Authentication encryption method and system with bidirectional linearity
Through an authenticated encryption scheme designed based on block ciphers and linear mixing functions, bidirectional online linearity is achieved in a resource-constrained environment, which solves the problem of balancing lightweight and bidirectional online linearity in existing technologies and provides efficient data confidentiality and integrity protection.
Patent Information
- Application Number
- CN202410286088.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-13
- Publication Date
- 2025-09-16
AI Technical Summary
Existing authenticated encryption schemes have difficulty achieving both lightweightness and bidirectional onlineness in resource-constrained environments, resulting in limited applications in scenarios such as radio frequency identification (RFID) tags, smart cards, secure batteries, and sensor networks.
An authenticated encryption scheme based on block cipher and linear mixing function is adopted. By selecting n-bit block cipher E and block length m, online linearity in encryption and decryption is achieved. It also supports serial implementation in resource-constrained environments, requiring a minimum storage space of only about 1 block.
It is linear in both encryption and decryption directions, providing confidentiality protection with n/2 bits of security strength and integrity protection with nm bits of security strength. It is suitable for resource-constrained environments and can achieve efficient computing in parallel in a multi-processor environment.
Smart Images

Figure CN120658412A_ABST
Abstract
Description
Technical Field
[0001] This invention, belonging to the field of cryptography, discloses an authenticated encryption scheme based on a block cipher and a linear mixing function. It exhibits bidirectional linearity, meaning that after obtaining t inputs, the tth output can be calculated in both the encryption and decryption directions. Furthermore, the scheme's parameter settings are flexible and variable, allowing the scheme's operational efficiency and security to be adjusted by selecting the length of the message blocks processed by each block cipher call. Background Art
[0002] Authenticated encryption schemes can simultaneously protect data confidentiality and integrity, while also authenticating the origin of the data. They are widely used in security protocols, digital certificates, and entity authentication. Since the 2009 promulgation of the international standard ISO / IEC 19772, "Information Technology Security Techniques - Authenticated Encryption," the design of authenticated encryption schemes has gradually diversified. A variety of scheme features, such as those with linked data, online linearity, resistance to ephemeral value reuse, and support for intermediate tags, have been proposed and garnered significant attention.
[0003] Online linearity is a key property of cryptographic algorithms. Data is fed into the algorithm unit by unit, and the algorithm outputs it unit by unit. In other words, after receiving t units of input data, the tth unit of output data can be output. Online linearity enables the algorithm to output data units in real time, without having to wait for all input data to be received or all output data to be generated. This makes it suitable for real-time communication. Furthermore, the algorithm requires little storage space, making it lightweight and suitable for resource-constrained environments.
[0004] The concept of online authenticated encryption was first formally defined in 2012. However, compared to online encryption, early online authenticated encryption schemes only had online linearity in the encryption direction because they usually had to wait for verification to complete before outputting the decrypted plaintext. This also led to the release of unverified plaintext (RUP) problem, which is the security issue that may arise from outputting the decrypted plaintext before verification is complete. It was not until 2015 that the concept of mutual authenticated encryption (OAE2) was proposed, and this problem was solved. In a mutual authenticated encryption scheme, the basic unit of input data is expanded from fixed packets to variable blocks. The encryption or decryption of each block is only related to the previous block, thus achieving online linearity in both encryption and decryption directions.
[0005] While the reduced storage space required for implementation is a significant performance advantage of linearity, and the lightweight nature of the algorithm has enormous application demand and potential in areas such as radio frequency identification (RFID) tags, smart cards, secure batteries, and sensor networks, there is currently a lack of authenticated encryption schemes that combine lightweightness with bidirectional linearity. To demonstrate this, the following describes existing authenticated encryption schemes or construction methods that offer linearity:
[0006] McOE, COPA, POET, ElmD, Marble, and other authenticated encryption schemes are linear. However, with the exception of ElmD, which uses intermediate labeling to achieve bidirectional linearity with large blocks when the storage space is large enough (no less than three packets), the other algorithms are only linear in the encryption direction.
[0007] Second, the CHAIN method can convert authenticated encryption schemes that resist ephemeral value reuse (such as SIV) into a two-way online authenticated encryption scheme. This method divides the input data into several blocks, encrypts / decrypts each block using the original authenticated encryption scheme, and uses the XOR value of the processed plaintext and ciphertext as the state chain value. Since the processing of each block requires calling the entire original authenticated encryption scheme, this method requires a storage space of at least 2 blocks.
