A lightweight encryption method that can accept any plaintext length
By adopting a lightweight encryption method on IoT devices, using Lai Massey structure and CTR encryption mode to build a five-layer structure, the problem of handling arbitrary plaintext lengths on resource-constrained devices is solved, and efficient encryption and decryption and security improvements are achieved.
Patent Information
- Application Number
- CN202210150979.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-18
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-02-18
AI Technical Summary
The existing encryption mode is difficult to handle any plaintext length on resource-constrained IoT devices, and the calculation amount is large, resulting in excessive device resource utilization and inability to operate efficiently.
The lightweight encryption method is adopted to build a five-layer structure through key generation, plaintext encryption and ciphertext decryption processes, and a five-layer structure is built using Lai Massey structure and CTR encryption mode, using symmetrical components to replace the hash function, so as to achieve consistent encryption and decryption processes and adapt to any plaintext length.
It improves the operation efficiency of the algorithm, saves the cost of software and hardware implementation, and improves the security of the algorithm, and adapts to IoT devices with limited resources.
Smart Images

Figure CN114513298B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network and information security, and more specifically, to a lightweight encryption method that can accept any plaintext length. Background Art
[0002] In the technical field of network and information security, encryption modes process plaintext with a length greater than the block length by invoking block ciphers. Traditional encryption modes include CBC, ECB, CTR, OCF, CFB, etc. These modes can only process data with a plaintext length that is an integer multiple of the block length. For plaintext that is less than an integer multiple of the block length, a padding method is adopted before encryption, which makes the length of the encrypted ciphertext greater than the length of the plaintext. This way will increase the overhead of the system and communication. In addition, the above encryption modes have the disadvantage of weak diffusion. To address this shortcoming, a batch of encryption modes that can accept any plaintext length have emerged, such as HCH, HCTR, and ABL. Most of these encryption modes use hash functions as components. The computational amount of hash functions is relatively large. If they are run on resource-constrained micro computing and processing devices, they will occupy a large amount of device resources, which is not conducive to the micro computing and processing devices to perform other important tasks.
[0003] With the rapid development of the Internet of Things, a large number of micro computing and processing devices have emerged. Such devices have weak computing capabilities and limited storage capabilities. The existing encryption modes based on hash functions have a large computational amount and are difficult to run on such devices. In this context, lightweight cryptography has emerged and become a research hotspot in cryptography. Lightweight cryptography is a concept proposed based on the application environment of cryptography and the actual resources available. Therefore, for those skilled in the art, how to design a lightweight encryption mode that can accept any plaintext length and can run on resource-constrained Internet of Things devices is an urgent problem to be solved. Summary of the Invention
[0004] In view of this, the present invention provides a lightweight encryption method that can accept any plaintext length to solve the problems in the background art and enable it to run on resource-constrained Internet of Things devices.
[0005] To achieve the above object, the present invention adopts the following technical solutions: A lightweight encryption method that can accept any plaintext length, and the specific steps are as follows:
[0006] Key generation: Transform the master key into a sub-key and a whitening key, wherein the whitening key is generated from associated data and the sub-key;
[0007] Plaintext Encryption: Using the sub-key and the whitening key, the plaintext is processed through a five-layer structure to obtain a ciphertext of the same length as the plaintext. The five-layer structure is mainly constructed using the Lai Massey structure and the CTR encryption mode;
[0008] Ciphertext Decryption: The original plaintext is obtained through the reverse process of plaintext encryption.
[0009] Optionally, the specific process of key generation is as follows:
[0010] The main key is split to generate intermediate keys, and the intermediate keys are combined in pairs to generate the sub-keys;
[0011] The whitening key is generated using the associated data and the sub-keys.
