Data security processing method and device

By hashing the chip's original random number pool in hardware devices, a secondary random number pool is formed, which solves the problem of low performance of true random number of chips and realizes the need for high-speed signature and encryption.

CN114297698BActive Publication Date: 2025-05-23BEIJING HUADA ZHIBAO ELECTRONICS SYST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111682314.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-29
Publication Date
2025-05-23
Estimated Expiration
2041-12-29

AI Technical Summary

Technical Problem

Chips in existing hardware devices need to generate high-speed random numbers, but the true random numbers generated by the chip itself are low in performance and cannot meet the needs of high-speed signatures or encryption.

Method used

By generating multiple random numbers, it forms a pool of original random numbers and hashing them to form a second-level random number pool. Use random numbers in the secondary random number pool to participate in signature or encryption operations to break through the bottleneck of low performance of hardware true random number generators.

Benefits of technology

It realizes that a small number of random numbers is continuously fetched from the original random number pool, and efficient random numbers are generated through hashing operations, meeting the needs of high-speed signature and encryption of the secure chip.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114297698B_ABST
    Figure CN114297698B_ABST
Patent Text Reader

Abstract

The present invention relates to a data security processing method and device, which belongs to the field of data security technology and solves the problem that the true random numbers generated by the existing chip itself have low performance and cannot meet the use requirements. The method includes: generating multiple random numbers and using the multiple random numbers as the original random number pool; randomly extracting the first part of the original random numbers from the original random number pool; performing hash calculation on the first part of the original random numbers and putting the hash calculation results into the secondary random number pool; and when signing a message to be signed or encrypting encrypted data, extracting part or all of the secondary random numbers from the secondary random number pool to participate in the signing or encryption operation. It breaks through the bottleneck of low performance of hardware true random number generators and meets the needs of high-speed signatures of security chips.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a data security processing method and device. Background Art

[0002] For elliptic curve asymmetric algorithms, such as the domestic commercial cryptographic algorithm SM2, random numbers are required for signature and encryption operations. In order to ensure the uniqueness of the operation results, random numbers need to be regenerated for each operation. The security chip in some cryptographic devices needs to perform high-speed signature or encryption, but the rate at which the chip hardware generates true random numbers may be low, which undoubtedly forms a bottleneck for the performance of high-speed signature or encryption. Summary of the invention

[0003] In view of the above analysis, the embodiments of the present invention aim to provide a data security processing method and device to solve the problem that the chip in the existing hardware device needs to generate random numbers at a high rate, but the true random numbers generated by the chip itself have low performance and cannot meet the usage requirements.

[0004] On the one hand, an embodiment of the present invention provides a data security processing method, including: generating multiple random numbers and using the multiple random numbers as an original random number pool; randomly extracting a first part of original random numbers from the original random number pool; performing hash calculation on the first part of original random numbers and placing the hash calculation result into a secondary random number pool; and when signing a message to be signed or encrypting data to be encrypted, extracting part or all of the secondary random numbers from the secondary random number pool to use the specified random numbers to participate in the signing or encryption operation.

[0005] The beneficial effects of the above technical solution are as follows: by taking a 256-byte original random number pool, a small number of random numbers can be continuously taken out from the random number pool, and a hash operation is performed on the number of random numbers, and the hash result or part of the hash result is used as the random number of this time, and is put into the secondary random number pool as the position offset for taking a certain number of random numbers from the original random number pool next time. This breaks through the bottleneck of low performance of hardware true random number generators and meets the requirements of high-speed signatures of security chips.

[0006] Based on a further improvement of the above method, obtaining a specified random number based on the partial secondary random number to participate in a signature or encryption operation further includes: using the sequence of each secondary random number in the partial secondary random number as a position offset of the original random number pool; reading the specified random number from the original random number pool according to the position offset of the original random number pool; and performing a hash calculation on the specified random number and updating the secondary random pool using the hash calculation result of the specified random number.

