Data processing method, device, processor, chip and electronic device

By using redundant bases to represent elements in the finite domain in the processor and performing inverse calculations, the permutation box computing performance is optimized, and the problem of low computing performance of cryptographic algorithms in the prior art is solved, and more efficient data processing performance and hardware implementation efficiency are achieved.

CN115242376BActive Publication Date: 2025-05-23HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210759972.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-05-23
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

In the prior art, when executing cryptographic algorithms in a processor, the replacement box computing performance is low, resulting in poor data processing performance.

Method used

The performance of the permutation box operation is optimized by representing elements of a finite domain using a redundant basis and performing inverse operations in the permutation box operation.

Benefits of technology

It improves the computing performance of the cryptographic algorithm, reduces the hardware implementation area, and improves the performance of the processor to execute the cryptographic algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115242376B_ABST
    Figure CN115242376B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a data processing method, device, processor, chip and electronic device, wherein the method includes: determining data to be processed, the data is processed using a cryptographic algorithm; in the current round of operation of the cryptographic algorithm, determining the input of the substitution box of the current round of operation; the input of the substitution box is an element of a finite field; using a redundant basis to represent the elements of the finite field; performing an inverse operation on the elements of the finite field represented by the redundant basis; determining the output of the substitution box according to the inverse operation result; determining the operation result of the current round of operation according to the output of the substitution box; and determining the processing result of the data according to the operation result. The data processing method provided by the embodiments of the present application can improve the operation performance of the cryptographic algorithm and reduce the hardware implementation area, so that when the processor uses the cryptographic algorithm to process data, the embodiments of the present application can improve the data processing performance and improve the processor performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of data processing technology, and specifically to a data processing method, device, processor, chip and electronic device. Background Art

[0002] Data can be encrypted and decrypted using a cryptographic algorithm, that is, a cryptographic algorithm can be an algorithm function used to encrypt and decrypt data. The cryptographic algorithm is based on a cryptographic protocol, such as the SM4 algorithm, the AES (Advanced Encryption Standard) algorithm, etc. When a processor uses a cryptographic algorithm to process data, the cryptographic algorithm generally needs to go through multiple rounds of iterative operations, and each round of operations involves Sbox (Substitution box) operations. On this basis, when the processor uses a cryptographic algorithm to process data, how to improve data processing performance has become a technical problem that technicians in this field need to solve urgently. Summary of the invention

[0003] In view of this, the embodiments of the present application provide a data processing method, device, processor, chip and electronic device to improve the scheme of the processor performing substitution box operations, improve the performance of the processor in executing cryptographic algorithms, and thus improve data processing performance.

[0004] To achieve the above objectives, the embodiments of the present application provide the following technical solutions.

[0005] In a first aspect, an embodiment of the present application provides a data processing method, including:

[0006] Determining data to be processed, wherein the data is processed using a cryptographic algorithm, wherein the cryptographic algorithm includes multiple rounds of iterative operations;

[0007] In a current round of operation of the cryptographic algorithm, an input of a substitution box of the current round of operation is determined; the input of the substitution box is an element of a finite field;

[0008] representing elements of the finite field using a redundant basis;

[0009] Performing an inverse operation on the elements of the finite field represented by the redundant basis; determining the output of the substitution box according to the inverse operation result;

[0010] Determine the result of the current round of operation according to the output of the substitution box;

[0011] The processing result of the data is determined according to the operation result.

[0012] In a second aspect, an embodiment of the present application provides a data processing device, including:

[0013] A round calculation unit is used to determine data to be processed, the data is processed using a cryptographic algorithm, wherein the cryptographic algorithm includes multiple rounds of iterative operations; in a current round of operations of the cryptographic algorithm, an input of a substitution box of the current round of operations is determined; the input of the substitution box is an element of a finite field; the elements of the finite field are represented using a redundant basis; an inverse operation is performed on the elements of the finite field represented using the redundant basis; an output of the substitution box is determined based on the inverse operation result; a calculation result of the current round of operations is determined based on the output of the substitution box; and a processing result of the data is determined based on the calculation result;

[0014] The key expansion unit is used to provide round keys in each round of cryptographic algorithms.

[0015] In a third aspect, an embodiment of the present application provides a processor, which is configured to execute the data processing method as described in the first aspect above.

[0016] In a fourth aspect, an embodiment of the present application provides a chip, comprising the processor as described in the third aspect above.

