SM4-based efficient authentication encryption method

By improving the authentication and encryption method of the SM4 algorithm, combining the ASCON framework and sponge structure, an efficient and secure authentication and encryption algorithm is designed, which solves the problems of insufficient security and efficiency in the existing technology, and achieves rapid encryption and attack resistance.

CN120602074APending Publication Date: 2025-09-05INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Patent Information

Application Number
CN202510709063.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing SM4-based authentication encryption methods have shortcomings in terms of security and efficiency, and it is difficult to meet the needs of efficiency and security at the same time.

Method used

Using the ASCON authentication encryption framework combined with the SM4 algorithm function design, a new and efficient authentication encryption method is designed by improving the permutation function, including initialization, encryption and decryption steps, and using the sponge structure to enhance security.

Benefits of technology

It achieves good security and efficiency, has strong resistance to differential attacks, fast running speed, is compatible with domestic passwords, and is suitable for a variety of scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602074A_ABST
    Figure CN120602074A_ABST
Patent Text Reader

Abstract

The invention discloses an efficient authentication encryption method based on SM4. The method comprises the following steps of: 1) initializing and generating an initial vector IV with the length of 128 bits, a secret key K of a national secret SM4 algorithm, a random number N with the length of 128 bits and associated data AD; 2) setting the length l of state updating data in the sponge structure to be 128 bits; 3) designing permutation operation # imgabs0 # 4 based on SM4 rounds of functions, generating S = IVKN in an authentication stage, sequentially executing # imgabs1 # to divide the associated data AD into a plurality of 128-bit data blocks, and performing round transformation on S to obtain a latest state S of fused associated data information; encrypting the plaintext M based on the state S and the key K to obtain a ciphertext C and an authentication tag T; and 5) completing decryption verification in a decryption stage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security and relates to an efficient authentication and encryption method based on SM4. Background Art

[0002] The SM4 algorithm is a block cipher with a block and key length of 128 bits. The core process of the SM4 algorithm is divided into the following three steps:

[0003] 1. Key expansion: The initial master key is transformed into 32 32-bit round keys through multiple rounds of nonlinear transformations;

[0004] 2. Encryption: The plaintext is a 128-bit data block, and 32 rounds of encryption are used to generate the corresponding 128-bit ciphertext;

[0005] 3. Decryption: The ciphertext is decrypted in reverse order using the round key and iterated through 32 rounds to restore the plaintext information.

[0006] The sponge structure is an efficient cryptographic design framework. Its core idea is to "absorb" input data and "squeeze" output results, and combine the permutation function to confuse the internal state to achieve efficient and secure hashing. The hash function based on the sponge structure uses the parameter "capacity c" to ensure anti-collision and anti-image attacks. Theoretically, its security strength is min(2 c / 2 ,2 n ), where n represents the output length of the hash function.

[0007] ASCON is a lightweight encryption algorithm based on the Substitution-Permutation Network (SPN) structure. Its authenticated encryption framework is implemented based on the sponge structure and can be divided into the following main steps: initialization, processing associated data, encrypting plaintext, and generating authenticated encryption tags. Security is guaranteed by modifying the parameter "capacity c". Theoretically, its security strength is 2 c / 2 In order to improve the existing authenticated encryption method based on SM4, the present invention is based on the ASCON authenticated encryption framework and obtains a new efficient authenticated encryption algorithm by replacing the permutation function with low depth and fast encryption speed. Summary of the Invention

[0008] In view of the problems existing in the prior art, the purpose of the present invention is to provide an efficient authentication encryption method based on SM4. The present invention is based on the ASCON authentication encryption framework and the SM4 algorithm round function design. The design mainly considers the authentication encryption and decryption steps of ASCON. The permutation function and its security requirements.

