Dynamic assembly-based national cryptographic algorithm rapid deployment implementation method and dynamic assembly-based national cryptographic algorithm rapid deployment implementation system

By providing a unified password basic component interface and dynamic assembly technology in big data scenarios, the time-consuming algorithm deployment problem in cross-platform data sharing is solved, and rapid password algorithm execution and random number generation are achieved.

CN120372639APending Publication Date: 2025-07-25JINAN INSTITUTE OF SUPERCOMPUTING TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510395802.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, complex cryptographic algorithms and privacy computing technologies are difficult to compatible with cross-platform data trusted sharing, and there are significant differences in algorithm implementation methods and interface forms under different platforms, resulting in time-consuming algorithm deployment steps and affecting the speed of encryption and random number generation.

Method used

By establishing a cryptographic basic component assembly interface in big data scenarios, a unified basic cryptographic component interface and assembly method is provided for different security protocols and algorithms. Dynamic assembly technology is adopted to read the algorithm component sequence text and execute the output results to avoid the compilation process.

Benefits of technology

It realizes the rapid deployment of cryptographic algorithms, improves the speed of encryption and decryption and random number generation, and has good versatility and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372639A_ABST
    Figure CN120372639A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic assembly-based national cryptographic algorithm rapid deployment implementation method and system, and the method comprises the steps: obtaining a to-be-deployed target algorithm; disassembling the target algorithm to be deployed to obtain a plurality of password components; combining the password components into a component sequence text according to a to-be-deployed target algorithm logic sequence; processing the component sequence text to obtain a calculation result of a to-be-deployed target algorithm; initializing the state of a target algorithm to be deployed; reading the component sequence text according to bytes, and performing corresponding processing according to the read characters; identifying the password component of the target algorithm to be deployed, reading parameters, performing corresponding operation, finishing execution, emptying the temporary character string, outputting a final character string if the ending position of the component sequence text is reached, and returning to the step of reading the component sequence text according to bytes if the ending position of the component sequence text is not reached.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cryptographic algorithm encryption and decryption, and particularly to a method and system for rapid deployment and implementation of national cryptographic algorithms based on dynamic assembly. Background Art

[0002] In cross-platform data trusted sharing, there is a problem that complex cryptographic algorithms and privacy computing technologies are difficult to be compatible. There are various security protocols and algorithms, and new protocols are constantly emerging. There are also significant differences in the implementation methods and interface forms of algorithms under different platforms.

[0003] Although standards have been proposed for the general cryptographic service interface specification to standardize the interfaces of cryptographic algorithms and protocols, it is still difficult to unify the interfaces for new non-standard security protocols and algorithms.

[0004] The existing technology for the deployment steps of algorithms includes: constructing the algorithm, compiling the algorithm, deploying the compiled algorithm to the target platform, executing the algorithm on the platform, and obtaining the output of the algorithm operation result. The defect of the existing technology is that the compilation step and deployment step of the algorithm are relatively time-consuming, resulting in a decrease in the speed of the algorithm output result. If the algorithm is used for encryption, the speed of obtaining the ciphertext result after encrypting the plaintext by the algorithm is slow; if the algorithm is used for generating random numbers, the speed of generating random numbers by the algorithm is slow. The main reason for the slow speed is that the existing technology needs to compile the algorithm, and the compilation process is time-consuming. Summary of the Invention

[0005] To solve the deficiencies of the existing technology, the present invention provides a method and system for rapid deployment and implementation of national cryptographic algorithms based on dynamic assembly; because complex cryptographic algorithms and security protocols are all based on basic cryptographic operations, by establishing the assembly interface of cryptographic basic components in the big data scenario, a unified basic cryptographic component interface and assembly method are provided for different security protocols and algorithms, and these basic components can be assembled according to the interface specification to implement flexible and configurable and extensible cryptographic protocols and algorithms, solving the problems of the interfaces and implementation of multi-party complex cryptographic algorithms and privacy computing security protocols in big data secure sharing. The present invention writes the component sequence text of the algorithm without considering the platform and optimization; dynamically assembles the algorithm, reads the sequence text, and then executes the algorithm to output the result, saving the time for algorithm execution; if the algorithm is used to implement encryption and decryption, the time for encryption and decryption can be greatly saved.

[0006] On the one hand, a method for rapid deployment and implementation of national cryptographic algorithms based on dynamic assembly is provided;

[0007] The method for rapid deployment and implementation of national cryptographic algorithms based on dynamic assembly includes:

[0008] Obtain the target algorithm to be deployed; disassemble the target algorithm to be deployed to obtain a number of cryptographic components; combine the cryptographic components into a component sequence text according to the logical order of the target algorithm to be deployed;

[0009] Process the component sequence text to obtain the calculation result of the target algorithm to be deployed; if the target algorithm performs an encryption operation, the obtained calculation result is the ciphertext corresponding to the plaintext; if the target algorithm performs a decryption operation, the obtained calculation result is the plaintext corresponding to the ciphertext; if the target algorithm performs a random number generation operation, the obtained calculation result is the generated random number;

[0010] Initialize the state of the target algorithm to be deployed;

[0011] Read the component sequence text byte by byte and perform corresponding processing according to the read characters;

[0012] Identify the cryptographic components of the target algorithm to be deployed, read the parameters, perform corresponding operations, and after completion, clear the temporary string. If the end position of the component sequence text is reached, output the final string. If the end position of the component sequence text is not reached, return to the step of reading the component sequence text byte by byte.

[0013] On the other hand, a rapid deployment implementation system for national cryptographic algorithms based on dynamic assembly is provided;

[0014] A rapid deployment implementation system for national cryptographic algorithms based on dynamic assembly includes:

[0015] A disassembling module, which is configured to: obtain the target algorithm to be deployed; disassemble the target algorithm to be deployed to obtain a number of cryptographic components; combine the cryptographic components into a component sequence text according to the logical order of the target algorithm to be deployed;

[0016] A deployment module, which is configured to: process the component sequence text to obtain the calculation result of the target algorithm to be deployed; if the target algorithm performs an encryption operation, the obtained calculation result is the ciphertext corresponding to the plaintext; if the target algorithm performs a decryption operation, the obtained calculation result is the plaintext corresponding to the ciphertext; if the target algorithm performs a random number generation operation, the obtained calculation result is the generated random number;

[0017] An initialization sub-module, which is configured to: initialize the state of the target algorithm to be deployed;

[0018] A reading sub-module, which is configured to: read the component sequence text byte by byte and perform corresponding processing according to the read characters;

[0019] An output sub-module, which is configured to: identify the cryptographic components of the target algorithm to be deployed, read parameters, perform corresponding operations, clear the temporary string after completion, output the final string if the end position of the component sequence text is reached, and return to the reading sub-module if the end position of the component sequence text is not reached.

[0020] In another aspect, an electronic device is further provided, including:

[0021] A memory for non-temporarily storing computer-readable instructions; and

[0022] A processor for running the computer-readable instructions,

[0023] wherein, when the computer-readable instructions are run by the processor, the method described in the first aspect above is executed.

[0024] In another aspect, a storage medium is further provided, which non-temporarily stores computer-readable instructions, wherein when the non-temporary computer-readable instructions are executed by a computer, the method described in the first aspect is executed.

[0025] In another aspect, a computer program product is further provided, including a computer program, and the computer program is used to implement the method described in the first aspect above when running on one or more processors.

[0026] The above technical solutions have the following advantages or beneficial effects:

[0027] The implementation and operation of a cryptographic algorithm and a security protocol composed of national cryptographic algorithm components can be achieved with one deployment. It has good versatility and strong scalability.

[0028] The national cryptographic algorithm is used to implement the encryption process of plaintext to obtain the encrypted ciphertext, and the encryption process does not require compilation.

[0029] The national cryptographic algorithm is used to generate random numbers, and the generated random numbers can be obtained. The process of generating random numbers does not require compilation, saving the time for the algorithm to be compiled. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] The specification drawings constituting a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.

[0031] Figure 1 It is a flowchart of the method for the first embodiment. DETAILED DESCRIPTION

[0032] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0033] Example 1

[0034] This example provides a method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly;

[0035] As Figure 1 shown, the method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly includes:

[0036] S101: Obtain the target algorithm to be deployed; disassemble the target algorithm to be deployed to obtain a number of cryptographic components; combine the cryptographic components into a component sequence text according to the logical order of the target algorithm to be deployed;

[0037] S102: Process the component sequence text to obtain the calculation result of the target algorithm to be deployed; if the target algorithm performs an encryption operation, the calculation result obtained is the ciphertext corresponding to the plaintext; if the target algorithm performs a decryption operation, the calculation result obtained is the plaintext corresponding to the ciphertext; if the target algorithm performs a random number generation operation, the calculation result obtained is the generated random number;

[0038] S102-1: Initialize the state of the target algorithm to be deployed;

[0039] S102-2: Read the component sequence text byte by byte and perform corresponding processing according to the read characters;

[0040] S102-3: Identify the cryptographic components of the target algorithm to be deployed, read the parameters, perform corresponding operations, and after completion, clear the temporary string. If the end position of the component sequence text is reached, output the final string. If the end position of the component sequence text is not reached, return to S102-2.

[0041] The advantages of the above technical solution are: The implementation and operation of the cryptographic algorithm and security protocol composed of national cryptographic algorithm components can be achieved with one deployment. It has good versatility and strong scalability.

