An encryption and decryption apparatus, encryption method, decryption method, and related products
By optimizing the Montgomery modular multiplication algorithm and the design of the parallel multiplier, the efficiency bottleneck of the traditional Montgomery modular multiplication algorithm is solved, and the computational efficiency of the ECC encryption and decryption process is improved, especially the speed acceleration in the ECC shared key generation and data encryption and decryption processes.
Patent Information
- Application Number
- CN202511566412.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-03-17
- Estimated Expiration
- 2045-10-30
AI Technical Summary
The traditional Montgomery modular multiplication algorithm has an efficiency bottleneck in ECC encryption and decryption. Frequent Montgomery reduction operations lead to huge computational overhead, which has become a key bottleneck restricting the efficiency of ECC encryption and decryption.
By optimizing the Montgomery modular multiplication algorithm, a two-stage computation process is adopted: the first stage performs initial multiplication and reduction, and the second stage performs multiplication and reduction in combination with pre-calculated parameters. Only two Montgomery reductions are needed to complete a modular multiplication operation from constant domain input to constant domain output, and multiple parallel multipliers are used to improve computational efficiency.
It significantly improves the overall operational efficiency of ECC encryption and decryption, reduces computational overhead, and accelerates the ECC operation process, especially significantly improving the speed in the ECC shared key generation and data encryption and decryption processes.
Smart Images

Figure CN121036982B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to an encryption / decryption device, encryption method, decryption method, and related products. Background Technology
[0002] With the increasing demand for network communication security and data protection, encryption technology has become the cornerstone of information security. Among them, Elliptic Curve Cryptography (ECC) is widely used in data encryption and digital signatures due to its advantages of high security and short key length. The core operation of ECC is elliptic curve dot multiplication, which is highly dependent on the underlying large number modular multiplication. Therefore, the efficiency of modular multiplication directly determines the overall performance of ECC encryption and decryption.
[0003] Currently, the Montgomery modular multiplication algorithm is the mainstream technique for implementing modular multiplication of large numbers. It avoids time-consuming division operations by converting the operation to the Montgomery field. However, the traditional Montgomery modular multiplication algorithm has a significant efficiency bottleneck: to complete a full modular multiplication operation from constant field input to constant field output, four Montgomery reductions are required: two for converting the input data to the Montgomery field, one for multiplication within the field, and the last for converting the result back to the constant field.
[0004] Such frequent reduction and field transformation operations result in enormous computational overhead, thus becoming a bottleneck restricting the efficiency of ECC encryption and decryption. Therefore, how to optimize the Montgomery modular multiplication algorithm to improve the overall computational efficiency of ECC encryption and decryption has become an urgent technical problem to be solved. Summary of the Invention
[0005] To address the aforementioned issues, this application provides an encryption / decryption device, encryption method, decryption method, and related products, with the aim of optimizing the computational process of the Montgomery modular multiplication algorithm, reducing computational overhead, and thereby improving the overall computational efficiency of ECC encryption and decryption.
[0006] The embodiments of this application disclose the following technical solutions:
[0007] The first aspect of this application provides an encryption / decryption device, which includes: an encryption / decryption module and a modular multiplication operation module connected to the encryption / decryption module;
[0008] The encryption / decryption module is used to send first data and second data to the modular multiplication module; the first data and the second data belong to the constant domain;
[0009] The modular multiplication module is used to perform multiplication operations using the first data and the second data to obtain a first multiplication result, and to perform Montgomery reduction on the first multiplication result to obtain the third data;
[0010] The modular multiplication module is further configured to perform multiplication operations using the third data and pre-calculated parameters to obtain a second multiplication result, and to perform Montgomery reduction on the second multiplication result to obtain the modular multiplication result; the pre-calculated parameters are calculated based on the modulus and base values in the preset elliptic curve parameters; the modular multiplication result belongs to the constant domain;
[0011] The modular multiplication module is also used to send the modular multiplication result to the encryption / decryption module;
[0012] The encryption / decryption module is also used to perform elliptic curve cryptography based on the modular multiplication result to obtain a key, and to encrypt or decrypt data using the key.
[0013] In an optional implementation, the device further includes a pre-calculation module;
[0014] The pre-calculation module is used to perform a modulo operation on the square of the base value and the modulus to obtain the pre-calculation parameters.
[0015] In an optional implementation, the modular multiplication module includes multiple parallel multipliers.
