A method and device for encrypting non-volatile memory in a security chip

By designing a four-round five-layer encryption circuit structure in the security chip, efficient encryption is achieved within one clock cycle, solving the encryption speed and data protection problems of non-volatile storage units, and is suitable for secure payment and its operation supervision.

CN110795775BActive Publication Date: 2025-09-23BEIJING TONGFANG MICROELECTRONICS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201810874225.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-08-03
Publication Date
2025-09-23
Estimated Expiration
2038-08-03

AI Technical Summary

Technical Problem

In the existing technology, the non-volatile storage units of security chips are vulnerable to physical attacks and power consumption analysis, and traditional encryption algorithms result in slow access speeds and cannot meet system requirements.

Method used

A non-volatile memory encryption device for security chips is designed. It adopts four-round encryption circuits and an encryption sequence generator. Each round of encryption circuit is divided into five layers, including key addition operation, nonlinear operation, linear operation and permutation operation units. Encryption is completed within one clock cycle through 2-4 rounds of symmetric algorithm, and mask protection is implemented during data movement.

Benefits of technology

It improves encryption speed and strength, prevents data leakage, solves encryption speed bottlenecks and data protection issues, and is suitable for secure payment and its operation supervision.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN110795775B_ABST
    Figure CN110795775B_ABST
Patent Text Reader

Abstract

The present invention provides an encryption method and device for non-volatile memory in a security chip. The encryption device for non-volatile memory in a security chip includes a main device, a bus, an encryption circuit, and non-volatile memory. The encryption circuit includes four round encryption circuits and an encryption sequence generator. Each round encryption circuit is divided into five layers of round encryption units. Each layer of round encryption units includes four components: a key addition operation unit, a nonlinear operation unit, a linear operation unit, and a permutation operation unit. When the round encryption circuits perform encryption, the first round encryption circuit begins encryption, and the remaining round encryption circuits perform encryption in sequence. After the encryption process is completed, the ciphertext is input into the non-volatile memory, completing the encryption process. The present invention utilizes a symmetric algorithm structure of 2 to 4 rounds to improve encryption strength and speed within a relatively small number of rounds. At the same time, the encryption method includes a nonlinear mask transformation method to ensure that there is no plaintext during the entire data transfer process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of chip security technology, and in particular to a method and device for encrypting a non-volatile memory in a security chip. Background Art

[0002] Embedded non-volatile memory cells are a crucial component of security chips. They typically store important sensitive information, such as system keys, which is precisely the information that security chips prioritize. Attackers can obtain data from non-volatile memory cells through physical attacks and fault injection, as well as through power analysis while reading data from non-volatile memory cells.

[0003] First, to prevent attackers from obtaining this critical information through physical attacks and fault injection, security chips typically use memory encryption to encrypt data stored in non-volatile storage cells. This prevents attackers from accessing data stored in non-volatile storage cells, only obtaining the encrypted data and not the actual data. However, due to manufacturing principles and processes, non-volatile storage cells typically have slow access speeds, a major bottleneck in security chip information processing. Memory encryption algorithms further slow access to non-volatile storage cells, making currently available data encryption algorithms inappropriate. For example, standard algorithms such as DES, AES, and SM4 require 16 rounds, 10 rounds, and 31 rounds, respectively. The size and encryption time required for memory encryption algorithms are unacceptable to systems. Even lightweight algorithms such as SIMMON still require at least 8 to 10 rounds, making them unsuitable for current system speeds. Therefore, a lightweight memory encryption algorithm is needed that can not only meet the requirements of cryptography for encryption algorithms but also solve the problem of encryption speed. The present invention solves the problem of encryption speed by designing a symmetric algorithm with at least 2 rounds but no more than 4 rounds, which can encrypt memory encryption data within one clock cycle.

[0004] Secondly, in order to prevent attackers from obtaining sensitive data by analyzing the energy information during the access process of non-volatile storage units, it is necessary to protect the entire process of moving sensitive data from the storage unit to the computing unit. The most direct way is to protect the entire process of moving sensitive data with a mask.