[0042] Further, in step S101: Obtain the target algorithm to be deployed, where the target algorithm to be deployed includes: national cryptography algorithm SM2, national cryptography algorithm SM3, national cryptography algorithm SM4, or a combined algorithm; the combined algorithm refers to any combination of the three algorithms SM2, SM3, and SM4. The plaintext can be encrypted using the target algorithm to be deployed to obtain the final ciphertext, or the ciphertext can be decrypted using the target algorithm to be deployed to obtain the final plaintext, or a random number can be generated using the target algorithm to be deployed to obtain the final random number.

[0043] Further, step S101 also includes:

[0044] Define data types, where the data types include: TECC elliptic curve points, large number TBN, bit string TBYTES, and string TSTRING;

[0045] Among them, the TECC elliptic curve point is 3 unsigned 256-bit integers (x, y, z coordinates), and the x, y, and z coordinates can be taken out using a.x, a.y, and a.z respectively. It is the default data type for SM2 operations;

[0046] The large number TBN is an unsigned 256-bit integer;

[0047] The bit string TBYTES does not exceed 1024 bytes;

[0048] The string TSTRING does not exceed 1024 bytes.

[0049] Further, step S101 also includes: Define several keywords according to the characteristics of the cryptographic components, and the cryptographic components shall meet the requirements of the keywords during assembly;

[0050] The keywords include: all function names, single-line comment #, end symbol $, MODE function parameters, the last parameter of SM2 operation, and the working mode parameters of SM4.

[0051] The MODE function parameters include: FAST, SAFE, or BALANCE;

[0052] The last parameter of the SM2 operation includes: SM2P or SM2N;

[0053] The working mode parameters of SM4 include:

[0054] {ECB / CBC / CTR / OFB / CFB128 / CFB64 / CFB8 / CFB1}.{ENC / DEC}

[0055] Further, step S101 also includes: Define rules:

[0056] If a string is enclosed in single quotes, it means that the characters within the single quotes do not require preprocessing, and the characters within the single quotes are regarded as a string;

[0057] Data starting with 0x / 0X is regarded as a hexadecimal bit string;

[0058] All spaces except for strings are deleted;

[0059] One function per line, with line breaks in Linux format.

[0060] Further, disassembling the target algorithm to be deployed to obtain several cryptographic components; among them, the disassembly principles include:

[0061] According to the predefined cryptographic components, search for the corresponding cryptographic components in the target algorithm to be deployed. If found, the disassembled cryptographic components are obtained; if not found, disassemble the target algorithm to be deployed into several operation processes, and continue to repeat the search process for each operation process until the corresponding cryptographic components are found.

[0062] Further, disassembling the target algorithm to be deployed to obtain several cryptographic components; among them, the cryptographic components include:

[0063] The first cryptographic component has a number of 0, the name of the first cryptographic component is MODE, the first cryptographic component is used to optimize the mode setting, the number of parameters of the first cryptographic component is 1; the syntax of the first cryptographic component is MODE(mode), and MODE(mode) means mode = FAST / SAFE / BALANCE; the implementation methods of the first cryptographic component are fast, safe, and balanced;

[0064] The number of the second cryptographic component is 1, the name of the second cryptographic component is SETU256, the second cryptographic component is used to set a 256-bit unsigned number, the number of parameters of the second cryptographic component is 2; the syntax of the second cryptographic component is SETU256(val,NUM); the second cryptographic component is used to set the parameter val as the input 256-bit unsigned number NUM;

[0065] The number of the third cryptographic component is 2, the name of the third cryptographic component is SETBYTES, the third cryptographic component is used to set a bit sequence, the number of parameters of the third cryptographic component is 2, the syntax of the third cryptographic component is SETBYTES(val,bitarray), and the third cryptographic component is used to set the parameter val as the input bit string bitarray;

[0066] The number of the fourth cryptographic component is 3, the name of the fourth cryptographic component is SETSTRING, the fourth cryptographic component is used to set a string, the number of parameters of the fourth cryptographic component is 2, the syntax of the fourth cryptographic component is SETSTRING(val,str), and the fourth cryptographic component is used to set the parameter val to the input string str, and str needs to be marked with single quotes.

[0067] The number of the fifth cryptographic component is 4, the name of the fifth cryptographic component is OUTPUT, the fifth cryptographic component is used to output the parameter content, the number of parameters of the fifth cryptographic component is 2, the syntax of the fifth cryptographic component is OUTPUT(ds,val), and the fifth cryptographic component is used to output the string 'ds = the value of val' according to the data type;

[0068] The number of the sixth cryptographic component is 6, the name of the sixth cryptographic component is SWAP, the sixth cryptographic component is used for byte reverse order, the number of parameters of the sixth cryptographic component is 4, the syntax of the sixth cryptographic component is SWAP(out,in,len,step), and the sixth cryptographic component is used to group the bit string with length len in in by step bytes, and perform byte reverse order operation on each group of data, which can be used for the conversion between bit strings and large number data types.

[0069] The number of the seventh cryptographic component is 15, the name of the seventh cryptographic component is RND, the seventh cryptographic component is a random number generator, the number of parameters of the seventh cryptographic component is 2, the syntax of the seventh cryptographic component is RND(a,len), and the seventh cryptographic component is used to generate a random number of len bytes and output it to a.

[0070] The number of the eighth cryptographic component is 0x61, the name of the eighth cryptographic component is BNADD, the eighth cryptographic component is used for large number addition, the number of parameters of the eighth cryptographic component is 4, the syntax of the eighth cryptographic component is BNADD(c,a,b,mode), and BNADD(c,a,b,mode) means c = a + b % mode; a, b, c, and mode are all 256 bits, where mode is a prime number.

[0071] The number of the ninth cryptographic component is 0x62, the name of the ninth cryptographic component is BNSUB, the ninth cryptographic component is used to implement large number subtraction, the number of parameters of the ninth cryptographic component is 4, the syntax of the ninth cryptographic component is BNSUB(c,a,b,mode), and BNSUB(c,a,b,mode) means c = a - b % mode; a, b, c, and mode are all 256 bits, where mode is a prime number.

[0072] The number of the tenth cryptographic component is 0x63, the name of the tenth cryptographic component is BNDIV2, the tenth cryptographic component is used to implement large number division by 2, the number of parameters of the tenth cryptographic component is 3, and the syntax of the tenth cryptographic component is BNDIV2(c, a, mode)

[0073] c = (a / 2) % mode; a, c, and mode are all 256 bits, where mode is a prime number.

[0074] The number of the eleventh cryptographic component is 0x64, the name of the eleventh cryptographic component is BNMUL, the eleventh cryptographic component is used to implement large number multiplication, the number of parameters of the eleventh cryptographic component is 4, the syntax of the eleventh cryptographic component is BNMUL(c, a, b, mode), and BNMUL(c, a, b, mode) means a = a * b % mode; a, b, c, and mode are all 256 bits, where mode is a prime number.

[0075] The number of the twelfth cryptographic component is 0x65, the name of the twelfth cryptographic component is BNSQR, the twelfth cryptographic component is used to implement large number exponentiation, the number of parameters of the twelfth cryptographic component is 3, the syntax of the twelfth cryptographic component is BNADD(a, b, mode), and BNADD(a, b, mode) means c = a * a % mode; a, c, and mode are all 256 bits, where mode is a prime number.

[0076] The number of the thirteenth cryptographic component is 0x66, the name of the thirteenth cryptographic component is BNINV, the thirteenth cryptographic component is used to implement large number modular inverse, the number of parameters of the thirteenth cryptographic component is 3, the syntax of the thirteenth cryptographic component is BNINV(c, a, mode), and BNINV(c, a, mode) means c = a -1 % mode; a, c, and mode are all 256 bits, where mode is a prime number.

[0077] The number of the fourteenth cryptographic component is 0x81, the name of the fourteenth cryptographic component is ECADD, the fourteenth cryptographic component is used to implement elliptic curve point addition, the number of parameters of the fourteenth cryptographic component is 4, the syntax of the fourteenth cryptographic component is ECADD(C, A, B, mode), and ECADD(C, A, B, mode) means C = A + B % mode; A, B, C are elliptic curve points, and the z coordinate of B is defaulted to 1, that is, the coordinates of B are (x, y, 1), where mode is a 256-bit prime number.

[0078] The number of the fifteenth cryptographic component is 0x82, the name of the fifteenth cryptographic component is ECSUB, the fifteenth cryptographic component is used to implement elliptic curve point subtraction, the number of parameters of the fifteenth cryptographic component is 4, ECSUB(C, A, B, mode), and ECSUB(C, A, B, mode) means C = A - B % mode; A, B, and C are elliptic curve points, and the z coordinate of B is defaulted to 1, that is, the coordinate of B is (x, y, 1), where mode is a 256-bit prime number.

[0079] The number of the sixteenth cryptographic component is 0x83, the name of the sixteenth cryptographic component is ECGADD, the sixteenth cryptographic component is used to implement standard elliptic curve point addition, the number of parameters of the sixteenth cryptographic component is 4, the syntax of the sixteenth cryptographic component is ECGADD(C, A, B, mode), and ECGADD(C, A, B, mode) means C = A + B % mode; A, B, and C are elliptic curve points; A, B, and C are elliptic curve points, and mode is a 256-bit prime number.