[0008] Third, the STREAM method can convert authenticated encryption schemes that use temporary values (such as OCB) into a two-way online authenticated encryption scheme. This method is similar to CHAIN. Each block of processing requires the complete original authenticated encryption scheme to be called. The difference is that the temporary value is combined with a counter to replace the original state, thus achieving a parallel implementation similar to the counter mode. The storage space required is not less than 2 blocks.
[0009] 4. dOAE-secure authenticated encryption scheme is a theoretical concept of online authenticated encryption that can maintain security after additional restrictions are imposed on data when temporary values are reused. It is between the security of online authenticated encryption schemes where temporary values cannot be reused and reusable, and lacks application scenarios and scheme examples.
[0010] It can be seen from this that there is currently no authenticated encryption scheme designed specifically for bidirectional online operations, and the storage space required for implementation is no less than 2 groups, which greatly limits the application of such schemes in resource-constrained environments. It is of great significance to construct an authenticated encryption scheme that takes into account both lightweight and bidirectional online operations. Summary of the Invention
[0011] The purpose of the present invention is to construct an authenticated encryption scheme that takes into account both lightness and bidirectional linearity. The scheme is an authenticated encryption scheme of a working mode class based on block cipher and linear mixing function design.
[0012] The technical solutions adopted in the present invention are as follows.
[0013] An authenticated encryption method with bidirectional onlineness comprises the following steps:
[0014] The participants jointly select an n-bit block cipher E, key K, and block length m;
[0015] The sender executes the encryption scheme, taking the key K, the temporary value N and the plaintext M as input, and outputs the ciphertext C and the tag T;
[0016] The receiver executes the decryption scheme, taking the key K, the temporary value N and the ciphertext C as input, verifies the correctness of the ciphertext C and outputs the correctly decrypted plaintext M.
[0017] Furthermore, the present invention includes scheme setting, encryption scheme and decryption scheme, which are described in detail as follows.
[0018] 1. Program Settings
[0019] The participants in the authenticated encryption scheme include the sender and the receiver.
[0020] The participants jointly select a block cipher algorithm E and determine a shared key K based on the requirements of the selected algorithm E, where the block length of the algorithm E is n bits and the key length is k bits. The block cipher key K is also the scheme key. In the scheme, E K Denotes block cipher encryption with K as the key, D K Denotes block cipher decryption with K as the key.
[0021] In addition, the participants need to agree on a parameter m, which is the length of the plaintext or ciphertext block processed each time the block cipher is called. m is required to be a positive integer not greater than n.
[0022] The scheme uses bit-level logical XOR operation (symbol is If A and B are bit strings of equal length, represents the bit string formed by the bit-level logical exclusive OR of A and B), and the multiplication operation over the finite field (symbolized by ·, the operation is related to the selected primitive polynomial).
[0023] 2. Encryption Scheme
[0024] The sender uses the key K, temporary value N and plaintext M as the input of the scheme, and calculates the output ciphertext C and tag T. Among them, the temporary value N is an n-bit bit string, and the ciphertext length |C| is related to the plaintext length |M|, which is expressed as Among them, |A| represents the number of bits in the bit string A, Represents the smallest integer not less than the value B.
[0025] The process is as follows:
[0026] 1) Initialization phase
[0027] Block cipher E K Encrypt the temporary value N to obtain the initial state S0, that is, S0 = E K (N); Divide the plaintext M into several m-bit blocks, denoted as M1,...,Ml , where |M i |=m(i=1,...,l-1) and |M l |≤m.
[0028] 2) Iterative encryption phase
[0029] Encryption is performed block by block in the order of plaintext blocks. Specifically, for the i-th plaintext block M i (i=1,...,l-2), M i and the nm bit representation of ordinal number i (denoted as [i] n-m ) are connected to obtain M i ||[i] n-m ; Then change the state chain value S i-1 With M i ||[i] n-m The linear mixing function ρ is inputted together to obtain a set of 2n-bit outputs (S i ,X i ),in ) is the updated state chain value, is the input of the block cipher; K Encryption X i Get ciphertext group C i And output, where |C i |=n; iterate the above steps until there are only two plaintext blocks M left l-1 and M l .