[0005] This invention is funded by the National Key R&D Program, Project No. 2017YFB0802600, "Key Technologies for Secure Payment and Its Operational Supervision." This project is a sub-project of this project. In response to this project, the present invention designs a method and device for encrypting non-volatile memory in security chips. This method directly converts encrypted data in the security chip's non-volatile memory into bus-encrypted data without the presence of any plaintext information, addressing security issues in secure payment and its operational supervision. Summary of the Invention

[0006] In view of the deficiencies in the above-mentioned prior art, the purpose of the present invention is to provide a method and device for encrypting a non-volatile memory in a security chip. The device for encrypting a non-volatile memory in a security chip includes an encryption circuit, which directly converts the encrypted data of the non-volatile memory in the security chip into bus encrypted data without any plaintext information, thereby solving the security problems in secure payment and its operation supervision.

[0007] In order to achieve the above technical objectives, the technical solution adopted by the present invention is:

[0008] A non-volatile memory encryption device for a security chip, the encryption device comprising a host device, a bus, and the non-volatile memory, the encryption device further comprising an encryption circuit, the encryption circuit comprising four round encryption circuits and an encryption sequence generator, the four round encryption circuits being divided into a first round encryption circuit, a second round encryption circuit, a third round encryption circuit, and a fourth round encryption circuit, and being sequentially connected, the encryption sequence generator being connected to each of the four round encryption circuits; each round encryption circuit being divided into five layers of round encryption units, the five layers of round encryption units being respectively a first layer of round encryption units, a second layer of round encryption units, a third layer of round encryption units, a fourth layer of round encryption units, and a fifth layer of round encryption units, each layer of round encryption units comprising four components: a key addition operation unit, a nonlinear operation unit, a linear operation unit, and a permutation operation unit;

[0009] When the encryption device performs encryption, the input data passes through the main device and becomes bus data after passing through the bus. The bus data is input to the encryption circuit and processed into a bus mask. The bus mask is input to the first round encryption unit in the round encryption circuit. The key addition unit and the nonlinear operation unit in the first round encryption unit include mask operations and perform nonlinear transformation of the bus mask. At the same time, the round encryption circuit selects the components of each round encryption unit in the five round encryption units of the round encryption circuit according to the low bit of the encryption key input externally, and the key addition unit and the nonlinear operation unit in each round encryption unit are selected. Unit, linear operation unit and permutation operation unit, execute the encryption order according to the output value of the encryption order generator, and when each layer of round encryption unit performs encryption, only one of the components is effective, and each layer of round encryption unit must contain a key addition operation unit and a nonlinear operation unit to perform encryption. When the round encryption circuit performs encryption, the first round encryption circuit starts to perform encryption, and the second round encryption circuit, the third round encryption circuit and the fourth round encryption circuit perform encryption in sequence. After the encryption process is completed, the fourth round encryption circuit inputs the encrypted output ciphertext into the non-volatile memory to complete the encryption process.

[0010] An encryption method for a non-volatile memory encryption device in a security chip, the encryption device comprising a host device, a bus, a non-volatile memory, and an encryption circuit, the encryption circuit comprising four round encryption circuits and an encryption sequence generator, the four round encryption circuits being divided into a first round encryption circuit, a second round encryption circuit, a third round encryption circuit, and a fourth round encryption circuit, and being sequentially connected, the encryption sequence generator being connected to each of the four round encryption circuits, each round encryption circuit being divided into five layers of round encryption units, the five layers of round encryption units being respectively a first layer of round encryption units, a second layer of round encryption units, a third layer of round encryption units, a fourth layer of round encryption units, and a fifth layer of round encryption units, each layer of round encryption units comprising four components: a key addition operation unit, a nonlinear operation unit, a linear operation unit, and a permutation operation unit. The specific steps of the encryption method are as follows:

[0011] Step 1: First, when the encryption device performs encryption, the input data passes through the master device and becomes bus data after passing through the bus. The bus data is input into the encryption circuit and processed into a bus mask. The bus mask is input into the first round encryption unit in the round encryption circuit.