[0080] The number of the seventeenth cryptographic component is 0x84, the name of the seventeenth cryptographic component is ECGSUB, the seventeenth cryptographic component is used to implement standard elliptic curve point subtraction, the number of parameters of the seventeenth cryptographic component is 4, the syntax of the seventeenth cryptographic component is ECGSUB(C, A, B, mode), and ECGSUB(C, A, B, mode) means C = A - B % mode; A, B, and C are elliptic curve points; A, B, and C are elliptic curve points, and mode is a 256-bit prime number.

[0081] The number of the eighteenth cryptographic component is 0x85, the name of the eighteenth cryptographic component is ECDOUBLE, the eighteenth cryptographic component is used to implement elliptic curve point doubling, the number of parameters of the eighteenth cryptographic component is 3, the syntax of the eighteenth cryptographic component is ECDOUBLE(C, A, mode), and ECDOUBLE(C, A, mode) means C = 2A % mode; A and C are elliptic curve points, and mode is a 256-bit prime number.

[0082] The number of the nineteenth cryptographic component is 0x86, the name of the nineteenth cryptographic component is ECTRIPLE, the nineteenth cryptographic component is used to implement elliptic curve point tripling, the number of parameters of the nineteenth cryptographic component is 3, the syntax of the nineteenth cryptographic component is ECTRIPLE(C, A, mode), and ECTRIPLE(C, A, mode) means C = 3A % mode; A and C are elliptic curve points, and mode is a 256-bit prime number.

[0083] The number of the twentieth cryptographic component is 0x87, the name of the twentieth cryptographic component is EC2PplusQ, the twentieth cryptographic component is used to implement elliptic curve 2P+Q, the number of parameters of the twentieth cryptographic component is 4, the syntax of the twentieth cryptographic component is EC2PplusQ(C,A,B,mode), and EC2PplusQ(C,A,B,mode) means C = 2A + B % mode; A, B, and C are elliptic curve points, and mode is a 256-bit prime number.

[0084] The number of the twenty-first cryptographic component is 0x88, the name of the twenty-first cryptographic component is EC2PminusQ, the twenty-first cryptographic component is used to implement elliptic curve 2P-Q, the number of parameters of the twenty-first cryptographic component is 4, the syntax of the twenty-first cryptographic component is EC2PminusQ(C,A,B,mode), and EC2PminusQ(C,A,B,mode) means C = 2A - B % mode; A, B, and C are elliptic curve points, and mode is a 256-bit prime number.

[0085] The number of the twenty-second cryptographic component is 0xA0, the name of the twenty-second cryptographic component is SM2KG, the twenty-second cryptographic component is used to implement SM2 fixed-point scalar multiplication, the number of parameters of the twenty-second cryptographic component is 3, the syntax of the twenty-second cryptographic component is SM2KG(out,k,imode), and SM2KG(out,k,imode) means out = k.G. If imode = 2, then the output is (X,Y,1). If imode = 3, then the output is (x,y,z).

[0086] The number of the twenty-third cryptographic component is 0xA1, the name of the twenty-third cryptographic component is SM2LQ. The twenty-third cryptographic component is used to implement non-fixed-point scalar multiplication, the number of parameters of the twenty-third cryptographic component is 4, the syntax of the twenty-third cryptographic component is SM2LQ(out,k,Q,imode), and SM2LQ(out,k,Q,imode) means out = k.Q. If imode = 2, then the output is (X,Y,1). If imode = 3, then the output is (x,y,z).

[0087] The number of the twenty-fourth cryptographic component is 0xA2, the name of the twenty-fourth cryptographic component is SM2KGLQ. The twenty-fourth cryptographic component is used to implement mixed-point double scalar multiplication, the number of parameters of the twenty-fourth cryptographic component is 5, the syntax of the twenty-fourth cryptographic component is SM2KGLQ(out,k,l,Q,imode), and SM2KGLQ(out,k,l,Q,imode) means Out = k.G + l.Q. If imode = 2, then the output is (X,Y,1). If imode = 3, then the output is (x,y,z).

[0088] The number of the 25th cryptographic component is 0xA3, the name of the 25th cryptographic component is SM2KPLQ, the 25th cryptographic component is used to implement non-fixed point double scalar multiplication, the number of parameters of the 25th cryptographic component is 5, the syntax of the 25th cryptographic component is SM2KGLQ(out,k,P,l,Q,imode), and SM2KGLQ(out,k,P,l,Q,imode) means Out = k.P + l.Q. If imode = 2, then the output is (X,Y,1); if imode = 3, then the output is (x,y,z).

[0089] The number of the 26th cryptographic component is 0xD0, the name of the 26th cryptographic component is SM3HASH, the 26th cryptographic component is used to implement SM3 hashing, the number of parameters of the 26th cryptographic component is 2, the syntax of the 26th cryptographic component is SM3HASH(out,a), and SM3HASH(out,a) means out = SM3(a), calculating the hash value of a and outputting it to out.

[0090] The number of the 27th cryptographic component is 0xD1, the name of the 27th cryptographic component is SM3HMAC, the 27th cryptographic component is used to obtain the hash message authentication code SM3 HMAC of the SM3 algorithm, the number of parameters of the 27th cryptographic component is 3, the syntax of the 27th cryptographic component is SM3HMAC(out,a,key), and SM3HMAC(out,a,key) means out = SM3HMAC(a,key), calculating the hash message authentication code HMAC value of a and key and outputting it to out.

[0091] The number of the 28th cryptographic component is 0xE0, the name of the 28th cryptographic component is SM4ENC, the 28th cryptographic component is used to implement SM4 encryption and decryption, the number of parameters of the 28th cryptographic component is 5, the syntax of the 28th cryptographic component is SM4ENC(o,i,key,iv,emode), and SM4ENC(o,i,key,iv,emode) means o = sm4(i,key,iv,emode), where key is the encryption key, iv is the initial vector, the ECB mode can be set to null, NULL or nil, and emode is {ECB / CBC / CTR / OFB / CFB128 / CFB64 / CFB8 / CFB1}.{ENC / DEC}.

[0092] The ECB mode and the CBC mode require the data length to be an integer multiple of 16 bytes.

[0093] The English full name corresponding to ECB is Electronic Codebook, and ECB represents the electronic codebook mode;

[0094] The English full name of CBC is Cipher Block Chaining, which represents the cipher block chaining mode;

[0095] The English full name of CTR is Counter, which represents the counter mode;

[0096] The English full name of OFB is Output Feedback, which represents the output feedback mode;

[0097] The English full name of CFB128 is Cipher Feedback(128-bit), which represents the cipher feedback mode, 128 bits;

[0098] The English full name of CFB64 is Cipher Feedback(64-bit), which represents the cipher feedback mode, 64 bits;

[0099] The English full name of CFB8 is Cipher Feedback(8-bit), which represents the cipher feedback mode, 8 bits;

[0100] The English full name of CFB1 is Cipher Feedback(1-bit), which represents the cipher feedback mode, 1 bit, also known as bit-by-bit CFB; ENC represents encryption; DEC represents decryption.

[0101] Further, the step of combining the password components into a component sequence text according to the target algorithm logic order to be deployed; wherein, the algorithm logic order means that algorithms are executed in a sequence of multiple operations, and this sequence is the algorithm logic.

[0102] Further, in S102-1: Initialize the state of the target algorithm to be deployed, including:

[0103] Set the line number iline = 1, set the end flag iend = 0, set the string array tmstr for temporary storage, and set the temporary string length thistrlen = 0;

[0104] Set the component sequence string pointer p, pointing to the start position of reading the component sequence text;

[0105] Set the parameter structure array cmps, and set the parameter quantity icmps = 0;

[0106] Set the output string outstr to be empty.

[0107] Further, in S102-2: Read the component sequence text byte by byte and perform corresponding processing according to the read characters, including:

[0108] Read each character of the component sequence text by byte and check the current character *p;

[0109] Case 1: If the current byte is 0, output the string outstr and exit;

[0110] Case 2: If the current byte is '$', set the end flag iend = 1. If thisstrlen > 0, set tmstr[thisstrlen] = 0, and go to step S102-3 to process the temporary string tmstr. Otherwise, output the string outstr and exit;

[0111] Case 3: If the current character is '\n', then p = p1 + 1 and iline + 1. If thisstrlen > 0, set tmstr[thisstrlen] = 0 and go to step S102-3 to process the temporary string tmstr;

[0112] Case 4: If the current byte is '#', find the pointer position p1 of the subsequent '\n' after the pointer p. If not found, set the end flag iend = 1; otherwise, set p = p1 + 1 and iline + 1. If thisstrlen > 0, set tmstr[thisstrlen] = 0 and go to step S102-3 to process the temporary string tmstr;

[0113] Case 5: If the current character is a single quote, find the second single quote p2. If found, append the characters between p and p2 to the temporary string tmstr, thisstrlen += (p2 - p), p = p2 + 1, and go to Case 1; if not found, report an error and exit;

[0114] Case 6: If the current character is a space, increment the value of p and go to Case 1;

[0115] Case 7: If it is other characters, append the current character to the temporary string tmstr, increment the value of p, and go to Case 1.

[0116] Further, in S102-3: Identify the password components of the target algorithm to be deployed, read the parameters, perform corresponding operations, and after completion, clear the temporary string, including:

[0117] (1-1): Use the delimiter to split the string tmstr to obtain several substrings, return the number of substrings icnt. If the left parenthesis is after the first substring and the right parenthesis is the last character, go to (1-2); otherwise, report an error and exit;

[0118] Exemplarily, split the string tmstr with the left parenthesis '(', right parenthesis ')' and comma ',' as delimiters into substrings and return the number of substrings icnt. If the left parenthesis is after the first substring and the right parenthesis is the last character, go to (1-2); otherwise, report an error and exit. Exemplarily, split RAND(r,32) into three substrings: RAND, r, and 32. At the same time, the left parenthesis is after RAND and the right parenthesis is the last character of the input string, which is a legal function.