[0016] In an optional implementation, the encryption / decryption module is specifically used to send the local private key and the public key of the communication peer to the modular multiplication module;
[0017] The modular multiplication module is used to perform calculations using the local private key and the public key of the communication peer to obtain a shared key, and then return the shared key to the encryption / decryption module.
[0018] In an optional implementation, the encryption / decryption module is further configured to send the local private key and the base point to the modular multiplication module;
[0019] The modular multiplication module is also used to perform calculations using the local private key and the base point to obtain the local public key, and return the local public key to the encryption / decryption module.
[0020] A second aspect of this application provides an encryption method applied to a first communication device, the first communication device including the encryption / decryption apparatus described in any implementation of the first aspect, the method comprising:
[0021] The first communication device obtains the first key through the encryption / decryption device;
[0022] The first communication device uses the first key to encrypt the data to obtain ciphertext data;
[0023] The first communication device sends the encrypted data to the second communication device.
[0024] A third aspect of this application provides a decryption method applied to a second communication device, wherein the second communication device is an encryption / decryption apparatus described in any implementation of the first aspect, and the method includes:
[0025] The second communication device receives encrypted data sent by the first communication device;
[0026] The second communication device obtains the second key using the encryption / decryption device;
[0027] The second communication device uses the second key to decrypt the ciphertext data to obtain the plaintext data.
[0028] A fourth aspect of this application provides a communication device that includes the encryption / decryption device described in any implementation of the first aspect.
[0029] The fifth aspect of this application provides a computer storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the encryption or decryption methods described in the second or third aspect.
[0030] The sixth aspect of this application provides a computer program product comprising computer-readable instructions for implementing the encryption or decryption methods described in the second or third aspect.
[0031] Compared with the prior art, this application has the following beneficial effects:
[0032] This application proposes an encryption / decryption device comprising: an encryption / decryption module for sending first data and second data to a modular multiplication module, wherein the first data and second data belong to the constant domain; a modular multiplication module for performing multiplication operations using the first data and second data to obtain a first multiplication result, and performing Montgomery reduction on the first multiplication result to obtain a third data; wherein the modular multiplication module is further configured to: perform multiplication operations using the third data and pre-calculated parameters to obtain a second multiplication result, and perform Montgomery reduction on the second multiplication result to obtain a modular multiplication result, wherein the pre-calculated parameters are calculated based on the modulus and base values in preset elliptic curve parameters, and the modular multiplication result belongs to the constant domain; the modular multiplication module is further configured to: send the modular multiplication result to the encryption / decryption module; the encryption / decryption module is further configured to: perform elliptic curve cryptography operations based on the modular multiplication result to obtain a key, and use the key to encrypt or decrypt data. The encryption / decryption device provided in this application achieves a fundamental improvement in computational efficiency through the optimized design of the modular multiplication module. This module employs a two-stage computation: the first stage performs initial multiplication and reduction, and the second stage performs subsequent multiplication and reduction based on pre-calculated parameters. Only two Montgomery reductions are needed to complete a full modular multiplication operation from constant domain input to constant domain output. This allows the modular multiplication module to avoid the additional reduction steps specifically for domain transformation required in traditional Montgomery modular multiplication. The encryption / decryption module efficiently executes the core modular multiplication calculations by directly calling this module, significantly accelerating the ECC operation process, reducing computational overhead, and thus improving the overall operational efficiency of ECC encryption and decryption. Attached Figure Description
[0033] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0034] Figure 1 A schematic diagram of the Montgomery modular multiplication process is provided for an embodiment of this application;
[0035] Figure 2 This is a schematic diagram of an encryption / decryption device provided in an embodiment of this application;
[0036] Figure 3 A schematic diagram of an optimized Montgomery modular multiplication process provided for embodiments of this application;
[0037] Figure 4 This is a schematic diagram of a parallel multiplication operation provided in an embodiment of this application;
[0038] Figure 5This is a schematic diagram of another parallel multiplication operation provided in an embodiment of this application;
[0039] Figure 6 A flowchart of an encryption method provided in an embodiment of this application;
[0040] Figure 7 This is a flowchart of a decryption method provided in an embodiment of this application. Detailed Implementation
[0041] As described earlier, Elliptic Curve Cryptography (ECC), as an important modern public-key cryptosystem, is widely used in security scenarios such as digital signatures and key exchange due to its high security strength and short key length. Compared with the traditional RSA (Rivest-Shamir-Adleman) encryption algorithm, ECC requires a shorter key length to achieve the same security strength. For example, a 256-bit ECC key is equivalent to a 3072-bit RSA key in terms of security strength. This gives ECC a significant advantage in environments with limited computing resources, such as IoT devices and mobile terminals.