[0012] Optionally, the specific process of plaintext encryption is as follows:
[0013] S1. Take plaintext of any length as input and divide the plaintext into a first plaintext and a second plaintext;
[0014] S2. Encrypt the first plaintext using a block cipher to obtain a first sub-plaintext; encrypt the second plaintext using the whitening key to obtain a second sub-plaintext;
[0015] S3. Perform a padding operation on the first sub-plaintext and the second sub-plaintext, and then perform an XOR operation on the first sub-plaintext and the second sub-plaintext. The XOR result and the sub-key are jointly input into a compression function. The value generated by the compression function is XORed with the first sub-plaintext to obtain a third plaintext, and the value generated by the compression function is XORed with the second sub-plaintext to obtain a fourth plaintext;
[0016] S4. Input the third plaintext into a non-linear component to form an initial vector, then use the CTR encryption mode to encrypt the initial vector to form an intermediate quantity, and perform an XOR operation on the intermediate quantity and the fourth plaintext to obtain a fifth plaintext;
[0017] S5. XOR the fifth plaintext with the third plaintext to obtain a sixth plaintext. The sixth plaintext and the sub-key are jointly input into a compression function. The value generated by the compression function is XORed with the fifth plaintext to obtain a seventh plaintext, and the value generated by the compression function is XORed with the third plaintext to obtain an eighth plaintext;
[0018] S6. Use a decryption algorithm on the eighth plaintext and encrypt the seventh plaintext using the whitening key. Concatenate the output results of the decryption algorithm and the whitening key encryption to obtain the final ciphertext.
[0019] Optionally, the whitening key is obtained by iterating over the associated data. The iteration operation is specifically as follows: The input is grouped by bytes, then circularly shifted left by one group length, and finally, the S-box substitution is performed on the first group, and the in-group circular shift is performed on the remaining groups.
[0020] Optionally, the associated data includes: the time information of the sent plaintext and the device information of the sent plaintext.
[0021] Optionally, the non-linear component is a set of identical and involutive S-boxes, and it is required to use S-boxes with a size of 4*4.
[0022] Optionally, in the five-layer structure, the first layer has the same structure as the fifth layer, and the second layer has the same structure as the fourth layer.
[0023] From the above technical solutions, it can be seen that compared with the prior art, the present invention discloses a lightweight encryption method that can accept any plaintext length, and has the following beneficial technical effects:
[0024] 1) The present invention realizes the consistency of the encryption and decryption processes of the algorithm by using involutive components and symmetric structures, and uses some simple and efficient components to replace the hash functions with large computational amounts in the prior art. Compared with the prior art, the running efficiency of the algorithm is improved, and the costs of software and hardware implementation are saved.
[0025] 2) The present invention adopts a variable-length whitening key that can adapt to the plaintext length, which effectively improves the security of the algorithm compared with the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0027] Figure 1 Schematic diagram of the round function WF in the present invention;
[0028] Figure 2 Flowchart of plaintext encryption in the present invention;
[0029] Figure 3 Schematic diagram of the compression function F in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0031] An embodiment of the present invention discloses a lightweight encryption method that can accept any plaintext length, and the specific steps are as follows:
[0032] Step 1: Key generation.
[0033] S1.1. Generate sub-keys using the master key: The device divides a 160-bit master key into 4 40-bit intermediate keys and generates 6 80-bit sub-keys through an extraction method;
[0034] S1.1.1. Division: Divide the master key PK into pk0||pk1||pk2||pk3 in sequence, where || is the concatenation symbol;
[0035] S1.1.2. Extraction: Combine 2 40-bit intermediate keys into an 80-bit sub-key according to an agreement. There are a total of 6 different combination methods, that is, there are 6 different sub-keys. Among them, k0 = pk0||pk1 is used for the underlying block encryption algorithm and the CTR encryption mode, k1 = pk0||pk2 is used for the underlying block decryption algorithm, k2 = pk0||pk3 and k3 = pk2||pk3 are respectively used to generate two whitening keys, and hk0 = pk1||pk2 and hk1 = pk1||pk3 are used for the compression function;
[0036] S1.2. Generate whitening keys using the associated data and sub-keys. The length of the whitening key is equal to the length of the right part of the plaintext after dividing the plaintext, that is, the length of the whitening key is indefinite, and the length of the whitening key is adjusted according to the length of the right part of the plaintext.
