Optimization method and system based on improved AES algorithm and ECC algorithm
By improving the combination of the AES algorithm and the ECC algorithm, adjusting the S-box affine transformation period and iterative output period, generating key pairs, and verifying through digital signatures, the problems of the traditional AES algorithm being easily cracked and lacking data integrity are solved, achieving higher security and data transmission reliability.
Patent Information
- Application Number
- CN202510691948.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-16
AI Technical Summary
The traditional AES algorithm has a fixed initial key that is easy to crack, a fixed key space that is vulnerable to exhaustive attacks, and lacks data integrity and message authentication mechanisms.
The improved AES algorithm is used to adjust the S-box affine transformation period and iterative output period, and the ECC algorithm is combined to generate a key pair. The digital signature is used to ensure data integrity and authenticate the message source. The elliptic curve parameter P-192 and the optimized point multiplication algorithm are used for encryption processing.
It improves the security and efficiency of the AES algorithm, enhances the randomness and unpredictability of the key, and ensures the integrity and confidentiality of data transmission.
Smart Images

Figure CN120658373A_ABST
Abstract
Claims
1. An optimization method based on an improved AES algorithm and an ECC algorithm, characterized by: The following steps are involved: (1) Select the elliptic curve parameters P-192 recommended by NIST, and the finite field is GF(p) for subsequent ECC algorithm related calculations; (2) The AES algorithm is modified by adjusting the affine transformation period of the S-box to 16 and the iterative output period to 256, and selecting the affine pair with the smallest strict avalanche effect distance from the multiple results obtained to construct the S-box; (3) Use the ECC algorithm to generate a key pair, and determine the elliptic curve parameters a, b, and p in the finite field to determine the elliptic curve E p (a, b), select a base point G(x, y), whose order is a large prime number n and satisfies nG = 0, and determine the integer K s ∈[1, n-1], in K p ∈E p (a, b) conditions, satisfying the equation K p =K s G, thereby obtaining a matching key pair (K s , K p ); (4) Use the ECC algorithm to encrypt the AES key. The sender selects a random integer r (r < n), and encodes the AES key K a into a point P p (a, b) on E m (x, y), calculate C1 = rG, C2 = M + rK Bp (K Bp (which is the public key of the receiver)), and send the binary tuple (C1, C2) to the receiver; (5) After receiving the binary (C1, C2), the receiver calculates C2-K Bs C1=P m +rK Bp -K Bs rG=P m +rK Bs G-rGK Bs =P m Get a point P m (K Bs is the recipient's private key), and then use the ECC decryption method to decrypt P m Get the AES key K a ; (6) Generate a digital signature. Take any integer k∈[1,n-1]. According to kG=(x1,y1) and x1 is an integer, calculate r=x1modn. If r=0, reselect k and use the SHA-1 hash function to calculate the hash value e=SHA(m) of the message m sent by the sender. Calculate s=k-1(e+K as r)modn(K as is the private key of the sender’s signature), if s=0, reselect k, and finally send the message m and signature (r, s); (7) Verify the digital signature, verify whether (r, s) satisfies r∈[1, n-1], s∈[1, n-1], calculate e=SHA(m), w=s -1 modn, u1=ewmodn, u2=rwmodn, U=u1G+u2K ap (K ap is the sender's public key), if U=0, verification fails, if U≠0, calculate v=x2modn, if v=r, verification succeeds, if v≠r, verification fails.
2. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 1, characterized in that: In the process of modifying the AES algorithm in step (2), a specific algorithm is used to screen out the affine pair with the smallest strict avalanche effect distance from multiple affine pair candidate results. The specific screening method is: For each candidate affine pair, calculate its strict avalanche distance metric, which quantitatively evaluates the degree of change in output data when the input data changes slightly. Rank all affine pair candidate results by strict avalanche distance metric; The affine pair with the smallest strict avalanche effect distance index is selected to construct the S-box of the modified AES algorithm.
3. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 2, characterized in that: In the process of generating a key pair using the ECC algorithm in step (3), the determination of the elliptic curve parameters a, b, and p follows the following rules: Parameters a and b satisfy the elliptic curve equation y 2 =x 3 +ax+b(modp), and the equation has an appropriate number of point sets over the finite field GF(p) to meet the encryption security requirements; The selection of the base point G(x, y) must ensure that its order n is a large prime number and that it is on the elliptic curve E p (a, b) has a higher discrete logarithm calculation difficulty to enhance the security of the key pair; Integer K s The selection of n adopts a random number generation algorithm to ensure that it is evenly distributed in the interval [1, n-1] to ensure the randomness and unpredictability of the key pair.
4. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 3, characterized in that: In step (4) AES key encryption process, the AES key Ka is encoded into E p (a, b) point P m The specific encoding method of (x, y) is: AES key K is encoded using a specific algorithm a The binary representation of is converted to the elliptic curve E p The point coordinates (x, y) on (a, b), the encoding algorithm must ensure that the encoding process is reversible, that is, it can be obtained from the encoded point P m (x, y) uniquely recovers the original AES key K a ; In the calculation of C1 = rG and C2 = M + rK Bp When performing the calculation, the optimized elliptic curve point multiplication algorithm and point addition algorithm are used to improve the calculation efficiency and reduce resource consumption while ensuring the accuracy of the calculation results.
5. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 4, characterized in that: In the process of generating the digital signature in step (6), the integer k is selected using a secure random number generator to ensure that it is randomly distributed and unpredictable within the interval [1, n-1]; In the calculation of r = x1modn and s = k-1(e+K a When sr)modn, an efficient modular operation algorithm is used to reduce calculation time and improve calculation efficiency; When sending the message m and signature (r, s), a secure and reliable communication protocol is used to ensure the integrity and confidentiality of the message and signature during transmission to prevent them from being tampered with or stolen.
6. A system for the optimization method based on the improved AES algorithm and ECC algorithm according to claim 5, characterized in that: include: The parameter selection module is used to select the elliptic curve parameters P-192 recommended by NIST, with the finite field being GF(p), for use in subsequent ECC algorithm-related calculations; AES algorithm modification module, used to modify the AES algorithm, adjust the S-box affine transformation period to 16, the iterative output period to 256, and select the affine pair with the smallest strict avalanche effect distance from multiple results to construct the S-box; The ECC key pair generation module is used to generate a key pair using the ECC algorithm and determine the elliptic curve parameters a, b and p in the finite field to determine the elliptic curve E p (a, b), select a base point G(x, y), whose order is a large prime number n and satisfies nG = 0, and determine the integer K s ∈[1, n-1], in K p ∈E p (a, b) conditions, satisfying the equation K p =K s G, thereby obtaining a matching key pair (K s , K p ); The AES key encryption module is used to encrypt the AES key using the ECC algorithm. The sender selects a random integer r (r < n) and encodes the AES key K a into a point P p (a, b) on E m (x, y), calculates C1 = rG, C2 = M + rK Bp (where K Bp is the public key of the receiver), and sends the binary tuple (C1, C2) to the receiver; AES key decryption module, used by the receiver to receive the binary (C1, C2) and calculate C2-K Bs C1=P m +rK Bp -K Bs rG=P m +rK Bs G-rGK Bs =P m Get a point P m (K Bs is the recipient's private key), and then use the ECC decryption method to decrypt P m Get the AES key K a ; The digital signature generation module is used to generate a digital signature. An integer k∈[1, n-1] is randomly selected. According to kG=(x1, y1) and x1 is an integer, r=x1modn is calculated. If r=0, k is reselected and the hash value e=SHA(m) of the message m sent by the sender is calculated using the SHA-1 of the Hash function. s=k-1(e+K as r)modn(K as is the private key of the sender’s signature), if s=0, reselect k, and finally send the message m and signature (r, s); Digital signature verification module, used to verify the digital signature, verify whether (r, s) satisfies r∈[1, n-1], s∈[1, n-1], calculate e=SHA(m), w=s -1 modn, u1=ewmodn, u2=rwmodn, U=u1G+u2K ap (K ap is the sender's public key), if U=0, verification fails, if U≠0, calculate v=x2modn, if v=r, verification succeeds, if v≠r, verification fails.
7. A system according to claim 6, characterized in that: In the AES algorithm modification module, the process of selecting the affine pair with the smallest strict avalanche effect distance includes: For each candidate affine pair, the strict avalanche distance metric is calculated based on the degree of change in the output data when the input data changes slightly. Rank all affine pair candidate results by strict avalanche distance metric; The affine pair with the smallest strict avalanche effect distance index is selected to construct the S-box of the modified AES algorithm.
8. A system according to claim 7, characterized in that: In the ECC key pair generation module, the elliptic curve parameters a, b, and p are determined according to the following rules: Parameters a and b satisfy the elliptic curve equation y 2 =x 3 +ax+b(modp), and the equation has an appropriate number of point sets over the finite field GF(p) to meet the encryption security requirements; The selection of the base point G(x, y) must ensure that its order n is a large prime number and that it is on the elliptic curve E p (a, b) has a higher discrete logarithm calculation difficulty to enhance the security of the key pair; Integer K s The selection of n adopts a random number generation algorithm to ensure that it is evenly distributed in the interval [1, n-1] to ensure the randomness and unpredictability of the key pair.
9. A system according to claim 8, characterized in that: In the AES key encryption module, the AES key K a Encoded to E p (a, b) point P m The specific form of (x, y) is: AES key K is encoded using a specific algorithm a The binary representation of is converted to the elliptic curve E p The point coordinates (x, y) on (a, b), the encoding algorithm must ensure that the encoding process is reversible, that is, it can be obtained from the encoded point P m (x, y) uniquely recovers the original AES key K a ; In the calculation of C1 = rG and C2 = M + rK Bp When performing the calculation, the optimized elliptic curve point multiplication algorithm and point addition algorithm are used to improve the calculation efficiency and reduce resource consumption while ensuring the accuracy of the calculation results.
10. A system according to claim 9, characterized in that: In the digital signature generation module, the integer k is selected using a secure random number generator to ensure that it is randomly distributed and unpredictable in the interval [1, n-1]. In the calculation of r = x1modn and s = k-1(e+K a When sr)modn, an efficient modular operation algorithm is used to reduce calculation time and improve calculation efficiency; When sending the message m and signature (r, s), a secure and reliable communication protocol is used to ensure the integrity and confidentiality of the message and signature during transmission to prevent tampering or theft; The digital signature verification module uses a verification algorithm corresponding to the digital signature generation module to verify the received message and signature to ensure the integrity of the message and the reliability of the source.
Citation Information
Patent Citations
Elliptic curve digital signature method
CN108667621A
Electric power data privacy communication method based on hybrid encryption algorithm
CN112511304A
Using a secret generator in an elliptic curve cryptography (ECC) digital signature scheme
US9800411B1