the bit position corresponding to the current mixed value; A skip step of, when the value corresponding to the current bit position of the plaintext message is 0, not performing an exclusive OR operation between the current intermediate value and the current mixed value in the current key mixing data; A second update step of updating the next mixed value as the current mixed value, and at the same time updating the intermediate value corresponding to the current exclusive OR operation as the current intermediate value. The next mixed value is the next mixed value of the current mixed value; A repetition step of sequentially repeating the first exclusive OR step, the skip step, and the second update step at least once until all the data in the current mixed key data have completed iterative calculation to obtain the current iterative compression intermediate data. The length of the current iterative compression intermediate data is 32 bits; A third update step of updating the next mixed key data as the current mixed key data. The next mixed key data is the next mixed key data of the current mixed key data; Sequentially repeating the assignment step, the determination step, the first exclusive OR step, the skip step, the second update step, the repetition step, and the third update step at least once until all the mixed data have completed calculation to obtain all the iterative compression intermediate data; A second exclusive OR step of performing consecutive exclusive OR operations on the last intermediate values of all the iterative compression intermediate data in sequence to obtain an exclusive OR output result. The length of the exclusive OR output result is 32 bits; Performing data processing on the exclusive OR output result according to the plaintext message to obtain the first message authentication code.

5. The method according to claim 4, characterized in that, Performing data processing on the exclusive OR output result according to the plaintext message to obtain the first message authentication code, including: When the length of the plaintext message is an integer multiple of the bit width, performing an exclusive OR operation on the exclusive OR output result and the last key in the second key stream to calculate the first message authentication code; When the length of the plaintext message is not an integer multiple of the bit width, determining the first message authentication code as the exclusive OR output result.

6. The method according to claim 4, characterized in that, The target message authentication code is iteratively calculated based on the second key stream and all the key mixing data. The target message authentication code includes a second message authentication code, and the length of the second message authentication code is 64 bits. It further includes: Repeat the assignment step, the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step in sequence at least once until all the iteratively compressed intermediate data is calculated to obtain a first exclusive-OR output result; Perform data processing on the first exclusive-OR output result according to the plaintext message to obtain a first tag intermediate value; Take the first intermediate value of the current iteratively compressed intermediate data as the second key value in the second key stream; Repeat the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step in sequence at least once until all the iteratively compressed intermediate data is calculated to obtain a second exclusive-OR output result; Perform data processing on the second exclusive-OR output result according to the plaintext message to obtain a second tag intermediate value; Concatenate the first tag intermediate value and the second tag intermediate value in order to obtain the second message authentication code.

7. The method according to claim 4, characterized in that The target message authentication code is iteratively calculated based on the second key stream and all the key mixing data. The target message authentication code includes a third message authentication code, and the third message authentication code is 128 bits. It further includes: Repeat the assignment step, the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step in sequence at least once until all the iteratively compressed intermediate data is calculated to obtain a third exclusive-OR output result; Perform data processing on the third exclusive-OR output result according to the plaintext message to obtain a third tag intermediate value; Take the first intermediate value of the current iteratively compressed intermediate data as the second key value in the second key stream; Repeat the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step in sequence at least once until all the iteratively compressed intermediate data is calculated to obtain a fourth exclusive-OR output result; Perform data processing on the fourth exclusive-OR output result according to the plaintext message to obtain a fourth tag intermediate value; Take the first intermediate value of the current iteratively compressed intermediate data as the third key value in the second key stream; Repeat the determination step, the first exclusive-OR step, the jump step, the second update step, the repetition step, the third update step, and the second exclusive-OR step in sequence at least once until all the iteratively compressed intermediate data is calculated to obtain a fifth exclusive-OR output result; Perform data processing on the fifth exclusive-OR output result according to the plaintext message to obtain a fifth tag intermediate value; Take the first intermediate value of the current iteratively compressed intermediate data as the fourth key value in the second key stream; Repeat the determining step, the first exclusive - OR step, the jumping step, the second updating step, the repeating step, the third updating step, and the second exclusive - OR step at least once in sequence until all the iterative compression intermediate data are calculated to obtain a sixth exclusive - OR output result; Perform data processing on the sixth exclusive - OR output result according to the plaintext message to obtain a sixth tag intermediate value; Concatenate the third tag intermediate value, the fourth tag intermediate value, the fifth tag intermediate value, and the sixth tag intermediate value in sequence to obtain the third message authentication code.

8. A communication device supporting variable authentication tag lengths, characterized in that, The device includes: An encryption unit, configured to obtain input data, generate a first key stream and a second key stream using the ZUC algorithm based on the input data, and encrypt the input data using the first key stream to obtain a ciphertext message. The input data includes an initial key, an initial vector, a constant term, and a plaintext message. The second key stream is one of a 32 - bit key stream, a 64 - bit key stream, and a 128 - bit key stream; A key mixing unit, configured to perform a key mixing step, perform a shift operation on the current key and the next key in the second key stream to obtain key - mixed data corresponding to the current key and the next key. The current key is the current key participating in the shift operation in the second key stream, and the next key is the next key adjacent to the current key in the second key stream. The length of the key - mixed data is 32 bits; An updating unit, configured to perform a first updating step to update the next key to the current key, and repeat the key mixing step and the first updating step at least once in sequence until all the keys in the second key stream participate in the shift operation to obtain all the key - mixed data; An iterative calculation unit, configured to iteratively calculate a target message authentication code according to the second key stream and all the key - mixed data. The length of the target message authentication code is 32 bits, or 64 bits, or 128 bits; A sending unit, configured to send the ciphertext message and the target message authentication code to a communication receiving party, so that the communication receiving party compares the verification message authentication code with the target message authentication code to determine whether the data transmission is correct. The verification message authentication code is a message authentication code generated by the communication receiving party based on the ciphertext message, the initial key, and the initial vector.

9. A computer-readable storage medium, characterized in that, The computer - readable storage medium includes a stored program, wherein when the program runs, it controls the device where the computer - readable storage medium is located to execute the method according to any one of claims 1 to 7.

10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by a processor, they implement the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Access control method and encryption system for PLC communication

    CN120512322A