[0012] Step 2: At the same time, the round encryption circuit selects the components of each round encryption unit in the five layers of the round encryption circuit according to the low bit of the externally input encryption key, and the key addition unit, nonlinear operation unit, linear operation unit and permutation operation unit in each round encryption unit execute the encryption sequence according to the output value of the encryption sequence generator. When each round encryption unit performs encryption, only one of the components is effective, and each round encryption unit must contain a key addition unit and a nonlinear operation unit to perform encryption;

[0013] Step 3: Based on the selection result of step 2, the first round encryption unit operation is performed. The input of the first round encryption unit operation is the first input data of the round encryption circuit of this round, and the output of the first round encryption unit operation is the first output data.

[0014] Step 4: Based on the selection result of step 2, a second-layer round encryption unit operation is performed. The second input data of the second-layer round encryption unit operation is output as the second output data. At the same time, the second input data value of the second-layer round encryption unit operation is equal to the first output data value of the first-layer round encryption unit operation.

[0015] Step 5: Based on the selection result of step 2, a third round encryption unit operation is performed. The third input data of the third round encryption unit operation is the third output data of the third round encryption unit operation. Meanwhile, the third input data value of the third round encryption unit operation is equal to the second output data value of the second round encryption unit operation.

[0016] Step 6: Based on the selection result of step 2, a fourth round encryption unit operation is performed. The fourth input data of the fourth round encryption unit operation is the fourth output data of the fourth round encryption unit operation. At the same time, the fourth input data value of the fourth round encryption unit operation is equal to the third output data value of the third round encryption unit operation.

[0017] Step 7: Based on the selection result of step 2, a fifth-layer round encryption unit operation is performed. The input of the fifth-layer round encryption unit operation is the fifth input data. The output of the fifth-layer round encryption unit operation is the output result of the fifth-layer round encryption unit operation. At the same time, the fifth input data value of the fifth-layer round encryption unit operation is equal to the fourth output data value of the fourth-layer round encryption unit operation. The output of the fifth-layer round encryption unit operation is the output of the round encryption circuit operation of this round.

[0018] Step 8: When the round encryption circuit performs encryption, the first round encryption circuit starts to perform the encryption steps from step 2 to step 7 above. The second round encryption circuit, the third round encryption circuit and the fourth round encryption circuit perform the encryption steps from step 2 to step 7 in sequence. After the encryption process is completed, the fourth round encryption circuit inputs the encrypted output ciphertext into the non-volatile memory to complete the encryption process.

[0019] The non-volatile memory encryption device for a security chip of the present invention adopts a structure comprising a host device, a bus, a non-volatile memory, and an encryption circuit. In particular, the encryption circuit includes four round encryption circuits and an encryption sequence generator, and each round encryption circuit is divided into five layers of round encryption units. The beneficial effects achieved are: first, utilizing a symmetric algorithm structure of 2 to 4 rounds, the algorithm is completed within one clock cycle, thereby improving encryption strength and speed within a smaller number of rounds; the encryption key participates not only in the encryption operation but also in the execution order of subunits in the round operation; and, at the same time, the encryption method for the non-volatile memory encryption device for a security chip includes a nonlinear mask transformation method for counteracting DPA / template attacks during the access process, ensuring that no plaintext is present during the entire data transfer process.

[0020] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a structural framework diagram of the encryption device specifically implemented in the present invention.

[0022] Figure 2 It is a structural diagram of an encryption circuit specifically implemented in the present invention.

[0023] Figure 3 This is a structural diagram of a round encryption circuit specifically implemented in the present invention.

[0024] Figure 4It is a diagram illustrating the steps of the encryption method specifically implemented by the present invention.