[0017] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising the chip as described in the fourth aspect above.

[0018] The data processing method provided by the embodiment of the present application can determine the data to be processed when the cryptographic algorithm is used to process the data; thereby, in the current round of operation of the cryptographic algorithm, the input of the substitution box is determined, wherein the input of the substitution box is an element of a finite field. On this basis, the embodiment of the present application can improve the operation mode of the substitution box, and when the input of the substitution box is an element of a finite field, a redundant basis is used to represent the element of the finite field; further, the embodiment of the present application can perform an inversion operation in the substitution box operation on the elements of the finite field represented by the redundant basis; thereby, the output of the substitution box is determined according to the result of the inversion operation. After obtaining the output of the substitution box, the embodiment of the present application can determine the operation result of the current round of operation according to the output of the substitution, so as to realize each round of operation when the processor executes the cryptographic algorithm. On the basis of realizing each round of operation of the cryptographic algorithm, the embodiment of the present application can determine the processing result of the data according to the operation result of the current round of operation, so as to realize the processing of the data.

[0019] It can be seen that, when the input of the substitution box is an element of a finite field, the embodiment of the present application can use a redundant basis to represent the element of the finite field, so as to perform substitution box operations based on the redundant basis to achieve the improvement of the substitution box operation in each round of the cryptographic algorithm. Since the redundant basis can balance the characteristics of the normal basis, which is fast in square operation but slow in multiplication operation, and the characteristics of the polynomial basis, which is slow in square operation but fast in multiplication operation, the embodiment of the present application performs the inversion operation in the substitution box operation based on the redundant basis, which can optimize the performance of the substitution box operation, thereby improving the operation performance of the cryptographic algorithm, and further improving the performance of processing data using the cryptographic algorithm; and, since the substitution box operation is performed based on the redundant basis, the hardware implementation area occupied by the substitution box operation through the substitution box lookup table can be reduced, so the embodiment of the present application can reduce the hardware implementation area of ​​the cryptographic algorithm. It can be seen that the data processing method provided by the embodiment of the present application can improve the operation performance of the cryptographic algorithm and reduce the hardware implementation area, so that when the processor uses the cryptographic algorithm to process data, the embodiment of the present application can improve the performance of the processor in executing the cryptographic algorithm, and further improve the processing performance of the data processed by the cryptographic algorithm, and at the same time, the embodiment of the present application can also improve the performance of the processor. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0021] Figure 1 This is an example diagram of the execution process of the SM4 algorithm.

[0022] Figure 2 An example diagram of a substitution box lookup table.

[0023] Figure 3 A flowchart of a data processing method provided in an embodiment of the present application.

[0024] Figure 4 A flow chart of a method for performing substitution box calculations provided in an embodiment of the present application.

[0025] Figure 5 is the first matrix A 1 Example diagram of .

[0026] Fig. 6A is the first isomorphic mapping matrix T 1 Example diagram of .

[0027] Figure 6B is the second isomorphic mapping matrix T 2 Example diagram of .

[0028] Figure 7 This is an example diagram of the operation process of the substitution box.

[0029] Fig. 8A is the first merge matrix B 1 Example diagram of .

[0030] Figure 8B is the third merge matrix B 3 Example diagram of .

[0031] Fig. 9 A block diagram of a data processing device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0033] When using a cryptographic algorithm to process data, take the SM4 algorithm as an example. The SM4 algorithm is a block cipher algorithm with a block size of 128 bits. The SM4 algorithm involves an encryption algorithm, a decryption algorithm, and a key expansion algorithm; wherein the encryption algorithm involves multiple rounds of encryption, the decryption algorithm involves multiple rounds of decryption, and the key expansion algorithm is used to generate round keys used for each round of encryption and decryption. In the SM4 algorithm, both the encryption algorithm and the key expansion algorithm can adopt a 32-round nonlinear iterative structure, and the encryption algorithm and the decryption algorithm use the same round key structure and algorithm structure (both are 32 rounds of operations), but the order of the round keys used by the encryption algorithm and the decryption algorithm is reversed. In other words, the encryption algorithm and the decryption algorithm have the same structure, but the order of the use of the round keys of the encryption algorithm and the decryption algorithm is opposite (that is, the round keys of the decryption algorithm are the reverse order of the round keys of the encryption algorithm).

