SM4 Encryption Circuit and Method for Implementing SM4 Encryption Operation

By completing multiple rounds of SM4 algorithm iterations in a single clock cycle, and using multiple rounds of keys and ciphertext generation operation units, the problem of large delay in the existing SM4 algorithm encryption circuit is solved, and a more efficient data encryption process is achieved.

CN112152781BActive Publication Date: 2025-06-10BEIJING STARBLAZE TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201910577949.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-06-28
Publication Date
2025-06-10
Estimated Expiration
2039-06-28

AI Technical Summary

Technical Problem

The existing SM4 algorithm encryption circuits have large delays in the encryption and decryption process, especially when processing larger sizes of data, resulting in increased system difficulty or complexity.

Method used

By completing two or more iterations defined by the SM4 algorithm in a single clock cycle, multiple round key generation operation units and ciphertext generation operation units are used to generate multiple round keys and ciphertext parameters in each round of iterations, reducing the overall delay of the encryption process.

Benefits of technology

It effectively reduces the overall delay in the encryption/decryption process of the SM4 algorithm, improves the efficiency of the data processing system, and especially reduces the complexity of the system when processing big data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112152781B_ABST
    Figure CN112152781B_ABST
Patent Text Reader

Abstract

This application relates to an encryption circuit for the SM4 algorithm and a method for implementing the SM4 encryption operation. The disclosed encryption device includes: a round key generation component and a ciphertext operation component; the round key generation component includes N serially connected round key generation operation units that generate N round key parameters in one round of iteration, where N >= 2; the ciphertext operation component includes N serially connected ciphertext generation operation units that generate N ciphertext parameters in one round of iteration. This application defines that two or more rounds of iteration are completed within a single clock cycle, and multiple rounds of iteration are calculated within each clock cycle, thereby reducing the overall latency of the encryption / decryption process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security, and in particular to an encryption circuit for an SM4 algorithm and a method for implementing an SM4 encryption operation. Background Art

[0002] The SM4 algorithm is a standard cryptographic algorithm provided by the State Cryptography Administration. The block length used by the SM4 algorithm is 128 bits, and the key length is also 128 bits. Both the encryption algorithm and the key expansion algorithm use a 32-round nonlinear iterative structure, and perform encryption operations in units of words (32 bits). Each iterative operation is a round of the transformation function F. The structure of the SM4 algorithm encryption / decryption algorithm is the same, except that the round keys used are opposite, where the decryption round key is the reverse order of the encryption round key.

[0003] Taking the encryption process as an example, when calculating each group, the input of the SM4 algorithm includes 128 bits of plaintext (denoted as X). X(i) represents 32 bits (4 bytes) of data, which comes from the plaintext X or the result of calculating the plaintext X. The input of the SM4 algorithm also includes an encryption key (denoted as MK) with a length of 128 bits. The encryption key KM is divided into 4 parts, denoted as MK0, MK1, MK2 and MK3, and the length of each part is 32 bits. The round key (denoted as rk(i), where i is an integer from 0 to 31) is generated from the encryption key MK. The SM4 algorithm performs 32 rounds of encryption on each 128-bit group. In the i-th round of encryption, the round key rk(i) is used.

[0004] The SM4 algorithm also uses system parameters FK = (FK0, FK1, FK2, FK3) and fixed parameters CK = (CK0, CK1, ....., CK31), where the length of FK0, FK1, FK2 and FK3 is 32 bits, and the length of each of CK0, CK1, ....., CK31 is also 32 bits.

[0005] Figure 1 A block diagram of an encryption device according to the SM4 algorithm is shown.

[0006] The encryption process of each group in the SM4 algorithm includes 32 rounds of iterations. In each round of iteration, a round key rk(i) is generated; and the round key rk(i) of the round is used to encrypt the calculation result of the plaintext in the round. The encrypted result of the 32nd round is transformed to obtain the encrypted ciphertext.

[0007] Figure 1 The encryption device includes a round key generating device (left side) and a ciphertext generating device (right side).

[0008] The round key generating device takes the encryption key MK as input, obtains the system parameter FK and the fixed parameter CK, and generates a round key rk(i) in each of 32 rounds of iterations and provides it to the ciphertext generating device.

[0009] The round key generation apparatus includes an XOR unit 110 , an XOR unit 120 , an S-box transformation unit 130 , a linear transformation unit 140 and an XOR unit 150 .

[0010] See also Figure 1 Before starting to encrypt the 128-bit group, the XOR unit 110 performs an XOR operation on the encryption key MK and the system parameter FK to obtain the parameter K. The parameter K used in the i-th iteration is recorded as (K(i), K(i+1), K(i+2), K(i+3)). The parameter K output by the XOR unit 110 is the parameter K(0), K(1), K(2), K(3)) used in the 0th iteration, K0=MK0^FK0, K1=MK1^FK1, K2=MK2^FK2, K3=MK3^FK3.

[0011] In each round of iteration, the XOR unit 120 calculates K(i+1)^K(i+2)^K(i+3)^CK(i), where "^" represents an XOR operation. The S-box transformation unit 130 performs an S-box transformation on the result of K(i+1)^K(i+2)^K(i+3)^CK(i), the linear transformation unit 140 performs a linear transformation on the output of the S-box transformation unit 130, and the XOR unit 150 performs an XOR operation on the output of the linear transformation unit 140 and K(i), and the result of the output of the XOR unit 150 is the parameter K(i+4), which serves as the round key rk(i) of this round (rk(i)=K(i+4)). The encryption key MK is XORed with the system parameter FK, and the S-box transformation performed by the S-box transformation unit 130 and the linear transformation performed by the linear transformation unit 140 in each round of iteration are operations defined in the SM4 algorithm standard and are known to those skilled in the art.

[0012] In the i-th iteration, the round key rk(i), i.e., the parameter K(i+4), is generated and used as the parameter K in the i+1-th iteration. The parameter K used in the i+1-th iteration is recorded as (K(i+2), K(i+3), K(i+4)), where K(i+2) and K(i+3) are the parameters used in the i-th iteration, and the parameter K(i+1+4) generated in the i+1-th iteration (also recorded as K(5) as the round key rk(i+1)) is used as the parameter K in the i+2-th iteration. Thus, K(i+4) output by the XOR unit 150 is provided to the ciphertext generation device and also provided to the XOR unit 120.

[0013] The ciphertext generating apparatus includes an XOR unit 160 , an S-box transformation unit 170 , a linear transformation unit 180 and an XOR unit 190 .

[0014] The ciphertext generating device obtains the 128-bit plaintext X to be encrypted and the round key rk(i) provided by the round key generating device as input.

[0015] The plaintext X is divided into four parts, denoted as X(0), X(1), X(2) and X(3), and the size of each part is 32 bits.

[0016] In the i-th round iteration, the XOR unit 160 performs an XOR operation on X(i+1), X(i+2), X(i+3) and rk(i), and the result is provided to the S-box unit 170. In the 0th round, X(1), X(2) and X(3) to be processed by the XOR unit 160 come from the input plaintext X, and rk(0) comes from K(4) provided by the round key generation device; in the i-th round iteration (i>=1), X(i+1) and X(i+2) to be processed by the XOR unit 160 have been provided to the XOR unit 160 in the previous round iteration, and X(i+3) comes from the output of the XOR unit 190 in the previous round iteration. Therefore, the output of the XOR unit 190 is coupled to the input of the XOR unit 160. In the i-th round iteration, rk(i) comes from K(i+4) provided by the round key generation device.

[0017] The S-box transformation unit 170 performs an S-box transformation on the result of X(i+1)^X(i+2)^X(i+3)^rk(i), the linear transformation unit 180 performs a linear transformation on the output of the S-box transformation unit 170, and the XOR unit 190 performs an XOR operation on the output of the linear transformation unit 180 and X(i), and the result of the output of the XOR unit 190 is X(i+4), which is provided to the XOR unit 160 for the next round of iteration. The S-box transformation performed by the S-box transformation unit 170 and the linear transformation performed by the linear transformation unit 180 in each round of iteration are operations defined in the SM4 algorithm standard and are known to those skilled in the art.

[0018] As an example, in each round of iteration, the ciphertext generating device waits for and uses the round key rk(i) for the round generated by the round key generating device.

[0019] After the 31st round of iteration is completed, the XOR unit 190 outputs X(35), which together with X(32), X(33) and X(34) obtained in the previous round of iteration constitutes the 128-bit ciphertext Y obtained by encrypting the plaintext X.

[0020] Understandably, Figure 1 Each unit of the encryption device shown in the figure can be implemented by an integrated circuit, a processor running a program, a programmable gate array, etc.

[0021] Figure 1 XOR unit 120, S-box transformation unit 130, linear transformation unit 140, XOR unit 150, XOR unit 160, S-box transformation unit 170, linear transformation unit 180 and XOR unit 190 are calculated once in each round of iteration, and these calculation units are reused in each round of iteration, which reduces the chip area required for implementing the encryption device on the integrated circuit chip, but requires at least 32 clock cycles to calculate each round of iteration, and the next round of iteration must use the calculation result of the previous round of iteration, which increases the delay of the encryption process. And for larger-sized data, it is split into multiple 128-bit groups during the encryption process, and 32 clock cycles are required for each group, so that for larger-sized data blocks, the encryption process introduces too large a delay. The same problem also exists in the decryption process. Summary of the invention

[0022] The encryption / decryption device is used as a component of a data processing system. The overall delay of data processing is the sum of the processing delays of each component of the data processing system. Some application scenarios require the lowest possible delay. If the encryption / decryption device takes up much processing time, the processing delay of other components needs to be reduced, which increases the difficulty or complexity of the data processing system. Therefore, it is desirable to reduce the processing delay of the encryption / decryption device.

[0023] As semiconductor technology improves, the switching speed of transistors becomes faster, so the time required for the circuit to process the same calculation becomes shorter, while the complexity of the calculation that can be completed in the same time becomes larger. According to an embodiment of the present application, two or more rounds of iterations defined by the SM4 algorithm are completed in a single clock cycle, and multiple rounds of iterations are calculated in each clock cycle, thereby reducing the overall delay of the encryption / decryption process of the SM4 algorithm.