[0025] Figure 5 This is a diagram illustrating the first round of encryption in the encryption method specifically implemented by the present invention. DETAILED DESCRIPTION

[0026] See Figure 1 , which is a structural framework diagram of an encryption device specifically implemented in the present invention. In this non-volatile memory encryption device used in a security chip, a host device 100 accesses non-volatile memory 400 in ciphertext form via bus 200 and encryption circuit 300. In this encryption device, host device 100 can be a CPU, or other processor such as a DSP or DMA. Encryption circuit 300 includes a round encryption circuit 301 and an encryption sequence generator 302.

[0027] See Figure 2 , which is a structural diagram of an encryption circuit according to a specific embodiment of the present invention. This encryption circuit, used in a non-volatile memory encryption device in a security chip, comprises an encryption circuit 300 comprising four round encryption circuits 301 and an encryption sequence generator 302. The four round encryption circuits 301 are divided into a first round encryption circuit 301a, a second round encryption circuit 301b, a third round encryption circuit 301c, and a fourth round encryption circuit 301d, and are connected sequentially. The encryption sequence generator 302 is connected to each of the four round encryption circuits 301.

[0028] See Figure 3 , which is a structural diagram of a round encryption circuit according to a specific embodiment of the present invention. This round encryption circuit (301a, 301b, 301c, or 301d) is used in a non-volatile memory encryption device in a security chip. Each round encryption circuit (301a, 301b, 301c, or 301d) is divided into five layers of round encryption units: a first layer, a second layer, a third layer, a fourth layer, and a fifth layer. Each layer of round encryption units includes four components: a key addition unit AK, a nonlinear operation unit NL, a linear operation unit L, and a permutation operation unit P. Figure 3In the embodiment, the round encryption circuit 301a is divided into five layers of round encryption units, which are respectively a first layer round encryption unit 310, a second layer round encryption unit 320, a third layer round encryption unit 330, a fourth layer round encryption unit 340 and a fifth layer round encryption unit 350; the first layer round encryption unit 310 includes four components: a key addition operation unit AK311, a nonlinear operation unit NL312, a linear operation unit L313 and a permutation operation unit P314; the second layer round encryption unit 320 includes four components: a key addition operation unit AK321, a nonlinear operation unit NL322, a linear operation unit L323 and a permutation operation unit P314. The fourth-layer round encryption unit 340 includes four components: a key addition operation unit AK341, a nonlinear operation unit NL342, a linear operation unit L343 and a permutation operation unit P344; the fifth-layer round encryption unit 350 includes four components: a key addition operation unit AK351, a nonlinear operation unit NL352, a linear operation unit L353 and a permutation operation unit P354.

[0029] See Figure 3When the encryption device performs encryption, the input data passes through the main device 100 and becomes bus data after passing through the bus 200. The bus data is input to the encryption circuit 300 and is processed into a bus mask. The bus mask is input to the first round encryption unit 310 in the round encryption circuit 301a. The key addition operation unit AK311 and the nonlinear operation unit NL312 in the first round encryption unit 310 include mask operations and perform nonlinear transformation of the bus mask. At the same time, the round encryption circuit 301a selects each layer (the first round encryption unit 310, the second round encryption unit 320, the third round encryption unit 330, the fourth round encryption unit 340, or the fifth round encryption unit 350) of the five round encryption units (the first round encryption unit 310, the second round encryption unit 320, the third round encryption unit 330, the fourth round encryption unit 340, or the fifth round encryption unit 350) of the round encryption circuit 301a according to the low bit of the encryption key input externally. The four components of the round encryption unit (first round encryption unit 310, second round encryption unit 320, third round encryption unit 330, fourth round encryption unit 340, or fifth round encryption unit 350) are key addition unit AK, nonlinear operation unit NL, linear operation unit L, and permutation operation unit P. The four components of the round encryption unit (first round encryption unit 310, second round encryption unit 320, third round encryption unit 330, fourth round encryption unit 340, or fifth round encryption unit 350) execute the encryption sequence according to the output value of the encryption sequence generator 302. When each round encryption unit performs encryption, only one of the components is effective. Each round encryption unit must include a key addition unit AK and a nonlinear operation unit NL to perform encryption. When the round encryption circuit 301 performs encryption, the first round encryption circuit 301a starts to perform encryption, and then the second round encryption circuit 301b, the third round encryption circuit 301c, and the fourth round encryption circuit 301d are used. The encryption is performed sequentially. After the encryption process is completed, the fourth round encryption circuit 301d inputs the encrypted ciphertext output into the non-volatile memory 400, completing the encryption process.

