An Encryption Device Based on SM9 Algorithm and Its Implementation Method
By decomposing and combining the finite domain operation and elliptic curve operation in the SM9 algorithm and combining the hardware, the problem of excessive hardware resource consumption in lightweight devices is solved, and the effect of efficient use of hardware resources and enhancing system security is achieved.
Patent Information
- Application Number
- CN202011591326.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-29
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-12-29
AI Technical Summary
In lightweight devices, the hardware implementation of the SM9 algorithm is huge due to the huge amount of computational power and bilinear pairs, resulting in excessive hardware resource consumption, which limits its application in lightweight devices such as passive tags.
By decomposing the finite domain operation and elliptic curve operation in the SM9 algorithm, the granularity of atomic operations in the algorithm is reduced, and the two sets of hardware are combined into one set of hardware, supporting the domain operation and elliptic curve operation of the base domain and the extended domain.
It realizes efficient utilization of hardware resources, reduces system power consumption, improves the application capabilities of SM9 algorithm in lightweight devices, and enhances system security and performance through hardware random number generators and hardware hash engines.
Smart Images

Figure CN114697032B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of security technologies, and in particular, to an encryption device based on the SM9 algorithm and its implementation method. Background Art
[0002] Lightweight devices such as smart cards and RFID cards have extensive applications in fields such as identity recognition and sensitive data storage. The increasing security requirements have promoted the application and popularization of public key cryptosystems. However, due to the limitations of computing power and hardware resources, integrating public key cryptosystems in lightweight devices faces many challenges.
[0003] For public key encryption algorithms, it is necessary to check whether the public key has expired before performing encryption operations to ensure its validity. This process requires the device to query according to the current time. For lightweight devices such as passive RFID tags, they do not have their own clock mechanism, and this process cannot be implemented. Due to the characteristics of its algorithm itself, it is not necessary to verify the validity period of the public key before SM9 encryption operations. Therefore, the SM9 algorithm has unique advantages in the application of lightweight devices.
[0004] In the SM9 algorithm, the modular exponentiation and bilinear pairing operations are extremely large, and their hardware implementation requires a large amount of resources. In traditional hardware implementation schemes of the SM9 algorithm, the hardware acceleration engine consists of two parts: a finite field operation hardware unit and an elliptic curve operation hardware unit. The finite field operation hardware unit completes modular addition, modular multiplication, and modular inverse operations. The elliptic curve operation hardware unit completes point addition, point doubling, and point multiplication operations on elliptic curves. Two sets of independent hardware units consume a large amount of power during operation. Therefore, in lightweight devices represented by passive tags, the use of the SM9 algorithm is restricted. Summary of the Invention
[0005] Aiming at the deficiencies existing in the above-mentioned prior art, the purpose of the present invention is an encryption device based on the SM9 algorithm and its implementation method. By decomposing the finite field operations and elliptic curve operations in the SM9 algorithm, the granularity of atomic operations in the algorithm is reduced, and the combination of two sets of hardware for field operations and elliptic curve operations is realized.
[0006] In order to achieve the above technical objectives, the technical solution adopted by the present invention is:
[0007] An encryption device based on the SM9 algorithm, the encryption device includes a central processor, an SM9 algorithm operation coprocessor, a data memory, and an instruction memory. Among them, the central processor is connected to the SM9 algorithm operation coprocessor, the data memory, and the instruction memory. The data memory is connected to the SM9 algorithm operation coprocessor, and the data memory is connected to the instruction memory through the central processor;
[0008] The SM9 algorithm operation coprocessor includes a low-granularity public key engine, a hardware hash engine, and a hardware random number generator engine;
[0009] The central processing unit executes the software scheduling of the SM9 algorithm, controls the storage unit to implement data transfer operations, and controls the coprocessor to achieve hardware acceleration;
[0010] The data memory is a non-volatile memory, which is used for the import, export, and temporary storage of the device operation data, and realizes the data interaction between the central processing unit and the SM9 algorithm operation coprocessor;
[0011] The instruction memory is a read-only memory, which is used to store the compiled SM9 algorithm library;
[0012] The SM9 algorithm operation coprocessor is used to provide hardware acceleration for the elliptic curve, hash, and finite field operations in the SM9 algorithm, and provide a reliable random source for the system security of the encryption device.