[0030] 3) Final encryption stage
[0031] For the second to last plaintext block M l-1 , M l-1 Connected with the nm bit representation of the ordinal number l-1, we get M l -1||[l-1] n-m ; Then change the state chain value S l-1 With M l -1||[l-1] n-m Common input linear mixing function ρ, then only need to calculate ); with block cipher E K Encryption X l-1 Get a group C * ; C * Divide into two parts, first intercept C * The leftmost n-m+|M l | bits constitute the l-1th block of ciphertext C l-1 And output, then the remaining part (ie C * The rightmost m-|M l| bits) is denoted as Z;
[0032] The last plaintext block M l Connect it with Z and fill nm "0" on the right to get M l ||Z||[0] n-m ; Set the status chain value S l-2 With M l ||Z||[0] n-m Common input linear mixing function ρ, now only need to calculate Block cipher E K Encrypted plaintext length |M|, output and X * XOR, the result is recorded as X l ; Finally, block cipher E K Encryption X l Get ciphertext group C l And output.
[0033] 2. Decryption Solution
[0034] The decryption scheme is the inverse of the encryption scheme, requiring verification of the ciphertext's correctness and output of the correctly decrypted plaintext. The receiver uses the key K, the temporary value N, and the ciphertext C as inputs, and calculates the output plaintext M or the error symbol ⊥ (indicating verification failure).
[0035] The process is as follows:
[0036] 1) Initialization phase
[0037] Block cipher E K Encrypt the temporary value N to obtain the initial state S0; divide the ciphertext C into several n-bit groups, denoted as C1,...,C l , where |C i |=n(i=1,...,l-2,l) and |C l-1 |≤n.
[0038] 2) Iterative decryption phase
[0039] For the i-th ciphertext block C i , using block cipher D K Decrypt C i Get X i ; Set the status chain value S i-1 With X i Common input linear mixing function ρ' to obtain a set of 2n-bit output in is the updated state chain value; intercept Check if the rightmost nm bits of [i] are equal to [i] n-mIf it is, the verification is successful and the decryption process continues, otherwise the symbol ⊥ is output and the decryption stops; if the verification is successful, intercept The leftmost m bits of the decrypted plaintext block M i And output; iterate the above steps until the last two ciphertext blocks C are left l-1 and C l Among them, the linear mixing function ρ and the function ρ' are a set of binary operations, but they are not inverse operations of each other. The function ρ maps (S, X) to (S', Y), and the function ρ' maps (S, Y) to (S', X).
[0040] 3) Final decryption stage
[0041] For the last ciphertext block C l , first with block cipher D K Decrypt C l Get X l ; Using block cipher E K Encrypt | C | -l (nm), output with X l XOR, the result is recorded as X * ; Set the status chain value S l-2 With X * Common input linear mixing function ρ', now only need to calculate interception Check if the rightmost nm bits of are equal to [0] n-m If it is, the verification is successful and the decryption process continues, otherwise the symbol ⊥ is output and the decryption stops; if the verification is successful, intercept The leftmost |C l-1 |-(nm) bits constitute the decrypted plaintext block M l And output, while intercepting The rest of the (from the leftmost |C l-1 The bit string from |-(nm)+1 bit to the mth bit) is denoted as Z;
[0042] Block cipher D K Decrypt C l -1||Z gets X l-1 ; Set the status chain value S l-2 With X l-1 Common input linear mixing function ρ', now only need to calculate interception The rightmost nm bits of , check whether they are equal to [l-1] n-m If it is, the verification is successful and the decryption process continues, otherwise the symbol ⊥ is output and the decryption stops; if the verification is successful, intercept The leftmost m bits of the decrypted plaintext block Ml-1 And output.
[0043] Based on the same inventive concept, the present invention also provides an authenticated encryption system with bidirectional onlineness, comprising:
[0044] A setting module is used for the participants to jointly select an n-bit block cipher E, a key K, and a block length m;
[0045] The encryption module is used to execute the encryption scheme, taking the key K, the temporary value N and the plaintext M as input and outputting the ciphertext C and the tag T;
[0046] The decryption module is used to execute the decryption scheme, taking the key K, the temporary value N and the ciphertext C as input, verifying the correctness of the ciphertext C and outputting the correctly decrypted plaintext M.
[0047] The present invention has linearity in both encryption and decryption directions, and can provide confidentiality protection with n / 2 bit security strength and integrity protection with nm bit security strength for data.
[0048] Furthermore, to adapt to different application requirements, the present invention supports serial implementation in a resource-constrained environment, requiring only about one group of storage space at a minimum; the present invention also supports calling the underlying block cipher in a parallel manner in a multi-processor environment. When the number of message blocks does not exceed the parallel processing capability, the total operation time of the present invention is close to the time required for one block cipher call.