[0034] Taking encryption operation as an example, Figure 1 The following is an example diagram showing the execution process of the SM4 algorithm. Figure 1 As shown, the input of the SM4 algorithm is plaintext X. After 32 rounds of iterative encryption operations and 1 reverse transformation, the output is ciphertext Y. The block size based on the SM4 algorithm is 128 bits, and the plaintext X and ciphertext Y can both be 128 bits.

[0035] Each round of encryption operation requires a round key generated by a key expansion algorithm. The round key can be obtained by expanding the key expansion algorithm based on the input master key. The master key length can also be 128 bits. Figure 1As shown, in the first round of encryption operation, the input plaintext X can be (X 0 , X 1 , X 2 , X 3 ), using the round key rk 0 After encryption operation, output (X 1 , X 2 , X 3 , X 4 ); In the second round of encryption operation, input (X 1 , X 2 , X 3 , X 4 ), using the round key rk 1 After encryption operation, output (X 2 , X 3 , X 4 , X 5 ); and so on, until the 32nd round of encryption operation, input (X 31 , X 32 , X 33 , X 34 ), using the round key rk 31 After encryption operation, output (X 32 , X 33 , X 34 , X 35 ); Then, the output of the 32nd round of encryption operation (X 32 , X 33 , X 34 , X 35 ) After the reverse transformation R, the output ciphertext Y is obtained, which can be expressed as (Y 0 , Y 1 , Y 2 , Y 3 In one implementation example, the reverse transformation can be expressed as: 0 ,Y 1 ,Y 2 ,Y 3 )=R(X 32 ,X 33 ,X 34 ,X 35 )=(X 35 ,X 34 ,X 33 ,X 32 ).

[0036] Combination Figure 1As shown, in the 32 rounds of encryption operation, for each round of encryption operation, the output of the previous round of encryption operation is encrypted using the round key of this round to obtain the output of this round of encryption operation. For example, in the encryption operation of the i+1th round, the input of the encryption operation can be (X i , X i+1 , X i+2 , X i+3 ), the output can be (X i+1 , X i+2 , X i+3 , X i+4 ), and the round key used in the encryption operation is rk i ; wherein i is an integer from 0 to 31, and i+1 is an integer from 1 to 32.

[0037] That is to say, one round of encryption operation can be used to calculate the next new state word X i+4 , the calculation process can be as follows: X i+4 =F(X i ,X i+1 ,X i+2 ,X i+3 ,rk i ); where F represents a round function. For example, in the i+1th round of encryption operation, the input of the round function F can be (X i , X i+1 , X i+2 , X i+3 ), combined with the round key rk i , the new next state X can be calculated i+4 Furthermore, F(X i ,X i+1 ,X i+2 ,X i+3 ,rk i ) can be expressed as: That is, the operation process of a round of encryption operation can be further expressed as: Among them, T is a composite operation, which is a A reversible transformation, the composite operation T can be composed of a nonlinear transformation τ and a linear transformation L. For example, T can be expressed as: T(.) = L(τ(.)).

[0038] For the linear transformation L, in an implementation example, the linear transformation L can be expressed as:

[0039] Among them, <<< represents a 32-bit circular left shift operation; ⊕ represents a 32-bit exclusive OR operation.

[0040] For the nonlinear transformation τ, the nonlinear transformation τ may include multiple (for example, 4) parallel Sboxes (substitution boxes) for operation; in an implementation example, assuming that the input of the nonlinear transformation τ is E, and E=(e 0 , e 1 , e 2 , e 3 ), then τ(E) can be expressed as:

[0041] τ(E)=(Sbox(e 0 ),Sbox(e 1 ),Sbox(e 2 ),Sbox(e 3 )).

[0042] The above describes the encryption algorithm process of the SM4 algorithm. Since the decryption algorithm in the SM4 algorithm is the inverse operation of the encryption algorithm, the round keys used are reversed from the encryption algorithm. For example, the round key sequence used by the decryption algorithm is (rk 31 , rk 32 ,…,rk 0 ), therefore, the content of the decryption algorithm can be obtained by referring to the content of the above encryption algorithm, and will not be further explained here.