[0037] Refer to Figure 1 , and the specific implementation of this step is as follows:
[0038] This step first calculates the number of iteration rounds r, that is, the multiple relationship between the right part of the plaintext and the block length. Then, perform an exclusive OR operation on the associated data and the sub-key k2 (k3), and the result of the exclusive OR is used as the input of the first-round round function WF. Then, perform r-round transformations according to the number of iteration rounds, and the output of each round is used as a component of the whitening key. For example, the output of the first-round round function WF is used as the first part of the whitening key. Finally, intercept the result according to the length of the right part of the plaintext to obtain the whitening key. The specific implementation is as follows:
[0039] S1.2.1. Calculate the number of iteration rounds , where R represents the right part of the plaintext, len(R) represents the bit length of R, and n represents the block length of the underlying block cipher algorithm;
[0040] S1.2.2. Round function WF:
[0041] The round function consists of two steps. In the first step, the input is divided into 10 groups by bytes, and then circularly shifted to the left by one group position to obtain the output of the first step. In the second step, the first group of the output from the previous step is placed into two S-boxes of size 4*4 for permutation, and the remaining 9 groups are circularly shifted within the group, with the shift amounts being 1, 2, 3, 4, 1, 2, 3, 4, 0 respectively;
[0042] S1.2.3. Loop and execute (1.2.2) for r times, and output an 80*r-bit bit string;
[0043] S1.2.4. Intercept the result:
[0044] Extract the left 64 bits from every 80 bits of the previous bit string to form the initial whitening key, and then discard the redundant part on the right of the initial whitening key according to the length of the right part of the plaintext. That is, if the length of the right part of the plaintext is L, the length of the whitening key is also made L through the discard operation.
[0045] Step 2: Encrypt the plaintext.
[0046] Refer to Figure 2 , and the specific implementation of this step is as follows:
[0047] S2.1. The device regards a plaintext bit string of any length as the input and divides it into left and right parts. The length of the left part is equal to the block length received by the underlying block cipher, and the length of the right part is the remaining length after removing one block length. Input the left part and the sub-key k0 into the underlying block cipher E to generate the left output of the first layer. The right part is XORed with the whitening key to generate the right output of the first layer;
[0048] S2.2. Perform a padding operation on the left output from the previous step, and then XOR the left and right parts and input them together with the sub-key hk0 into the compression function F. The compression function F is executed in two stages, namely the absorption stage and the extraction stage. Finally, the results output by the compression function F are XORed with the left and right parts respectively. The implementation of the compression function F can refer to Figure 3。The compression function F is an iterative structure composed of the function P, and the function P consists of a cyclic shift and a non-linear permutation. The compression function F is executed in two stages, namely the absorption stage and the extraction stage. In the absorption stage, each execution of the function P absorbs 8 bits of the data to be compressed and the sub-key, and the number of iterations is determined by the length of the data to be compressed. In the extraction stage, each execution of the function P extracts 8 bits, and a total of 8 executions are performed, that is, the compression function F finally outputs 64-bit data.
[0049] S2.1.1. Completion operation:
[0050] Pad the left output of the previous step with enough zero bits to make its length equal to that of the right part;
[0051] S2.1.2. Absorption stage:
[0052] In the absorption stage, the input intermediate state and sub-key are mainly compressed byte by byte. Assume that the input of the compression function F is the intermediate state M and the sub-key RK, and the length of the intermediate state M is L. Define two initial states B and C with 8 zero bits each. First, divide both M and RK into groups of 8 bits each. Then, in the first round, XOR the first byte of M with the initial state B, and XOR the first byte of RK with the initial state C. The results of the two XOR operations are concatenated into a 16-bit bit string and then input into the function P for the next step of processing. The function P first circularly shifts the 16-bit bit string to the left, and the number of bits shifted is determined by the number of rounds. For example, in the first round, the bit string is circularly shifted one bit to the left. Then, the result of the circular shift is input into a non-linear component composed of 4 identical S-boxes for permutation, and the permutation result is split into two parts and input into the next round. The number of rounds is determined by to decide, that is, after absorbing the entire intermediate state M. The sub-key RK is reused in the absorption stage, that is, when the 10th group of the sub-key is used up, the first group of the sub-key will be used again as part of the input of the function P in the next round;
[0053] S2.1.3. Extraction stage:
[0054] In the extraction stage, a total of 64 bits of output are mainly extracted by executing the function P multiple times. The 8 bits output by the function P are used as part of the output of the round function F. The function P is executed 8 times in total, and a total of 8 results of 8 bits can be extracted, that is, the round function outputs 64-bit results.