[0030] See Figure 4, which is a diagram illustrating the steps of the encryption method specifically implemented in the present invention. The encryption method of the present invention for a non-volatile memory encryption device in a security chip, the encryption device includes a main device, a bus, a non-volatile memory, and an encryption circuit. The encryption circuit includes four round encryption circuits and an encryption sequence generator. The four round encryption circuits are divided into a first round encryption circuit, a second round encryption circuit, a third round encryption circuit, and a fourth round encryption circuit, and are connected in sequence. The encryption sequence generator is connected to each of the four round encryption circuits. Each round encryption circuit is divided into five layers of round encryption units. The five layers of round encryption units are respectively a first layer of round encryption units, a second layer of round encryption units, a third layer of round encryption units, a fourth layer of round encryption units, and a fifth layer of round encryption units. Each layer of round encryption units includes four components: a key addition operation unit, a nonlinear operation unit, a linear operation unit, and a permutation operation unit. The specific steps of the encryption method are as follows:

[0031] Step 1: First, when the encryption device performs encryption, the input data passes through the master device and becomes bus data after passing through the bus. The bus data is input into the encryption circuit and processed into a bus mask. The bus mask is input into the first round encryption unit in the round encryption circuit.

[0032] Step 2: At the same time, the round encryption circuit selects the components of each round encryption unit in the five layers of the round encryption circuit according to the low bit of the externally input encryption key, and the key addition unit, nonlinear operation unit, linear operation unit and permutation operation unit in each round encryption unit execute the encryption sequence according to the output value of the encryption sequence generator. When each round encryption unit performs encryption, only one of the components is effective, and each round encryption unit must contain a key addition unit and a nonlinear operation unit to perform encryption;

[0033] Step 3: Based on the selection result of step 2, perform the first round encryption unit operation. The input of the first round encryption unit operation is the first input data input_round of the round encryption circuit, and the first output data of the first round encryption unit operation is output_layer1.

[0034] Step 4: Based on the selection result of step 2, a second-layer round encryption unit operation is performed. The second input data of the second-layer round encryption unit operation is input_layer2, and the output data of the second-layer round encryption unit operation is output_layer2. At the same time, the second input data value of the second-layer round encryption unit operation is equal to the first output data value of the first-layer round encryption unit operation, that is, input_layer2 = output_layer1;

[0035] Step 5: Based on the selection result of step 2, a third-layer round encryption unit operation is performed. The third input data of the third-layer round encryption unit operation is input_layer3, and the output data of the third-layer round encryption unit operation is output_layer3. At the same time, the third input data value of the third-layer round encryption unit operation is equal to the second output data value of the second-layer round encryption unit operation, that is, input_layer3 = output_layer2;

[0036] Step 6: Based on the selection result of step 2, a fourth-layer round encryption unit operation is performed. The fourth input data of the fourth-layer round encryption unit operation is input_layer4, and the output data of the fourth-layer round encryption unit operation is output_layer4. At the same time, the fourth input data value of the fourth-layer round encryption unit operation is equal to the third output data value of the third-layer round encryption unit operation, that is, input_layer4 = output_layer3;

[0037] Step 7: Based on the selection result of step 2, a fifth-layer round encryption unit operation is performed. The input of the fifth-layer round encryption unit operation is the fifth input data input_layer5. The output of the fifth-layer round encryption unit operation is the output result of the fifth-layer round encryption unit operation. At the same time, the fifth input data value of the fifth-layer round encryption unit operation is equal to the fourth output data value of the fourth-layer round encryption unit operation, that is, input_layer5=output_layer4. The output of the fifth-layer round encryption unit operation is the output of the round encryption circuit operation of this round.