[0043] From the above description, it can be seen that cryptographic algorithms such as the SM4 algorithm need to go through multiple rounds of iterative operations. For example, the encryption algorithm of the SM4 algorithm needs to go through multiple rounds of iterative encryption operations, and the decryption algorithm of the SM4 algorithm needs to go through multiple rounds of iterative decryption operations. Moreover, in each round of operations, it is necessary to calculate the operation results of each round through nonlinear transformation τ; for example, when performing encryption operations, the i+1th round of encryption operations needs to calculate the next new state word X through nonlinear transformation τ. i+4 .

[0044] In each round of operation of a cryptographic algorithm such as the SM4 algorithm, as an implementation example, the nonlinear transformation τ can be implemented by looking up a substitution box lookup table. For example, for each substitution box (Sbox) of the nonlinear transformation, the first 4 bits of the 8-bit input of the substitution box are used as rows and the last 4 bits are used as columns, so that the values ​​of the corresponding rows and columns are searched through the substitution box lookup table to obtain the output of the substitution box. Figure 2 An example diagram showing a substitution box lookup table is shown for reference.

[0045] Although the substitution box lookup table can be used to obtain the output of the substitution box in each round of the SM4 algorithm to achieve nonlinear transformation, and then the nonlinear transformation result of each round of operation is used to determine the result of each round of operation. However, the storage space occupied by the substitution box lookup table is large (for example, Figure 2The storage space occupied by the substitution box lookup table shown is 2048 bits), which will increase the hardware implementation area of ​​the cryptographic algorithm such as the SM4 algorithm. In particular, when a random mask is used to defend against power consumption analysis, the newly constructed substitution box lookup table will occupy a larger hardware implementation area. In an implementation example, the cryptographic algorithm such as the SM4 algorithm can be implemented by hardware, for example, by hardware such as a processor or a cryptographic coprocessor using the hardware instructions of the cryptographic algorithm such as the SM4 algorithm to implement the cryptographic algorithm such as the SM4 algorithm.

[0046] In order to reduce the area occupied by the substitution box lookup table for hardware implementation, as an implementation example, in each round of operation of a cryptographic algorithm such as the SM4 algorithm, nonlinear transformation can be implemented by means of a finite composite field. For example, a normal basis is used to represent the elements of a finite field, and the output of the substitution box (Sbox) is calculated using the normal basis, thereby avoiding the storage of the entire substitution box lookup table, thereby achieving the effect of reducing the hardware implementation area.

[0047] However, there is still a need to improve the performance of cryptographic algorithms based on the use of normal bases to represent elements of finite fields to implement substitution box (Sbox) operations. The inventors of the present application have found that when using normal bases to represent elements of finite fields, the characteristics of normal bases are that square operations are fast, but multiplication operations are slow; and finite fields can also be represented by polynomial bases, redundant bases, etc. Among them, the characteristics of polynomial bases are that square operations are slow, but multiplication operations are fast; and redundant bases balance the advantages and disadvantages of normal bases and polynomial bases.

[0048] Based on this, the embodiment of the present application considers improving the operation mode of the substitution box in each round of operation of the cryptographic algorithm such as the SM4 algorithm, and using a redundant basis to represent the finite field GF(2 8 ) to calculate the output of the substitution box (Sbox); and then use the output of the substitution box to determine the result of each round of operation.

[0049] Based on the above ideas, Figure 3 An optional flow chart of the data processing method provided in the embodiment of the present application is shown as an example. Figure 3 As shown, the method flow may include the following steps.

[0050] In step S310, data to be processed is determined, and the data is processed using a cryptographic algorithm, wherein the cryptographic algorithm includes multiple rounds of iterative operations.

[0051] The embodiments of the present application may utilize cryptographic algorithms to process data, such as utilizing cryptographic algorithms to encrypt plaintext data, or utilizing cryptographic algorithms to decrypt ciphertext data; accordingly, the data to be processed may be plaintext data to be encrypted or ciphertext data to be decrypted.

[0052] In step S311, in the current round of operation of the cryptographic algorithm, the input of the substitution box of the current round of operation is determined.

[0053] Cryptographic algorithms such as the SM4 algorithm and the AES algorithm include multiple rounds of iterative operations, and the operations performed in the current round can be called the current round operations. Taking the SM4 algorithm as an example, in the current round of operations, the composite operation of the nonlinear transformation τ and the linear transformation L can be used to determine the operation result of the current round of operations (for example, the new state word of the current round of operations). In an implementation example, taking the encryption algorithm of the SM4 algorithm as an example, in the i+1th round of operations, the composite operation T of the linear transformation L and the nonlinear change τ can be used to determine the new state word X of the i+1th round of operations. i+4 .

