Optimization method and system based on improved AES algorithm and ECC algorithm

By improving the combination of the AES algorithm and the ECC algorithm, adjusting the S-box affine transformation period and iterative output period, generating key pairs, and verifying through digital signatures, the problems of the traditional AES algorithm being easily cracked and lacking data integrity are solved, achieving higher security and data transmission reliability.

CN120658373APending Publication Date: 2025-09-16BEIJING INSPUR CLOUD COMPUTING CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510691948.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

The traditional AES algorithm has a fixed initial key that is easy to crack, a fixed key space that is vulnerable to exhaustive attacks, and lacks data integrity and message authentication mechanisms.

Method used

The improved AES algorithm is used to adjust the S-box affine transformation period and iterative output period, and the ECC algorithm is combined to generate a key pair. The digital signature is used to ensure data integrity and authenticate the message source. The elliptic curve parameter P-192 and the optimized point multiplication algorithm are used for encryption processing.

Benefits of technology

It improves the security and efficiency of the AES algorithm, enhances the randomness and unpredictability of the key, and ensures the integrity and confidentiality of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658373A_ABST
    Figure CN120658373A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of software application, in particular to an optimization method and system based on an improved AES algorithm and an ECC algorithm, and the method comprises the following steps: selecting an elliptic curve parameter P-192 recommended by an NIST, the finite field being GF (p), and using the elliptic curve parameter P-192 and the finite field being GF (p) for subsequent ECC algorithm related calculation; the AES algorithm is transformed, specifically, the affine transformation period of an S box is adjusted to be 16, the iteration output period is adjusted to be 256, and an affine pair with the minimum strict avalanche effect distance is selected from multiple obtained results to construct the S box; the method has the beneficial effects that the space capacity is increased by increasing the S box affine transformation period, improving the security of the AES algorithm, adjusting the iteration output period, increasing the efficiency of AES encryption by strictly selecting the affine pair with the minimum avalanche effect distance, improving the security of AES encryption by increasing the ECC encryption of the secret key, and improving the security of the AES encryption by increasing the ECC digital signature verification. And the data integrity is ensured.
Need to check novelty before this filing date? Find Prior Art

Claims

1. An optimization method based on an improved AES algorithm and an ECC algorithm, characterized by: The following steps are involved: (1) Select the elliptic curve parameters P-192 recommended by NIST, and the finite field is GF(p) for subsequent ECC algorithm related calculations; (2) The AES algorithm is modified by adjusting the affine transformation period of the S-box to 16 and the iterative output period to 256, and selecting the affine pair with the smallest strict avalanche effect distance from the multiple results obtained to construct the S-box; (3) Use the ECC algorithm to generate a key pair, and determine the elliptic curve parameters a, b, and p in the finite field to determine the elliptic curve E p (a, b), select a base point G(x, y), whose order is a large prime number n and satisfies nG = 0, and determine the integer K s ∈[1, n-1], in K p ∈E p (a, b) conditions, satisfying the equation K p =K s G, thereby obtaining a matching key pair (K s , K p ); (4) Use the ECC algorithm to encrypt the AES key. The sender selects a random integer r (r < n), and encodes the AES key K a into a point P p (a, b) on E m (x, y), calculate C1 = rG, C2 = M + rK Bp (K Bp (which is the public key of the receiver)), and send the binary tuple (C1, C2) to the receiver; (5) After receiving the binary (C1, C2), the receiver calculates C2-K Bs C1=P m +rK Bp -K Bs rG=P m +rK Bs G-rGK Bs =P m Get a point P m (K Bs is the recipient's private key), and then use the ECC decryption method to decrypt P m Get the AES key K a ; (6) Generate a digital signature. Take any integer k∈[1,n-1]. According to kG=(x1,y1) and x1 is an integer, calculate r=x1modn. If r=0, reselect k and use the SHA-1 hash function to calculate the hash value e=SHA(m) of the message m sent by the sender. Calculate s=k-1(e+K as r)modn(K as is the private key of the sender’s signature), if s=0, reselect k, and finally send the message m and signature (r, s); (7) Verify the digital signature, verify whether (r, s) satisfies r∈[1, n-1], s∈[1, n-1], calculate e=SHA(m), w=s -1 modn, u1=ewmodn, u2=rwmodn, U=u1G+u2K ap (K ap is the sender's public key), if U=0, verification fails, if U≠0, calculate v=x2modn, if v=r, verification succeeds, if v≠r, verification fails.

2. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 1, characterized in that: In the process of modifying the AES algorithm in step (2), a specific algorithm is used to screen out the affine pair with the smallest strict avalanche effect distance from multiple affine pair candidate results. The specific screening method is: For each candidate affine pair, calculate its strict avalanche distance metric, which quantitatively evaluates the degree of change in output data when the input data changes slightly. Rank all affine pair candidate results by strict avalanche distance metric; The affine pair with the smallest strict avalanche effect distance index is selected to construct the S-box of the modified AES algorithm.

3. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 2, characterized in that: In the process of generating a key pair using the ECC algorithm in step (3), the determination of the elliptic curve parameters a, b, and p follows the following rules: Parameters a and b satisfy the elliptic curve equation y 2 =x 3 +ax+b(modp), and the equation has an appropriate number of point sets over the finite field GF(p) to meet the encryption security requirements; The selection of the base point G(x, y) must ensure that its order n is a large prime number and that it is on the elliptic curve E p (a, b) has a higher discrete logarithm calculation difficulty to enhance the security of the key pair; Integer K s The selection of n adopts a random number generation algorithm to ensure that it is evenly distributed in the interval [1, n-1] to ensure the randomness and unpredictability of the key pair.

4. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 3, characterized in that: In step (4) AES key encryption process, the AES key Ka is encoded into E p (a, b) point P m The specific encoding method of (x, y) is: AES key K is encoded using a specific algorithm a The binary representation of is converted to the elliptic curve E p The point coordinates (x, y) on (a, b), the encoding algorithm must ensure that the encoding process is reversible, that is, it can be obtained from the encoded point P m (x, y) uniquely recovers the original AES key K a ; In the calculation of C1 = rG and C2 = M + rK Bp When performing the calculation, the optimized elliptic curve point multiplication algorithm and point addition algorithm are used to improve the calculation efficiency and reduce resource consumption while ensuring the accuracy of the calculation results.

5. The optimization method based on the improved AES algorithm and ECC algorithm according to claim 4, characterized in that: In the process of generating the digital signature in step (6), the integer k is selected using a secure random number generator to ensure that it is randomly distributed and unpredictable within the interval [1, n-1]; In the calculation of r = x1modn and s = k-1(e+K a When sr)modn, an efficient modular operation algorithm is used to reduce calculation time and improve calculation efficiency; When sending the message m and signature (r, s), a secure and reliable communication protocol is used to ensure the integrity and confidentiality of the message and signature during transmission to prevent them from being tampered with or stolen.