[0024] According to a first aspect of the present application, a first encryption device according to the first aspect of the present application is provided, comprising: a round key generation component and a ciphertext operation component; the round key generation component comprises N round key generation operation units connected in series, generating N round key parameters in one round of iteration, N>=2; the ciphertext operation component comprises N ciphertext generation operation units connected in series, generating N ciphertext parameters in one round of iteration; in one round of iteration: the i-th round key parameter output by the i-th round key generation operation unit of the multiple round key generation operation units is provided to the i+1-th round key generation operation unit of the multiple round key generation operation units, so that the i+1-th round key generation operation unit outputs the i+1-th round key parameter of this round of iteration; wherein i is a positive integer and 0 <i<=N,代表了轮密钥生成运算单元在串连的所述多个轮密钥生成运算单元的排序位置;所述多个轮密钥生成运算单元的最后一个轮密钥生成运算单元的输出的本轮迭代的最后一轮密钥参数被提供给所述多个轮密钥生成运算单元的最前一个轮密钥生成运算单元,以进行下一轮的轮密钥参数的生成;所述第i轮密钥生成运算单元的输出的所述第i轮密钥参数被作为轮密钥提供给所述第i密文生成运算单元;所述第i+1轮密钥生成运算单元的输出的所述第i+1轮密钥参数被作为轮密钥提供给所述第i+1密文生成运算单元;所述多个密文生成运算单元的第i密文生成运算单元输出的第i密文参数被提供给所述多个密文生成运算单元的第i+1密文生成运算单元,以使所述第i+1密文生成运算单元输出第i+1密文参数;所述多个密文生成运算单元的最后一个密文生成运算单元输出的本轮最后一个密文参数被提供给所述多个密文生成运算单元的的最前密文生成运算单元。

[0025] According to the first encryption device of the first aspect of the present application, a second encryption device according to the first aspect of the present application is provided, wherein, if the last ciphertext parameter of this round output by the last ciphertext generation operation unit of the multiple ciphertext generation operation units is the parameter output of the last round, then the last ciphertext parameter together with the first three ciphertext parameters sequentially iterated with the last ciphertext parameter constitute the ciphertext output.

[0026] According to the first or second encryption device of the first aspect of the present application, a third encryption device according to the first aspect of the present application is provided, wherein, if the first round key generation unit of the multiple round key generation operation units starts the generation of the first round round key parameters, then the first round round key initial parameters are obtained by the XOR operation of the first XOR unit in the round key generation component that is connected in series before the multiple round key generation operation units, and are provided to the first round key generation unit.

[0027] According to the third encryption device of the first aspect of the present application, a fourth encryption device according to the first aspect of the present application is provided, wherein the first XOR unit performs an XOR operation on the encryption key and the system parameter to obtain the initial parameter of the first-round round key.

[0028] According to one of the first to fourth encryption devices of the first aspect of the present application, a fifth encryption device according to the first aspect of the present application is provided, wherein if the first ciphertext generation operation unit among the plurality of round key generation operation units enables the iteration of the first-round ciphertext parameter, the initial parameter of the first-round ciphertext is the plaintext to be encrypted.

[0029] According to the second aspect of the present application, a first encryption device according to the second aspect of the present application is provided, comprising: a round key generation component and a ciphertext operation component; the round key generation component comprises N round key generation operation units connected in series, generating N round key parameters in one round of iteration, N>=2; the ciphertext operation component comprises N ciphertext generation operation units connected in series, generating N ciphertext parameters in one round of iteration; the round key generation component and the ciphertext operation component each perform i-1 rounds of iteration, i is an integer; the j-th round key generation operation unit of the multiple round key generation operation units outputs the j-th round key parameter K(N*i+j+3) of the i-th round and provides it to the j+1-th round key generation unit, so that the j+1-th round key generation operation unit outputs the j+1-th round key parameter K(N*i+j+4) of the i-th round iteration; wherein j is a positive integer and 0 <j<=N,代表了轮密钥生成运算单元在串连的所述多个轮密钥生成运算单元的排序位置;所述多个轮密钥生成运算单元的最后一个轮密钥生成运算单元输出的第i轮的第N个轮密钥参数K(N*i+N+3)被提供给所述多个轮密钥生成运算单元的第一个轮密钥生成运算单元,以作为密钥参数K(N(i+1)+3)开启第i+1轮轮密钥参数的迭代;所述多个密文生成运算单元的第j轮密文生成运算单元输出的第i轮第j个密文参数X(N*i+j+3)被提供给所述多个密文生成单元的第j+1密文生成运算单元;所述第j轮密钥生成运算单元的输出的所述第i轮的第j个轮密钥参数K(N*i+j+3)被作为轮密钥rk(n*i+j-1)提供给所述第j密文生成运算单元;所述第j+1轮密钥生成运算单元的输出的所述第i轮的第j+1个轮密钥参数K(N*i+j+4)被作为轮密钥rk(n*i+j)提供给所述第j+1密文生成运算单元;所述多个密文生成运算单元的最后一个密文生成运算单元的输出的密文参数X(N*i+N+3)被提供给所述多个密文生成运算单元的最前一个密文生成运算单元,以作为密文参数X(N(i+1)+3)开启第i+1轮密文参数的迭代;其中,K为轮密钥参数,X为密文参数,rk为轮密钥、i为轮数。

[0030] According to the third aspect of the present application, there is provided a first encryption method according to the third aspect of the present application, including the following steps: The first round key parameter K(2*i + 4) output by the first set of round key generation operation units is provided to the second set of round key generation units, so that the second set of round key generation operation units output the second round key parameter K(2*i + 5) of the i-th round iteration; The second round key parameter K(2*i + 5) output by the second set of round key generation operation units is provided to the first set of round key generation operation units to start the iteration of the (i + 1)-th round key parameter as the key parameter K(2(i + 1) + 3); The first ciphertext parameter X(2*i + 4) output by the first set of ciphertext generation operation units is provided to the second set of ciphertext generation units, and the round key parameter K(2*i + 5) output by the second set of round key generation operation units is provided to the second set of ciphertext generation units as the round key rk(2*i + 1), so that the second set of ciphertext generation units output the second ciphertext parameter X(2*i + 5) of the i-th round; The ciphertext parameter X(2*i + 5) output by the second set of ciphertext generation units is provided to the first set of ciphertext generation units to start the iteration of the (i + 1)-th round ciphertext parameter as the ciphertext parameter X(2(i + 1) + 3); where, K is the round key parameter, X is the ciphertext parameter, rk is the round key, and i is the number of rounds.

[0031] According to the first encryption method of the third aspect of the present application, there is provided a second encryption method according to the third aspect of the present application, wherein the first set of round key generation units calculates K(2*i + 1) ^ K(2*i + 2) ^ K(2*i + 3) ^ CK(2*i), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an exclusive OR operation on the parameter after the linear transformation with the round key parameter K(2*i) to obtain the first round key parameter K(2*i + 4) of the i-th round; where, CK is a fixed parameter.

[0032] According to the second encryption method of the third aspect of the present application, there is provided a third encryption method according to the third aspect of the present application, wherein the round key parameter K(2*i + 4) generated by the first set of round key generation units is provided to the first set of ciphertext generation units as the first round key rk(2*i) of the i-th round, so that the first set of ciphertext generation units output the first ciphertext parameter X(2*i + 4) of the i-th round.

[0033] According to one of the first to third encryption methods of the third aspect of the present application, a fourth encryption method of the third aspect of the present application is provided. Among them, if i = 0, the round key parameters K(2*i), K(2*i + 1), K(2*i + 2), K(2*i + 3) used by the first set of round key generation units are K(0), K(1), K(2), K(3); K(0), K(1), K(2), K(3) are obtained by exclusive-or operation of the first exclusive-or unit and provided to the first set of round key generation units.

[0034] According to the fourth encryption method of the third aspect of the present application, a fifth encryption method of the third aspect of the present application is provided. Among them, the first exclusive-or unit performs an exclusive-or operation on the encryption key MK and the system parameter FK to obtain the round key parameters K(0), K(1), K(2), K(3).

[0035] According to one of the second to fifth encryption methods of the third aspect of the present application, a sixth encryption method of the third aspect of the present application is provided. Among them, the second set of round key generation units calculates K(2*i + 2) ^ K(2*i + 3) ^ K(2*i + 4) ^ CK(2*i + 2), performs an S-box transformation on the calculated parameters, performs a linear transformation on the parameters after the S-box transformation, and performs an exclusive-or operation on the parameters after the linear transformation with the round key parameter K(2*i + 1) to obtain the second round key parameter K(2*i + 5) of this round.

[0036] According to one of the first to sixth encryption methods of the third aspect of the present application, a seventh encryption method of the third aspect of the present application is provided. Among them, the second set of round key generation units directly uses the output of the first set of round key generation operation units for exclusive-or operation; the first set of round key generation units directly uses the output of the second set of round key generation operation units for exclusive-or operation.

[0037] According to one of the first to seventh encryption methods of the third aspect of the present application, an eighth encryption method of the third aspect of the present application is provided. Among them, the first set of round key generation units and the second set of round key generation units complete the output of the round keys within a predetermined iteration time interval.

[0038] According to one of the first to eighth encryption methods of the third aspect of the present application, a ninth encryption method of the third aspect of the present application is provided. Among them, the first set of ciphertext generation units calculates X(2*i + 1) ^ X(2*i + 2) ^ X(2*i + 3) ^ rk(2*i), performs an S-box transformation on the calculated parameters, performs a linear transformation on the parameters after the S-box transformation, and performs an exclusive-or operation on the parameters after the linear transformation with the ciphertext parameter X(2*i) to obtain the first ciphertext parameter X(2*i + 4) of the i-th round.

[0039] According to one of the first to ninth encryption methods of the third aspect of the present application, the tenth encryption method of the third aspect of the present application is provided, wherein the second ciphertext generation unit calculates X(2*i + 2)^X(2*i + 3)^X(2*i + 4)^rk(2*i + 1), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an exclusive OR operation on the parameter after the linear transformation with the ciphertext parameter X(2*i + 1) to obtain the second ciphertext parameter X(2*i + 5) of the i-th round.

[0040] According to the ninth encryption method of the third aspect of the present application, the eleventh encryption method of the third aspect of the present application is provided, wherein if i = 0, the ciphertext parameters X(2*i), X(2*i + 1), X(2*i + 2), X(2*i + 3) used by the first ciphertext generation unit are X(0), X(1), X(2), X(3); X(0), X(1), X(2), X(3) are the input plaintext X.

[0041] According to one of the first to eleventh encryption methods of the third aspect of the present application, the twelfth encryption method of the third aspect of the present application is provided, wherein the first ciphertext generation unit and the second ciphertext generation unit complete the output of the ciphertext parameters within a predetermined iteration time interval.

[0042] According to one of the first to twelfth encryption methods of the third aspect of the present application, the thirteenth encryption method of the third aspect of the present application is provided, wherein the second ciphertext generation unit directly or at any time performs an exclusive OR operation on the output of the first ciphertext generation unit and the output of the second round key generation unit.