[0119] (1-2): Determine whether the first substring is one of the names in the structure array set. If so, return the serial number funcode of the string and the number of parameters fcnt. Moreover, fcnt = icnt - 1, and perform different operations according to funcode; otherwise, report an error and exit.

[0120] The structure of the structure array includes: serial number, name, and number of parameters;

[0121] The structure array set includes:

[0122] {0,"MODE",1},{1,"SETU256",2},{2,"SETBYTES",3},

[0123] {3,"SETSTRING",2},{4,"OUTPUT",2},{6,"SWAP",4},

[0124] {15,"RND",2},{0x61,"BNADD",4},{0x62,"BNSUB",4},

[0125] {0x63,"BNDIV2",3},{0x64,"BNMUL",4},{0x65,"BNSQR",3},

[0126] {0x66,"BNINV",3},{0x81,"ECADD",4},{0x82,"ECSUB",4},

[0127] {0x83,"ECGADD",4},{0x84,"ECGSUB",4},{0x85,"ECDOUBLE",3},

[0128] {0x86,"ECTRIPLE",3},{0x87,"EC2PplusQ",4},{0x88,"EC2PminusQ",4},

[0129] {0xA0, "SM2KG", 3}, {0xA1, "SM2LQ", 4}, {0xA2, "SM2KGLQ", 5},

[0130] {0xA3, "SM2KPLQ", 6}, {0xD0, "SM3HASH", 2}, {0xD1, "SM3HMAC", 3},

[0131] {0xE0, "SM4ENC", 5}。

[0132] Further, performing different operations according to funcode includes:

[0133] (2-1) If funcode = 0, read the content of the second substring. If the content of the second substring is 'FAST' or 'SAFT' or 'BALANCE', set the optimization mode; otherwise, report an error and exit.

[0134] (2-2) If funcode = 1, read the content of the second substring and set the parameter large number serial number ibg = 0;

[0135] (2-2-1) If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively; check whether there is a parameter name in the parameter structure array cmps that is the same as a; go to (2-2-2);

[0136] Otherwise, check the parameter name that is the same as the second substring and go to (2-2-3);

[0137] (2-2-2) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0138] (2-2-3) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to 256-bit large integer, and the data length to 32 bytes.

[0139] (2-2-4) Read the content of the third substring, convert it to a 256-bit unsigned integer BN, and set cmps[cmpsid].[ibg] = BN.

[0140] Further, performing different operations according to funcode includes:

[0141] (2-3) If funcode = 2, read the content of the second substring and set the parameter large number serial number ibg = 0;

[0142] (2-3-1) If the second substring is in the form of a.x, a.y, or a.z, set ibg to 0, 1, and 2 respectively, and check if there is a parameter name in the parameter structure array cmps that is the same as a. Then proceed to (2-3-2);

[0143] Otherwise, check for a parameter name that is the same as the second substring and proceed to (2-3-3);

[0144] (2-3-2) If there is a match and the data type is 256-bit unsigned integer, elliptic curve coordinates, or bit sequence, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0145] (2-3-3) If no match is found, add a new parameter, set cmpsid = icmps, increment icmps by 1, set the parameter data type to 256-bit bit sequence, and set the data length to 32 bytes.

[0146] (2-3-4) Read the content of the third substring, convert it to a 256-bit bit sequence BT, and set cmps[cmpsid].[ibg] = BT.

[0147] Further, the different operations performed according to funcode also include:

[0148] (2-4) If funcode = 3, read the content of the second substring and check if there is a parameter name in the parameter structure array cmps that is the same as the second substring;

[0149] If there is a match and the data type is a string, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0150] If no match is found, add a new parameter, set cmpsid = icmps, increment icmps by 1, set the parameter data type to string; set cmps[cmpsid].str = the third substring.

[0151] If the national cryptographic algorithm encrypts the plaintext, set the content of parameter cmps[cmpsid] to the plaintext, and the outstr output in step (2-5) outputs the corresponding ciphertext.

[0152] (2-5) If funcode = 4, read the content of the second substring, append the content of the second substring to outstr, and then append '=' after outstr;

[0153] Read the content of the third substring, and check if there is a parameter name in the parameter structure array `cmps` that is the same as the second substring. If it exists, output the content according to the data type, and then append '\n' to `outstr`. Otherwise, report an error and exit.

[0154] (2-6) If `funcode` = 6, then read the content of the second substring, and set the large number parameter serial number `ibg` = 0.

[0155] (2-6-1) If the substring form is `a.x`, `a.y`, or `a.z`, set `ibg` to 0, 1, and 2 respectively, and check if there is a parameter name in the parameter structure array `cmps` that is the same as `a`, then enter (2-6-1-1);

[0156] Otherwise, check for a parameter name that is the same as the second substring, and enter (2-6-1-2);

[0157] (2-6-1-1) If there is one, and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number `cmpsid`. If the data type does not match, report an error and exit;

[0158] (2-6-1-2) If not found, add a new parameter, `cmpsid` = `icmps`, and at the same time `icmps` + 1, set the parameter data type to 256-bit bit sequence, and the data length to 32 bytes;

[0159] (2-6-2) Read the content of the third substring, and set the large number parameter serial number `ibg1` = 0.

[0160] If the substring form is `a.x`, `a.y`, or `a.z`, set `ibg1` to 0, 1, and 2 respectively, and check if there is a parameter name in the parameter structure array `cmps` that is the same as `a`, then enter (2-6-2-1);

[0161] Otherwise, check for a parameter name that is the same as the second substring, and enter (2-6-2-2);

[0162] (2-6-2-1) If there is one, and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number `cmpsid1`. If the data type does not match, report an error and exit;

[0163] (2-6-2-2) If not found, report an error and exit.

[0164] (2-6-3) Read the content of the fourth substring, convert it to an integer `len`. If it fails, report an error and exit. If the length of `len` is greater than the data length of `cmps[cmpsid1]`, report an error and exit.

[0165] (2-6-4) Read the content of the fifth substring, convert it to an integer step. If it fails, report an error and exit. If the length of step is greater than the data length of cmps[cmpsid1], report an error and exit. If the length of step is less than or equal to the data length of cmps[cmpsid1], then extract a bit string of len length, group it by step bytes, perform byte reverse order operation on each group of data, and then output it to cmps[cmpsid].[ibg].

[0166] Further, the performing different operations according to funcode further includes:

[0167] (2-7) If funcode = 15, then read the content of the third substring, convert the content of the third substring to an integer rlen. If it fails, report an error and exit.

[0168] (2-7-1) Read the content of the second substring, and set the parameter large number serial number ibg = 0;

[0169] If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-7-2);

[0170] Otherwise, check for a parameter name that is the same as the third substring, and enter (2-7-3);

[0171] (2-7-2) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0172] (2-7-3) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to bit sequence, and the data length to rlen bytes. Call the random number generator to generate rlen bytes of random numbers, and cmps[cmpsid].[ibg] = the generated random numbers.

[0173] Further, the performing different operations according to funcode further includes:

[0174] (2-8): funcode = 0x61, 0x62, 0x64; 0x61 is 256-bit unsigned integer modulo addition; 0x62 is 256-bit unsigned integer modulo subtraction; 0x64 is 256-bit unsigned integer modulo multiplication; the processing procedures of 0x61, 0x62, and 0x64 are the same; the processing procedure of 0x61 is as follows:

[0175] (2-8-1): Read the content of the second substring. Set the large number serial number of the parameter ibg = 0. If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-8-1-1);

[0176] Otherwise, check for a parameter name that is the same as the second substring, and enter (2-8-1-2);

[0177] (2-8-1-1): If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0178] (2-8-1-2): If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1. Set the parameter data type to 256-bit unsigned integer. If the substring form is a.x, a.y, or a.z, the data length is 96 bytes, otherwise the data length is 32 bytes.

[0179] (2-8-2): Read the content of the third substring. Set the large number serial number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-8-2-1);

[0180] Otherwise, check for a parameter name that is the same as the third substring, and enter (2-8-2-1);

[0181] (2-8-2-1): If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid1; if the data type does not match, report an error and exit;

[0182] (2-8-3): Read the content of the fourth substring. Set the large number serial number of the parameter ibg2 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-8-3-1);

[0183] Otherwise, check for a parameter name that is the same as the fourth substring, and enter (2-8-3-1);

[0184] (2-8-3-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid2; if the data type does not match, report an error and exit;

[0185] (2-8-4): Read the content of the fifth substring and compare it with the set modulo string. If found, set the modulus iMODEBN; otherwise, report an error and exit.

[0186] When funcode = 0x61, set icmps[cmpsid].[ibg] = (icmps[cmpsid1].[ibg1] + icmps[cmpsid2].[ibg2]) % iMODBN;

[0187] When funcode = 0x62, set icmps[cmpsid].[ibg] = (icmps[cmpsid1].[ibg1] - icmps[cmpsid2].[ibg2]) % iMODBN;

[0188] When funcode = 0x64, set icmps[cmpsid].[ibg] = (icmps[cmpsid1].[ibg1] * icmps[cmpsid2].[ibg2]) % iMODBN.