[0054] Taking the SM4 algorithm as an example, when the substitution box operation method of the nonlinear transformation is improved, the nonlinear transformation includes parallel operations of multiple substitution boxes (for example, 4 parallel substitution boxes are operated to form a nonlinear transformation). Based on this, as an optional implementation, in the current round of operations, the embodiment of the present application can determine the input of the nonlinear transformation of the current round of operations, wherein the nonlinear transformation includes parallel operations of multiple substitution boxes (Sbox); further, the input of each substitution box in the current round of operations is determined through the input of the nonlinear transformation.

[0055] In some embodiments, the embodiments of the present application can obtain the output of the previous round of operation and the round key used in the current round in the current round of operation; from the output of the previous round of operation and the round key used in the current round, determine the input of the nonlinear transformation of the current round of operation. As an example, taking the encryption algorithm of the SM4 algorithm as an example, in the jth round of operation, the output of the previous round of operation is (X i , X i+1 , X i+2 , X i+3 ), the round key used in the current round of operation is rk i , then the input of the nonlinear transformation of the jth round of operation can be (X i+1 , X i+2 , X i+3 , rk i ); that is, in the encryption algorithm, the last three state words output by the previous round of operation and the round key used in the current round are used as the input of the nonlinear transformation of the current round of operation.

[0056] Further, taking the SM4 algorithm as an example, after determining the input of the nonlinear transformation of the current round of operation, based on the fact that the nonlinear transformation includes parallel operation of multiple substitution boxes, the embodiment of the present application can determine the input of each substitution box from the input of the nonlinear transformation. As an example, taking the encryption algorithm of the SM4 algorithm as an example, in the i+1th round of operation, the input of the nonlinear transformation τ can be (X i+1 , Xi+2 , X i+3 , rk i ),but The length of the last 8 bits is 32 bits, and each 8-bit data can be used as the input of the 4 substitution boxes in the nonlinear transformation in turn; for example, the first 8-bit data is used as the input of the first substitution box in the nonlinear transformation, the second 8-bit data is used as the input of the second substitution box in the nonlinear transformation, the third 8-bit data is used as the input of the third substitution box in the nonlinear transformation, and the fourth 8-bit data is used as the input of the fourth substitution box in the nonlinear transformation. In other words, in the encryption algorithm, the last three state words output by the previous round of operation and the round key used in the current round can be used as the input of each substitution box in turn.

[0057] In the embodiment of the present application, the input of the substitution box can be an element of a finite field. For example, the input of a substitution box can be set to e (for example, e can be 8 bits of any item in the 32 bits of data after the encryption algorithm), then in the jth round of operation of the encryption algorithm, e is the finite field GF(2 8 ) elements.

[0058] In step S312, redundant bases are used to represent elements of the finite field.

[0059] In the embodiment of the present application, a redundant basis can be used to represent the elements of a finite field, and the input of a substitution box can be regarded as an element of a finite field. Therefore, in the embodiment of the present application, a redundant basis can be used to represent the input of the substitution box. For example, for any input e of a substitution box, e is a finite field GF(2 8 ), the embodiment of the present application can use a redundant basis to represent the finite field GF(2 8 ) elements.

[0060] In some embodiments, the present invention can set a target set corresponding to the redundant basis (defined as the target set F), and the target set F is isomorphic to the finite field GF (2 8 ), then for the input of any substitution box, when a redundant basis is used to represent an element of a finite field, the embodiment of the present application can use the elements in the target set corresponding to the redundant basis to represent the element of the finite field, and an element of a finite field is represented using multiple bits with redundancy.

[0061] For ease of understanding, let the expression of the target set F be {<(x+1)mod(x 9 +1)>∪{0},+,·}, where + represents addition and dot represents multiplication. The above expression can be understood as an expression in algebraic number theory; there are 2 8 elements, and each element is a function of (x+1)mod(x9 +1), where the lowercase x here represents the unknown quantity in the element, which is different from the plaintext input of the encryption algorithm represented by the uppercase X above; under the above definition, the set F is isomorphic to the finite field GF(2 8 ), so the finite field GF(2 8 ) can be represented by the elements in the target set F corresponding to the redundant basis. In an implementation example, 9 bits can represent the finite field GF(2 8 ) is an element of ; for example, let a(x) and b(x) be the finite field GF(2 8 ), then a(x) can be expressed as a(x)=a 0 +a 1 x+...+a 8 x, b(x) can be expressed as b(x)=b 0 +b 1 x+...+b 8 x; It should be noted that in the above example, a(x) and b(x) can be expressed as polynomials. In this implementation example, when a redundant basis is used to represent the elements of a finite field, 9 bits can be used to represent the finite field GF(2 8 ), which is 8 bits more than the normal basis or polynomial basis to represent the finite field GF(2 8 ) is a redundant representation.