[0007] Based on a further improvement of the above method, the original random number pool includes 16×16 random numbers and is stored in the memory of the security chip, and each of the secondary random numbers is a one-byte hexadecimal number, wherein the sequence of each secondary random number in the partial secondary random numbers as the position offset of the original random number pool further includes: using the left character in the hexadecimal number as the row offset position corresponding to the row of the original random number pool; and using the right character in the hexadecimal number as the column offset position corresponding to the column of the original random number pool.

[0008] Based on a further improvement of the above method, the original random number pool is stored in the memory of the security chip.

[0009] Based on a further improvement of the above method, performing hash calculation on the first part of the original random number and placing the hash calculation result into the secondary random number pool further includes: storing the hash calculation result of the specified random number in the secondary random number pool of the memory of the security chip to update the previous secondary random number in the secondary random number pool to the random number.

[0010] Based on the further improvement of the above method, using the specified random number to participate in the signing operation further includes: the processor of the security chip receives the message to be signed and signs the message to be signed: data-connecting the first hash value with the message to be signed to obtain connection data; using a hash algorithm to calculate the second hash value based on the connection data; calculating the elliptic curve point according to the specified random number and the elliptic curve base point; calculating the first component of the signature value according to the elliptic curve point and the second hash value, and calculating the second component of the signature value according to the first component of the signature value, the user private key and the specified random number; transmitting the first component of the signature value and the second component of the signature value to the outside of the security chip.

[0011] Based on the further improvement of the above method, using the specified random number to participate in the encryption operation further includes: the processor of the security chip receives the data to be encrypted and signs the data to be encrypted: calculates a first elliptic curve point based on a first random number and an elliptic curve base point; calculates a second elliptic curve point based on the first random number and a public key; uses the first elliptic curve point and the second elliptic curve point to participate in encrypting plaintext; and transmits the encrypted data to the outside of the security chip.

[0012] On the other hand, an embodiment of the present invention provides a data security processing device including: an original random number pool generation module, which generates multiple random numbers and uses the multiple random numbers as the original random number pool; an extraction module, which is used to randomly extract a first part of original random numbers from the original random number pool; a second random number pool generation module, which is used to perform hash calculation on the first part of original random numbers and put the hash calculation results into a secondary random number pool; and a signing or encryption operation module, which is used to extract part or all of the secondary random numbers from the secondary random number pool to participate in the signing or encryption operation when signing a message to be signed or encrypting data to be encrypted.

[0013] Based on the further improvement of the above device, the specified random number acquisition module further includes: a position offset module, used to use each secondary random number sequence in the partial secondary random numbers as the position offset of the original random number pool; a reading module, used to read the specified random number from the original random number pool according to the position offset of the original random number pool; and a signing or encryption module, used to perform hash calculation on the specified random number and update the secondary random pool using the hash calculation result of the specified random number.

[0014] Based on the further improvement of the above device, the original random number pool includes 16×16 random numbers and is stored in the memory of the security chip, and each of the secondary random numbers is a one-byte hexadecimal number, wherein the position offset module further includes: a row offset submodule, used to use the left character in the hexadecimal number as the row offset position corresponding to the row of the original random number pool; and a column offset submodule, used to use the right character in the hexadecimal number as the column offset position corresponding to the column of the original random number pool.

[0015] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects:

[0016] 1. By taking the original random number pool of 256 bytes, a small number of random numbers can be continuously taken out from the random number pool, and the number of random numbers are hashed, and the hash result or part of the hash result is used as the random number of this time, and put into the secondary random number pool as the position offset for taking a certain number of random numbers from the original random number pool next time. This breaks through the bottleneck of low performance of hardware true random number generators and meets the needs of high-speed signatures of security chips.

[0017] 2. Through the above invention, in a 256-byte random number pool, if 16 bytes of random numbers are taken each time, up to 16 to the power of 16 different random numbers can be taken; if 8 bytes of random numbers are taken each time, up to 8 to the power of 32 different random numbers can be taken.