[0042] ECC's security is based on the intractability of the elliptic curve discrete logarithm problem, and its core operation is the dot product on an elliptic curve. The dot product operation requires a series of dot additions and doubling operations. Specifically, for two distinct points P=(x1,y1) and Q=(x2,y2) on an elliptic curve, where P≠Q, the coordinates of the dot product R of P and Q are (x3,y3). The calculation process is as follows:
[0043] slope ,in for Modulo N, the inverse element.
[0044] x-axis .
[0045] ordinate .
[0046] For points on the elliptic curve The coordinates of the result Z=2W, which is a multiple of W, are (x5, y5). The calculation process is as follows:
[0047] slope Where 'a' is the elliptic curve parameter, for Modulo N, the inverse element.
[0048] x-axis .
[0049] ordinate .
[0050] Understandably, these dot addition and doubling operations are actually based on a large number of arithmetic operations performed over finite fields, with modular multiplication accounting for the majority of the computational overhead. Therefore, the efficiency of modular multiplication directly determines the overall performance of ECC encryption and decryption.
[0051] To accelerate modular multiplication operations, the Montgomery modular multiplication algorithm is widely used. This algorithm avoids time-consuming division operations by transforming the operation to a Montgomery field. In a Montgomery field, data u is represented in the form uR mod N, where N is the modulus and R is a base value coprime to N, typically 2. k k is the bit width of N.
[0052] The core of Montgomery modular multiplication is the Montgomery reduction operation, namely:
[0053] ;
[0054] in satisfy It replaces traditional modular arithmetic with simple multiplication and shift operations.
[0055] For example, when calculating A × B mod N, the Montgomery algorithm can be used to break down the modular multiplication operation into REDC(REDC(A × B)). Here, REDC is Montgomery reduction, which is essentially a step for quickly calculating the remainder.
[0056] However, current Montgomery modular multiplication algorithms suffer from significant efficiency bottlenecks: completing a full modular multiplication operation from constant-domain input to constant-domain output, such as A × B mod N, where A and B are both in the constant domain, requires four Montgomery reductions. See details... Figure 1 , Figure 1 This is a schematic diagram of a Montgomery modular multiplication process provided in an embodiment of this application.
[0057] like Figure 1 As shown, converting the input constant-domain data A to the Montgomery domain requires one Montgomery reduction, as does converting the input constant-domain data B to the Montgomery domain. Performing operations on the converted Montgomery-domain data A and B within the Montgomery domain requires another Montgomery reduction to obtain the result belonging to the Montgomery domain. Finally, converting the result belonging to the Montgomery domain back to the constant domain requires another Montgomery reduction. Reduction operations are the most time-consuming operations in the entire encryption / decryption process. Therefore, such frequent Montgomery reduction operations lead to huge computational overhead, becoming a key bottleneck restricting ECC performance.
[0058] To address the aforementioned problems, the inventors have developed an encryption / decryption device, encryption method, decryption method, and related products.
[0059] The encryption / decryption device includes: an encryption / decryption module for sending first data and second data to a modular multiplication module, wherein the first data and second data belong to the constant domain; a modular multiplication module for performing multiplication operations using the first data and second data to obtain a first multiplication result, and performing Montgomery reduction on the first multiplication result to obtain a third data; wherein the modular multiplication module is further used for: performing multiplication operations using the third data and pre-calculated parameters to obtain a second multiplication result, and performing Montgomery reduction on the second multiplication result to obtain a modular multiplication result, wherein the pre-calculated parameters are calculated based on the modulus and base values in the preset elliptic curve parameters, and the modular multiplication result belongs to the constant domain; the modular multiplication module is further used for: sending the modular multiplication result to the encryption / decryption module; the encryption / decryption module is further used for: performing elliptic curve cryptography operations based on the modular multiplication result to obtain a key, and using the key to encrypt or decrypt data.