[0038] Step 8: When the round encryption circuit performs encryption, the first round encryption circuit starts to perform the encryption steps from step 2 to step 7 above. The second round encryption circuit, the third round encryption circuit and the fourth round encryption circuit perform the encryption steps from step 2 to step 7 in sequence. After the encryption process is completed, the fourth round encryption circuit inputs the encrypted output ciphertext into the non-volatile memory to complete the encryption process.

[0039] See Figure 4 , is a diagram illustrating the steps of the encryption method specifically implemented in the present invention. The encryption method of the present invention for the non-volatile memory encryption device in the security chip, such as Figure 4 As shown, in step 2, the lower 10 bits of the input encryption key are 2'b 11_00_01_11_00, and the effective components of this round of operation are: permutation operation unit P314, key addition operation unit AK321, nonlinear operation unit NL332, permutation operation unit P344 and linear operation unit L353.

[0040] In step 3, the component permutation operation unit P314 is an effective component of the first round encryption unit, that is, the input data is permuted. After P permutation, the i-th bit of the input data is replaced by the P(i)-th bit of the output data, as shown in Table 1:

[0041] i 0 1 2 3 4 5 6 7 P(i) 0 8 16 24 1 9 17 25 i 8 9 10 11 12 13 14 15 P(i) 2 10 18 26 3 11 19 27 i 16 17 18 19 20 21 22 23 P(i) 4 12 20 28 5 13 21 29 i 24 25 26 27 28 29 30 31 P(i) 6 14 22 30 7 15 23 31

[0042] In step 4, the component key addition operation unit AK321 is a valid component, and the second-layer round encryption unit operation is key addition, that is, the output of the second-layer round encryption unit Output_layer2 = key_h xor input_layer2;

[0043] In step 5, the nonlinear operation unit NL332 is a valid component, and the third-layer round encryption unit performs a nonlinear operation. In this specific embodiment, the nonlinear operation is SBOX permutation, that is, the output of the third-layer round encryption unit Output_layer3 = Sbox (input_layer3). Taking a 4x4 Sbox operation as an example, the input is 4-bit data and the output is 4-bit data. The input and output relationship of Sbox is shown in Table 2:

[0044] x 0 1 2 3 4 5 6 7 Sbox(x) A 7 5 F 1 3 0 C x 8 9 A B C D E F Sbox(x) D E 9 8 B 6 2 4

[0045] When the input data is more than 4 bits, the layer operation is implemented in a splicing manner; for example, if the bus data width is 32 bits, 8 4x4 SBOX operations are required; Output_layer3[3:0] = Sbox(input_layer3[3:0]), Output_layer3[7:4] = Sbox (input_layer3[7:4])...Output_layer3[31:28] = Sbox(input_layer3[31:28]).

[0046] In step 6, the component permutation operation unit P344 is a valid component, and the fourth-layer round encryption unit operation is a permutation operation. The operation method is the same as step 3. The i-th bit of the input data is replaced by the P(i)-th bit of the output data after P permutation. The generation method of P(i) can be the same as that in Table 1 or different from that in Table 1.

[0047] Finally, in step 7, the component linear operation unit L353 is a valid component, and the fifth-layer round encryption unit operation is a linear operation. The operation formula can be used as follows:

[0048] Output_layer5=L(input_layer5)=(input_layer5<<7)xor (input_layer5<<23)xor(input_layer5>>13), the output of this round is Output_layer5.