[0018] 3. The random numbers obtained from the random number pool of the present invention can also be used as seeds of deterministic random bit generators (DRBG) to generate deterministic pseudo-random numbers, and the random numbers can be used for session keys of symmetric algorithms, private keys of elliptic curve asymmetric algorithms, key streams of stream encryption, etc. In the present invention, the above-mentioned technical solutions can also be combined with each other to achieve more preferred combination solutions. Other features and advantages of the present invention will be described in the subsequent description, and some advantages may become obvious from the description, or may be understood by implementing the present invention. The objects and other advantages of the present invention can be realized and obtained through the contents particularly pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings are only for the purpose of illustrating particular embodiments and are not to be considered limiting of the present invention. Like reference symbols denote like components throughout the drawings.

[0020] Figure 1 Flow chart of a data security processing method according to an embodiment of the present invention.

[0021] Figure 2 The digital signature generation algorithm process according to an embodiment of the present invention.

[0022] Figure 3 The following is an encryption algorithm flow according to an embodiment of the present invention.

[0023] Figure 4 is a block diagram of a data security processing device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] The preferred embodiments of the present invention are described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not used to limit the scope of the present invention.

[0025] A specific embodiment of the present invention discloses a data security processing method. Figure 1 As shown, the data security processing method includes, in step S102, generating multiple random numbers and using the multiple random numbers as an original random number pool; in step S104, randomly extracting a first part of the original random numbers from the original random number pool; in step S106, performing hash calculation on the first part of the original random numbers and placing the hash calculation results into a secondary random number pool; and in step S108, when signing a message to be signed or encrypting data to be encrypted, extracting part or all of the secondary random numbers from the secondary random number pool to participate in the signing or encryption operation.

[0026] Compared with the prior art, in the data security processing method provided in this embodiment, a 256-byte original random number pool is taken, and a small number of random numbers can be continuously taken out from the random number pool, and a hash operation is performed on the number of random numbers. The hash result or part of the hash result is used as the random number for this time, and is put into the secondary random number pool as the position offset for taking a certain number of random numbers from the original random number pool next time.

[0027] In the following, reference will be made to Figure 1 , each step of the data security processing method according to an embodiment of the present invention is described in detail.

[0028] In step S102, multiple random numbers are generated and used as an original random number pool. The original random number pool is stored in the memory of the security chip. Specifically, the multiple random numbers are used as the original random number pool and stored in the memory of the security chip. For example, the security chip generates 256 bytes of true random numbers through a true random number generator.

[0029] In step S104, a first portion of original random numbers is randomly extracted from an original random number pool.

[0030] In step S106, a hash calculation is performed on the first part of the original random number and the hash calculation result is placed in the secondary random number pool. The hash calculation is performed on the first part of the original random number and the hash calculation result is placed in the secondary random number pool further includes: storing the current secondary random number in the secondary random number pool of the memory of the security chip to update the previous secondary random number in the secondary random number pool to the current secondary random number. Specifically, the hash calculation result of the specified random number is stored in the secondary random number pool of the memory of the security chip to update the previous secondary random number in the secondary random number pool to the current secondary random number.

[0031] In step S108, when signing a message to be signed or encrypting data to be encrypted, extract part or all of the secondary random numbers from the secondary random number pool to participate in the signing or encryption operation. Specifically, obtaining the specified random number for signing or encryption operation according to the partial secondary random number further includes: taking each secondary random number sequence in the partial secondary random number as the position offset of the original random number pool; reading the specified random number from the original random number pool according to the position offset of the original random number pool; and performing hash calculation on the specified random number and updating the secondary random pool using the hash calculation result of the specified random number. The original random number pool includes 16×16 random numbers and is stored in the memory of the security chip, and each secondary random number is a one-byte hexadecimal number. Taking each secondary random number sequence in the partial secondary random number as the position offset of the original random number pool further includes: taking the left character in the hexadecimal number as the row offset position corresponding to the row of the original random number pool; and taking the right character in the hexadecimal number as the column offset position corresponding to the column of the original random number pool.