[0049] Furthermore, the block cipher used in the present invention can be selected according to user needs. The user only needs to determine the primitive polynomial on the finite field (thereby specifying the calculation method of the multiplication operation) and the user-selectable parameters in the present invention (such as the block length m) according to the group size n to realize the bidirectional linear authenticated encryption provided by the present invention.
[0050] Furthermore, the present invention allows users to adjust the efficiency and security of the scheme by selecting the block length m. When the packet length n is given, m can take any value less than n (it is recommended that m be no less than n / 2). To maintain the security of the scheme, the number of message blocks per query should be less than 2. n-m When m is not less than n / 2, the average number of block cipher calls required to encrypt a block of plaintext is between 1 and 2, making the present invention highly efficient in authenticated encryption schemes that output plaintext before verification. As the value of m increases, the efficiency of the present invention increases, while the integrity protection provided by the verification data decreases. As the value of m decreases, the efficiency of the present invention decreases, while the integrity protection is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 It is a process diagram of the encryption scheme.
[0052] Figure 2 It is a process diagram of the decryption scheme. DETAILED DESCRIPTION
[0053] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below through specific examples.
[0054] In the specific embodiment of the present invention, the block cipher E is the SM4 block cipher algorithm, and the block length n and the key length k are both 128. The primitive polynomial p(x)=x is selected. 128 +x 7 +x 2 +x+1, at this time, for the bit string A, if the leftmost bit of A is 0, then 2·A is equal to the bit string obtained by cyclically shifting A left by 1 bit; if the leftmost bit of A is 1, then 2·A is equal to the bit string obtained by cyclically shifting A left by 1 bit and then XORing it with 0 120 The bit string obtained by 10000111, where 0 120 10000111 is the bit string representation of p(x). Select m to satisfy n / 2≤m<n, and accordingly determine that the value of the ordinal number is not greater than 2. n-m , that is, the number of blocks of a message under a given key cannot be greater than 2 n -m .
[0055] 1. Encryption Scheme
[0056] Input: key K, temporary value N, plaintext M.
[0057] 1) Using block cipher E K Encrypt the temporary value N to obtain the initial state S0.
[0058] 2) Divide the received plaintext into blocks M1,...,M according to m bits l , the last block M l The bit length may be less than m bits.
[0059] Due to storage space limitations, iterative encryption can be performed after the received plaintext is divided into blocks, rather than waiting until the entire plaintext data is received and divided. The ordinal number i can be directly represented as a bit string using a counter, or the integer i can be converted to a bit string and padded on the left with enough zeros based on the required bit string length to obtain an nm-bit representation of i.
[0060] 3) For M input in sequence i , M i with[i] n-m (nm bits of ordinal number i) are connected to obtain M i ||[i]n-m ;calculate Block cipher E K Encryption X i Get ciphertext group C i , output C i ; Iterate this step until the last two blocks M are left l-1 and M l .
[0061] 4) M l-1 and [l-1] n-m Connect them to get M l-1 ||[l-1] n-m ;calculate Block cipher E K Encryption X l-1 Get a group C * ; Intercept C * The leftmost n-m+|M l | bits as C l-1 , output C l-1 .
[0062] 5) Intercept C * The rightmost m-|M l | bits are denoted as Z, and M l Connect it with Z and fill nm "0" on the right to get M l ||Z||[0] n-m ;calculate
[0063] 6) Using block cipher E K Encrypted plaintext length |M|, output and X * XOR, the result is recorded as X l .
[0064] The ordinal / counter value l and the last plaintext block M l The length of the entire plaintext can be calculated as |M|=(l-1)m+|M l |, so there is no need to record the plaintext length separately.
[0065] 7) Using block cipher E K Encryption X l The result is recorded as C l , output C l .
[0066] 2. Decryption Solution
[0067] Input: key K, temporary value N, ciphertext C.
[0068] 1) Using block cipher E KEncrypt the temporary value N to obtain the initial state S0.
[0069] 2) Divide the received ciphertext into blocks C1,...,C l , the penultimate block C l-1 The bit length of may be less than n bits.
[0070] Due to storage space limitations, the received ciphertext can be divided block by block and then iterative decryption can be performed, rather than waiting for the entire ciphertext data to be received and divided before performing iterative decryption.
[0071] 3) For C input in sequence i , using block cipher D K Decrypt C i Get X i ;calculate interception Check if the rightmost nm bits of [i] are equal to [i] n-m :If no, output symbol ⊥ and stop decryption; if yes, intercept The leftmost m bits of i , output M i . Iterate this step until there are only two ciphertext blocks C left. l-1 and C l .