[0009] The technical solution of the present invention is:

[0010] An efficient authentication encryption method based on SM4, comprising the following steps:

[0011] 1) Initialize and generate a 128-bit initial vector IV, the key K of the national secret SM4 algorithm, a 128-bit random number N, and associated data AD;

[0012] 2) Set the state update data length l in the sponge structure to 128 bits and the security parameter length c in the sponge structure to 256 bits; set p a The number of SM4 algorithm rounds used in the permutation is a=15, p b The number of rounds of the SM4 algorithm used in the permutation is b = 10, and the intermediate state is 384 bits; the plaintext M is grouped, and each group is 128 bits long; the linear diffusion transformation L is defined as (x0||x1||x2)<<<i means that the 48 8-bit word vectors after the concatenation of x0, x1, and x2 are cyclically shifted to the left by i positions;

[0013] 3) Design permutation operation based on SM4 wheel function x0, x1, x2 are all 128-bit vectors;

[0014]

[0015] 4) Authentication and encryption phase executes 41) to 44):

[0016] 41) Generate the initial state S = IV||K||N through the initial vector IV, key K, and random number N, and execute The replaced state S is then XORed with the key K to update the state S←

[0017]

[0018] 42) Divide the associated data AD into multiple 128-bit data blocks. If the last data block is less than 128 bits, fill it with 128 bits. Then, perform the following round transformation on the final state S obtained in 41: First, for each data block AD i and the first l bits of state S l , perform the calculation Then update the state S When all rounds of operations are completed, the obtained state S is compared with the preset fixed tag data (0 383 ||1) Perform XOR to obtain the latest state S of the fused associated data information;

[0019] 43) Pad and split the plaintext M into t 128-bit plaintext blocks, i.e., M = M1||M2||…||M t; Process the first t-1 plaintext blocks in sequence, for the i-th plaintext block M in the first t-1 plaintext blocks i :First, M i Encryption generates ciphertext blocks Using ciphertext block C i Replace the first 128 bits of state S and update the state For the last plaintext block M t use And update Get the complete ciphertext C=C1||C2||…||C t ;

[0020] 44) State S is XORed with key K to update state implement XOR the updated state S with the key K to obtain the authentication tag Finally, the ciphertext C and authentication tag T are obtained;

[0021] 5) Authentication and decryption phase executes 51) to 54):

[0022] 51) Generate the initial state S = IV||K||N through the initial vector IV, key K, and random number N, and execute After the replacement, the state S is XORed with the key K to update the state

[0023] 52) Then perform the following round transformation on the final state S obtained in 51): First, for each data block AD i and the first l bits of state S l , perform the calculation Then update the state S

[0024] When all rounds of operations are completed, the obtained state S is compared with the preset fixed tag data (0 383 ||1) Perform XOR to obtain the latest state S of the fused associated data information;

[0025] 53) Split the ciphertext data C into t 128-bit data, that is, C = C1||C2||…||C t ; For each plaintext block C in the first t-1 plaintext blocks i Decrypted Execute S l ←C t and update status

[0026] Restore the first t-1 plaintext blocks in sequence; for C t use And call Remove plaintext block M t Padding data at the end to obtain the complete ciphertext

[0027] M=M1||M2||…||M t ;

[0028] 54) State S is XORed with key K to update state implement Then XOR the updated state S with the key K to get the authentication tag If T * = T, then it is determined that the ciphertext C and the associated data AD have not been tampered with, otherwise T * ≠T, tampering occurs and authentication fails.

[0029] Furthermore, the permutation operation p a ,p b The general formula is Nonlinear layer express Combine with L k times; SM4 r (x) represents the r-round SM4 algorithm.

[0030] Furthermore, the number of composite times k=3, and the number of rounds r=10 or 15.

[0031] Furthermore, the key K is 128 bits long, and the associated data AD is additional information that does not need to be encrypted but requires integrity protection in the authentication encryption algorithm.

[0032] Furthermore, a random number generator is used to generate a vector with a length of 128 bits as the initial vector IV.

[0033] A server, characterized in that it includes a memory and a processor, the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the above method.

[0034] A computer-readable storage medium stores a computer program thereon, wherein the computer program implements the above method when executed by a processor.

[0035] The advantages of the present invention are as follows:

[0036] 1. The present invention has good safety, such as p a The SM4 round function is combined with MDS linear diffusion in the permutation design. It has been verified that the security of 3 rounds of anti-differential attack reaches 2 -410 ,Combined with the ASCON authentication encryption structure, the sponge structure further enhances the security of the algorithm.