[0032] Participating in a signature operation (e.g., an SM2 signature operation) using a specified random number further includes: the processor of the security chip receives a message to be signed and signs the message to be signed: data-connecting the first hash value with the message to be signed to obtain connection data; calculating a second hash value based on the connection data using a hash (e.g., SM3) algorithm; calculating an elliptic curve point according to a specified random number and an elliptic curve base point; calculating a first component of a signature value according to the elliptic curve point and the second hash value, and calculating a second component of the signature value according to the first component of the signature value, a user private key, and a specified random number; transmitting the first component of the signature value and the second component of the signature value to the outside of the security chip. Participating in an SM2 encryption operation using a specified random number further includes: the processor of the security chip receives data to be encrypted and signs the data to be encrypted: calculating a first elliptic curve point according to a first random number and an elliptic curve base point; calculating a second elliptic curve point according to the first random number and a public key; encrypting plaintext using the first elliptic curve point and the second elliptic curve point; transmitting the encrypted data to the outside of the security chip.

[0033] A specific embodiment of the present invention discloses a data security processing device, referring to Figure 4 The data security processing device includes: an original random number pool generation module 402, an extraction module 404, a second random number pool generation module 406 and a specified random number acquisition module 408.

[0034] Specifically, the original random number pool generation module 402 generates a plurality of random numbers and uses the plurality of random numbers as an original random number pool.

[0035] The extraction module 404 is used to randomly extract a first part of original random numbers from the original random number pool.

[0036] The second random number pool generation module 406 is used to perform hash calculation on the first part of the original random number and put the hash calculation result (ie, the random number) into the secondary random number pool.

[0037] The signature or encryption operation module 408 is used to extract part or all of the secondary random numbers from the secondary random number pool to participate in the signature or encryption operation when signing a signature message or encrypting encrypted data. The designated random number acquisition module further includes: a position offset module, which is used to use each secondary random number sequence in the partial secondary random number as the position offset of the original random number pool; a reading module, which is used to read the designated random number from the original random number pool according to the position offset of the original random number pool; and an update module, which is used to perform hash calculation on the designated random number and update the secondary random pool using the hash calculation result of the designated random number.

[0038] The original random number pool includes 16×16 random numbers and is stored in the memory of the security chip, and each secondary random number is a one-byte hexadecimal number, wherein the position offset module further includes: a row offset submodule for using the left character in the hexadecimal number as a row offset position corresponding to the row of the original random number pool; and a column offset submodule for using the right character in the hexadecimal number as a column offset position corresponding to the column of the original random number pool.

[0039] In the following, reference will be made to Figures 2 to 3 , the data security processing method according to an embodiment of the present invention is described in detail by way of a specific example.

[0040] The chip randomly generates 256 bytes of true random numbers through a true random number generator. This number of random numbers is used as the original random number pool and stored in the memory of the security chip. It is reused through the algorithm of the present invention. The specific algorithm is:

[0041] When the original random number pool is used for the first time, a small number of random numbers, such as 16 bytes, are randomly selected from the original random number pool, or the first 16 bytes in the pool are selected, and a hash operation is performed on the 16-byte random number, and the 16 bytes of the hash result are taken and put into the secondary random number pool, and stored in the memory of the security chip. When the original random number pool is used for the second time, the size of each random number in the secondary random number pool is used as the position offset of the random number to be taken this time, and the random number at that position is taken from the original random number pool as a random number for this random number, until 16 bytes are taken, and a hash operation is performed on the 16-byte random number, and the 16 bytes of the hash result are taken and put into the secondary random number pool.

[0042] 1) The original random number pool generated by the true random number generator is as shown in Table 1, a total of 256 bytes:

[0043] 0 1 2 3 4 5 6 7 8 9 A B C D E F 0 c3 8a cd 1c 60 bf fc be dd e7 1e d7 4d 70 1a b2 1 d9 53 d4 9b 55 3d 91 a2 6a cf 5a 38 c5 d1 7e 6d 2 62 7b e9 30 72 cb b0 80 58 7a 84 ac 51 10 b8 ee 3 ff 07 96 e2 c1 f1 9d ce a1 e6 04 f7 44 d2 b6 88 4 5d 1b 33 61 d8 69 87 8e 16 5f 56 03 02 95 e2 79 5 aa 7f 76 68 05 31 da f8 5e 9c 6e 2a ed 65 8d 6c 6 00 3a f0 c9 35 52 63 93 74 57 15 0f 66 f 9e bd 7 50 2d 24 78 37 32 1d 8c 40 a5 99 39 a7 11 c7 af 8 b3 06 21 e8 36 a8 77 97 3b 2b ea 0e 01 d3 e0 22 9 18 09 48 b4 3e b7 89 de 9a 49 20 75 2f 46 a9 27 A bc e1 c4 41 b1 90 fb ab fa 2c 85 0d f9 ca e5 54 B 13 d5 4c 83 b5 08 a4 12 98 8b ba 3f f2 29 2e d6 C 4e fd 81 d0 4a 6b 71 59 17 f3 43 28 c8 5c 14 a0 D cc e4 0a 64 b9 6f 5b 4b 34 7c ef 7d 86 67 82 26 E 94 ae 23 0c 92 25 45 a3 9f c6 73 f5 4f eb c0 ad F dc 3c c2 a6 42 df 8f bb 1f f6 19 ec 96 db 47 0b

[0044] 2) Get random number for the first time:

[0045] Step 1: Take the first 16 bytes from the original random number pool

[0046] c3 8a cd 1c 60 bf fc be dd e7 1e d7 4d 70 1a b2

[0047] Step 2: Perform the domestic hash algorithm SM3 operation on the 16-byte data, and the hash result is:

[0048] 1f af 01 25 15 af 6f 7b 7f 1b 48 8d f3 6d ad f7 f6 7a bb 04 32 f7 c746 ce 01 4a d4 4f 0a d5 28

[0049] Step 3: Take the first 16 bytes of the hash result as the random number used this time and put it into the secondary random number pool

[0050] 1f af 01 25 15 af 6f 7b 7f 1b 48 8d f3 6d ad f7

[0051] 3) Get random number for the second time:

[0052] Step 1: Take out each random number from the secondary random number pool in turn as the position offset of the original random number pool, and take out the original random number of the position offset

[0053] Offset[1f]=6d

[0054] Offset[af]=54

[0055] Offset

[01] =8a

[0056] Offset

[25] = cb

[0057] Offset

[15] =3d

[0058] Offset[af]=54

[0059] Offset[6f]=bd

[0060] Offset[7b]=39

[0061] Offset[7f]=af

[0062] Offset[1b]=38

[0063] Offset

[48] =16

[0064] Offset[8d]=d3

[0065] Offset[f3]=a6

[0066] Offset[6d]=fe

[0067] Offset[ad]=ca

[0068] Offset[f7]=bb

[0069] The random number used for this extraction is:

[0070] 6d 54 8a cb 3d 54 bd 39 af 38 16 d3 a6 fe ca bb

[0071] Step 2: Perform SM3 hash operation on the 16 bytes of data

[0072] Step 3: Take the first 16 bytes of the hash result as the random number used this time and put it into the secondary random number pool

[0073] 4) By analogy, the third random number is taken from the secondary random number pool in turn, each random number is used as the position offset of the original random number pool, and another 16-byte random number is taken from the original random number pool, and the secondary random number pool is replaced again.

[0074] 2.2.2 Update of original random number pool

[0075] For the sake of random number security, after taking a certain number of times from the original random number pool, such as 100 times, the original random number pool needs to be updated. The specific process repeats 2.2.1

[0076] 2.2.3 Specific application examples

[0077] 1) Generation algorithm of national secret algorithm SM2 digital signature

[0078] refer to Figure 2 , let the message to be signed be M. In order to obtain the digital signature (r, s) of message M, user A as the signer should implement the following operation steps:

[0079] A1. Place

[0080] A2. Calculation Convert the data type of e to an integer according to the methods given in 4.2.4 and 4.2.3 of GB / T XXXXX.1-xxxx;

[0081] A3. Use a random number generator to generate a random number k∈[1,n-1];

[0082] A4. Calculate the elliptic curve point (x1, y1) = [k]G, and convert the data type of x1 to an integer according to the method given in GB / T XXXXX.1-XXXX 4.2.8;

[0083] A5, calculate r = (e + x1) mod n, if r = 0 or r + k = n, return to A3;

[0084] A6. Calculate s = ((1 + dA) - 1·(kr·dA)) mod n. If s = 0, return to A3.