[0043] According to the fourth aspect of the present application, a first encryption method according to the fourth aspect of the present application is provided, including the following steps: The j-th round key parameter K(16*i + j + 4) output by one of the round key generation operation units from the 0th group to the 14th group is provided to the (j + 1)-th round key generation operation unit, so that the (j + 1)-th round key generation operation unit outputs the (j + 1)-th round key parameter K(16*i + (j + 1) + 4) of the i-th iteration; The sixteenth round key parameter K(16*i + 19) of the i-th iteration output by the 15th round key generation operation unit is provided to the first round key generation operation unit as the key parameter K(16*(i + 1) + j + 3) to start the iteration of the (i + 1)-th round key parameter; The j-th ciphertext parameter X(16*i + j + 4) of the i-th round output by one of the ciphertext generation operation units from the 0th group to the 14th group is provided to the (j + 1)-th ciphertext generation operation unit, and the round key parameter K(16*i + (j + 1) + 4) output by the (j + 1)-th round key generation operation unit is provided to the (j + 1)-th ciphertext generation operation unit as the round key rk(16*i + j + 1), so that the (j + 1)-th ciphertext generation operation unit outputs the (j + 1)-th ciphertext parameter X(16*i + (j + 1) + 4) of the i-th round; The sixteenth ciphertext parameter X(16*i + 19) of the i-th round output by the 15th ciphertext generation operation unit is provided to the first ciphertext generation operation unit of the (i + 1)-th round as the ciphertext parameter X(16*(i + 1) + j + 3) to start the iteration of the (i + 1)-th round ciphertext parameter; where, K is the round key parameter, X is the ciphertext parameter, rk is the round key, i is the number of rounds, j is the group number of the round key generation operation unit and the ciphertext generation operation unit, and 0 <= j <= 15.

[0044] According to the first encryption method of the fourth aspect of the present application, a second encryption method according to the fourth aspect of the present application is provided, wherein the j-th round key generation unit calculates K(16*i + j + 1) ^ K(16*i + j + 2) ^ K(16*i + j + 3) ^ CK(16*i + j), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an exclusive OR operation on the parameter after the linear transformation with the round fixed parameter CK(16*i + j) to obtain the j-th round key parameter K(16*i + j + 4) of the i-th round; where, CK is a fixed parameter.

[0045] According to the first or second encryption method of the fourth aspect of the present application, a third encryption method according to the fourth aspect of the present application is provided, wherein the round key parameter K(16*i + j + 4) generated by the j-th round key generation unit is provided to the j-th ciphertext generation unit as the j-th round key rk(16*i + j) of the i-th round, so that the j-th ciphertext generation unit outputs the j-th ciphertext parameter X(16*i + j + 4) of the i-th round.

[0046] According to the first or second encryption method of the fourth aspect of the present application, a fourth encryption method according to the fourth aspect of the present application is provided. Among them, if i = 0 and j = 0, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 0th group of round key generation units are K(0), K(1), K(2), K(3) respectively; K(0), K(1), K(2), K(3) are obtained by exclusive-or operation of the first exclusive-or unit and provided to the 0th group of round key generation units.

[0047] According to the first or second encryption method of the fourth aspect of the present application, a fifth encryption method according to the fourth aspect of the present application is provided. Among them, if i = 0 and j = 1, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 1st group of round key generation units are K(1), K(2), K(3), K(4) respectively; K(1), K(2), K(3) are obtained by exclusive-or operation of the first exclusive-or unit and provided to the 1st group of round key generation units; K(4) is the round key parameter output by the 0th group of round key generation units in the 0th round.

[0048] According to the first or second encryption method of the fourth aspect of the present application, a sixth encryption method according to the fourth aspect of the present application is provided. Among them, if i = 0 and j = 2, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 2nd group of round key generation units are K(2), K(3), K(4), K(5) respectively; K(2), K(3) are obtained by exclusive-or operation of the first exclusive-or unit and provided to the 2nd group of round key generation units; K(4) and K(5) are the round key parameters output by the 0th group of round key generation units and the 1st group of round key generation units in the 0th round respectively.

[0049] According to the first or second encryption method of the fourth aspect of the present application, a seventh encryption method according to the fourth aspect of the present application is provided. Among them, if i = 0 and j = 3, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 3rd group of round key generation units are K(3), K(4), K(5), K(6) respectively; K(3) is obtained by exclusive-or operation of the first exclusive-or unit and provided to the 3rd group of round key generation units; K(4), K(5), K(6) are the round key parameters output by the 0th group of round key generation units, the 1st group of round key generation units and the 2nd group of round key generation units in the 0th round respectively.

[0050] According to the first or second encryption method of the fourth aspect of the present application, the eighth encryption method according to the fourth aspect of the present application is provided, wherein, if i = 0 and j >= 4, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the j-th round key generation unit are respectively the round key parameters output by the (j - 4)-th, (j - 3)-th, (j - 2)-th, and (j - 1)-th round key generation units in the 0-th round.

[0051] According to the first or second encryption method of the fourth aspect of the present application, the ninth encryption method according to the fourth aspect of the present application is provided, wherein, if i = 1 and j = 0, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 0-th round key generation unit are respectively K(16), K(17), K(18), K(19); K(16), K(17), K(18), K(19) are respectively the round key parameters output by the 12-th, 13-th, 14-th, and 15-th round key generation units in the 0-th round.

[0052] According to the first or second encryption method of the fourth aspect of the present application, the tenth encryption method according to the fourth aspect of the present application is provided, wherein, if i = 1 and j = 1, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 1-st round key generation unit are respectively K(17), K(18), K(19), K(20); K(17), K(18), K(19) are respectively the round key parameters output by the 13-th, 14-th, 15-th round key generation units in the 0-th round, and K(20) is the round key parameter output by the 0-th round key generation unit in the 1-st round.

[0053] According to the first or second encryption method of the fourth aspect of the present application, the eleventh encryption method according to the fourth aspect of the present application is provided, wherein, if i = 1 and j = 2, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the 2-nd round key generation unit are respectively K(18), K(19), K(20), K(21); K(18), K(19) are respectively the round key parameters output by the 14-th, 15-th round key generation units in the 0-th round, and K(20), K(21) are respectively the round key parameters output by the 0-th, 1-st round key generation units in the 1-st round.

[0054] According to the first or second encryption method of the fourth aspect of the present application, there is provided a twelfth encryption method according to the fourth aspect of the present application. Wherein, when i = 1 and j = 3, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the third round key generation unit are K(19), K(20), K(21), K(22) respectively; K(19) is the round key parameter output by the fifteenth round key generation unit in the 0th round, and K(20), K(21), K(22) are the round key parameters output by the 0th, 1st, and 2nd round key generation units in the 1st round respectively.

[0055] According to the first or second encryption method of the fourth aspect of the present application, there is provided a thirteenth encryption method according to the fourth aspect of the present application. Wherein, when i = 1 and j >= 4, the round key parameters K(16*i + j), K(16*i + j + 1), K(16*i + j + 2), K(16*i + j + 3) used by the jth round key generation unit are the round key parameters output by the (j - 4)th, (j - 3)th, (j - 2)th, and (j - 1)th round key generation units in the 1st round respectively.

[0056] According to the first encryption method of the fourth aspect of the present application, there is provided a fourteenth encryption method according to the fourth aspect of the present application. Wherein, the jth ciphertext generation unit calculates X(16*i + j + 1) ^ X(16*i + j + 2) ^ X(16*i + j + 3) ^ rk(16*i + j), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an exclusive-or operation on the parameter after the linear transformation with the round key parameter X(16*i + j) to obtain the jth round key parameter K(16*i + j + 4) in the ith round; wherein, CK is a fixed parameter.

[0057] According to the fourteenth encryption method of the fourth aspect of the present application, there is provided a fifteenth encryption method according to the fourth aspect of the present application. Wherein, when i = 0 and j = 0, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the 0th ciphertext generation unit are X(0), X(1), X(2), X(3) respectively; X(0), X(1), X(2), X(3) are the plaintext inputs.

[0058] According to the fourteenth encryption method of the fourth aspect of the present application, the sixteenth encryption method of the fourth aspect of the present application is provided. Among them, if i = 0 and j = 1, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the first group of ciphertext generation units are X(1), X(2), X(3), X(4) respectively; X(1), X(2), X(3) are plaintext inputs, and X(4) is the ciphertext parameter output by the 0th group of ciphertext generation units in the 0th round.

[0059] According to the fourteenth encryption method of the fourth aspect of the present application, the seventeenth encryption method of the fourth aspect of the present application is provided. Among them, if i = 0 and j = 2, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the second group of ciphertext generation units are X(2), X(3), X(4), X(5) respectively; X(2), X(3) are plaintext inputs, and X(4), X(5) are the ciphertext parameters output by the 0th group and the first group of ciphertext generation units in the 0th round respectively.

[0060] According to the fourteenth encryption method of the fourth aspect of the present application, the eighteenth encryption method of the fourth aspect of the present application is provided. Among them, if i = 0 and j = 3, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the third group of ciphertext generation units are X(3), X(4), X(5), X(6) respectively; X(3) is the plaintext input, and X(4), X(5), X(6) are the ciphertext parameters output by the 0th group, the first group, and the second group of ciphertext generation units in the 0th round respectively.

[0061] According to the fourteenth encryption method of the fourth aspect of the present application, the nineteenth encryption method of the fourth aspect of the present application is provided. Among them, if i = 0 and j >= 4, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the jth group of ciphertext generation units are the ciphertext parameters output by the (j - 4)th group, the (j - 3)th group, the (j - 2)th group, and the (j - 1)th group of ciphertext generation units in the 0th round respectively.

[0062] According to the fourteenth encryption method of the fourth aspect of the present application, the twentieth encryption method of the fourth aspect of the present application is provided. Among them, if i = 1 and j = 0, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the 0th group ciphertext generation unit are X(16), X(17), X(18), X(19) respectively; X(16), X(17), X(18), X(19) are the ciphertext parameters output by the 12th group, 13th group, 14th group and 15th group ciphertext generation units in the 0th round respectively.

[0063] According to the fourteenth encryption method of the fourth aspect of the present application, the twenty-first encryption method of the fourth aspect of the present application is provided. Among them, if i = 1 and j = 1, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the 1st group ciphertext generation unit are X(17), X(18), X(19), X(20) respectively; X(17), X(18), X(19) are the ciphertext parameters output by the 13th group, 14th group and 15th group ciphertext generation units in the 0th round respectively, and X(20) is the ciphertext parameter output by the 0th group ciphertext generation unit in the 1st round.

[0064] According to the fourteenth encryption method of the fourth aspect of the present application, the twenty-second encryption method of the fourth aspect of the present application is provided. Among them, if i = 1 and j = 2, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the 2nd group ciphertext generation unit are X(18), X(19), X(20), X(21) respectively; X(18), X(19) are the ciphertext parameters output by the 14th group and 15th group ciphertext generation units in the 0th round respectively, and X(20), X(21) are the ciphertext parameters output by the 0th group and 1st group ciphertext generation units in the 1st round respectively.