[0060] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0061] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this application should have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms "first," "second," and similar terms used in the embodiments of this application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are only used to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0062] The encryption / decryption device provided in this application is applied to the field of ECC encryption / decryption and is adapted to the core computational requirement of elliptic curve multiplication. In ECC, the implementation of dot product operations heavily relies on a large number of large number modular multiplication operations. The encryption / decryption device provided in this application directly improves the efficiency of ECC operations through a modular multiplication operation module with targeted optimization design.
[0063] See Figure 2 The figure is a schematic diagram of the structure of an encryption / decryption device provided in an embodiment of this application, as shown below. Figure 2 As shown, the encryption / decryption device provided in this application embodiment includes: an encryption / decryption module 201 and a modular multiplication operation module 202 connected to the encryption / decryption module 201.
[0064] In this embodiment, the encryption / decryption module 201 and the modular multiplication module 202 can be connected via a bus or other means.
[0065] The encryption / decryption module 201 is responsible for ECC operation flow control, such as data transmission and reception, key generation, data encryption or decryption, etc.
[0066] Specifically, the encryption / decryption module 201 is used to send the first data and the second data to the modular multiplication module 202.
[0067] In this embodiment of the application, the encryption / decryption module 201 determines the first data and the second data to be performed in the modular multiplication operation according to the ECC operation scenario (such as public key generation and shared key calculation), and sends the first data and the second data to the modular multiplication operation module 202, wherein the first data and the second data both belong to the constant field.
[0068] For example, in an ECC operation scenario, it is necessary to perform modular multiplication on constant field data A and constant field data B. In this case, the encryption / decryption module 201 sends constant field data A as the first data and constant field data B as the second data to the modular multiplication module 202.
[0069] The modular multiplication module 202 is the core of the encryption / decryption device provided in this application embodiment, used to perform optimized Montgomery modular multiplication operations. The modular multiplication module 202 is configured to perform the following operations:
[0070] The first multiplication result is obtained by multiplying the first and second data, and then Montgomery reduction is performed on the first multiplication result to obtain the third data.
[0071] In this embodiment of the application, after receiving the first data and the second data sent by the encryption / decryption module 201, the modular multiplication module 202 first performs a multiplication operation using the first data and the second data to obtain the first multiplication result.
[0072] After obtaining the first multiplication result, the modular multiplication module 202 performs Montgomery reduction on the first multiplication result to obtain the third data. The Montgomery reduction process is based on the Montgomery algorithm.
[0073] In one example implementation, the first data is A, the second data is B, and the modular multiplication module 202 performs a multiplication operation using A and B to obtain the first multiplication result C = A × B. Then, Montgomery reduction is performed on the first multiplication result C to obtain the third data D = REDC(C).
[0074] The modular multiplication module 202 is also used to perform multiplication operations using the third data and pre-calculated parameters to obtain the second multiplication result, and to perform Montgomery reduction on the second multiplication result to obtain the modular multiplication result.
[0075] It is understandable that during the ECC encryption and decryption process, an elliptic curve is pre-defined, along with preset elliptic curve parameters, including the modulus N, base value R, base point G, curve coefficients a and b, etc.
[0076] In this embodiment, the pre-calculated parameters are obtained based on the modulus N and base value R in the preset elliptic curve parameters.
[0077] Optionally, to improve computation speed, the encryption / decryption device also includes a pre-computation module. The pre-computation module is used to perform a modulo operation on the square of the base value with respect to the modulus to obtain the pre-computation parameter, i.e., R. 2 mod N.
[0078] After obtaining the third data, the modular multiplication module 202 performs a multiplication operation on the third data and the pre-calculated parameters to obtain the second multiplication result.
[0079] After obtaining the second multiplication result, the modular multiplication module 202 performs Montgomery reduction on the second multiplication result to obtain the modular multiplication result. The Montgomery reduction process is based on the Montgomery algorithm, and the modular multiplication result belongs to the constant domain.
[0080] Taking A as the first data, B as the second data, C as the first multiplication result, D as the third data, E as the pre-calculated parameter, F as the second multiplication result, and K as the modular multiplication result as an example, the following derivation process proves the correctness of the modular multiplication result obtained by the modular multiplication module 202:
[0081] ;
[0082] According to the fundamental properties of Montgomery fields, R' is the multiplicative inverse of R modulo N, i.e. ,therefore:
[0083] ;
[0084] Substituting into the above formula, we get:
[0085] .