[0085] A7. Convert the data types of r and s to byte strings according to the details given in GB / T XXXXX.1-XXXX 4.2.2. The signature of message M is (r, s).

[0086] 2) National secret algorithm SM2 digital signature generation algorithm process

[0087] It can be seen from the operation steps and the flow chart that a certain number of random numbers need to be generated in the third step of the SM2 signature operation. Therefore, if the SM2 signature operation is performed in a security chip, but the performance of the hardware true random number output of the security chip is low, it will affect the performance of the security chip that requires high-speed signatures. Therefore, the solution proposed in the present invention will break through the bottleneck of low performance of the hardware true random number generator and meet the demand for high-speed signatures of security chips.

[0088] 3) National secret algorithm SM2 encryption algorithm

[0089] Suppose the message to be sent is a bit string M, and klen is the bit length of M.

[0090] In order to encrypt the plaintext M, user A as the encryptor should implement the following operation steps, refer to Figure 3 :

[0091] A1. Use a random number generator to generate a random number k∈[1,n-1];

[0092] A2. Calculate the elliptic curve point C1=[k]G=(x1,y1), and convert the data type of C1 into a bit string according to the method given in GB / T XXXXX.1-XXXX4.2.9 and 4.2.5;

[0093] A3. Calculate the elliptic curve point S = [h] PB. If S is a point at infinity, report an error and exit.

[0094] A4. Calculate the elliptic curve point [k]PB=(x2,y2). According to the method given in 4.2.6 and 4.2.5 of GB / T XXXXX.1-XXXX, convert the data types of coordinates x2 and y2 into bit strings.

[0095] A5. Calculate t=KDF(x2||y2, klen). If t is a string of all 0 bits, return to A1.

[0096] A6. Calculation

[0097] A7. Calculate C3 = Hash(x2||M||y2);

[0098] A8. Output ciphertext C=C1||C3||C2.

[0099] 3) National secret algorithm SM2 encryption algorithm process

[0100] It can be seen from the operation steps and the flow chart that a certain number of random numbers need to be generated in the first step of the SM2 encryption operation. Therefore, if the SM2 encryption operation is performed in a security chip, but the performance of the hardware true random number output of the security chip is low, the performance of the security chip that requires SM2 high-speed encryption will be affected. Therefore, the solution proposed by the present invention will break through the bottleneck of low performance of the hardware true random number generator and meet the requirements of SM2 high-speed encryption of the security chip.

[0101] Through the above invention, in theory, in a 256-byte random number pool, if 16 bytes of random numbers are taken each time, up to 16 to the power of 16 different random numbers can be taken; if 8 bytes of random numbers are taken each time, up to 8 to the power of 32 different random numbers can be taken.

[0102] In addition, the random numbers obtained from the random number pool of the present invention can also be used as seeds of deterministic random bit generators (DRBG) to generate deterministic pseudo-random numbers. The random numbers can be used for session keys of symmetric algorithms, private keys of elliptic curve asymmetric algorithms, key streams of stream encryption, etc.

[0103] By taking a 256-byte original random number pool, a small number of random numbers can be continuously taken out from the random number pool, and a hash operation is performed on the number of random numbers. The hash result or part of the hash result is used as the random number for this time, and is put into the secondary random number pool as the position offset for taking a certain number of random numbers from the original random number pool next time.

[0104] Those skilled in the art will appreciate that all or part of the processes of the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the program can be stored in a computer-readable storage medium, wherein the computer-readable storage medium is a disk, an optical disk, a read-only storage memory, or a random access memory, etc.