[0189] Furthermore, the performing different operations according to funcode further includes:

[0190] (2-9): funcode = 0x63, 0x65, 0x66; 0x63 is modular exponentiation of 256-bit unsigned integers; 0x65 is modular division by 2 of 256-bit unsigned integers; 0x66 is modular inverse of 256-bit unsigned integers; the processing procedures of 0x63, 0x65 and 0x66 are the same; the processing procedure of 0x63 is as follows:

[0191] (2-9-1): Read the content of the second substring and set the parameter large number serial number ibg = 0. If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-9-1-1); otherwise, check for a parameter name that is the same as the second substring and enter (2-9-1-2);

[0192] (2-9-1-1) If there is, and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0193] (2-9-1-2) If not found, add a new parameter, cmpsid = icmps, and increment icmps by 1. Set the parameter data type to 256-bit unsigned integer. If the substring form is a.x, a.y, or a.z, the data length is 96 bytes; otherwise, the data length is 32 bytes.

[0194] (2-9-2): Read the content of the third substring. Set the parameter large number sequence number ibg1 = 0. If the substring form is a.x, a.y, or a.z, set the parameter large number sequence numbers ibg1 to 0, 1, and 2 respectively. Check if there is a parameter name in the parameter structure array cmps that is the same as a, and proceed to (2-9-2-1);

[0195] Otherwise, check for a parameter name that is the same as the third substring and proceed to (2-9-2-1);

[0196] (2-9-2-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinates, extract the sequence number cmpsid1. If the data type does not match, report an error and exit;

[0197] (2-9-3): Read the content of the fourth substring and compare it with the set modulus string. If found, set the modulus iMODEBN; otherwise, report an error and exit.

[0198] funcode = 0x63, set icmps[cmpsid].[ibg] = (icmps[cmpsid1].[ibg1] * icmps[cmpsid1].[ibg1]) % iMODBN;

[0199] funcode = 0x65, set icmps[cmpsid].[ibg] = (icmps[cmpsid1].[ibg1] / 2) % iMODBN;

[0200] funcode = 0x66, set icmps[cmpsid].[ibg] = (icmps[cmpsid1].[ibg1]) -1 % iMODBN.

[0201] Furthermore, the different operations performed according to funcode also include:

[0202] (2-10): funcode = 0x81, 0x82, 0x83, 0x84; 0x81, 0x82, 0x83, 0x84 respectively represent elliptic curve point addition, point subtraction, standard point addition, and standard point subtraction; the processing methods of elliptic curve point addition, point subtraction, standard point addition, and standard point subtraction are the same. The processing steps of the elliptic curve point addition include:

[0203] (2-10-1): Read the content of the second substring, set the large number serial number ibg = 0 of the parameter, and find the parameter name in the parameter structure array cmps that is the same as the second substring;

[0204] If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0205] If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to elliptic curve coordinates, and the data length to 96 bytes.

[0206] (2-10-2): Read the content of the third substring, set the large number serial number ibg1 = 0 of the parameter, and find the parameter name in the parameter structure array cmps that is the same as the third substring;

[0207] If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid1; if the data type does not match, report an error and exit;

[0208] If not found, report an error and exit;

[0209] (2-10-3): Read the content of the fourth substring, set the large number serial number ibg2 = 0 of the parameter, and check whether there is a parameter name in the parameter structure array cmps that is the same as the fourth substring. If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid2. If the data type does not match, report an error and exit; if not found, report an error and exit;

[0210] (2-10-4): Read the content of the fifth substring and compare it with the set modulus string. If found, set the modulus iMODEBN, otherwise report an error and exit.

[0211] funcode = 0x81, set icmps[cmpsid] = the result of the point addition operation of the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) and (icmps[cmpsid2].[0], icmps[cmpsid2].[1], 1) with the prime number as iMODBN.

[0212] funcode = 0x82, set icmps[cmpsid] to the result of the point subtraction operation between the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) of prime number iMODBN and (icmps[cmpsid2].[0], icmps[cmpsid2].[1], 1).

[0213] funcode = 0x83, set icmps[cmpsid] to the result of the point addition operation between the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) of prime number iMODBN and (icmps[cmpsid2].[0], icmps[cmpsid2].[1], icmps[cmpsid2].[2]).

[0214] funcode = 0x84, set icmps[cmpsid] to the result of the point subtraction operation between the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) of prime number iMODBN and (icmps[cmpsid2].[0], icmps[cmpsid2].[1], icmps[cmpsid2].[2]).

[0215] Furthermore, the performing different operations according to funcode further includes:

[0216] (2 - 11) funcode = 0x85 and 0x86 are respectively for elliptic curve point doubling and point tripling operations. The processing steps for elliptic curve point doubling and point tripling operations are the same. The specific operations for elliptic curve point doubling include:

[0217] (2 - 11 - 1) Read the content of the second substring, set the large number serial number ibg = 0 to find the parameter name in the parameter structure array cmps that is the same as the second substring;

[0218] If there is such a parameter and the data type is elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0219] If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to elliptic curve coordinates and the data length to 96 bytes.

[0220] (2-11-2) Read the content of the third substring, set the large number serial number of the parameter ibg1 = 0, and search for the parameter name in the parameter structure array cmps that is the same as the third substring.

[0221] If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid1. If the data type does not match, report an error and exit; if not found, report an error and exit.

[0222] funcode = 0x85, set icmps[cmpsid] = the result of the point doubling operation of the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) with the prime number iMODBN.

[0223] funcode = 0x86, set icmps[cmpsid] = the result of the point tripling operation of the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) with the prime number iMODBN.

[0224] Furthermore, the performing different operations according to funcode further includes:

[0225] (2-12) funcode = 0x87 and 0x88 are respectively the elliptic curve point doubling addition and point doubling subtraction operations; the processing processes of the elliptic curve point doubling addition and point doubling subtraction operations are the same. The processing process of the elliptic curve point doubling addition includes:

[0226] (2-12-1) Read the content of the second substring, set the large number serial number of the parameter ibg = 0, and search for the parameter name in the parameter structure array cmps that is the same as the second substring;

[0227] If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit;

[0228] If not found, add a new parameter cmpsid = icmps, and at the same time perform an increment operation on icmps, set the parameter data type to elliptic curve coordinates, and the data length to 96 bytes.

[0229] (2-12-2) Read the content of the third substring, set the large number serial number of the parameter ibg1 = 0, and search for the parameter name in the parameter structure array cmps that is the same as the third substring.

[0230] If there is any, and the data type is elliptic curve coordinates, extract the serial number cmpsid1. If the data type does not match, report an error and exit. If not found, report an error and exit.

[0231] funcode = 0x87, set icmps[cmpsid] = the result of performing point doubling operation on the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) with prime number iMODBN and then performing point addition operation with (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]).

[0232] funcode = 0x88, set icmps[cmpsid] = the result of performing point doubling operation on the elliptic curve point (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]) with prime number iMODBN and then performing point addition operation with (icmps[cmpsid1].[0], icmps[cmpsid1].[1], icmps[cmpsid1].[2]).

[0233] Furthermore, the performing different operations according to funcode further includes:

[0234] (2-13) funcode = 0xA0, the component is SM2 fixed-point scalar multiplication;

[0235] (2-13-1) Read the content of the second substring, set the large number serial number ibg = 0 to find the parameter name in the parameter structure array cmps that is the same as the second substring. If there is any, and the data type is elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit. If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to elliptic curve coordinates and the data length to 96 bytes.

[0236] (2-13-2) Read the content of the third substring, set the large number serial number ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively to find whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-13-2-1);

[0237] Otherwise, find the parameter name that is the same as the third substring and enter (2-13-2-1);

[0238] (2-13-2-1) If there is any, and the data type is 256-bit unsigned integer or elliptic curve coordinates, extract the serial number cmpsid1. If the data type does not match, report an error and exit;

[0239] (2-13-3) Read the content of the fourth substring, convert the content of the fourth substring into an integer to output the coordinate type ot. If it fails, report an error and exit. If ot is not equal to 2 or 3, report an error and exit.

[0240] If ot = 2, then output affine coordinates, and set (icmps[cmpsid].[0], icmps[cmpsid].[1]) = SM2 fixed-point scalar multiplication, (icmps[cmpsid1].[ibg1]).G,

[0241] If ot = 3, then output Jacobian weighted mapping coordinates, and set (icmps[cmpsid].[0], icmps[cmpsid].[1], icmps[cmpsid].[2]) = SM2 fixed-point scalar multiplication, (icmps[cmpsid1].[ibg1]).G; where G is the SM2 curve base point.

[0242] Further, the performing different operations according to funcode further includes:

[0243] (2-14) funcode = 0xA1, and the component is SM2 non-fixed-point scalar multiplication;

[0244] (2-14-1) Read the content of the second substring, and find the parameter name in the parameter structure array cmps that is the same as the second substring. If there is any, and the data type is elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit; if not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to elliptic curve coordinates, and the data length to 96 bytes.

[0245] (2-14-2) Read the content of the third substring, and set the parameter large number serial number ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-14-2-1);

[0246] Otherwise, find the parameter name that is the same as the third substring, and enter (2-14-2-1);

[0247] (2-14-2-1) If there is any, and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid1. If the data type does not match, report an error and exit.

[0248] (2-14-3) Read the content of the fourth substring, and find the parameter name in the parameter structure array cmps that is the same as the fourth substring. If there is any, and the data type is elliptic curve coordinate, extract the serial number cmpsid2. If the data type does not match, report an error and exit. If not found, report an error and exit.