[0013] Preferably, the low-granularity public key engine processes the field operations and elliptic curve point operations on the base field and the extension field in the SM9 algorithm.
[0014] Preferably, the hardware random number generator engine adopts a feedback oscillator loop circuit structure based on clock jitter.
[0015] Preferably, the hardware random number generator engine generates random numbers that meet the security requirements of the national cryptography algorithm SM9 protocol, and provides them to the low-granularity public key engine for operation to ensure the security of the algorithm implementation.
[0016] Preferably, the hardware hash engine is used for the hash operation in the SM9 algorithm protocol to implement the SM9 algorithm.
[0017] An implementation method based on the SM9 algorithm, based on the encryption device described above, the specific steps of the implementation method are as follows:
[0018] Step 1: Power on the system, start the central processing unit, and the central processing unit is in the standby state, waiting for external instructions;
[0019] Step 2: Input an external instruction to start the SM9 algorithm operation, and perform data transmission, and transfer the system parameters and SM9 algorithm input data of the encryption device to the target address;
[0020] Step 3: The central processing unit executes the instruction to start the SM9 algorithm operation coprocessor;
[0021] Step 4: Start the hardware random number generator engine to generate random numbers;
[0022] Step 5: Start the low-granularity public key engine, read the random number generated in the above Step 4, perform SM9 algorithm operations, and generate an intermediate operation result;
[0023] Step 6: Start the hardware hash engine, read the intermediate operation result generated in Step 5, perform hash operations, and return the hash operation result to the low-granularity public key engine for subsequent SM9 algorithm operations;
[0024] Step 7: When the SM9 algorithm operation coprocessor is running, the central processor assists the SM9 algorithm operation coprocessor in scheduling between the low-granularity public key engine, the hardware random number generator engine, and the hardware hash engine;
[0025] Step 8: After the SM9 algorithm operation coprocessor finishes the operation, generate a final operation result, and the encryption device performs data transmission and moves the final operation result to the target address.
[0026] For the encryption device based on the SM9 algorithm and its implementation method of the present invention, the encryption device adopts a structure of a central processor, an SM9 algorithm operation coprocessor, a data memory, and an instruction memory. The beneficial effects obtained are:
[0027] First, in the encryption device, a low-granularity public key engine is introduced. By decomposing the granularity of the extension field operation and the elliptic curve operation, a set of field operation hardware units on a basic field supports the field operations and elliptic curve operations of the basic field and the extension field, realizing that one set of hardware supports four operations, improving the utilization rate of hardware resources, and reducing the system power consumption of the encryption device.
[0028] Second, the hardware random number generator engine of the present invention ensures the randomness of data from the entropy source. Compared with the traditional software random number generation algorithm, it has a more stable and secure random source, improving the security of the SM9 algorithm protocol layer.
[0029] Third, the hardware hash acceleration engine in the present invention accelerates the implementation performance of the SM9 algorithm and reduces the load on the central processor. Description of the Drawings
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0031] Figure 1 It is a structural diagram of the encryption device based on the SM9 algorithm in the specific implementation of the present invention.
[0032] Figure 2 This is the schematic diagram of the implementation of the low-granularity public key engine in the specific implementation of the present invention.