6. A system for the optimization method based on the improved AES algorithm and ECC algorithm according to claim 5, characterized in that: include: The parameter selection module is used to select the elliptic curve parameters P-192 recommended by NIST, with the finite field being GF(p), for use in subsequent ECC algorithm-related calculations; AES algorithm modification module, used to modify the AES algorithm, adjust the S-box affine transformation period to 16, the iterative output period to 256, and select the affine pair with the smallest strict avalanche effect distance from multiple results to construct the S-box; The ECC key pair generation module is used to generate a key pair using the ECC algorithm and determine the elliptic curve parameters a, b and p in the finite field to determine the elliptic curve E p (a, b), select a base point G(x, y), whose order is a large prime number n and satisfies nG = 0, and determine the integer K s ∈[1, n-1], in K p ∈E p (a, b) conditions, satisfying the equation K p =K s G, thereby obtaining a matching key pair (K s , K p ); The AES key encryption module is used to encrypt the AES key using the ECC algorithm. The sender selects a random integer r (r < n) and encodes the AES key K a into a point P p (a, b) on E m (x, y), calculates C1 = rG, C2 = M + rK Bp (where K Bp is the public key of the receiver), and sends the binary tuple (C1, C2) to the receiver; AES key decryption module, used by the receiver to receive the binary (C1, C2) and calculate C2-K Bs C1=P m +rK Bp -K Bs rG=P m +rK Bs G-rGK Bs =P m Get a point P m (K Bs is the recipient's private key), and then use the ECC decryption method to decrypt P m Get the AES key K a ; The digital signature generation module is used to generate a digital signature. An integer k∈[1, n-1] is randomly selected. According to kG=(x1, y1) and x1 is an integer, r=x1modn is calculated. If r=0, k is reselected and the hash value e=SHA(m) of the message m sent by the sender is calculated using the SHA-1 of the Hash function. s=k-1(e+K as r)modn(K as is the private key of the sender’s signature), if s=0, reselect k, and finally send the message m and signature (r, s); Digital signature verification module, used to verify the digital signature, verify whether (r, s) satisfies r∈[1, n-1], s∈[1, n-1], calculate e=SHA(m), w=s -1 modn, u1=ewmodn, u2=rwmodn, U=u1G+u2K ap (K ap is the sender's public key), if U=0, verification fails, if U≠0, calculate v=x2modn, if v=r, verification succeeds, if v≠r, verification fails.

7. A system according to claim 6, characterized in that: In the AES algorithm modification module, the process of selecting the affine pair with the smallest strict avalanche effect distance includes: For each candidate affine pair, the strict avalanche distance metric is calculated based on the degree of change in the output data when the input data changes slightly. Rank all affine pair candidate results by strict avalanche distance metric; The affine pair with the smallest strict avalanche effect distance index is selected to construct the S-box of the modified AES algorithm.

8. A system according to claim 7, characterized in that: In the ECC key pair generation module, the elliptic curve parameters a, b, and p are determined according to the following rules: Parameters a and b satisfy the elliptic curve equation y 2 =x 3 +ax+b(modp), and the equation has an appropriate number of point sets over the finite field GF(p) to meet the encryption security requirements; The selection of the base point G(x, y) must ensure that its order n is a large prime number and that it is on the elliptic curve E p (a, b) has a higher discrete logarithm calculation difficulty to enhance the security of the key pair; Integer K s The selection of n adopts a random number generation algorithm to ensure that it is evenly distributed in the interval [1, n-1] to ensure the randomness and unpredictability of the key pair.

9. A system according to claim 8, characterized in that: In the AES key encryption module, the AES key K a Encoded to E p (a, b) point P m The specific form of (x, y) is: AES key K is encoded using a specific algorithm a The binary representation of is converted to the elliptic curve E p The point coordinates (x, y) on (a, b), the encoding algorithm must ensure that the encoding process is reversible, that is, it can be obtained from the encoded point P m (x, y) uniquely recovers the original AES key K a ; In the calculation of C1 = rG and C2 = M + rK Bp When performing the calculation, the optimized elliptic curve point multiplication algorithm and point addition algorithm are used to improve the calculation efficiency and reduce resource consumption while ensuring the accuracy of the calculation results.

10. A system according to claim 9, characterized in that: In the digital signature generation module, the integer k is selected using a secure random number generator to ensure that it is randomly distributed and unpredictable in the interval [1, n-1]. In the calculation of r = x1modn and s = k-1(e+K a When sr)modn, an efficient modular operation algorithm is used to reduce calculation time and improve calculation efficiency; When sending the message m and signature (r, s), a secure and reliable communication protocol is used to ensure the integrity and confidentiality of the message and signature during transmission to prevent tampering or theft; The digital signature verification module uses a verification algorithm corresponding to the digital signature generation module to verify the received message and signature to ensure the integrity of the message and the reliability of the source.

Citation Information

Patent Citations

  • Elliptic curve digital signature method

    CN108667621A

  • Electric power data privacy communication method based on hybrid encryption algorithm

    CN112511304A

  • Using a secret generator in an elliptic curve cryptography (ECC) digital signature scheme

    US9800411B1