[0249] (2-14-4) Read the content of the fifth substring, convert the content of the fifth substring into an integer output coordinate type ot. If it fails, report an error and exit. If ot is not equal to 2 or 3, report an error and exit.

[0250] If ot = 2, then output affine coordinates, and set (icmps[cmpsid].[0], icmps[cmpsid].[1]) = SM2 non-fixed point scalar multiplication, (icmps[cmpsid1].[ibg1]).icmps[cmpsid2];

[0251] If ot = 3, then output Jacobian weighted mapping coordinates, and set (icmps[cmpsid].[0], icmps[cmpsid].[1], icmps[cmpsid].[2]) = SM2 non-fixed point scalar multiplication, (icmps[cmpsid1].[ibg1]).icmps[cmpsid2].

[0252] Further, the performing different operations according to funcode further includes:

[0253] (2-15) funcode = 0xA2, and the component is SM2 mixed point double scalar multiplication;

[0254] (2-15-1) Read the content of the second substring, set the large number serial number of the parameter ibg = 0, and find the parameter name in the parameter structure array cmps that is the same as the second substring. If there is any, and the data type is elliptic curve coordinate, extract the serial number cmpsid. If the data type does not match, report an error and exit. If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to elliptic curve coordinate, and the data length to 96 bytes.

[0255] (2-15-2) Read the content of the third substring, and set the large number serial number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, and 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-15-2-1);

[0256] Otherwise, search for the parameter name that is the same as the third substring, and enter (2-15-2-1);

[0257] (2-15-2-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid1. If the data type does not match, report an error and exit;

[0258] (2-15-3) Read the content of the fourth substring, and set the large number serial number of the parameter ibg2 = 0. If the substring form is a.x, a.y, or a.z, set ibg2 to 0, 1, and 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-15-3-1);

[0259] Otherwise, search for the parameter name that is the same as the fourth substring, and enter (2-15-3-1);

[0260] (2-15-3-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid2; if the data type does not match, report an error and exit;

[0261] (2-15-4) Read the content of the fifth substring, and search for the parameter name in the parameter structure array cmps that is the same as the fourth substring. If there is one and the data type is elliptic curve coordinate, extract the serial number cmpsid3. If the data type does not match, report an error and exit; if not found, report an error and exit;

[0262] (2-15-5) Read the content of the sixth substring, convert it to an integer and output the coordinate type ot. If it fails, report an error and exit; if ot is not equal to 2 or 3, report an error and exit.

[0263] If ot = 2, then output the affine coordinate, and set (icmps[cmpsid].[0], icmps[cmpsid].[1]) = SM2 mixed point double scalar multiplication, (icmps[cmpsid1].[ibg1]).G+(icmps[cmpsid2].[ibg2]).icmps[cmpsid3];

[0264] If ot = 3, then output the Jacobian weighted mapping coordinates, and set (icmps[cmpsid].[0], icmps[cmpsid].[1], icmps[cmpsid].[2]) = SM2 mixed point double scalar multiplication, ((icmps[cmpsid1].[ibg1]).G+(icmps[cmpsid2].[ibg2]).icmps[cmpsid3].

[0265] Furthermore, the step of performing different operations according to funcode further includes:

[0266] (2-16) funcode = 0xA3, and the component is SM2 non-fixed point double scalar multiplication;

[0267] (2-16-1) Read the content of the second substring, set the large number serial number ibg = 0 of the parameter to find the parameter name in the parameter structure array cmps that is the same as the second substring. If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit; if not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to elliptic curve coordinates, and the data length is 96 bytes;

[0268] (2-16-2) Read the content of the third substring, set the large number serial number ibg1 = 0 of the parameter. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-16-2-1);

[0269] Otherwise, find the parameter name that is the same as the third substring and enter (2-16-2-1);

[0270] (2-16-2-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinates, extract the serial number cmpsid1. If the data type does not match, report an error and exit;

[0271] (2-16-3) Read the content of the fourth substring, find the parameter name in the parameter structure array cmps that is the same as the fourth substring. If there is one and the data type is elliptic curve coordinates, extract the serial number cmpsid2. If the data type does not match, report an error and exit; if not found, report an error and exit;

[0272] (2-16-4) Read the content of the fifth substring, set the parameter large number serial number ibg2 = 0. If the substring form is a.x, a.y, or a.z, set ibg2 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-16-4-1);

[0273] Otherwise, search for the parameter name that is the same as the fourth substring, and then enter (2-16-4-1);

[0274] (2-16-4-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid3. If the data type does not match, report an error and exit;

[0275] (2-16-5) Read the content of the sixth substring, search for the parameter name in the parameter structure array cmps that is the same as the fourth substring. If there is one and the data type is elliptic curve coordinate, extract the serial number cmpsid4. If the data type does not match, report an error and exit; if not found, report an error and exit;

[0276] (2-16-6) Read the content of the seventh substring, convert it to an integer and output the coordinate type ot. If it fails, report an error and exit. If ot is not equal to 2 or 3, report an error and exit.

[0277] If ot = 2, then output the affine coordinate, and set (icmps[cmpsid].[0], icmps[cmpsid].[1]) = SM2 mixed point double scalar multiplication, (icmps[cmpsid1].[ibg1])..icmps[cmpsid2]+(icmps[cmpsid3].[ibg3]).icmps[cmpsid3],

[0278] If ot = 3, then output the Jacobian weighted mapping coordinate, and set (icmps[cmpsid].[0], icmps[cmpsid].[1], icmps[cmpsid].[2]) = SM2 mixed point double scalar multiplication (icmps[cmpsid1].[ibg1])..icmps[cmpsid2]+(icmps[cmpsid3].[ibg3]).icmps[cmpsid3].

[0279] Furthermore, the different operations performed according to funcode also include:

[0280] (2-17) funcode = 0xD0, and the component is SM3 hash;

[0281] (2-17-1) Read the content of the second substring, set the large number sequence number of the parameter ibg = 0. If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check if there is a parameter name in the parameter structure array cmps that is the same as a. Then enter (2-17-1-1);

[0282] Otherwise, check for a parameter name that is the same as the second substring, and enter (2-17-1-2);

[0283] (2-17-1-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, or bit sequence, extract the sequence number cmpsid1. If the data type does not match, report an error and exit;

[0284] (2-17-1-2) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to bit sequence, and the data length to 32 bytes.

[0285] (2-17-2) Read the content of the third substring, set the large number sequence number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check if there is a parameter name in the parameter structure array cmps that is the same as a. Then enter (2-17-2-1); Otherwise, check for a parameter name that is the same as the third substring, and enter (2-17-2-1);

[0286] (2-17-2-1) If there is one, extract the sequence number cmpsid1, data type itype, and data length n. Otherwise, report an error and exit.

[0287] (2-17-3) Perform the SM3 hashing operation on the n-byte itype-type data in icmps[cmpsid1], and output it to icmps[cmpsid].[ibg].

[0288] Further, the performing different operations according to funcode further includes:

[0289] (2-18) funcode = 0xD0, and the component is the SM3 hash message authentication code;

[0290] (2-18-1) Read the content of the second substring, set the large number sequence number of the parameter ibg = 0. If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check if there is a parameter name in the parameter structure array cmps that is the same as a. Then enter (2-18-1-1);

[0291] Otherwise, search for the parameter name that is the same as the second substring, and go to (2-18-1-2);

[0292] (2-18-1-1) If there is one, and the data type is 256-bit unsigned integer or elliptic curve coordinates, or bit sequence, extract the serial number cmpsid1. If the data types do not match, report an error and exit;

[0293] (2-18-1-2) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1. Set the parameter data type to bit sequence and the data length to 32 bytes.

[0294] (2-18-2) Read the content of the third substring, and set the large number serial number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively. Search in the parameter structure array cmps to see if there is a parameter name the same as a, and go to (2-18-2-1);

[0295] Otherwise, search for the parameter name that is the same as the third substring, and go to (2-18-2-1);

[0296] (2-18-2-1) If there is one, extract the serial number cmpsid1, the data type itype, and the data length n. Otherwise, report an error and exit.

[0297] (2-18-3) Read the content of the fourth substring, and set the large number serial number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively. Search in the parameter structure array cmps to see if there is a parameter name the same as a, and go to (2-18-3-1);

[0298] Otherwise, search for the parameter name that is the same as the fourth substring, and go to (2-18-3-1);

[0299] (2-18-3-1) If there is one, extract the serial number cmpsid2, the data type itype1, and the data length n1. Otherwise, report an error and exit.

[0300] (2-18-4) Set the key to the n1-byte itype1 type data in icmps[cmpsid2], and perform the SM3 hashing operation on the n-byte itype type data in icmps[cmpsid1], and output to icmps[cmpsid].[ibg]

[0301] Furthermore, the performing different operations according to funcode further includes:

[0302] (2-19) The funcode = 0xE0, and the component is SM4 encryption and decryption;

[0303] (2-19-1) Read the content of the third substring. Set the large number serial number ibg1 = 0 of the parameter. If the form of the substring is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-19-11);

[0304] Otherwise, check the parameter name that is the same as the third substring, and enter (2-19-11);

[0305] (2-19-11) If there is, extract the serial number cmpsid1, data type itype, and data length n. Otherwise, report an error and exit.