[0065] According to the fourteenth encryption method of the fourth aspect of the present application, the twenty-third encryption method of the fourth aspect of the present application is provided. Among them, if i = 1 and j = 3, the ciphertext parameters X(16*i + j), X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3) used by the 3rd group ciphertext generation unit are X(19), X(20), X(21), X(22) respectively; X(19) is the ciphertext parameter output by the 15th group ciphertext generation unit in the 0th round, and X(20), X(21), X(22) are the ciphertext parameters output by the 0th group, 1st group and 2nd group ciphertext generation units in the 1st round respectively.

[0066] According to the fourteenth encryption method of the fourth aspect of the present application, the twenty-fourth encryption method of the fourth aspect of the present application is provided. Among them, if i = 1 and j >= 4, the ciphertext parameters X(16 * i + j), X(16 * i + j + 1), X(16 * i + j + 2), X(16 * i + j + 3) used by the j-th ciphertext generation unit are the ciphertext parameters output by the (j - 4)-th, (j - 3)-th, (j - 2)-th, and (j - 1)-th ciphertext generation units in the first round, respectively.

[0067] According to the fifth aspect of the present application, the first encryption method of the fifth aspect of the present application is provided. The encryption method includes the following steps: The j-th round key parameter K(j + 4) output by one of the round key generation operation units of the 0th to 30th groups is provided to the (j + 1)-th round key generation operation unit, so that the (j + 1)-th round key generation operation unit outputs the (j + 1)-th round key parameter K((j + 1) + 4); the j-th ciphertext parameter X(j + 4) output by one of the ciphertext generation operation units of the 0th to 30th groups is provided to the (j + 1)-th ciphertext generation operation unit, and the round key parameter K((j + 1) + 4) output by the (j + 1)-th round key generation operation unit is provided to the (j + 1)-th ciphertext generation operation unit as the round key rk(j + 1), so that the (j + 1)-th ciphertext generation operation unit outputs the (j + 1)-th ciphertext parameter X((j + 1) + 4); where, K is the round key parameter, X is the ciphertext parameter, rk is the round key, and j is the group number of the round key generation operation unit and the ciphertext generation operation unit, 0 <= j <= 31.

[0068] According to the first encryption method of the fifth aspect of the present application, the second encryption method of the fifth aspect of the present application is provided. Among them, the ciphertext parameters X(32), X(33), X(34), X(35) output by the 28th, 29th, 30th, and 31st ciphertext generation operation units constitute the ciphertext output.

[0069] According to the first or second encryption method of the fifth aspect of the present application, the third encryption method of the fifth aspect of the present application is provided. Among them, the j-th round key generation unit calculates K(j + 1) ^ K(j + 2) ^ K(j + 3) ^ CK(j), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an exclusive OR operation on the parameter after the linear transformation with the fixed parameter CK(j) to obtain the j-th round key parameter K(j + 4); where, CK is the fixed parameter.

[0070] According to the third encryption method of the fifth aspect of the present application, the fourth encryption method of the fifth aspect of the present application is provided. Wherein, when j = 0, the round key parameters K(j), K(j + 1), K(j + 2), K(j + 3) used by the 0th group round key generation unit are K(0), K(1), K(2), K(3) respectively; K(0), K(1), K(2), K(3) are obtained by the exclusive OR operation of the head exclusive OR unit and provided to the 0th group round key generation unit.

[0071] According to the third encryption method of the fifth aspect of the present application, the fifth encryption method of the fifth aspect of the present application is provided. Wherein, when j = 1, the round key parameters K(j), K(j + 1), K(j + 2), K(j + 3) used by the 1st group round key generation unit are K(1), K(2), K(3), K(4) respectively; K(1), K(2), K(3) are obtained by the exclusive OR operation of the head exclusive OR unit and provided to the 1st group round key generation unit; K(4) is the round key parameter output by the 0th group round key generation unit.

[0072] According to the third encryption method of the fifth aspect of the present application, the sixth encryption method of the fifth aspect of the present application is provided. Wherein, when j = 2, the round key parameters K(j), K(j + 1), K(j + 2), K(j + 3) used by the 2nd group round key generation unit are K(2), K(3), K(4), K(5) respectively; K(2), K(3) are obtained by the exclusive OR operation of the head exclusive OR unit and provided to the 2nd group round key generation unit; K(4), K(5) are the round key parameters output by the 0th group and the 1st group round key generation units respectively.

[0073] According to the third encryption method of the fifth aspect of the present application, the seventh encryption method of the fifth aspect of the present application is provided. Wherein, when j = 3, the round key parameters K(j), K(j + 1), K(j + 2), K(j + 3) used by the 3rd group round key generation unit are K(3), K(4), K(5), K(6) respectively; K(2) is obtained by the exclusive OR operation of the head exclusive OR unit and provided to the 2nd group round key generation unit; K(4), K(5), K(6) are the round key parameters output by the 0th group, the 1st group and the 2nd group round key generation units respectively.

[0074] According to the third encryption method of the fifth aspect of the present application, the eighth encryption method of the fifth aspect of the present application is provided. Wherein, when j >= 4, the round key parameters K(j), K(j + 1), K(j + 2), K(j + 3) used by the jth group round key generation unit are the round key parameters output by the j - 4th group, the j - 3rd group, the j - 2nd group and the j - 1st group round key generation units respectively.

[0075] According to the first or second encryption method of the fifth aspect of the present application, the ninth encryption method according to the fifth aspect of the present application is provided. Among them, the j-th ciphertext generation unit calculates X(j + 1)^X(j + 2)^X(j + 3)^rk(j), performs S-box transformation on the calculated parameter, performs linear transformation on the parameter after S-box transformation, and performs exclusive OR operation on the parameter after linear transformation with the ciphertext parameter X(j) to obtain the j-th ciphertext parameter X(j + 4); where CK is a fixed parameter.

[0076] According to the ninth encryption method of the fifth aspect of the present application, the tenth encryption method according to the fifth aspect of the present application is provided. Among them, when j = 0, the ciphertext parameters X(j), X(j + 1), X(j + 2), X(j + 3) used by the 0-th ciphertext generation unit are X(0), X(1), X(2), X(3) respectively; X(0), X(1), X(2), X(3) are plaintext inputs.

[0077] According to the ninth encryption method of the fifth aspect of the present application, the eleventh encryption method according to the fifth aspect of the present application is provided. Among them, when j = 1, the ciphertext parameters X(j), X(j + 1), X(j + 2), X(j + 3) used by the 1-st ciphertext generation unit are X(1), X(2), X(3), X(4) respectively; X(1), X(2), X(3) are plaintext inputs, and X(4) is the ciphertext parameter output by the 0-th ciphertext generation unit.

[0078] According to the ninth encryption method of the fifth aspect of the present application, the twelfth encryption method according to the fifth aspect of the present application is provided. Among them, when j = 2, the ciphertext parameters X(j), X(j + 1), X(j + 2), X(j + 3) used by the 2-nd ciphertext generation unit are X(2), X(3), X(4), X(5) respectively; X(2), X(3) are plaintext inputs, and X(4), X(5) are the ciphertext parameters output by the 0-th and 1-st ciphertext generation units.

[0079] According to the ninth encryption method of the fifth aspect of the present application, the thirteenth encryption method according to the fifth aspect of the present application is provided. Among them, when j = 3, the ciphertext parameters X(j), X(j + 1), X(j + 2), X(j + 3) used by the 3-rd ciphertext generation unit are X(3), X(4), X(5), X(6) respectively; X(3) is a plaintext input, and X(4), X(5), X(6) are the ciphertext parameters output by the 0-th, 1-st, and 2-nd ciphertext generation units.

[0080] According to the ninth encryption method of the fifth aspect of the present application, the fourteenth encryption method of the fifth aspect of the present application is provided. When j >= 4, the ciphertext parameters X(j), X(j + 1), X(j + 2), and X(j + 3) used by the j-th ciphertext generation unit are respectively the ciphertext parameters output by the (j - 4)-th, (j - 3)-th, (j - 2)-th, and (j - 1)-th ciphertext generation units. BRIEF DESCRIPTION OF THE DRAWINGS

[0081] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0082] Figure 1 The block diagram of an encryption device according to the SM4 algorithm is shown;

[0083] Figure 2 The block diagram of an encryption device according to the SM4 algorithm of an embodiment of the present application is shown;

[0084] Figure 3 The block diagram of an encryption device according to the SM4 algorithm of another embodiment of the present application is shown;

[0085] Figure 4 The block diagram of an encryption device according to the SM4 algorithm of still another embodiment of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0086] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0087] Figure 2 The block diagram of an encryption device according to the SM4 algorithm of an embodiment of the present application is shown.

[0088] According to Figure 2 The encryption device according to the embodiment includes a round key generation device (left side) and a ciphertext generation device (right side), and completes the encryption process that the standard SM4 algorithm completes through 32 rounds of iteration in 16 rounds of iteration.

[0089] The round key generation device takes the encryption key MK as input and obtains the system parameter FK and the fixed parameter CK. According to Figure 2In an embodiment, in the i-th round of 16 rounds of iteration (i = 0 to 15), the round key generation device provides two round keys to the ciphertext generation device, denoted as rk(2*i) and rk(2*i + 1) respectively, and the ciphertext generation device generates X(2*i + 4) and X(2*i + 5).

[0090] The round key generation device includes exclusive OR unit 210, exclusive OR unit 220, S-box transformation unit 230, linear transformation unit 240, exclusive OR unit 250, exclusive OR unit 225, S-box transformation unit 235, linear transformation unit 245, and exclusive OR unit 255. Exclusive OR unit 210, exclusive OR unit 220, S-box transformation unit 230, linear transformation unit 240, and exclusive OR unit 250 are used to generate the round key rk(2*i) in each round of iteration, and exclusive OR unit 225, S-box transformation unit 235, linear transformation unit 245, and exclusive OR unit 255 are used to generate the round key rk(2*i + 1) in each round of iteration.

[0091] See Figure 2 , before starting to encrypt a 128-bit block, exclusive OR unit 210 performs an exclusive OR operation on the encryption key MK and the system parameter FK to obtain the parameter K. In the i-th round of iteration, the parameter K used to generate the round key rk(2*i) is denoted as (K(2*i), K(2*i + 1), K(2*i + 2), K(2*i + 3)). The parameter K output by exclusive OR unit 210 is the parameter K(0), K(1), K(2), K(3)) used in the 0-th round of iteration, K0 = MK0 ^ FK0, K1 = MK1 ^ FK1, K2 = MK2 ^ FK2, K3 = MK3 ^ FK3.