[0037] 2. The present invention is efficient and easy to implement, uses the SM4 standard algorithm, has mature software and hardware, has good compatibility with domestic encryption, and can be widely used in related scenarios.

[0038] 3. Compared to other existing patents (publication numbers CN107342865 A / CN111555859 A / CN116366230 A), this invention offers significant performance advantages. Specifically, the proposed efficient authenticated encryption algorithm based on SM4 has a low encryption depth and high encryption speed. During the encryption phase, only three SM4 iterations (10 rounds) are required, resulting in a minimum SM4 depth of 30 rounds, while other solutions require a full SM4 round run each time. Given the same implementation and security strength, the proposed algorithm offers a speed advantage.

[0039] 4. The algorithm proposed in this invention designs a large state permutation based on SM4, which belongs to the underlying cryptographic component and has potential applications in other cryptographic primitives. For example, the p of this algorithm can be a Permutation or p b Permutation is used to construct a sponge-structured hash function, which is more scalable than other patented solutions. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 This is the structural diagram of the basic component sponge.

[0041] Figure 2 This is a flow chart of the efficient authentication encryption algorithm based on SM4.

[0042] Figure 3 This is the flow chart of the efficient authentication and decryption algorithm based on SM4. DETAILED DESCRIPTION

[0043] The present invention will be described in further detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0044] 1. Efficient authentication encryption algorithm initialization security parameters

[0045] a. The random initialization vector (IV) is 128 bits long, the key (K) is 128 bits, the random number (N) is 128 bits, and the associated data (AD) is used. The IV is a vector of a specified length generated by a random number generator and is unpredictable. The IV contains no valid information to ensure that encrypted plaintexts of the same type will result in different ciphertexts, thus resisting chosen-plaintext attacks. Associated data (AD) is additional information that does not require encryption but requires integrity protection in authenticated encryption algorithms, such as the sender ID, receiver ID, timestamp, and message sequence number.

[0046] b. The state update data length l in the sponge structure is 128 bits, and the data security length c is 256 bits. Length c is the security parameter length in the sponge structure, and the number of bits in the intermediate state is determined by l + c = 128 + 256 = 384 bits.

[0047] cp a The permutation uses SM4 round number a=15, p b The permutation uses SM4 round number b=10, and the intermediate state is 384 bits.

[0048] d. Group the plaintext M, each group is 128 bits long, and the key K is 128 bits long using the SM4 algorithm. r (x) represents the r-round SM4 algorithm.

[0049] e. The linear diffusion transform L is defined as

[0050] f. Based on SM4 design x0, x1, and x2 are all 128-bit vectors. The data in the SM4 round function lookup table are all 128-bit vectors, totaling 384 bits of initial input, i.e., the 384-bit state vector in step b.

[0051] Based on the design of SM4 wheel function a 、p b The operation is as follows:

[0052]

[0053] 2. Authentication and encryption process

[0054] a. State initialization: Generate the initial state S = IV||K||N through the initial vector IV, key K, and random number N, and execute The replaced state S is then XORed with the key K to update the state

[0055] b. Associated data processing: Fill and split the associated data AD into multiple 128-bit data, ie AD = AD1 || AD2 || ... AD m , and the last block is padded with "10" to 128 bits. For the state S obtained in step a, the following round transformation is performed: First, for each data block AD i and the first l bits of state S l , perform the calculation Then perform the state update function on state S When all rounds of operations are completed, the data is compared with the pre-set fixed tag data (0 383||1) is XORed to obtain the updated latest state S that integrates the associated data information. Among them, the fixed tag data is pre-set to prevent AD m information leak.

[0056] c. Message encryption stage: The plaintext data M is padded and divided into multiple 128-bit data, that is, M = M1||M2||…||M t For each block M in the first t-1 plaintext blocks i Encrypt and generate ciphertext blocks Using ciphertext block C i Replace the first 128 bits of state S and execute the intermediate round function to update the state Process the first t-1 plaintext blocks in sequence; for the last plaintext block M t use And update S r ←C t , Get the complete ciphertext C=C1||C2||…||C t .

[0057] d. Authentication tag generation phase: state S is XORed with key K to update state implement The updated state S is then XORed with the key K to obtain the authentication tag Finally, the ciphertext C and authentication tag T are obtained, see Figure 2 .