[0306] (2-19-2) Read the content of the fourth substring. Set the large number serial number ibg2 = 0 of the parameter. If the form of the substring is a.x, a.y, or a.z, then set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-19-21);

[0307] Otherwise, check the parameter name that is the same as the fourth substring, and enter (2-19-21);

[0308] (2-19-21) If there is, extract the serial number cmpsid2, data type itype1, and data length n1. Otherwise, report an error and exit;

[0309] (2-19-3) Read the content of the fifth substring. Set the large number serial number ibg3 = 0. If the form of the substring is a.x, a.y, or a.z, set ibg3 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-19-31); Otherwise, check the parameter name that is the same as the fifth substring, and enter (2-19-31);

[0310] (2-19-31) If there is, extract the serial number cmpsid3, data type itype2, and data length n2. Otherwise, report an error and exit;

[0311] (2-19-4) Read the content of the fifth substring,

[0312] If the content of the fifth substring is 'ECB.ENC', then the encryption mode imode = 0, and imode = 0 indicates ECB mode encryption;

[0313] If the content of the fifth substring is 'ECB.DEC', the encryption mode imode = 0x80, indicating ECB mode decryption;

[0314] If the content of the fifth substring is 'CBC.ENC', the encryption mode imode = 1, indicating CBC mode encryption;

[0315] If the content of the fifth substring is 'CBC.DEC', the encryption mode imode = 0x81, indicating CBC mode decryption;

[0316] If the content of the fifth substring is 'CTR.ENC', the encryption mode imode = 2, indicating CTR mode encryption;

[0317] If the content of the fifth substring is 'CTR.DEC', the encryption mode imode = 0x82, indicating CTR mode decryption;

[0318] If the content of the fifth substring is 'CFB128.ENC', the encryption mode imode = 3, indicating CFB128 mode encryption;

[0319] If the content of the fifth substring is 'CFB128.DEC', the encryption mode imode = 0x83, indicating CFB128 mode decryption;

[0320] If the content of the fifth substring is 'CFB64.ENC', the encryption mode imode = 4, indicating CFB64 mode encryption;

[0321] If the content of the fifth substring is 'CFB64.DEC', the encryption mode imode = 0x84, indicating CFB64 mode decryption;

[0322] If the content of the fifth substring is 'CFB8.ENC', the encryption mode imode = 5, indicating CFB8 mode encryption;

[0323] If the content of the fifth substring is 'CFB8.DEC', the encryption mode imode = 0x85, indicating CFB8 mode decryption;

[0324] If the content of the fifth substring is 'CFB1.ENC', the encryption mode imode = 6, indicating CFB1 mode encryption;

[0325] If the content of the fifth substring is 'CFB1.DEC', the encryption mode imode = 0x86, indicating CFB1 mode decryption;

[0326] If the content of the fifth substring is 'OFB.ENC', the encryption mode imode = 7, indicating OFB mode encryption;

[0327] If the content of the fifth substring is 'OFB.DEC', the encryption mode imode = 0x87, indicating decryption in OFB mode;

[0328] Otherwise, report an error and exit.

[0329] Furthermore, the performing different operations according to funcode further includes:

[0330] (2 - 20) Read the content of the fifth substring, set the large number sequence number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg3 to 0, 1, 2 respectively, and search whether there is a parameter name in the parameter structure array cmps that is the same as a. Otherwise, search for the parameter name that is the same as the fifth substring. If there is, extract the sequence number cmpsid3, the data type itype2, and the data length n2. Otherwise, report an error and exit.

[0331] (2 - 21) Read the content of the second substring, set the large number sequence number of the parameter ibg = 0. If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and search whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2 - 21 - 1);

[0332] Otherwise, search for the parameter name that is the same as the second substring and enter (2 - 21 - 2);

[0333] (2 - 21 - 1) If there is, extract the sequence number cmpsid1, the data type itype0. If the data length < n, report an error and exit;

[0334] (2 - 21 - 2) If not found, add a new parameter cmpsid = icmps, and at the same time perform an increment operation on icmps, set the parameter data type itype0 to a bit sequence, and the data length to n bytes.

[0335] (2 - 22) Set the key as the 16 - byte itype1 - type data in icmps[cmpsid2] (pad with 0 if less than 16 bytes), and the initial vector IV as the 16 - byte itype2 - type data in icmps[cmpsid3] (pad with 0 if less than 16 bytes). Perform the SM4 imode - mode encryption and decryption operation on the n - byte itype - type data in icmps[cmpsid1], and output the encryption and decryption operation result to the n - byte itype0 - type data array in icmps[cmpsid].

[0336] (2 - 23) If funcode is other values, report an error and exit.

[0337] (2-24) Clear tmstr, thisstrlen = 0; If iend is not equal to 0, output the string outstr and exit; otherwise, go to S102-2.

[0338] Example Two

[0339] This example provides a system for quickly deploying the national cryptographic algorithm based on dynamic assembly, including:

[0340] A disassembly module, which is configured to: obtain the target algorithm to be deployed; disassemble the target algorithm to be deployed to obtain a number of cryptographic components; combine the cryptographic components into a component sequence text according to the logical order of the target algorithm to be deployed;

[0341] A deployment module, which is configured to: process the component sequence text to obtain the calculation result of the target algorithm to be deployed; if the target algorithm performs an encryption operation, the obtained calculation result is the ciphertext corresponding to the plaintext; if the target algorithm performs a decryption operation, the obtained calculation result is the plaintext corresponding to the ciphertext; if the target algorithm performs a random number generation operation, the obtained calculation result is the generated random number;

[0342] An initialization sub-module, which is configured to: initialize the state of the target algorithm to be deployed;

[0343] A reading sub-module, which is configured to: read the component sequence text byte by byte and perform corresponding processing according to the read characters;

[0344] An output sub-module, which is configured to: identify the cryptographic components of the target algorithm to be deployed, read the parameters, perform corresponding operations, clear the temporary string after execution, output the final string if the end position of the component sequence text is reached, and return to the reading sub-module if the end position of the component sequence text is not reached.

[0345] It should be noted here that the above disassembly module and deployment module correspond to steps S101 to S102 in Example One. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above Example One. It should be noted that the above modules, as part of the system, can be executed in a computer system such as a set of computer executable instructions.

[0346] In the above embodiments, the descriptions of each embodiment have their own emphases. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0347] The proposed system can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the above modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed.

[0348] Embodiment 3

[0349] This embodiment also provides an electronic device, including: one or more processors, one or more memories, and one or more computer programs; wherein, the processor is connected to the memory, and the one or more computer programs are stored in the memory. When the electronic device runs, the processor executes the one or more computer programs stored in the memory, so that the electronic device executes the method described in Embodiment 1 above.

[0350] It should be understood that in this embodiment, the processor may be a central processing unit CPU, and the processor may also be other general-purpose processors, digital signal processors DSP, application-specific integrated circuits ASIC, off-the-shelf programmable gate arrays FPGA or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0351] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the memory may also include a non-volatile random memory. For example, the memory may also store information about the device type.

[0352] In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software.

[0353] The method in Embodiment 1 can be directly embodied as being executed by the hardware processor, or completed by the combination of the hardware and software modules in the processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0354] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with this embodiment can be implemented by electronic hardware or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0355] Embodiment 4

[0356] This embodiment also provides a computer-readable storage medium for storing computer instructions. When the computer instructions are executed by a processor, the method described in Embodiment 1 is completed.

[0357] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for quickly deploying the national cryptographic algorithm based on dynamic assembly, characterized in that Including: Obtain the target algorithm to be deployed; Decompose the target algorithm to be deployed to obtain a number of cryptographic components; Combine the cryptographic components into a component sequence text according to the logical order of the target algorithm to be deployed; Process the component sequence text to obtain the calculation result of the target algorithm to be deployed; If the target algorithm performs an encryption operation, the obtained calculation result is the ciphertext corresponding to the plaintext; If the target algorithm performs a decryption operation, the obtained calculation result is the plaintext corresponding to the ciphertext; If the target algorithm performs a random number generation operation, the obtained calculation result is the generated random number; Initialize the state of the target algorithm to be deployed; Read the component sequence text byte by byte and perform corresponding processing according to the read characters; Identify the cryptographic components of the target algorithm to be deployed, read the parameters, perform corresponding operations, and after completion, clear the temporary string. If the end position of the component sequence text is reached, output the final string. If the end position of the component sequence text is not reached, return to the step of reading the component sequence text byte by byte.

2. The method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly according to claim 1, characterized in that, For the component sequence text, read it byte by byte and perform corresponding processing according to the read characters, including: Read each character of the component sequence text byte by byte and check the current character *p; Case 1: If the current byte is 0, output the string outstr and exit; Case 2: If the current byte is '$', set the end flag iend = 1. If thisstrlen > 0, set tmstr[thisstrlen] = 0, go to the step of identifying the cryptographic components of the target algorithm to be deployed, and process the temporary string tmstr. Otherwise, output the string outstr and exit; Case 3: If the current character is '\n', then p = p1 + 1, iline + 1. If thisstrlen > 0, set tmstr[thisstrlen] = 0, go to the step of identifying the cryptographic components of the target algorithm to be deployed, and process the temporary string tmstr; Case 4: If the current byte is '#', find the pointer position p1 of the subsequent '\n' of the pointer p. If not found, set the end flag iend = 1; otherwise, set p = p1 + 1, iline + 1. If thisstrlen > 0, set tmstr[thisstrlen] = 0, go to the step of identifying the cryptographic components of the target algorithm to be deployed, and process the temporary string tmstr; Case 5: If the current character is a single quote, find the second single quote p2. If found, append the characters between p and p2 to the temporary string tmstr, thisstrlen += (p2 - p), p = p2 + 1, and go to Case 1; if not found, report an error and exit; Case 6: If the current character is a space, increment the value of p and go to Case 1; Case 7: If it is other characters, append the current character to the temporary string tmstr, increment the value of p, and go to Case 1.