[0072] 4) Using block cipher D K Decrypt C l Get X l ; Using block cipher E K Encrypt | C | -l (nm), output with X l XOR, the result is recorded as X * ;calculate interception Check if the rightmost nm bits of are equal to [0] n-m :If no, output symbol ⊥ and stop decryption; if yes, intercept The leftmost |C l-1 |-(nm) bits as M l , output M l .
[0073] 5) Interception Counting from the leftmost |C l-1 |-(nm)+1 bits to the mth bit are denoted as Z. Using block cipher D K Decrypt C l-1 ||Z gets X l-1 ;calculate interception The rightmost nm bits of , check whether they are equal to [l-1] n-m :If not, output symbol ⊥ and stop decryption; if yes, intercept The leftmost m bits of l-1 , output M l-1 .
[0074] This invention is suitable for resource-constrained environments such as smart cards, secure batteries, and sensor networks, achieving data confidentiality, integrity protection, and data origin authentication with minimal storage space. It is also suitable for efficient authenticated encryption in multi-processor environments, with total computation time approaching that required for a single block cipher call.
[0075] The present invention belongs to the working mode of block cipher, and different block cipher algorithms such as AES, PRESENT, etc. can be selected for implementation.
[0076] In the present invention, the linear mixing function ρ can be formally described as The matching function ρ' can be described as For block ciphers with different block lengths, users need to select the corresponding primitive polynomial p(x) according to the block length n of the block cipher to determine the multiplication operation "·" on the finite field. For example, when n = 128, you can select p(x) = x 128 +x 7 +x 2 +x+1; when n=64, p(x)=x 64 +x 4 +x 3 +x+1; when n=256, you can choose p(x)=x 256 +x 10 +x 5 +x 2 +1.
[0077] In the present invention, users can select different functions ρ and ρ' according to the application environment. It is necessary to ensure that: ρ and ρ' are calculated correctly; the two elements of ρ output are different; and the S obtained after the iterative call defined in the present invention is i are different from each other with high probability.
[0078] Another embodiment of the present invention provides an authenticated encryption system with bidirectional onlineness, comprising:
[0079] A setting module is used for the participants to jointly select an n-bit block cipher E, a key K, and a block length m;
[0080] The encryption module is used to execute the encryption scheme, taking the key K, the temporary value N and the plaintext M as input and outputting the ciphertext C and the tag T;
[0081] The decryption module is used to execute the decryption scheme, taking the key K, the temporary value N and the ciphertext C as input, verifying the correctness of the ciphertext C and outputting the correctly decrypted plaintext M.
[0082] Another embodiment of the present invention provides a computer device (computer, server, smart phone, etc.), which includes a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing each step in the method of the present invention.
[0083] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, magnetic disk, optical disk), wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the steps of the method of the present invention are implemented.
[0084] The specific embodiments of the present invention disclosed above are intended to facilitate understanding and implementation of the present invention. Those skilled in the art will appreciate that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the embodiments disclosed in this specification; the scope of protection of the present invention shall be determined by the scope defined in the claims.
Claims
1. A bidirectional online authentication encryption method, characterized in that: The following steps are involved: The participants jointly select an n-bit block cipher E, key K, and block length m; The sender executes the encryption scheme, taking the key K, the temporary value N and the plaintext M as input, and outputs the ciphertext C and the tag T; The receiver executes the decryption scheme, taking the key K, the temporary value N and the ciphertext C as input, verifies the correctness of the ciphertext C and outputs the correctly decrypted plaintext M.
2. The method according to claim 1, characterized in that The temporary value N is an n-bit bit string, and the ciphertext length |C| is related to the plaintext length |M|.