[0086] To provide a more comprehensive and clear explanation of the optimized Montgomery modular multiplication process performed by the modular multiplication module 202, the following section will combine... Figure 3 The calculation process will be introduced. Figure 3 This is a schematic diagram of an optimized Montgomery modular multiplication process provided for an embodiment of this application.
[0087] like Figure 3 As shown, the input constant domain data A and input constant domain data B are multiplied to obtain the first multiplication result C in the constant domain; Montgomery reduction is performed on the first multiplication result C to obtain the third data D in the Montgomery domain; the third data D is multiplied by the pre-computed parameter E to obtain the second multiplication result F in the Montgomery domain, where the pre-computed parameter... Performing a Montgomery reduction on the second multiplication result F yields the modular multiplication result in the constant field. This is achieved through the above formula derivation process and... Figure 3 The description demonstrates that the modular multiplication module 202 in this embodiment can correctly calculate the modular multiplication result through two Montgomery reduction operations, and the final result is directly located in the constant domain without the need for additional domain transformation operations. Compared with traditional methods, this reduces two reduction operations, significantly improving the efficiency of modular multiplication calculation. The modular multiplication module 202 is also used to send the modular multiplication result to the encryption / decryption module 201.
[0088] In this embodiment of the application, after obtaining the modular multiplication result, the modular multiplication module 202 can return the modular multiplication result to the encryption / decryption module 201 according to the actual connection method with the encryption / decryption module 201.
[0089] After receiving the modular multiplication result, the encryption / decryption module 201 is also used to perform elliptic curve cryptography based on the modular multiplication result to obtain a key, and use the key to encrypt or decrypt the data.
[0090] In this embodiment of the application, after receiving the constant field modular multiplication result returned by the modular multiplication module 202, the encryption / decryption module 201 generates a key in combination with the ECC operation logic, and uses the generated key to perform encryption or decryption operations on the data.
[0091] In this embodiment, a fundamental improvement in computational efficiency is achieved through the optimized design of the modular multiplication module. This module employs a two-stage computation: the first stage performs initial multiplication and reduction, and the second stage performs subsequent multiplication and reduction based on pre-calculated parameters. Only two Montgomery reductions are required to complete a full modular multiplication operation from constant domain input to constant domain output. This allows the modular multiplication module to avoid the additional reduction steps specifically for domain transformation required in traditional Montgomery modular multiplication. The encryption / decryption module efficiently executes the core modular multiplication calculation by directly calling this module, significantly accelerating the ECC operation process, reducing computational overhead, and thus improving the overall operational efficiency of ECC encryption and decryption.
[0092] The traditional Montgomery modular multiplication method relies on a single 32-bit multiplier to complete the calculation through iteration. The number of iterations doubles for every 32 bits increase in data length. For example, 64-bit data requires 2×2=4 multiplication operations, and 256-bit data requires 8×8=64 multiplication operations plus 56 additional addition and shift operations, which is inefficient.
[0093] Optionally, to further improve the computational efficiency of modular multiplication, the modular multiplication module 202 includes multiple parallel multipliers.
[0094] In the embodiments of this application, the parallel multiplier can employ multiple parallel 32-bit basic multipliers, which can simultaneously execute multiple 32-bit multiplication operations, significantly reducing the number of iterations, improving the efficiency of multiplication operations, and thus improving the computational efficiency of modular multiplication operations.
[0095] In one example implementation, the modular multiplication module 202 includes eight parallel 32-bit basic multipliers.
[0096] Figure 4 This is a schematic diagram of a parallel multiplication operation provided in an embodiment of the present application, which is used to implement synchronous multiplication of 256-bit data through eight parallel 32-bit basic multipliers.
[0097] like Figure 4 As shown, the horizontal axis is marked with bit segments "0", "1", "2"... "15", and the vertical axis divides the data into eight independent operation regions, each corresponding to a 32-bit multiplier. During operation, the 256-bit data to be multiplied is split into eight data blocks with a 32-bit granularity and input into the eight operation regions shown in the diagram. All multipliers are driven by the same clock signal and can synchronously complete eight groups of 32-bit multiplication operations within a single clock cycle.
[0098] Figure 4 The parallel computing structure avoids the problem of exponential growth in hardware area caused by excessively long multiplier bit widths. Designing a single 256-bit multiplier would result in a hardware area far greater than the total area of eight 32-bit multipliers. Figure 4 The parallel computing structure, while controlling the area, compresses the multiplication operation of 256-bit data from the traditional 8 iterations to a single synchronous operation, greatly reducing the computation time.