[0033] Figure 3 This is the flowchart of the implementation method based on the SM9 algorithm in the specific implementation of the present invention. Specific Embodiments
[0034] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0035] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0036] Refer to Figure 1 , which is the structural diagram of the encryption device based on the SM9 algorithm in the specific implementation of the present invention. The encryption device includes a central processing unit (abbreviated as "CPU") 100, an SM9 algorithm arithmetic coprocessor 200, a data memory 300, and an instruction memory 400. Among them, the central processing unit 100 is connected to the SM9 algorithm arithmetic coprocessor 200, the data memory 300, and the instruction memory 400. The data memory 300 is connected to the SM9 algorithm arithmetic coprocessor 200, and the data memory 300 is connected to the instruction memory 400 through the central processing unit 100;
[0037] The SM9 algorithm arithmetic coprocessor 200 includes a low-granularity public key engine 210, a hardware random number generator engine 220, and a hardware hash engine 230;
[0038] The central processing unit 100 executes the software scheduling of the SM9 algorithm, controls the storage unit to implement data transfer operations, and controls the coprocessor to achieve hardware acceleration;
[0039] The data memory 300 is a non-volatile memory, which is used for importing, exporting, and temporarily storing the operation data of the device, and realizing the data interaction between the central processing unit 100 and the SM9 algorithm arithmetic coprocessor 200;
[0040] The instruction memory 400 is a read-only memory, which is used to store the compiled SM9 algorithm library;
[0041] The SM9 algorithm arithmetic coprocessor 200 is used to provide hardware acceleration for elliptic curve, hash, and finite field operations in the SM9 algorithm, and provide a reliable random source for the system security of the encryption device.
[0042] Refer toFigure 1 , in this specific implementation, the hardware random number generator engine 220 adopts a feedback oscillator loop circuit structure based on clock jitter. This structure is independent of the digital process and can generate a high-speed and stable true random source. Compared with traditional software random number generation algorithms, it has higher security and saves the running time of the central processing unit.
[0043] See Figure 1 , in this specific implementation, the hardware hash engine 230 is implemented based on the national cryptographic SM9 algorithm and is used for hash operations in the SM9 protocol. When implementing the hash engine, a non-pipelined structure with multiple rounds of iterative merging is adopted. On the premise of ensuring the data throughput rate, the system frequency is reduced, and a low-frequency and low-power hardware unit suitable for lightweight devices is realized.
[0044] See Figure 2 , which is the implementation schematic diagram of the low-granularity public key engine in the specific implementation of the present invention. In this specific embodiment, the low-granularity public key engine 210 processes the field operations and elliptic curve point operations on the base field and the extended field in the SM9 algorithm. By decomposing the extended field operations and elliptic curve operations into granularities, a set of field operation hardware units on the base field is used for Figure 2 the expansion and scheduling shown in Figure 2 , in
[0045] See Figure 3 , which is the flowchart of the implementation method based on the SM9 algorithm in the specific implementation of the present invention. In this specific embodiment, the specific steps of the implementation method are as follows:
[0046] Step 1: When the system is powered on, the central processing unit 100 is started and the central processing unit 100 is in the standby state, waiting for external instructions;
[0047] Step 2: Input an external instruction to start the SM9 algorithm operation and perform data transmission, and move the system parameters of the encryption device and the SM9 algorithm input data to the target address;
[0048] Step 3: The central processing unit 100 executes an instruction to start the SM9 algorithm operation coprocessor 200;
[0049] Step 4: Start the hardware random number generator engine 220 to generate random numbers;
[0050] Step 5: Start the low-granularity public key engine 210, read the random number generated in the above Step 4, perform SM9 algorithm operations, and generate an intermediate operation result;
[0051] Step 6: Start the hardware hash engine 230, read the intermediate operation result generated in Step 5, perform a hash operation, and return the hash operation result to the low-granularity public key engine 210 for subsequent SM9 algorithm operations;
[0052] Step 7: When the SM9 algorithm operation coprocessor 200 is running, the central processing unit 100 assists the SM9 algorithm operation coprocessor 200 in scheduling between the low-granularity public key engine 210, the hardware random number generator engine 220, and the hardware hash engine 230;
[0053] Step 8: After the SM9 algorithm operation coprocessor 200 finishes the operation, generate a final operation result, and the encryption device performs data transmission and moves the final operation result to the target address.