[0092] In the i-th round of iteration, exclusive OR unit 220 calculates K(2*i + 1) ^ K(2*i + 2) ^ K(2*i + 3) ^ CK(2*i). The S-box transformation unit 230 performs an S-box (Sbox) transformation on the output of exclusive OR unit 220, the linear transformation unit 240 performs a linear transformation on the output of the S-box transformation unit 230, and exclusive OR unit 250 performs an exclusive OR operation on the output of the linear transformation unit 240 and K(2*i), and the result output by exclusive OR unit 250 is the parameter K(2*i + 4), which is used as the round key rk(2*i) of this round (rk(2*i) = K(2*i + 4)) and is provided to exclusive OR unit 260 of the ciphertext generation device.

[0093] In the i-th iteration, the parameter K(2*i + 4) output by the XOR unit 250 is also provided to the XOR unit 225 for calculating K(2*i + 2) ^ K(2*i + 3) ^ K(2*i + 4) ^ CK(2*i + 1). The XOR unit 225 calculates K(2*i + 2) ^ K(2*i + 3) ^ K(2*i + 4) ^ CK(2*i + 1). The S-box transformation unit 235 performs an S-box (Sbox) transformation on the output of the XOR unit 225, the linear transformation unit 245 performs a linear transformation on the output of the S-box transformation unit 235, and the XOR unit 255 performs an XOR operation on the output of the linear transformation unit 245 and K(2*i + 1) to obtain the result output by the XOR unit 255 as the parameter K(2*i + 5), which is used as the round key rk(2*i + 1) (rk(2*i + 1) = K(2*i + 5)) of this round and is provided to the XOR unit 265 of the ciphertext generation device.

[0094] It can be understood that in the i-th iteration, the parameter K(2*i + 2) ^ K(2*i + 3) used by the XOR unit 225 is the same as the parameter K(2*i + 2) ^ K(2*i + 3) used by the XOR unit 220. Therefore, in each iteration, these two parameters are provided to both the XOR unit 220 and the XOR unit 225. And the parameter K(2*i + 1) used by the XOR unit 255 is the same as the parameter K(2*i + 1) used by the XOR unit 220. Therefore, in each iteration, the parameter K(2*i + 1) is provided to both the XOR unit 220 and the XOR unit 255.

[0095] In the i-th iteration, the parameter K(2*i + 4) required by the XOR unit 225 has to wait for the calculation result of the XOR unit 250 in the i-th round. And in the (i + 1)-th round, the parameter K(2(i + 1) + 1) required by the XOR unit 220 comes from the parameter K(2*i + 3) used in the previous round (the i-th round), and the parameters K(2(i + 1) + 2) and K(2(i + 1) + 3) required by the XOR unit 220 come from the outputs of the XOR unit 250 and the XOR unit 255 in the previous round (the i-th round) respectively; the parameter K(2(i + 1) + 2) required by the XOR unit 225 comes from the parameter K(2*i + 4) used in the previous round (the i-th round), and the parameters K(2(i + 1) + 3) and K(2(i + 1) + 4) required by the XOR unit 225 come from the output of the XOR unit 255 in the previous round (the i-th round) and the output of the XOR unit 250 in the current round (the (i + 1)-th round) respectively.

[0096] Optionally, in the i-th round of calculation, although the XOR unit 225 needs to wait for the XOR unit 250 to provide it with the parameter K(2*i + 4) before it can start calculating the round key rk(2*1 + 1), there is no need to provide an additional control signal to the XOR unit 255 to indicate that the XOR unit 250 has output the parameter K(2*i + 4). Instead, the XOR unit 255 directly uses the output of the XOR unit 250 for the XOR operation. After a period of time, if the XOR unit 250 outputs the correct parameter K(2*i + 4), the XOR result output by the XOR unit 255 can also correctly reflect the calculation result of K(2*i + 2)^K(2*i + 3)^K(2*i + 4)^CK(2*i + 1), and then the S-box transformation unit 235, the linear transformation unit 245, and the XOR unit 255 can also generate correct calculation results accordingly. Thus, although according to Figure 2 the embodiment of, two round keys are generated in each round of iteration, there is no need to add an additional control device to indicate the timing for the XOR unit 225, the S-box transformation unit 235, the linear transformation unit 245, and the XOR unit 255 to start the calculation. Instead, the same or substantially the same structure and control method as those of the XOR unit 220, the S-box transformation unit 230, the linear transformation unit 240, and the XOR unit 250 are used, and the time interval for each round of iteration is set to ensure that within the time interval, the XOR unit 250 and the XOR unit 255 can complete the output of the round key rk(2*i) and the round key rk(2*i + 1).

[0097] Continuing to refer to Figure 2 , the ciphertext generation device includes an XOR unit 260, an S-box transformation unit 270, a linear transformation unit 280, an XOR unit 290, an XOR unit 265, an S-box transformation unit 275, a linear transformation unit 285, and an XOR unit 295.

[0098] The ciphertext generation device takes the 128-bit plaintext X to be encrypted and the round keys rk(2*i) and rk(2*i + 1) provided by the round key generation device as inputs.

[0099] In the i-th round of iteration, the XOR unit 260 performs an XOR operation on X(2*i + 1), X(2*i + 2), X(2*i + 3) and rk(2*i), and the result is provided to the S-box unit 270. In the 0-th round, X(1), X(2) and X(3) to be processed by the XOR unit 260 come from the input plaintext X, and rk(0) comes from K(4) provided by the round key generation device; in the i-th round of iteration (i >= 1), X(2*i + 1) to be processed by the XOR unit 260 has been provided to the XOR unit 260 in the previous round of iteration, while X(2*i + 2) comes from the output of the XOR unit 290 in the previous round of iteration, and X(2*i + 3) comes from the output of the XOR unit 295 in the previous round of iteration. Thus, the outputs of the XOR unit 290 and the XOR unit 295 are coupled to the inputs of the XOR unit 260.

[0100] The S-box transformation unit 270 performs an S-box transformation on the output of the XOR unit 260, the linear transformation unit 280 performs a linear transformation on the output of the S-box transformation unit 270, and the XOR unit 290 performs an XOR operation on the output of the linear transformation unit 280 and X(i), and the result output by the XOR unit 290 is X(2*i + 4), and is provided to the XOR unit 260 for the next round of iteration. Optionally, the S-box transformation unit 270, the linear transformation unit 280 and the XOR unit 290 directly or at any time perform calculations on the outputs of their previous stages without waiting for the control device or the previous stage to indicate that the calculations of the previous stage are completed.

[0101] In the i-th round of iteration, the parameter X(2*i + 4) output by the XOR unit 290 is also provided to the XOR unit 265 for calculating X(2*i + 2) ^ X(2*i + 3) ^ X(2*i + 4) ^ rk(2*i + 1), and the result is provided to the S-box unit 275.

[0102] The S-box transformation unit 275 performs an S-box transformation on the output of the XOR unit 265, the linear transformation unit 285 performs a linear transformation on the output of the S-box transformation unit 275, and the XOR unit 295 performs an XOR operation on the output of the linear transformation unit 285 and X(i), and the result output by the XOR unit 295 is X(2*i + 5), and is provided to the XOR unit 260 for the next round of iteration. Optionally, the S-box transformation unit 275, the linear transformation unit 285 and the XOR unit 295 directly or at any time perform calculations on the outputs of their previous stages without waiting for the control device or the previous stage to indicate that the calculations of the previous stage are completed.

[0103] Set the time interval for each round of iteration to ensure that within the time interval, the XOR unit 260, S-box transformation unit 270, linear transformation unit 280, XOR unit 290, XOR unit 265, S-box transformation unit 275, linear transformation unit 285, and XOR unit 295 complete the output of X(2*i + 4) and X(2*i + 5).

[0104] As an example, in each round of iteration, the ciphertext generation device has to wait for and use the round keys rk(2*i) and rk(2*i + 1) generated by the round key generation device for that round. Optionally, the XOR unit 265 directly or at any time calculates the output of its predecessors (XOR unit 290 and XOR unit 255) without waiting for the control device or the predecessors to indicate that the calculation of the predecessors is completed. Set the time interval for each round of iteration to ensure that within the time interval, the XOR unit 265 receives the correct output from its predecessors (XOR unit 290 and XOR unit 255), and within that time interval, the calculation of X(2*i + 5) is completed from the XOR unit 265 to the XOR unit 295. And according to this time interval, set the clock cycle for each round of iteration of the control encryption device.

[0105] After the 15th round of iteration is completed, the XOR unit 290 outputs X(34) and the XOR unit 295 outputs X(35), and together with X(32) and X(33) obtained from the previous rounds of iteration, they form the 128-bit ciphertext Y obtained by encrypting the plaintext X.

[0106] According to one or more embodiments of the present application, the 32 rounds of iteration defined in the standard SM4 algorithm are completed in 16 rounds of iteration, 8 rounds of iteration, 4 rounds of iteration, 2 rounds of iteration, or even 1 round of iteration. And those skilled in the art can also make technical solutions for completing the encryption / decryption calculation of the SM algorithm in non-integer powers of 2 rounds of iteration according to the teachings of the embodiments of the present application.

[0107] Figure 3 Shows a block diagram of an encryption device for the SM4 algorithm according to another embodiment of the present application.

[0108] According to Figure 3 The encryption device according to the embodiment of completes the encryption process that the standard SM4 algorithm completes through 32 rounds of iteration in 2 rounds of iteration, including a round key generation device (left side) and a ciphertext generation device (right side).

[0109] According to Figure 3 The embodiment of, the round key generation device includes 16 groups of operation units, and each group of operation units includes an XOR unit, an S-box transformation unit, a linear transformation unit, and another XOR unit. As an example, Figure 3 shows the 0th group of operation units, including an XOR unit 320, an S-box transformation unit 330, a linear transformation unit 340, and an XOR unit 350. Figure 3 Also shown is the first set of arithmetic units, including an exclusive OR unit 322, an S-box transformation unit 332, a linear transformation unit 342, and an exclusive OR unit 352; Figure 3 Also shown is the 15th set of arithmetic units, including an exclusive OR unit 32n, an S-box transformation unit 33n, a linear transformation unit 34n, and an exclusive OR unit 35n.

[0110] Within each set of arithmetic units, an exclusive OR unit (e.g., 320, 322, 32n) performs an exclusive OR operation on the input data, an S-box transformation unit (e.g., 330, 332, 33n) performs an S-box (Sbox) transformation on the output of the exclusive OR unit, a linear transformation unit (e.g., 340, 342, 34n) performs a linear transformation on the output of the S-box transformation unit, and a second exclusive OR unit (e.g., 350, 352, 35n) performs an exclusive OR operation on the output of the linear transformation unit. The result obtained is the round key. Except for the last set, the output of the second exclusive OR unit (e.g., 350, 352, 35n) of each set of arithmetic units is provided as input to the exclusive OR unit (e.g., 320, 322, 32n) of the next set of arithmetic units.