[0105] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. A data security processing method, It is characterized in that include: Generate a plurality of random numbers and use the plurality of random numbers as an original random number pool; Randomly extracting a first part of original random numbers from the original random number pool; Performing hash calculation on the first part of the original random number and placing the hash calculation result into the secondary random number pool; as well as When signing a message to be signed or encrypting data to be encrypted, extracting part or all of the secondary random numbers from the secondary random number pool to participate in the signing or encryption operation; Using the sequence of each secondary random number in the partial secondary random numbers as the position offset of the original random number pool; Reading a specified random number from the original random number pool according to the position offset of the original random number pool; as well as A hash calculation is performed on the specified random number and the secondary random number pool is updated using the hash calculation result of the specified random number.

2. The data security processing method according to claim 1, It is characterized in that The original random number pool includes 16×16 random numbers and is stored in the memory of the security chip, and each of the secondary random numbers is a one-byte hexadecimal number, wherein the sequence of each secondary random number in the partial secondary random numbers is used as the position offset of the original random number pool further includes: Using the left character in the hexadecimal number as the row offset position corresponding to the row of the original random number pool; and The right characters in the hexadecimal number are used as the column offset position corresponding to the column of the original random number pool.

3. The data security processing method according to claim 1, It is characterized in that The original random number pool is stored in the memory of the security chip.

4. The data security processing method according to claim 2, It is characterized in that Performing hash calculation on the first part of the original random number and placing the hash calculation result into the secondary random number pool further includes: The hash calculation result of the designated random number is stored in a secondary random number pool of the memory of the security chip to update the previous secondary random number in the secondary random number pool to the random number.

5. The data security processing method according to claim 2, It is characterized in that Using the specified random number to participate in the signature operation further includes: The processor of the security chip receives the message to be signed and signs the message to be signed: Performing data concatenation of the first hash value and the message to be signed to obtain concatenated data; Calculating a second hash value based on the connection data using a hash algorithm; Calculate an elliptic curve point according to the specified random number and the elliptic curve base point; Calculate a first component of the signature value according to the elliptic curve point and the second hash value, and calculate a second component of the signature value according to the first component of the signature value, a user private key, and the specified random number; The first component of the signature value and the second component of the signature value are transmitted outside the security chip.

6. The data security processing method according to claim 2, It is characterized in that Using the specified random number to participate in the encryption operation further includes: The processor of the security chip receives the data to be encrypted and signs the data to be encrypted: Calculate a first elliptic curve point according to the first random number and the elliptic curve base point; Calculate a second elliptic curve point according to the first random number and the public key; Encrypting plaintext using the first elliptic curve point and the second elliptic curve point; The encrypted data is transmitted outside the security chip.

7. A data security processing device, It is characterized in that include: An original random number pool generation module generates a plurality of random numbers and uses the plurality of random numbers as an original random number pool; An extraction module, used for randomly extracting a first part of original random numbers from the original random number pool; A second random number pool generating module, configured to perform hash calculation on the first part of the original random numbers and put the hash calculation result into a secondary random number pool; as well as A signing or encryption operation module, used to extract part or all of the secondary random numbers from the secondary random number pool to participate in the signing or encryption operation using the designated random numbers when signing a message to be signed or encrypting data to be encrypted; A position offset module, used to use each secondary random number sequence in the partial secondary random numbers as a position offset of the original random number pool; A reading module, configured to read the specified random number from the original random number pool according to a position offset of the original random number pool; as well as An updating module is used to perform a hash calculation on the specified random number and update the secondary random number pool using the hash calculation result of the specified random number.

8. The data security processing device according to claim 7, It is characterized in that The original random number pool includes 16×16 random numbers and is stored in the memory of the security chip, and each of the secondary random numbers is a one-byte hexadecimal number, wherein the position shift module further includes: a row offset submodule, configured to use the left character in the hexadecimal number as a row offset position corresponding to a row of the original random number pool; and The column offset submodule is used to use the right character in the hexadecimal number as the column offset position corresponding to the column of the original random number pool.

Citation Information

Patent Citations

  • Data signature method and device in block chain, computer equipment and storage medium

    CN110781140A