[0049] In the first-round encryption circuit, the first-layer round encryption unit and the second-layer round encryption unit are the key addition operation unit AK and the nonlinear operation unit NL, respectively. At this time, the nonlinear operation unit NL has the function of removing the bus mask. Therefore, the input data is the plaintext after the bus mask. The output data after the operation of the second-layer round encryption unit no longer carries the bus plaintext information, but is encrypted intermediate data. Therefore, during the encryption process of the first-round encryption circuit, no plaintext appears throughout the entire process.

[0050] See also Figure 5 The figure shows the steps of the first-round encryption circuit encryption method implemented in the present invention. In this encryption method, the input bus plaintext is defined as P and the bus mask is defined as BM. Therefore, the bus data input of the first-round encryption circuit is PBM = P^BM. The high-order bits of the encryption key of the first-round encryption circuit are Key_h. The key addition operation unit AK311 is implemented as follows:

[0051] Output_layer1=AK111(PBM,Key_h)=P^BM^Key_h;

[0052] The second round encryption unit operates the nonlinear operation unit NL322, still taking the 4X4sbox as an example:

[0053] Output_layer2=SBox_m(Output_layer1)=SBox_m(P^BM^ Key_h)=Sbox(P^Key_h),

[0054] When BM[3:0]=4'h1, the implementation of SBox_m(x) is shown in Table 3, and the implementation of the corresponding SBox is shown in Table 3.

[0055]

[0056]

[0057] Table 3 4x4 S-box Sbox_m when M=4'h1 after introducing random mask

[0058] The present invention is applicable not only to non-volatile memories, but also to storage units such as RAM and ROM. Moreover, in the present invention, the number of rounds, the number of layers per round, the bus width and the key length can be replaced with other values.

[0059] The present invention is not limited to the embodiments discussed above, and the above description of the specific embodiments is intended to describe and illustrate the technical solutions involved in the present invention. Based on the obvious transformations or substitutions inspired by the present invention, for example, the linear transformation scheme is the truncation, shifting and XOR operation of the operands; different truncation bits, different shift bits, different XOR numbers; including but not limited to nonlinear transformation methods, such as SBOX, addition, etc., should also be considered to fall within the scope of protection of the present invention; the above specific embodiments are used to reveal the best implementation method of the present invention, so that ordinary technicians in this field can apply the various embodiments of the present invention and various alternatives to achieve the purpose of the present invention.

Claims

1. A non-volatile memory encryption device for a security chip, characterized in that: include: An encryption circuit and a non-volatile memory; the encryption circuit includes a plurality of sequentially connected round encryption circuits and a single encryption sequence generator, and each of the round encryption circuits includes multiple layers of round encryption units; each layer of the round encryption units includes: a key addition operation unit, a nonlinear operation unit, a linear operation unit, and a permutation operation unit; The encryption order generator is used to determine the unit components for performing encryption operations in each layer of the round encryption units according to the low-bit selection of the external input key, and determine the execution order of the round encryption units in each layer; The non-volatile memory is used to receive the encrypted ciphertext after the encryption operation is completed; The multi-layer round encryption unit includes: a first-layer round encryption unit, a second-layer round encryption unit, a third-layer round encryption unit, a fourth-layer round encryption unit, and a fifth-layer round encryption unit; when the round encryption unit in each layer performs the encryption operation, only one unit component is effective; The multiple sequentially connected round encryption circuits include: a first-round encryption circuit, a second-round encryption circuit, a third-round encryption circuit, and a fourth-round encryption circuit; the first-round encryption circuit, the second-round encryption circuit, the third-round encryption circuit, and the fourth-round encryption circuit perform encryption operations in sequence, and the fourth-round encryption circuit sends the encrypted ciphertext after completing the encryption operation to the non-volatile memory.