[0055] S2.3. Put the left output of the previous layer into a non-linear component to obtain an initial vector, and then encrypt the initial vector using the CTR encryption mode to generate an intermediate quantity of sufficient length for XOR with the right part. The specific implementation is as follows:
[0056] S2.3.1. Split the 64-bit intermediate state input into the non-linear component into groups of 4 bits each, and perform a permutation to obtain a 64-bit initial vector. The non-linear component consists of 16 identical and involutory S-boxes, and the size of the S-box is specified as 4*4;
[0057] S2.3.2. After receiving the initial vector and the sub-key k0, start running the CTR encryption mode to generate intermediate quantities;
[0058] S2.4. This step is similar to the operation in step S2.2, except that the sub-key hk1 is used;
[0059] S2.5. This step is similar to step S2.1. The main difference is that the underlying block encryption algorithm E is replaced with the underlying block decryption algorithm D, and different sub-keys k1 are used. In addition, the right part also performs the operation of XOR whitening key;
[0060] Step 3: Decrypt the ciphertext.
[0061] The encryption and decryption processes of the present invention are the same. The only difference is the order of using the sub-keys. Just use the sub-keys in reverse order, and then the decryption function can be realized through the same process as encryption. The specific details of key usage are: the order of using the keys during encryption is (k0, wk0), hk0, k0, hk1, (k1, wk2), and the order of using the keys during decryption is (k1, wk2), hk1, k0, hk0, (k0, wk0).
[0062] The various embodiments in this specification are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description in the method part.
[0063] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A lightweight encryption method that can accept any plaintext length, characterized in that, The specific steps are as follows: Key generation: Transform the master key into a sub-key and a whitening key, where the whitening key is generated from associated data and the sub-key; Plaintext encryption: Use the sub-key and the whitening key to process the plaintext through a five-layer structure to obtain a ciphertext of the same length as the plaintext, where the five-layer structure is constructed using the Lai-Massey structure and the CTR encryption mode; The specific process of the plaintext encryption is as follows: S1. Take the plaintext of any length as input and divide the plaintext into a first plaintext and a second plaintext; S2. Encrypt the first plaintext using a block cipher to obtain a first sub-plaintext; encrypt the second plaintext using the whitening key to obtain a second sub-plaintext; S3. Perform a complement operation on the first sub-plaintext and the second sub-plaintext, and then perform an XOR operation on the first sub-plaintext and the second sub-plaintext. The XOR result and the sub-key are jointly input into a compression function. The value generated by the compression function is XORed with the first sub-plaintext to obtain a third plaintext, and the value generated by the compression function is XORed with the second sub-plaintext to obtain a fourth plaintext; S4. Input the third plaintext into a non-linear component to form an initial vector, then encrypt the initial vector using the CTR encryption mode to form an intermediate quantity, and perform an XOR operation on the intermediate quantity and the fourth plaintext to obtain a fifth plaintext; S5. XOR the fifth plaintext with the third plaintext to obtain a sixth plaintext. The sixth plaintext and the sub-key are jointly input into a compression function. The value generated by the compression function is XORed with the fifth plaintext to obtain a seventh plaintext, and the value generated by the compression function is XORed with the third plaintext to obtain an eighth plaintext; S6. Use a decryption algorithm on the eighth plaintext and encrypt the seventh plaintext using the whitening key. Concatenate the output results of the decryption algorithm and the whitening key encryption to obtain the final ciphertext; Ciphertext decryption: Obtain the original plaintext through the reverse process of plaintext encryption.
2. The lightweight encryption method capable of accepting any plaintext length according to claim 1, wherein The specific process of the key generation is as follows: Split the master key to generate intermediate keys, and combine the intermediate keys in pairs to generate the sub-key; Generate the whitening key using the associated data and the sub-key.
3. A lightweight encryption method capable of accepting any plaintext length according to claim 1, characterized in that Obtain the whitening key through iterative operations on the associated data. The iterative operations are specifically as follows: Group the input by bytes, then circularly shift it to the left by one group length, and finally perform an S-box substitution on the first group and a cyclic shift within the group on the remaining groups.
4. A lightweight encryption method capable of accepting any plaintext length according to claim 1, characterized in that, The associated data includes: time information of the sent plaintext, device information of the sent plaintext.
5. A lightweight encryption method capable of accepting any plaintext length according to claim 1, characterized in that, The non-linear component is a set of identical and involutory S-boxes, and it is required to use S-boxes of size 4*4.
6. A lightweight encryption method capable of accepting any plaintext length according to claim 1, characterized in that, In the five-layer structure, the first layer is the same as the fifth layer structure, and the second layer is the same as the fourth layer structure.
Citation Information
Patent Citations
Plaintext data encryption method and equipment
CN107257279A
Lightweight inter-satellite information encryption transmission method based on low-earth-orbit satellite internet of things
CN111147230A