3. The method according to claim 1, characterized in that The encryption scheme includes: Initialization phase: using block cipher E K Encrypt the temporary value N to obtain the initial state S0; divide the plaintext M into several m-bit blocks, denoted as M1,...,M l ; Iterative encryption phase: Encrypt the plaintext blocks one by one in the order of the plaintext blocks; for the i-th plaintext block M i i=1,...,l-2,M i Connected with the nm bit representation of the ordinal number i, we get M i ||[i] n-m ; Then change the state chain value S i-1 With M i ||[i] n-m The linear mixing function ρ is inputted together to obtain a set of 2n-bit outputs (S i ,X i ),in is the updated state chain value, is the input of the block cipher; K Encryption X i Get ciphertext group C i And output, where |C i |=n; iterate the above steps until there are only two plaintext blocks M left l-1 and M l ; Final encryption phase: For the second-to-last plaintext block M l-1 , M l-1 Connected with the nm bit representation of the ordinal number l-1, we get M l-1 ||[l-1] n-m ; Then change the state chain value S l-1 With M l-1 ||[l-1] n-m Common input linear mixing function ρ, then only need to calculate Block cipher E K Encryption X l-1 Get a group C * ; C * Divide into two parts, first intercept C * The leftmost n-m+|M l | bits constitute the l-1th block of ciphertext C l-1 And output, then record the remaining bit string as Z; record the last plaintext block M l Connect with Z and fill nm "0" on the right to get M l ||Z||[0] n-m ; Set the status chain value S l-2 With M l ||Z||[0] n-m Common input linear mixing function ρ, now only need to calculate Block cipher E K Encrypted plaintext length |M|, output and X * XOR, the result is recorded as X l ; Finally, block cipher E K Encryption X l Get ciphertext group C l And output.
4. The method according to claim 1, wherein The decryption scheme includes: Initialization phase: using block cipher E K Encrypt the temporary value N to obtain the initial state S0; divide the ciphertext C into several n-bit groups, denoted as C1,...,C l , where |C i |=n,i=1,...,l-2,l,and|C l-1 |≤n; Iterative decryption phase: For the i-th ciphertext block C i , using block cipher D K Decrypt C i Get X i ; Set the status chain value S i-1 With X i Common input linear mixing function ρ' to obtain a set of 2n-bit output in is the updated state chain value; intercept Check if the rightmost nm bits of [i] are equal to [i] n-m If it is, the verification is successful and the decryption process continues, otherwise the symbol ⊥ is output and the decryption stops; if the verification is successful, intercept The leftmost m bits of the decrypted plaintext block M i And output; iterate the above steps until there are only two ciphertext blocks C left l-1 and C l ; Among them, the linear mixing function ρ and the function ρ' are a set of binary operations, but they are not inverse operations of each other. The function ρ maps (S,X) to (S',Y), and the function ρ' maps (S,Y) to (S',X); Final decryption phase: For the last ciphertext block C l , first with block cipher D K Decrypt C l Get X l ; Using block cipher E K Encrypt | C | -l (nm), output with X l XOR, the result is recorded as X * ; Set the status chain value S l-2 With X * Common input linear mixing function ρ', now only need to calculate interception Check if the rightmost nm bits of are equal to [0] n-m If it is, the verification is successful and the decryption process continues, otherwise the symbol ⊥ is output and the decryption stops; if the verification is successful, intercept The leftmost |C l-1 |-(nm) bits constitute the decrypted plaintext block M l And output, while intercepting The remaining bit string is denoted as Z; the block cipher D K Decrypt C l-1 ||Z gets X l-1 ; Set the status chain value S l-2 With X l-1 Common input linear mixing function ρ', now only need to calculate interception The rightmost nm bits of , check whether they are equal to [l-1] n-m If it is, the verification is successful and the decryption process continues, otherwise the symbol ⊥ is output and the decryption stops; if the verification is successful, intercept The leftmost m bits of the decrypted plaintext block M l-1 And output.
5. The method according to claim 1, wherein It is linear in both encryption and decryption directions, and can provide confidentiality protection with n / 2 bits of security strength and integrity protection with nm bits of security strength for data.
6. The method according to claim 1, characterized in that It supports serial implementation in resource-constrained environments and supports calling the underlying block cipher in parallel in a multi-processor environment. When the number of message blocks does not exceed the parallel processing capability, the total operation time is close to the time required for one block cipher call.
7. The method according to claim 1, characterized in that The user is supported to adjust the efficiency and security of the scheme by selecting the block length m. When the packet length n is given, m can take any value less than n. To maintain the security of the scheme, the number of message blocks in each query should be less than 2. n-m .
8. An authenticated encryption system with bidirectional linearity, characterized in that: include: A setting module is used for the participants to jointly select an n-bit block cipher E, a key K, and a block length m; The encryption module is used to execute the encryption scheme, taking the key K, the temporary value N and the plaintext M as input and outputting the ciphertext C and the tag T; The decryption module is used to execute the decryption scheme, taking the key K, the temporary value N and the ciphertext C as input, verifying the correctness of the ciphertext C and outputting the correctly decrypted plaintext M.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method according to any one of claims 1 to 7 is implemented.