[0111] In each round of iteration, each set of arithmetic units generates a round key, and the generated round key is provided to the corresponding set of the ciphertext generation device.

[0112] In the i-th round of iteration (0 <= i <= 1), 16 round keys are generated, denoted as rk(16*i), rk(16*i + 1), rk(16*i + 2), ……, rk(16*i + 15). The 16 round keys generated in the i-th round of iteration are represented by rk(16*i + j), where j represents the group number of the arithmetic unit that generates the round key, 0 <= j <= 15. Generally, the j-th set of arithmetic units includes an exclusive OR unit 32j, an S-box transformation unit 33j, a linear transformation unit 34j, and an exclusive OR unit 35j.

[0113] In the i-th iteration, the input of the exclusive-OR unit (32j) of the j-th group of arithmetic units is the parameter K(16*i + j + 1) ^ K(16*i + j + 2) ^ K(16*i + j + 3) ^ CK(16*i + j). When i = 0 and j = 0, the parameter K output by the exclusive-OR unit 310 is the parameter K(0), K(1), K(2), K(3)) used by the 0-th group of arithmetic units, where the exclusive-OR unit 32j uses the parameters K(1), K(2), K(3), and the exclusive-OR unit 35j uses the parameter K(0). When i = 0 and j = 1, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the exclusive-OR unit 32j come from the parameters K(2) and K(3) and the current-round (i = 0) output of the exclusive-OR unit 35j of the 0-th group of arithmetic units, respectively. When i = 0 and j = 2, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the exclusive-OR unit 32j come from the parameter K(3) and the current-round (i = 0) outputs of the exclusive-OR units 35j of the 0-th and 1-st groups of arithmetic units, respectively. When i = 0 and j >= 3, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the exclusive-OR unit 32j come from the current-round (i = 0) outputs of the exclusive-OR units 35j of the (j - 3)-th, (j - 2)-th, and (j - 1)-th groups of arithmetic units, respectively.

[0114] When i = 0 and j <= 3, the parameter K(16*i + j) used by the exclusive-OR unit 35j comes from the exclusive-OR unit 310. Correspondingly, the output of the exclusive-OR unit 310 is coupled to the input of the exclusive-OR unit 35j. When i = 0 and j >= 4, the parameter K(16*i + j) used by the exclusive-OR unit 35j comes from the exclusive-OR unit 35[j - 4] of the (j - 4)-th group of arithmetic units. Correspondingly, the output of the exclusive-OR unit 35[j - 4] is coupled to the input of the exclusive-OR unit 35j.

[0115] When i = 1 and j = 0, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the XOR unit 32j are respectively from the outputs of the XOR units 35j of the 13th, 14th, and 15th groups of arithmetic units in the previous round (i = 0). When i = 1 and j = 1, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the XOR unit 32j are respectively from the outputs of the XOR units 35j of the 14th and 15th groups of arithmetic units in the previous round (i = 0), and the output of the XOR unit 35j of the 0th group of arithmetic units in the current round (i = 1). When i = 1 and j = 2, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the XOR unit 32j are from the output of the XOR unit 35j of the 15th group of arithmetic units in the previous round (i = 0), and the outputs of the XOR units 35j of the 0th and 1st groups of arithmetic units in the current round (i = 1). When i = 1 and j >= 3, the parameters K(16*i + j + 1), K(16*i + j + 2), and K(16*i + j + 3) used by the XOR unit 32j are respectively from the outputs of the XOR units 35j of the (j - 3)th, (j - 2)th, and (j - 1)th groups of arithmetic units in the current round (i = 1).

[0116] When i = 1 and j = 0, the parameter K(16*i + j) used by the XOR unit 35j is from the output of the XOR unit 35j of the 12th group of arithmetic units in the previous round (i = 0); when i = 1 and j = 1, the parameter K(16*i + j) used by the XOR unit 35j is from the output of the XOR unit 35j of the 13th group of arithmetic units in the previous round (i = 0); when i = 1 and j = 2, the parameter K(16*i + j) used by the XOR unit 35j is from the output of the XOR unit 35j of the 14th group of arithmetic units in the previous round (i = 0); when i = 1 and j = 3, the parameter K(16*i + j) used by the XOR unit 35j is from the output of the XOR unit 35j of the 15th group of arithmetic units in the previous round (i = 0). When i = 1 and j >= 4, the parameter K(16*i + j) used by the XOR unit 35j is from the output of the XOR unit 35[j - 4] of the (j - 4)th group of arithmetic units in the current round (i = 1). Correspondingly, the output of the XOR unit 35[j - 4] is coupled to the input of the XOR unit 35j, where when j < 4, the value of "[j - 4]" is taken as j - 4 + 16.

[0117] And set the time interval for each round of iteration to ensure that within the time interval, the round key generation device completes the generation of 16 round keys and provides them to the corresponding groups of the ciphertext generation device.

[0118] According to Figure 3In an embodiment, the ciphertext generation device includes 16 groups of arithmetic units, and each group of arithmetic units includes an exclusive OR unit, an S-box transformation unit, a linear transformation unit, and an exclusive OR unit. As an example, Figure 3 shows the 0th group of arithmetic units of the ciphertext generation device, including an exclusive OR unit 360, an S-box transformation unit 370, a linear transformation unit 380, and an exclusive OR unit 390. Figure 3 also shows the 1st group of arithmetic units of the ciphertext generation device, including an exclusive OR unit 362, an S-box transformation unit 372, a linear transformation unit 382, and an exclusive OR unit 392; Figure 3 also shows the 15th group of arithmetic units of the ciphertext generation device, including an exclusive OR unit 36n, an S-box transformation unit 37n, a linear transformation unit 38n, and an exclusive OR unit 39n.

[0119] Within each group of arithmetic units of the ciphertext generation device, the exclusive OR unit (e.g., 360, 362, 36n) performs an exclusive OR operation on the input data, the S-box transformation unit (e.g., 370, 372, 37n) performs an S-box (Sbox) transformation on the output of the exclusive OR unit, the linear transformation unit (e.g., 380, 382, 38n) performs a linear transformation on the output of the S-box transformation unit, and the second exclusive OR unit (e.g., 390, 392, 39n) performs an exclusive OR operation on the output of the linear transformation unit. Except for the last group, the output of the second exclusive OR unit (e.g., 359, 392, 39n) of each group of arithmetic units is provided as an input to the exclusive OR unit (e.g., 360, 362, 36n) of the next group of arithmetic units.

[0120] In the i-th round of iteration (0 <= i <= 1), the second exclusive OR unit of each group of arithmetic units of the ciphertext generation device generates 16 calculation results, denoted as X(16*i + 4), X(16*i + 5), X(16*i + 6), ……, X(16*i + 19). The 16 calculation results generated in the i-th round of iteration are represented by X(16*i + 4 + j), where j represents the group number of the arithmetic unit that generates the round key, 0 <= j <= 15. Generally, the j-th group of arithmetic units includes an exclusive OR unit 36j, an S-box transformation unit 37j, a linear transformation unit 38j, and an exclusive OR unit 39j.

[0121] In the i-th round of iteration, the inputs to the exclusive OR unit (36j) of the j-th group of arithmetic units of the ciphertext generation device are the parameters X(16*i + j + 1), X(16*i + j + 2), X(16*i + j + 3), and rk(16*i + j).

[0122] When i = 0 and j = 0, the XOR unit 360 uses the plaintexts X(1), X(2), X(3) and rk(0), and the XOR unit 39j uses the plaintext X(0). When i = 0 and j = 1, the parameters X(16*i + j + 1), X(16*i + j + 2) and X(16*i + j + 3) used by the XOR unit 36j are from the plaintexts X(2) and X(3) and the current round (i = 0) output X(4) of the XOR unit 390 of the 0th group of arithmetic units respectively. When i = 0 and j = 2, the parameters X(16*i + j + 1), X(16*i + j + 2) and X(16*i + j + 3) used by the XOR unit 36j are from the plaintext X(3) and the current round (i = 0) outputs (X(4) and X(5)) of the XOR units 39j of the 0th and 1st groups of arithmetic units respectively. When i = 0 and j >= 3, the parameters X(16*i + j + 1), X(16*i + j + 2) and X(16*i + j + 3) used by the XOR unit 36j are from the current round (i = 0) outputs of the XOR units 39j of the (j - 3)th, (j - 2)th and (j - 1)th groups of arithmetic units respectively.

[0123] When i = 0 and j <= 3, the X(16*i + j) used by the XOR unit 39j comes from the plaintext X. Correspondingly, the plaintext is provided to the input of the XOR unit 39j. When i = 0 and j >= 4, the X(16*i + j) used by the XOR unit 39j comes from the XOR unit 39[j - 4] of the (j - 4)th group of arithmetic units of the ciphertext generation device. Correspondingly, the output of the XOR unit 39[j - 4] is coupled to the input of the XOR unit 39j.

[0124] When i = 1 and j = 0, the parameters X(16*i + j + 1), X(16*i + j + 2), and X(16*i + j + 3) used by the XOR unit 36j are respectively from the outputs of the XOR units 39j of the 13th, 14th, and 15th groups of arithmetic units in the previous round (i = 0). When i = 1 and j = 1, the parameters X(16*i + j + 1), X(16*i + j + 2), and X(16*i + j + 3) used by the XOR unit 36j are respectively from the outputs of the XOR units 39j of the 14th and 15th groups of arithmetic units in the previous round (i = 0), and the output of the XOR unit 39j of the 0th group of arithmetic units in the current round (i = 1). When i = 1 and j = 2, the parameters X(16*i + j + 1), X(16*i + j + 2), and X(16*i + j + 3) used by the XOR unit 36j are from the output of the XOR unit 39j of the 15th group of arithmetic units in the previous round (i = 0), and the outputs of the XOR units 39j of the 0th and 1st groups of arithmetic units in the current round (i = 1). When i = 1 and j >= 3, the parameters X(16*i + j + 1), X(16*i + j + 2), and X(16*i + j + 3) used by the XOR unit 36j are respectively from the outputs of the XOR units 39j of the (j - 3)th, (j - 2)th, and (j - 1)th groups of arithmetic units in the current round (i = 1).

[0125] When i = 1 and j = 0, the parameter X(16*i + j) used by the XOR unit 39j is from the output of the XOR unit 39j of the 12th group of arithmetic units in the previous round (i = 0); when i = 1 and j = 1, the parameter X(16*i + j) used by the XOR unit 39j is from the output of the XOR unit 39j of the 13th group of arithmetic units in the previous round (i = 0); when i = 1 and j = 2, the parameter X(16*i + j) used by the XOR unit 39j is from the output of the XOR unit 39j of the 14th group of arithmetic units in the previous round (i = 0); when i = 1 and j = 3, the parameter X(16*i + j) used by the XOR unit 39j is from the output of the XOR unit 39j of the 15th group of arithmetic units in the previous round (i = 0). When i = 1 and j >= 4, the parameter X(16*i + j) used by the XOR unit 39j is from the output of the XOR unit 39[j - 4] of the (j - 4)th group of arithmetic units in the current round (i = 1). Correspondingly, the output of the XOR unit 39[j - 4] is coupled to the input of the XOR unit 39j, where when j < 4, the value of "[j - 4]" is taken as j - 4 + 16.