[0058] Authentication and decryption process

[0059] a. State initialization: Consistent with the encryption phase, the initial state S = IV||K||N is generated by the initial vector IV, key K, and random number N, and then executed. After the replacement, the state S is XORed with the key K to update the state

[0060] b. Associated data processing: Consistent with the encryption stage, the associated data AD is padded and divided into multiple 128-bit data blocks, i.e. AD = AD1||AD2||…AD m , the last data block is padded to 128 bits using the "10" method. i and the first l bits of state S l , perform the calculation Execute the intermediate round function to update the status Finally, with the fixed label data (0 383 ||1) Perform an XOR. Note that the operation at this stage is consistent with step b in the authenticated encryption process.

[0061] c. Message decryption phase: Split the ciphertext data C into multiple 128-bit data, i.e. C = C1||C2||…||C t For each plaintext block C in the first t-1 plaintext blocks i Decryption, execution Execute S l ←C t And the intermediate round function updates the status Restore the first t-1 plaintext blocks in sequence; for C t use And call Remove the padding at the end of the plaintext, find the first "1" bit from the back to the front, remove the subsequent "0" bits, and obtain the complete ciphertext M=M1||M2||…||M t .

[0062] d. Authentication tag verification phase: state S is XORed with key K to update state implement Then XOR with the key K to get the authentication tag Compared with the accepted authentication tag T, if T * =T, it means that the ciphertext C and the associated data AD have not been tampered with, otherwise T * ≠T, tampering occurs and authentication fails. Figure 3 .

[0063] 3. p based on SM4 wheel function design a ,p b Replacement

[0064] a. Permutation: Let x0, x1, x2 be 128-bit vectors, each represented by 16 8-bit words. Definition The subscript k takes the value of a or b, which means p a ,p b .

[0065] a1. Linear layer (x0||x1||x2)<<<i indicates that the 48 8-bit word vectors formed by the concatenation of x0, x1, and x2 are circularly shifted left by i positions. Let T1, T2, T3, ...., T48 be the 48 8-bit words formed by the concatenation, forming the word vector (T1, T2, T3, ...., T48). Then, circularly shifted left by 1 position, the word vector becomes (T2, T3, T4, ...., T48, T1).

[0066] a2. Non-linear layer express Recombined with L k times.

[0067] b. Recommended parameter settings: In the algorithm parameter settings, the number of compound times k = 3, the number of rounds r = 10 or 15, p a =

[0068] Differential Probabilistic Security Analysis: L is the MDS matrix, so there are at least 4 active SM4s in two consecutive rounds r , so the structure 3 wheels have at least 5 active SM4 r , combined with SM4 analysis, SM4 10 The maximum difference probability is 2 -52 , The maximum difference probability is 2 -5*52 =2 -260 , The maximum difference probability is 2 -5*82 =2 -410 ,satisfy Design security requirements.

[0069] The present invention can be substituted with block encryption techniques similar to the SM4 round function and other authenticated encryption modes, which were initially considered in the design of the present invention. Ultimately, based on the balance between security and efficiency, the SM4 block algorithm and the ASCON authenticated encryption structure were selected.

[0070] 1. The SM4 group round function in this patent may be replaced by other block cipher algorithms, such as AES, PRESENT, and CLEFIA, which may achieve different degrees of optimization in computational efficiency and security.

[0071] 2. The ASCON authentication encryption structure in this patent has the possibility of being replaced. For example, the Duplex structure, OCB mode, GCM mode, COLM mode, etc. can all be used to design authentication encryption algorithms with similar functions in terms of computational efficiency and security.

[0072] In summary, this patent has conducted technical tests on the above-mentioned alternative technologies and finally selected the optimal SM4 round function and ASCON authentication encryption structure.

[0073] While specific embodiments of the present invention have been disclosed for illustrative purposes, intended to facilitate understanding and implementation of the present invention, those skilled in the art will appreciate that various substitutions, variations, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the disclosure of the preferred embodiments, and the scope of protection claimed in the present invention shall be determined by the scope of the claims.