2. The device according to claim 1, characterized in that The input of the first round encryption unit operation is the first input data of the round encryption circuit of this round, and the output of the first round encryption unit operation is the first output data; The second round encryption unit operates on second input data, and the second round encryption unit operates on second output data; the data value of the second input data is the same as the data value of the first output data; The third round encryption unit operates on third input data, and the third round encryption unit operates on third output data; the data value of the third input data is equal to the data value of the second output data; The fourth round encryption unit operates on fourth input data, and the fourth round encryption unit operates on fourth output data; the data value of the fourth input data is equal to the data value of the third output data; The fifth round encryption unit operates on the fifth input data, and the fifth round encryption unit operates and outputs the fifth output data; the data value of the fifth input data is equal to the data value of the fourth output data, and the fifth output data is the output of the current round encryption circuit operation.

3. The device according to claim 1, characterized in that Also includes: Master device and bus; The master device is configured to convert input data into bus data via the bus, and transmit the bus data to the encryption circuit; The encryption circuit is configured to process the bus data to obtain a bus mask, and send the bus mask to the first round encryption unit; The first-layer round encryption unit is configured to perform mask operation and nonlinear transformation processing on the bus mask through the key addition operation unit and the nonlinear operation unit.

4. An encryption method for a non-volatile memory encryption device in a security chip, characterized in that: The encryption device comprises: an encryption circuit and a non-volatile memory; the encryption circuit comprises a plurality of sequentially connected round encryption circuits and a single encryption sequence generator, and each of the round encryption circuits comprises multiple layers of round encryption units; each layer of the round encryption units comprises: a key addition operation unit, a nonlinear operation unit, a linear operation unit, and a permutation operation unit; The method comprises: Controlling the encryption sequence generator to determine, based on the low-order bit selection of the external input key, the unit components for performing encryption operations in the round encryption units of each layer, and determining the activation order of the round encryption units of each layer; Controlling the non-volatile memory to receive the encrypted ciphertext after the encryption operation is completed; The multi-layer round encryption unit includes: a first-layer round encryption unit, a second-layer round encryption unit, a third-layer round encryption unit, a fourth-layer round encryption unit, and a fifth-layer round encryption unit; when the round encryption unit in each layer performs the encryption operation, only one unit component is effective; The multiple sequentially connected round encryption circuits include: a first-round encryption circuit, a second-round encryption circuit, a third-round encryption circuit, and a fourth-round encryption circuit; the first-round encryption circuit, the second-round encryption circuit, the third-round encryption circuit, and the fourth-round encryption circuit perform encryption operations in sequence, and the fourth-round encryption circuit sends the encrypted ciphertext after completing the encryption operation to the non-volatile memory.

5. The method according to claim 4, characterized in that The input of the first round encryption unit operation is the first input data of the round encryption circuit of this round, and the output of the first round encryption unit operation is the first output data; The second round encryption unit operates on second input data, and the second round encryption unit operates on second output data; the data value of the second input data is the same as the data value of the first output data; The third round encryption unit operates on third input data, and the third round encryption unit operates on third output data; the data value of the third input data is equal to the data value of the second output data; The fourth round encryption unit operates on fourth input data, and the fourth round encryption unit operates on fourth output data; the data value of the fourth input data is equal to the data value of the third output data; The fifth round encryption unit operates on the fifth input data, and the fifth round encryption unit operates and outputs the fifth output data; the data value of the fifth input data is equal to the data value of the fourth output data, and the fifth output data is the output of the current round encryption circuit operation.

6. The method according to claim 4, characterized in that The encryption device further includes: a host device and a bus; the method further includes: controlling the master device to convert input data into bus data via the bus, and transmitting the bus data to the encryption circuit; Controlling the encryption circuit to process the bus data to obtain a bus mask, and sending the bus mask to the first round encryption unit; The first-layer round encryption unit is controlled to perform mask operation and nonlinear transformation processing on the bus mask through the key addition operation unit and the nonlinear operation unit.

Citation Information

Patent Citations

  • Encryption device for nonvolatile memory in security chip

    CN208848200U