[0126] And set the time interval for each round of iteration to ensure that within the time interval, each arithmetic unit of the ciphertext generation device has completed the calculation of the current round.

[0127] After the completion of the first round of iteration, the XOR unit 39n outputs X(35), and the XOR units 39j of the 12th - 14th groups of operation units respectively output X(32), X(33), and X(34). Using X(32), X(33), X(34), and X(35) to form the 128 - bit ciphertext Y obtained by encrypting the plaintext X.

[0128] Figure 4 The block diagram of the encryption device of the SM4 algorithm according to another embodiment of the present application is shown.

[0129] According to Figure 4 The encryption device of the embodiment includes a round - key generation device (left side) and a ciphertext generation device (right side), and completes the encryption process that the standard SM4 algorithm completes through 32 rounds of iteration in 1 round of iteration.

[0130] In 1 round of iteration, the round - key generation device generates 32 round keys and provides them to the ciphertext generation device. The ciphertext generation device encrypts the plaintext using the 32 round keys to generate the ciphertext.

[0131] According to Figure 4 the embodiment, the round - key generation device includes 32 groups of operation units, and each group of operation units includes an XOR unit, an S - box transformation unit, a linear transformation unit, and another XOR unit. By way of example, Figure 4 the 0th group of operation units is shown in, including an XOR unit 420, an S - box transformation unit 430, a linear transformation unit 440, and an XOR unit 450. Figure 4 The 1st group of operation units is also shown in, including an XOR unit 422, an S - box transformation unit 432, a linear transformation unit 442, and an XOR unit 452; Figure 4 Another group of operation units is also shown in, including an XOR unit 42n, an S - box transformation unit 43n, a linear transformation unit 44n, and an XOR unit 45n.

[0132] Within each group of operation units, the XOR unit performs an XOR operation on the input data, the S - box transformation unit performs an S - box (Sbox) transformation on the output of the XOR unit, the linear transformation unit performs a linear transformation on the output of the S - box transformation unit, and the second XOR unit performs an XOR operation on the output of the linear transformation unit. The result obtained is the round key. Except for the last group, the output of the second XOR unit of each group of operation units is provided as an input to the XOR unit (e.g., 320, 322, 32n) of the next group of operation units.

[0133] In each round of iteration, the output of the second XOR unit of each group of operation units serves as the round key, and the generated round key is provided to the corresponding group of the ciphertext generation device.

[0134] In one round of iteration, 32 round keys are generated, denoted as rk(0), rk(1), rk(2), ……, rk(31). The 32 generated round keys are represented by rk(j), where j represents the group number of the operation unit that generates this round key, and 0 <= j <= 31. Generally, the j-th group of operation units includes an XOR unit 42j, an S-box transformation unit 43j, a linear transformation unit 44j, and an XOR unit 45j.

[0135] In one round of iteration, the input of the XOR unit (42j) of the j-th group of operation units is the parameter K(j + 1) ^ K(j + 2) ^ K(j + 3) ^ CK(j). When j = 0, the parameter K output by the XOR unit 410 is the parameter K(0), K(1), K(2), K(3) used by the 0-th group of operation units, where the XOR unit 42j uses the parameters K(1), K(2), K(3), and the XOR unit 45j uses the parameter K(0). When j = 1, the parameters K(j + 1), K(j + 2), and K(j + 3) used by the XOR unit 42j come from the parameters K(2) and K(3) and the output of the XOR unit 45j of the 0-th group of operation units respectively. When j = 2, the parameters K(j + 1), K(j + 2), and K(j + 3) used by the XOR unit 42j come from the parameter K(3) and the outputs of the XOR units 45j of the 0-th and 1-st groups of operation units respectively. When j >= 3, the parameters K(j + 1), K(j + 2), and K(j + 3) used by the XOR unit 42j come from the outputs of the XOR units 45j of the (j - 3)-th, (j - 2)-th, and (j - 1)-th groups of operation units respectively.

[0136] When j <= 3, the parameter K(j) used by the XOR unit 45j comes from the XOR unit 410. Correspondingly, the output of the XOR unit 410 is coupled to the input of the XOR unit 45j. When j >= 4, the parameter K(j) used by the XOR unit 45j comes from the XOR unit 45[j - 4] of the (j - 4)-th group of operation units. Correspondingly, the output of the XOR unit 45[j - 4] is coupled to the input of the XOR unit 45j.

[0137] And set the time interval of one round of iteration to ensure that within the time interval, the round key generation device completes the generation of 32 round keys and provides them to the corresponding groups of the ciphertext generation device.

[0138] In one iteration, each group of arithmetic units of the round key generation device sequentially generates the round key rk(j), and transfers it to the corresponding group of arithmetic units of the ciphertext generation device and the next group of arithmetic units of the round key generation device. In one example, instead of providing a control signal for the controller to start the operation to each group of arithmetic units, each group of arithmetic units calculates its input signal at any time, so that when its input signal changes (for example, the previous group of arithmetic units outputs a calculation result), the calculation result of the current group of arithmetic units also changes accordingly. Thus, in one iteration, the round key rk(j) is generated and provided to the ciphertext generation device sequentially in time in the increasing order of j, and each group of arithmetic units of the ciphertext generation device outputs X(j + 4) after receiving the round key rk(j). Thus, in one iteration, X(j + 4) is generated sequentially in time in the increasing order of j. After obtaining X(35), the ciphertext Y is formed using X(32), X(33), X(34) and X(35).

[0139] According to Figure 4 the embodiment of, the ciphertext generation device includes 32 groups of arithmetic units, and each group of arithmetic units includes an exclusive OR unit, an S-box transformation unit, a linear transformation unit and another exclusive OR unit. By way of example, Figure 4 shows the 0th group of arithmetic units of the ciphertext generation device, including an exclusive OR unit 460, an S-box transformation unit 470, a linear transformation unit 480 and an exclusive OR unit 490. Figure 4 also shows the 1st group of arithmetic units of the ciphertext generation device, including an exclusive OR unit 462, an S-box transformation unit 472, a linear transformation unit 482 and an exclusive OR unit 492; Figure 4 also shows the 31st group of arithmetic units of the ciphertext generation device, including an exclusive OR unit 46n, an S-box transformation unit 47n, a linear transformation unit 48n and an exclusive OR unit 49n.

[0140] Within each group of arithmetic units of the ciphertext generation device, the exclusive OR unit (for example, 460, 462, 46n) performs an exclusive OR on the input data, the S-box transformation unit performs an S-box (Sbox) transformation on the output of the exclusive OR unit, the linear transformation unit performs a linear transformation on the output of the S-box transformation unit, and the second exclusive OR unit (for example, 490, 492, 49n) performs an exclusive OR operation on the output of the linear transformation unit. Except for the last group, the output of the second exclusive OR unit of each group of arithmetic units is provided as an input to the exclusive OR unit of the next group of arithmetic units.

[0141] In 1 round of iteration, the second XOR unit of each group of arithmetic units in the ciphertext generation device generates 32 calculation results, denoted as X(4), X(5), X(6), ……, X(35) respectively. Use X(32), X(33), X(34) and X(35) to form the 128-bit ciphertext Y obtained by encrypting the plaintext X. Let the 32 calculation results generated in 1 round of iteration be represented by X(4 + j), where j represents the group number of the arithmetic unit that generates the round key, 0 <= j <= 31. Generally, the j-th group of arithmetic units includes an XOR unit 46j, an S-box transformation unit 47j, a linear transformation unit 48j and an XOR unit 49j.

[0142] In 1 round of iteration, the inputs of the XOR unit (46j) of the j-th group of arithmetic units in the ciphertext generation device are the parameters X(j + 1), X(j + 2), X(j + 3) and rk(j). The round key rk(j) comes from the output of the j-th group of arithmetic units in the round key generation device.

[0143] When j = 0, the XOR unit 460 uses the plaintext X(1), X(2), X(3) and the round key rk(0), and the XOR unit 49j uses the plaintext X(0). When j = 1, the parameters X(j + 1), X(j + 2) and X(j + 3) used by the XOR unit 46j come from the plaintext X(2) and X(3) and the output X(4) of the XOR unit 490 of the 0-th group of arithmetic units respectively. When j = 2, the parameters X(j + 1), X(j + 2) and X(j + 3) used by the XOR unit 46j come from the plaintext X(3) and the outputs (X(4) and X(5)) of the XOR units 49j of the 0-th and 1-st groups of arithmetic units respectively. When j >= 3, the parameters X(j + 1), X(j + 2) and X(j + 3) used by the XOR unit 46j come from the outputs of the XOR units 49j of the (j - 3)-th, (j - 2)-th and (j - 1)-th groups of arithmetic units respectively.

[0144] When j <= 3, the X(j) used by the XOR unit 49j comes from the plaintext X, and correspondingly, the plaintext is provided to the input of the XOR unit 49j. When j >= 4, the X(j) used by the XOR unit 49j comes from the output of the XOR unit 49[j - 4] of the (j - 4)-th group of arithmetic units in the ciphertext generation device, and correspondingly, the output of the XOR unit 49[j - 4] is coupled to the input of the XOR unit 49j.

[0145] And set the time interval for each round of iteration to ensure that within the time interval, each arithmetic unit in the ciphertext generation device has completed the calculation of the current round.

[0146] In another example, according to Figure 4The encryption device of the embodiment operates in a pipeline mode. Each group of arithmetic units of the round key generation device includes a cache unit for caching the data required by the arithmetic units of this group; each group of arithmetic units of the ciphertext generation device also includes a cache unit for caching the data required by the arithmetic units of this group. In one cycle of the pipeline, each group of arithmetic units uses the data provided by its own cache unit to calculate the output of the arithmetic units of this group. For example, the output of the j-th group of arithmetic units of the round key generation device is the round key rk(j), and the output of the j-th group of arithmetic units of the ciphertext generation device is X(j + 4). In each cycle of the pipeline, the output of the arithmetic units is provided to the corresponding arithmetic units and cached by the corresponding arithmetic units. For example, the output of the j-th group of arithmetic units of the round key generation device is provided to the (j + 1)-th group of arithmetic units of the round key generation device and the j-th group of arithmetic units of the ciphertext generation device; the output of the j-th group of arithmetic units of the ciphertext generation device is provided to the (j + 1)-th group of arithmetic units of the ciphertext generation device. Thus, in each cycle, 128-bit plaintext X is provided to the ciphertext generation device. After the pipeline is filled, 32 encryption results are generated in each cycle. The result generated by the j-th group of arithmetic units of the ciphertext generation device in each cycle is Xk(j + 4), and this result corresponds to the 128-bit plaintext Xk provided to the ciphertext generation device k (= j) cycles before the current cycle. And in each cycle, the 31st group of arithmetic units uses Xk(31), Xk(32), Xk(33) and Xk(34) to generate Xk(35), and uses Xk(32), Xk(33), Xk(34) and Xk(35) to form the ciphertext Y obtained by encrypting the plaintext Xk, so as to output the encryption result (ciphertext Y) of 1 copy of 128-bit plaintext X in each cycle, improving the throughput (bandwidth) of the encryption device.