[0099] Figure 5 This is a schematic diagram of another parallel multiplication operation provided in an embodiment of this application, which is used to achieve synchronous multiplication of 512-bit data by calling 8 parallel 32-bit basic multipliers multiple times.
[0100] like Figure 5 As shown, Figure 5 The code uses bit field labels in different regions (such as "1", "2", ... "30") to present the combined process of multiple rounds of parallel multiplication and subsequent shifting and addition. When a 512-bit multiplication operation is required, the 512-bit data is split into four 256-bit data blocks, and then processed through four calls. Figure 4 The eight groups of 32-bit parallel multiplication operations shown in the diagram complete the multiplication operations of four groups of 256-bit data respectively.
[0101] After performing the multiplication operations, the results of the four multiplications are shifted left by the corresponding number of bits according to the bit width requirements, ensuring that all results are superimposed on the same dimension. Then, an addition operation is performed to complete the accumulation, finally obtaining a complete 512-bit multiplication result.
[0102] Compared to a traditional single 32-bit multiplier, Figure 5 The parallel multiplication operation scheme shown requires only 8 multiplications and 8 additions, which significantly reduces the number of operations, data caching, and data retrieval. Moreover, the longer the data, the greater the reduction in time.
[0103] Optionally, in the ECC shared key generation scenario, the encryption / decryption module 201 is specifically used to send the local private key and the public key of the communication peer to the modular multiplication module 202.
[0104] The modular multiplication module 202 is used to perform calculations using the local private key and the public key of the communication peer to obtain a shared key, and then return the shared key to the encryption / decryption module 201.
[0105] In this application embodiment, the communication peer refers to another communication entity that establishes an encrypted communication link with the local communication device and needs to jointly generate a shared key. This entity needs to have encryption and decryption capabilities compatible with the local communication device. That is, the communication peer also needs to deploy the encryption and decryption device of this application embodiment (or an equivalent device that supports synchronous operation on the same hardware and Montgomery modular multiplication optimization logic) to ensure that both parties can complete key negotiation through consistent operation logic.
[0106] For example, if the local communication device is an IoT sensor (deployed with the encryption / decryption device provided in the embodiments of this application), the communication peer can be an IoT gateway (also deployed with the encryption / decryption device provided in the embodiments of this application); if the local device is a mobile phone (integrating the encryption / decryption device provided in the embodiments of this application), the communication peer can be a payment terminal (integrating the encryption / decryption device provided in the embodiments of this application).
[0107] The core function of the communication peer is to generate its own ECC key pair, send the public key to the local communication device, and receive the public key from the local communication device. Through the encryption and decryption devices deployed by both parties, they generate the same shared key.
[0108] In this embodiment, the private key is a random large integer that needs to be kept strictly confidential, while the public key is a point on a preset elliptic curve determined based on the private key and preset elliptic curve parameters, and can be publicly transmitted to the communication peer.
[0109] In this embodiment of the application, the encryption / decryption module 201 will store the local private key d A The public key Q of the communication peer B Send to modular multiplication module 202. Modular multiplication module 202 uses local private key d. A The public key Q of the communication peer B Perform calculations to obtain the shared key S, where the shared key S is d. A and Q B The dot product operation is performed. The modular multiplication module 202 is used to perform all the underlying modular multiplication operations in this dot product calculation to accelerate the generation of the shared key.
[0110] Optionally, in the ECC key generation scenario, the encryption / decryption module 201 is also used to send the local private key and base point to the modular multiplication module 202;
[0111] The modular multiplication module 202 is also used to perform calculations using the local private key and the base point to obtain the local public key, and return the local public key to the encryption / decryption module 201.
[0112] In this embodiment of the application, the encryption / decryption module 201 will store the local private key d A The base point G in the preset elliptic curve parameters is sent to the modular multiplication module 202. The modular multiplication module 202 uses the local private key d A Calculate with the base point G to obtain the local public key Q. A The local public key Q A For d A The dot product operation is performed on G. The modular multiplication module 202 is used to perform all the underlying modular multiplication operations in this dot product calculation to accelerate the generation of the local public key.
[0113] In this embodiment, the modular multiplication module 202 completes all the underlying modular multiplication operations involved in the ECC encryption and decryption process. The modular multiplication module 202 reduces the number of reductions in a single modular multiplication from the traditional four to two, which greatly improves the speed of the entire multiplication operation, accelerates the generation of public keys and shared keys, and thus improves the overall efficiency of ECC encryption and decryption.