Claims

1. An efficient authentication and encryption method based on SM4, comprising the following steps: 1) Initialize and generate a 128-bit initial vector IV, the key K of the national secret SM4 algorithm, a 128-bit random number N, and associated data AD; 2) Set the state update data length l in the sponge structure to 128 bits and the security parameter length c in the sponge structure to 256 bits; set p a The number of SM4 algorithm rounds used in the permutation is a=15, p b The number of rounds of the SM4 algorithm used in the permutation is b = 10, and the intermediate state is 384 bits; the plaintext M is grouped, and each group is 128 bits long; the linear diffusion transformation L is defined as The 48 8-bit word vectors after the concatenation of x0, x1, and x2 are circularly shifted to the left by i positions; 3) Design permutation operation based on SM4 wheel function x0, x1, x2 are all 128-bit vectors; 4) Authentication and encryption phase executes 41) to 44): 41) Generate the initial state S = IV||K||N through the initial vector IV, key K, and random number N, and execute The replaced state S is then XORed with the key K to update the state 42) Divide the associated data AD into multiple 128-bit data blocks. If the last data block is less than 128 bits, fill it with 128 bits. Then, perform the following round transformation on the final state S obtained in 41: First, for each data block AD i and the first l bits of state S l , perform the calculation Then update the state S When all rounds of operations are completed, the obtained state S is compared with the preset fixed tag data (0 383 ||1) Perform XOR to obtain the latest state S of the fused associated data information; 43) Pad and split the plaintext M into t 128-bit plaintext blocks, i.e., M = M1||M2||…||M t ; Process the first t-1 plaintext blocks in sequence, for the i-th plaintext block M in the first t-1 plaintext blocks i :First, M i Encryption generates ciphertext blocks Using ciphertext block C i Replace the first 128 bits of state S and update the state For the last plaintext block M t use And update S r ←C t , Get the complete ciphertext C=C1||C2||…||C t ; 44) State S is XORed with key K to update state implement XOR the updated state S with the key K to obtain the authentication tag Finally, the ciphertext C and authentication tag T are obtained; 5) Authentication and decryption phase executes 51) to 54): 51) Generate the initial state S = IV||K||N through the initial vector IV, key K, and random number N, and execute After the replacement, the state S is XORed with the key K to update the state 52) Then perform the following round transformation on the final state S obtained in 51): First, for each data block AD i and the first l bits of state S l , perform the calculation Then update the state S When all rounds of operations are completed, the obtained state S is compared with the preset fixed tag data (0 383 ||1) Perform XOR to obtain the latest state S of the fused associated data information; 53) Split the ciphertext data C into t 128-bit data, that is, C = C1||C2||…||C t ; For each plaintext block C in the first t-1 plaintext blocks i Decrypted Execute S l ←C t and update status Restore the first t-1 plaintext blocks in sequence; for C t use And call S l ←C t , Remove plaintext block M t Padding data at the end to obtain the complete ciphertext M=M1||M2||…||M t ; 54) State S is XORed with key K to update state implement Then XOR the updated state S with the key K to get the authentication tag If T * = T, then it is determined that the ciphertext C and the associated data AD have not been tampered with, otherwise T * ≠T, tampering occurs and authentication fails.

2. The method according to claim 1, characterized in that Permutation operation p a ,p b The general formula is Nonlinear layer express Recombined with L k times; SM4 r (x) represents the r-round SM4 algorithm.

3. The method according to claim 2, characterized in that The number of composites k=3, and the number of rounds r=10 or 15.

4. The method according to claim 1, 2 or 3, characterized in that: The key K is 128 bits long, and the associated data AD is additional information that does not need to be encrypted but requires integrity protection in the authentication encryption algorithm.

5. The method according to claim 1, 2 or 3, characterized in that: A random number generator is used to generate a vector with a length of 128 bits as the initial vector IV.

6. A server, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 5.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Authentication encryption algorithm and decryption algorithm based on SM4

    CN107342865A

  • SM4-GCM algorithm and application in network security protocol

    CN111555859A

  • Circuit architecture of SM4 authentication encryption algorithm and control method

    CN116366230A

Cited By

  • Data transmission method and system for meteorological satellite communication system

    CN121690338A