[0147] Optionally, a 128-bit encryption key MK is provided to the round key generation device. Further, after the pipeline is filled, 32 round keys are generated in each cycle. These round keys do not come from the same encryption key MK, but respectively correspond to the 32 encryption keys MK provided to the round key generation device in the past 32 cycles. Compared with the plaintext X, its corresponding encryption key MK is provided to the round key generation device one cycle earlier, so that when the plaintext X is provided to the ciphertext generation device, the round key rk(0) required by the 0th-level arithmetic units of the ciphertext generation device is already ready.

[0148] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application. Obviously, those skilled in the art can make various changes and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. An encryption device, comprising: a round key generation component and a ciphertext operation component; The round key generation component includes N serially connected round key generation operation units, generating N round key parameters in one round of iteration, N >= 2; the ciphertext operation component includes N serially connected ciphertext generation operation units, generating N ciphertext parameters in one round of iteration; In one round of iteration: The i-th round key parameter output by the i-th round key generation operation unit among the N round key generation operation units is provided to the (i + 1)-th round key generation operation unit among the N round key generation operation units, so that the (i + 1)-th round key generation operation unit outputs the (i + 1)-th round key parameter of this round of iteration; where i is a positive integer and 0 < i <= N, representing the sorting position of the round key generation operation unit among the N serially connected round key generation operation units; The last round key parameter of this round of iteration output by the last round key generation operation unit among the N round key generation operation units is provided to the first round key generation operation unit among the N round key generation operation units for generating the round key parameters of the next round; The i-th round key parameter output by the i-th round key generation operation unit is provided as the round key to the i-th ciphertext generation operation unit; the (i + 1)-th round key parameter output by the (i + 1)-th round key generation operation unit is provided as the round key to the (i + 1)-th ciphertext generation operation unit; The i-th ciphertext parameter output by the i-th ciphertext generation operation unit among the multiple ciphertext generation operation units is provided to the (i + 1)-th ciphertext generation operation unit among the multiple ciphertext generation operation units, so that the (i + 1)-th ciphertext generation operation unit outputs the (i + 1)-th ciphertext parameter; The last ciphertext parameter of this round output by the last ciphertext generation operation unit among the multiple ciphertext generation operation units is provided to the first ciphertext generation operation unit among the multiple ciphertext generation operation units.

2. An encryption device, comprising: a round key generation component and a ciphertext operation component; The round key generation component includes N serially connected round key generation operation units, generating N round key parameters in one round of iteration, N >= 2; the ciphertext operation component includes N serially connected ciphertext generation operation units, generating N ciphertext parameters in one round of iteration; The round key generation component and the ciphertext operation component each perform i - 1 rounds of iteration, i being an integer; The j-th round key parameter K(N * i + j + 3) of the i-th round output by the j-th round key generation operation unit among the N round key generation operation units is provided to the (j + 1)-th round key generation unit, so that the (j + 1)-th round key generation operation unit outputs the (j + 1)-th round key parameter K(N * i + j + 4) of the i-th round of iteration; where j is a positive integer and 0 < j <= N, representing the sorting position of the round key generation operation unit among the N serially connected round key generation operation units; The Nth round key parameter K(N*i+N+3) output by the last round key generation operation unit among the N round key generation operation units is provided to the first round key generation operation unit among the N round key generation operation units as the key parameter K(N(i+1)+3) to start the iteration of the round key parameters for the (i+1)th round; The ith round and jth ciphertext parameter X(N*i+j+3) output by the jth round ciphertext generation operation unit among the multiple ciphertext generation operation units is provided to the (j+1)th ciphertext generation operation unit among the multiple ciphertext generation units; The ith round and jth round key parameter K(N*i+j+3) output by the jth round key generation operation unit is provided to the jth ciphertext generation operation unit as the round key rk(n*i+j-1); the ith round and (j+1)th round key parameter K(N*i+j+4) output by the (j+1)th round key generation operation unit is provided to the (j+1)th ciphertext generation operation unit as the round key rk(n*i+j); The ciphertext parameter X(N*i+N+3) output by the last ciphertext generation operation unit among the multiple ciphertext generation operation units is provided to the foremost ciphertext generation operation unit among the multiple ciphertext generation operation units as the ciphertext parameter X(N(i+1)+3) to start the iteration of the ciphertext parameters for the (i+1)th round; wherein, K is the round key parameter, X is the ciphertext parameter, rk is the round key, and i is the number of rounds.

3. An encryption method, comprising the following steps: The first round key parameter K(2*i+4) of the ith round output by the first group of round key generation operation units is provided to the second group of round key generation units, so that the second group of round key generation operation units output the second round key parameter K(2*i+5) of the ith round iteration; The second round key parameter K(2*i+5) of the ith round output by the second group of round key generation operation units is provided to the first group of round key generation operation units as the key parameter K(2(i+1)+3) to start the iteration of the round key parameters for the (i+1)th round; The first ciphertext parameter X(2*i+4) of the ith round output by the first group of ciphertext generation operation units is provided to the second group of ciphertext generation operation units, and the round key parameter K(2*i+5) output by the second group of round key generation operation units is provided to the second group of ciphertext generation operation units as the round key rk(2*i+1), so that the second group of ciphertext generation operation units output the second ciphertext parameter X(2*i+5) of the ith round; The ciphertext parameter X(2*i+5) output by the second group of ciphertext generation operation units is provided to the first group of ciphertext generation operation units as the ciphertext parameter X(2(i+1)+3) to start the iteration of the ciphertext parameters for the (i+1)th round; wherein, K is the round key parameter, X is the ciphertext parameter, rk is the round key, and i is the number of rounds.

4. The encryption method according to claim 3, wherein, The first set of round key generation units calculates K(2*i + 1) ^ K(2*i + 2) ^ K(2*i + 3) ^ CK(2*i), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an XOR operation on the parameter after the linear transformation with the round key parameter K(2*i) to obtain the first round key parameter K(2*i + 4) of the i-th round; where CK is a fixed parameter.

5. The encryption method according to claim 4, wherein, the round key parameter K(2*i + 4) generated by the first set of round key generation units is provided to the first set of ciphertext generation units as the first round key rk(2*i) of the i-th round, so that the first set of ciphertext generation units outputs the first ciphertext parameter X(2*i + 4) of the i-th round.

6. The encryption method according to claim 4 or 5, wherein, The second set of round key generation units calculates K(2*i + 2) ^ K(2*i + 3) ^ K(2*i + 4) ^ CK(2*i + 2), performs an S-box transformation on the calculated parameter, performs a linear transformation on the parameter after the S-box transformation, and performs an XOR operation on the parameter after the linear transformation with the round key parameter K(2*i + 1) to obtain the second round key parameter K(2*i + 5) of this round.

7. One of the encryption methods according to claims 3 - 5, wherein, The second set of round key generation units directly uses the output of the first set of round key generation operation units for XOR operation; the first set of round key generation units directly uses the output of the second set of round key generation operation units for XOR operation.

8. One of the encryption methods according to claims 3 - 5, wherein, The first set of round key generation units and the second set of round key generation units complete the output of the round keys within a predetermined iterative time interval.

9. An encryption method, comprising the following steps: The j-th round key parameter K(16*i + j + 4) of the i-th round iteration output by one of the round key generation operation units from the 0-th group to the 14-th group is provided to the (j + 1)-th group of round key generation operation units, so that the (j + 1)-th group of round key generation operation units outputs the (j + 1)-th round key parameter K(16*i + (j + 1) + 4) of the i-th round iteration; The sixteenth round key parameter K(16*i + 19) of the i-th round iteration output by the 15-th group of round key generation operation units is provided to the first set of round key generation operation units to start the iteration of the round key parameters of the (i + 1)-th round as the key parameter K(16(i + 1) + j + 3); The j-th ciphertext parameter X(16*i + j + 4) of the i-th round output by one of the ciphertext generation operation units from the 0-th group to the 14-th group is provided to the (j + 1)-th group of ciphertext generation operation units, and the round key parameter K(16*i + (j + 1) + 4) output by the (j + 1)-th group of round key generation operation units is provided to the (j + 1)-th group of ciphertext generation operation units as the round key rk(16*i + j + 1), so that the (j + 1)-th group of ciphertext generation operation units outputs the (j + 1)-th ciphertext parameter X(16*i + (j + 1) + 4) of the i-th round; The sixteenth ciphertext parameter X(16*i + 19) of the i-th round output by the ciphertext generation operation unit of the 15th group is provided to the ciphertext generation operation unit of the first group of the (i + 1)-th round as the ciphertext parameter X(16*(i + 1)+j + 3) to start the iteration of the ciphertext parameters of the (i + 1)-th round; Wherein, K is the round key parameter, X is the ciphertext parameter, rk is the round key, i is the number of rounds, j is the group number of the round key generation operation unit and the ciphertext generation operation unit, and 0 <= j <= 15.

10. An encryption method, including the following steps: The j-th round key parameter K(j + 4) output by one of the round key generation operation units of the 0th group to the 30th group is provided to the round key generation operation unit of the (j + 1)-th group, so that the round key generation operation unit of the (j + 1)-th group outputs the (j + 1)-th round key parameter K((j + 1)+4); The j-th ciphertext parameter X(j + 4) output by one of the ciphertext generation operation units of the 0th group to the 30th group is provided to the ciphertext generation operation unit of the (j + 1)-th group, and the round key parameter K((j + 1)+4) output by the round key generation operation unit of the (j + 1)-th group is provided as the round key rk(j + 1) to the ciphertext generation operation unit of the (j + 1)-th group, so that the ciphertext generation operation unit of the (j + 1)-th group outputs the (j + 1)-th ciphertext parameter X((j + 1)+4); Wherein, K is the round key parameter, X is the ciphertext parameter, rk is the round key, j is the group number of the round key generation operation unit and the ciphertext generation operation unit, and 0 <= j <= 31.

Citation Information

Patent Citations

  • High-speed encryption and decryption method used for wireless local area network

    CN103269480A

  • System for realizing SM4 block symmetric cipher algorithm

    CN103812641A