[0114] Based on the encryption / decryption apparatus provided in the foregoing embodiments, this application also provides an encryption method, which is applied to a first communication device, the first communication device including any of the encryption / decryption apparatuses in the above-described apparatus embodiments. Figure 6 This is a flowchart illustrating an encryption method provided in an embodiment of this application. Figure 6 As shown, the method includes the following steps:
[0115] S601, The first communication device obtains the first key through the encryption / decryption device.
[0116] In this embodiment of the application, the first communication device and the second communication device are communication counterparts, and the first key is a shared key obtained through a built-in encryption and decryption device.
[0117] Specifically, the first communication device sends its local private key and the second communication device's public key to the modular multiplication module through the encryption / decryption module in its built-in encryption / decryption device.
[0118] The modular multiplication module uses the local private key of the first communication device and the public key of the second communication device to perform calculations and obtain a shared key, namely the first key.
[0119] S602. The first communication device uses the first key to encrypt the data and obtain ciphertext data.
[0120] In one example implementation, the first communication device can use the first key obtained in the aforementioned steps to perform key derivation processing to generate a session key for symmetric encryption. Specifically, valid information can be extracted from the coordinates of the first key as key material for symmetric encryption. For example, the x-coordinate of the first key can be extracted, and the final symmetric encryption key can be derived from the x-coordinate of the first key using the HKDF-SHA256 algorithm. Finally, the plaintext data is encrypted using the symmetric encryption key in AES-GCM encryption mode to obtain the encrypted ciphertext data.
[0121] S603, The first communication device sends encrypted data to the second communication device.
[0122] In this embodiment of the application, the encrypted data is transmitted through a communication link established by the first communication device and the second communication device.
[0123] In this embodiment of the application, the first communication device can select a communication protocol according to the actual application scenario and encapsulate the encrypted data into protocol data units.
[0124] Optionally, to prevent replay attacks and detect transmission errors, frame sequence numbers and checksums can be appended to the protocol data units before transmission.
[0125] Optionally, to avoid communication interruption due to channel interference, if transmission fails, the first communication device initiates a retransmission mechanism, with a maximum of a preset number of retransmissions. The specific preset number of retransmissions can be set according to actual needs.
[0126] In one example implementation, the first communication device encapsulates the encrypted data within an application data record of the TLS 1.3 protocol and ensures reliable data transmission to the second communication device via the TCP protocol. The specific transmission process includes: after establishing a TCP connection, negotiating encryption parameters via the TLS handshake protocol; segmenting the encrypted data into appropriately sized TLS records; adding a sequence number and MAC checksum to each record; and ensuring the data arrives intact through a reliable transmission mechanism.
[0127] The encryption method provided in this application embodiment encrypts data through a communication device with an integrated and optimized encryption / decryption device, which significantly improves the efficiency of ECC key generation and data processing, resulting in a significant improvement in the overall encryption speed.
[0128] Based on the encryption / decryption apparatus provided in the foregoing embodiments, this application also provides an encryption method, which is applied to a second communication device, the second communication device including any of the encryption / decryption apparatuses in the above-described apparatus embodiments. Figure 7 This is a flowchart illustrating a decryption method provided in an embodiment of this application. Figure 7 As shown, the method includes the following steps:
[0129] S701, The second communication device receives encrypted data sent by the first communication device.
[0130] In this embodiment of the application, the encrypted data is transmitted through a communication link established by the first communication device and the second communication device.
[0131] In one example implementation, the second communication device receives ciphertext data encapsulated in the TLS 1.3 protocol via the TCP protocol. The specific receiving process includes: establishing a TCP connection and completing the TLS handshake protocol parameter negotiation; receiving the TLS record and verifying the sequence number and MAC checksum; reassembling the data to obtain the complete ciphertext data; and storing the ciphertext data in a secure buffer for subsequent decryption.
[0132] S702, The second communication device obtains the second key using the encryption / decryption device.
[0133] In this embodiment of the application, the second communication device uses its encryption and decryption device to obtain a second key that is the same as the first key, based on the same elliptic curve parameters and key algorithm as the first communication device.