[0054] The above has introduced in detail an encryption device based on the SM9 algorithm and its implementation method provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
[0055] It should be noted that the various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0056] It should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements but also other elements inherent to these process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0057] The foregoing description of the disclosed embodiments enables those skilled in the art to practice or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Thus, the present invention is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An encryption device based on the SM9 algorithm, characterized in that, the encryption device includes a central processing unit, an SM9 algorithm operation coprocessor, a data memory, and an instruction memory. Among them, the central processing unit is connected to the SM9 algorithm operation coprocessor, the data memory, and the instruction memory. The data memory is connected to the SM9 algorithm operation coprocessor, and the data memory is connected to the instruction memory through the central processing unit; The SM9 algorithm operation coprocessor includes a low-granularity public key engine, a hardware hash engine, and a hardware random number generator engine; the low-granularity public key engine processes the field operations and elliptic curve point operations on the base field and the extension field in the SM9 algorithm; the hardware hash engine is used for the hash operation in the SM9 algorithm protocol to implement the SM9 algorithm; the hardware random number generator engine adopts a feedback oscillator loop circuit structure based on clock jitter; the central processing unit executes the software scheduling of the SM9 algorithm and controls the storage unit to implement data transfer operations and controls the coprocessor to achieve hardware acceleration; The data memory is a non-volatile memory, which is used for the import, export, and temporary storage of device operation data, and realizes the data interaction between the central processing unit and the SM9 algorithm operation coprocessor; The instruction memory is a read-only memory, which is used to store the compiled SM9 algorithm library; The SM9 algorithm operation coprocessor is used to provide hardware acceleration for the elliptic curve, hash, and finite field operations in the SM9 algorithm, and provide a reliable random source for the system security of the encryption device.
2. The encryption device based on the SM9 algorithm according to claim 1, characterized in that, the hardware random number generator engine generates random numbers that meet the security requirements of the national cryptographic algorithm SM9 protocol and provides them to the low-granularity public key engine for operation.
3. An implementation method based on the SM9 algorithm, based on the encryption device according to any one of claims 1 to 2, characterized in that, the specific steps of the implementation method are as follows: Step 1: Power on the system, start the central processing unit, and the central processing unit is in the standby state, waiting for external instructions; Step 2: Input external instructions to start the SM9 algorithm operation and perform data transmission, and move the system parameters and SM9 algorithm input data of the encryption device to the target address; Step 3: The central processing unit executes the instruction to start the SM9 algorithm operation coprocessor; Step 4: Start the hardware random number generator engine to generate random numbers; Step 5: Start the low-granularity public key engine, read the random numbers generated in the above step 4, perform SM9 algorithm operations, and generate intermediate operation results; Step 6: Start the hardware hash engine, read the intermediate operation results generated in step 5, perform hash operations, and return the hash operation results to the low-granularity public key engine for subsequent SM9 algorithm operations; Step 7: When the SM9 algorithm operation coprocessor is running, the central processor assists the SM9 algorithm operation coprocessor in scheduling between the low-granularity public key engine, the hardware random number generator engine, and the hardware hash engine; the low-granularity public key engine processes the field operations and elliptic curve point operations on the base field and the extension field in the SM9 algorithm; the hardware hash engine is used for the hash operation in the SM9 algorithm protocol to implement the SM9 algorithm; the hardware random number generator engine adopts a feedback oscillator loop circuit structure based on clock jitter; Step 8: After the SM9 algorithm operation coprocessor finishes the operation, it generates the final operation result, and the encryption device performs data transmission and moves the final operation result to the target address.
Citation Information
Patent Citations
Acceleration method for SM9 identification cryptographic algorithm
CN108650078A
Encryption method and device for nonvolatile memory in security chip
CN110795775A