3. The method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly according to claim 1, characterized in that, Identify the cryptographic components of the target algorithm to be deployed, read the parameters, perform corresponding operations, and after completion, clear the temporary string, including: (1-1): Use the delimiter to split the string tmstr to obtain several substrings, return the number of substrings icnt. If the left parenthesis is after the first substring and the right parenthesis is the last character, go to (1-2); otherwise, report an error and exit. (1-2): Determine whether the first substring is one of the names in the structure array set. If so, return the serial number funcode of the string and the number of parameters fcnt. Moreover, fcnt = icnt - 1, and perform different operations according to funcode; otherwise, report an error and exit.

4. The method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly according to claim 1, characterized in that, The different operations performed according to funcode include: (2-1) If funcode = 0, read the content of the second substring. If the content of the second substring is 'FAST' or 'SAFT' or 'BALANCE', set the optimization mode; otherwise, report an error and exit. (2-2) If funcode = 1, read the content of the second substring and set the large number serial number of the parameter ibg = 0. (2-2-1) If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively; check whether there is a parameter name in the parameter structure array cmps that is the same as a; enter (2-2-2). Otherwise, find the parameter name that is the same as the second substring and enter (2-2-3). (2-2-2) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate, extract the serial number cmpsid. If the data type does not match, report an error and exit. (2-2-3) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to 256-bit large integer and the data length to 32 bytes. (2-2-4) Read the content of the third substring, convert it to a 256-bit unsigned integer BN, and set cmps[cmpsid].[ibg] = BN.

5. The method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly according to claim 1, characterized in that, The different operations performed according to funcode include: (2-3) If funcode = 2, read the content of the second substring and set the large number serial number of the parameter ibg = 0. (2-3-1) If the second substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-3-2). Otherwise, find the parameter name that is the same as the second substring and enter (2-3-3). (2-3-2) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number cmpsid. If the data type does not match, report an error and exit. (2-3-3) If not found, add a new parameter, cmpsid = icmps, and at the same time perform an increment operation on icmps. Set the parameter data type to 256-bit bit sequence and the data length to 32 bytes; (2-3-4) Read the content of the third substring, convert it to a 256-bit bit sequence BT, and set cmps[cmpsid].[ibg] = BT.

6. The method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly according to claim 1, characterized in that, The different operations performed according to funcode also include: (2-4) If funcode = 3, then read the content of the second substring and check whether there is a parameter name in the parameter structure array cmps that is the same as the second substring; If there is, and the data type is a string, extract the serial number cmpsid. If the data type does not match, report an error and exit; If not found, add a new parameter, cmpsid = icmps, and at the same time perform an increment operation on icmps. Set the parameter data type to string; set cmps[cmpsid].str = the third substring; If the national cryptography algorithm encrypts the plaintext, set the content of the parameter cmps[cmpsid] to the plaintext, and the outstr in step (2-5) outputs the corresponding ciphertext; (2-5) If funcode = 4, then read the content of the second substring, append the content of the second substring to outstr, and then append '=' after outstr; Read the content of the third substring and check whether there is a parameter name in the parameter structure array cmps that is the same as the second substring. If there is, output the content according to the data type, and then append '\n' after outstr. Otherwise, report an error and exit; (2-6) If funcode = 6, then read the content of the second substring and set the large number serial number of the parameter ibg = 0, (2-6-1) If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-6-1-1); Otherwise, check for a parameter name that is the same as the second substring and enter (2-6-1-2); (2-6-1-1) If there is, and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number cmpsid. If the data type does not match, report an error and exit; (2-6-1-2) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1. Set the parameter data type to 256-bit bit sequence and the data length to 32 bytes; (2-6-2) Read the content of the third substring and set the large number serial number of the parameter ibg1 = 0, If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, and enter (2-6-2-1); Otherwise, search for the parameter name that is the same as the second substring, and go to (2-6-2-2); (2-6-2-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number cmpsid1. If the data type does not match, report an error and exit; (2-6-2-2) If not found, report an error and exit; (2-6-3) Read the content of the fourth substring and convert it to an integer len. If it fails, report an error and exit; If the length of len is greater than the data length of cmps[cmpsid1], report an error and exit; (2-6-4) Read the content of the fifth substring and convert it to an integer step. If it fails, report an error and exit; If the length of step is greater than the data length of cmps[cmpsid1], report an error and exit; If the length of step is less than or equal to the data length of cmps[cmpsid1], then extract the bit string of length len, group it by step bytes, perform byte reverse order operation on each group of data, and then output it to cmps[cmpsid].[ibg].

7. The method for quickly deploying and implementing the national cryptographic algorithm based on dynamic assembly according to claim 1, characterized in that The above-mentioned performing different operations according to funcode further includes: (2-7) If funcode = 15, then read the content of the third substring, convert the content of the third substring to an integer rlen. If it fails, report an error and exit; (2-7-1) Read the content of the second substring and set the large number serial number of the parameter ibg = 0; If the substring form is a.x, a.y, or a.z, respectively set ibg to 0, 1, 2, and search for whether there is a parameter name in the parameter structure array cmps that is the same as a, and go to (2-7-2); Otherwise, search for the parameter name that is the same as the third substring, and go to (2-7-3); (2-7-2) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinate or bit sequence, extract the serial number cmpsid. If the data type does not match, report an error and exit; (2-7-3) If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1, set the parameter data type to bit sequence, and the data length to rlen bytes; Call the random number generator to generate rlen bytes of random numbers, and cmps[cmpsid].[ibg] = the generated random numbers; The above-mentioned performing different operations according to funcode further includes: (2-8): funcode = 0x61, 0x62, 0x64; 0x61 is 256-bit unsigned integer modular addition; 0x62 is 256-bit unsigned integer modular subtraction; 0x64 is 256-bit unsigned integer modular multiplication; The processing processes of 0x61, 0x62, and 0x64 are the same; The processing process of 0x61 is as follows: (2-8-1): Read the content of the second substring, set the large number serial number of the parameter ibg = 0. If the substring form is a.x, a.y, or a.z, set ibg to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-8-1-1); Otherwise, check for a parameter name that is the same as the second substring, and enter (2-8-1-2); (2-8-1-1): If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinates, extract the serial number cmpsid. If the data type does not match, report an error and exit; (2-8-1-2): If not found, add a new parameter, cmpsid = icmps, and at the same time icmps + 1. Set the parameter data type to 256-bit unsigned integer. If the substring form is a.x, a.y, or a.z, the data length is 96 bytes, otherwise the data length is 32 bytes; (2-8-2): Read the content of the third substring, set the large number serial number of the parameter ibg1 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-8-2-1); Otherwise, check for a parameter name that is the same as the third substring, and enter (2-8-2-1); (2-8-2-1): If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinates, extract the serial number cmpsid1; if the data type does not match, report an error and exit; (2-8-3): Read the content of the fourth substring, set the large number serial number of the parameter ibg2 = 0. If the substring form is a.x, a.y, or a.z, set ibg1 to 0, 1, 2 respectively, and check whether there is a parameter name in the parameter structure array cmps that is the same as a, then enter (2-8-3-1); Otherwise, check for a parameter name that is the same as the fourth substring, and enter (2-8-3-1); (2-8-3-1) If there is one and the data type is 256-bit unsigned integer or elliptic curve coordinates, extract the serial number cmpsid2; if the data type does not match, report an error and exit; (2-8-4): Read the content of the fifth substring and compare it with the set modulus string. If found, set the modulus iMODEBN, otherwise report an error and exit.

8. A fast deployment implementation system for national cryptography algorithms based on dynamic assembly, characterized in that, Including: A disassembling module, which is configured to: obtain a target algorithm to be deployed; Disassemble the target algorithm to be deployed to obtain a number of cryptographic components; combine the cryptographic components into a component sequence text according to the logical order of the target algorithm to be deployed; A deployment module, which is configured to: process the component sequence text to obtain the calculation result of the target algorithm to be deployed; If the target algorithm performs an encryption operation, the obtained calculation result is the ciphertext corresponding to the plaintext; If the target algorithm performs a decryption operation, the obtained calculation result is the plaintext corresponding to the ciphertext; If the target algorithm performs a random number generation operation, the calculation result obtained is the generated random number; An initialization sub-module, which is configured to: initialize the state of the target algorithm to be deployed; A reading sub-module, which is configured to: read the component sequence text byte by byte and perform corresponding processing according to the read characters; An output sub-module, which is configured to: identify the password components of the target algorithm to be deployed, read the parameters, perform corresponding operations, clear the temporary string after completion, output the final string if the end position of the component sequence text is reached, and return to the reading sub-module if the end position of the component sequence text is not reached.

9. An electronic device, characterized in that it includes: A memory for non-temporarily storing computer-readable instructions; And A processor for running the computer-readable instructions, wherein, when the computer-readable instructions are run by the processor, the method described in any one of claims 1-7 above is executed.

10. A storage medium, characterized in that, Non-temporarily storing computer-readable instructions, wherein when the non-temporary computer-readable instructions are executed by a computer, the method described in any one of claims 1-7 is executed.