[0134] In one example implementation, the process of obtaining the second key includes: the second communication device sending its local private key and the first communication device's public key to the modular multiplication module through the encryption / decryption module in its built-in encryption / decryption device; the modular multiplication module using the second communication device's local private key and the first communication device's public key to perform calculations and obtain a shared key point, i.e., the second key.
[0135] S703, the second communication device uses the second key to decrypt the ciphertext data and obtain the plaintext data.
[0136] In this embodiment, the second communication device uses the obtained second key to derive a symmetric decryption key for decryption using the same encryption algorithm as the first communication device. The symmetric decryption key is then used to decrypt the received ciphertext data to recover the original plaintext data.
[0137] In one example implementation, the decryption process includes: decrypting the ciphertext data using a symmetric decryption key and the AES-GCM decryption algorithm; and reconstructing the decrypted data into complete plaintext data.
[0138] The decryption method provided in this application decrypts data through a communication device with an integrated and optimized encryption / decryption apparatus, which significantly improves the efficiency of ECC key generation and decryption processing, resulting in a significant improvement in the overall decryption speed.
[0139] Furthermore, this application also provides a communication device, including any of the encryption / decryption devices described in the above-described device embodiments.
[0140] Furthermore, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of an encryption or decryption method as described in any of the method embodiments.
[0141] Furthermore, embodiments of this application also provide a computer program product, which includes computer-readable instructions for implementing the encryption or decryption method as described in any of the method embodiments.
[0142] It should be noted that the various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for the device and product embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments. The device and product embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0143] The above description is merely one specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An encryption and decryption apparatus characterized by comprising: The device comprises an encryption / decryption module and a modular multiplication module connected to the encryption / decryption module. The encryption / decryption module is configured to send first data and second data to the modular multiplication module; the first data and the second data belong to a constant field. The modular multiplication module is configured to perform multiplication operation on the first data and the second data to obtain a first multiplication result, and perform Montgomery reduction on the first multiplication result to obtain third data. The modular multiplication module is further configured to perform multiplication operation on the third data and a pre-computed parameter to obtain a second multiplication result, and perform Montgomery reduction on the second multiplication result to obtain a modular multiplication result; the pre-computed parameter is calculated based on a modulus and a base value in preset elliptic curve parameters; the modular multiplication result belongs to the constant field. The modular multiplication module is further configured to send the modular multiplication result to the encryption / decryption module. The encryption / decryption module is further configured to perform elliptic curve cryptography operation based on the modular multiplication result to obtain a key, and encrypt or decrypt data by using the key. The encryption / decryption module is specifically configured to send a local private key and a public key of a communication peer end to the modular multiplication module. The modular multiplication module is configured to perform calculation on the local private key and the public key of the communication peer end to obtain a shared key, and return the shared key to the encryption / decryption module. The encryption / decryption module is further configured to send a local private key and a base point to the modular multiplication module. The modular multiplication module is further configured to perform calculation on the local private key and the base point to obtain a local public key, and return the local public key to the encryption / decryption module. The device further comprises a pre-computation module. The pre-computation module is configured to perform modulus operation on a square of the base value on the modulus to obtain the pre-computed parameter.
2. The apparatus of claim 1, wherein, The modular multiplication module comprises a plurality of parallel multipliers.
3. An encryption method characterized by, The application is applied to a first communication device, the first communication device comprises the encryption / decryption device in any one of claims 1-2, and comprises: The first communication device obtains a first key by using the encryption / decryption device. The first communication device encrypts data by using the first key to obtain ciphertext data. The first communication device sends the ciphertext data to a second communication device.
4. A decryption method characterized by, The application is applied to a second communication device, the second communication device comprises the encryption / decryption device in any one of claims 1-2, and comprises: The second communication device receives ciphertext data sent by a first communication device. The second communication device obtains a second key by using the encryption / decryption device. The second communication device decrypts the ciphertext data by using the second key to obtain plaintext data.
5. A communication device, characterized by The encryption / decryption device in any one of claims 1-2.
6. A computer storage medium, characterized in that, A computer program is stored thereon, and the computer program is executed by a processor to implement the steps of the encryption method in claim 3 or the decryption method in claim 4.
7. A computer program product, characterised in that, The computer program product comprises computer readable instructions for implementing the encryption method in claim 3 or the decryption method in claim 4.
Citation Information
Patent Citations
Key packaging lightweight method and system based on number-theory transformation, medium and equipment
CN117714054A
Processing device, accelerator, and method for federated learning
US20220147873A1