[0062] In step S313, an inverse operation is performed on the elements of the finite field represented by the redundant basis; and the output of the substitution box is determined according to the result of the inverse operation.

[0063] For any substitution box, when the input of the substitution box is an element of a finite field, and the embodiment of the present application uses a redundant basis to represent the elements of the finite field, the embodiment of the present application can implement the inverse operation in the substitution box operation based on the redundant basis, and then determine the output of the substitution box according to the result of the inverse operation.

[0064] In some embodiments, the target set F (the target set F is isomorphic to the finite field GF (2 8 )), when operating any substitution box, the embodiment of the present application can be based on the first matrix A 1 The first affine transformation, and the first isomorphism mapping matrix T 1 The first isomorphic mapping transforms the elements of the finite field represented by the redundant basis to the target set F; and then performs an inverse operation in the target set F. After obtaining the inverse operation result, the embodiment of the present application can further transform the inverse operation result based on the second isomorphic mapping matrix T 2 The second isomorphic mapping, and based on the second matrix A2 The second affine transformation of , transforming back to the finite field GF(2 8 ), and thus obtain the output of the substitution box. In an implementation example, let the input of a substitution box be e, and e is a finite field GF(2 8 ) and represented using a redundant basis, the output of the substitution box Sbox(e) can be expressed as:

[0065] Sbox(e)=I(e·A 1 ·T 1 +C·T 1 )·T 2 ·A 2 +C.

[0066] As an optional implementation, the first matrix A of the first affine transformation 1 and the second matrix A of the second affine transformation 2 The matrix form of can refer to the above description; the first isomorphic mapping T 1 The target set F can be isomorphic to the finite field GF(2 8 ), the second isomorphic mapping T 2 Can be T 1 is the inverse mapping of (that is, the second isomorphic mapping is the inverse mapping of the first isomorphic mapping).

[0067] In step S314, the result of the current round of operations is determined according to the output of the substitution box.

[0068] Taking the SM4 operation as an example, in the current round of the SM4 operation, after obtaining the output of each substitution box, the embodiment of the present application can obtain the nonlinear transformation result of the nonlinear transformation based on the output of the parallel operation of multiple substitution boxes in the nonlinear transformation; then perform a linear transformation based on the nonlinear transformation result to obtain the operation result of the composite operation; and then determine the operation result of the current round of the operation (for example, the new state word calculated by the current round of the operation) based on the operation result of the composite operation.

[0069] In one example, taking the encryption algorithm of the SM4 algorithm as an example, in the jth round of operation, the embodiment of the present application can obtain a nonlinear transformation result of the nonlinear transformation τ according to the output of the parallel operation of the four substitution boxes; then, using T(.)=L(τ(.)), the nonlinear transformation result is linearly transformed to obtain the operation result of the composite operation T; for example, the operation result of the composite operation T is T(X i+1 +X i+2 +X i+3 +rk i ); thus the result of the compound operation is combined with the first status word (e.g. X i ) to obtain the new state word X calculated by the current round of operationi+4 ,For example:

[0070]

[0071] In step S315, the processing result of the data is determined according to the calculation result.

[0072] In some embodiments, after obtaining the operation result of the current round of operation, if the current round of operation is the last round of operation of the cryptographic algorithm, the embodiment of the present application can directly obtain the processing result of the data based on the operation result of the current round of operation; for example, in the data encryption processing process taking the SM4 algorithm as an example, the embodiment of the present application can reverse the operation result of the current round of operation when the current round of operation is the last round of operation of the cryptographic algorithm, and obtain the ciphertext data after data encryption, thereby determining the processing result of the data. In other embodiments, after obtaining the operation result of the current round of operation, if the current round of operation is not the last round of operation of the cryptographic algorithm, the embodiment of the present application can perform iterative operations of the remaining rounds of the cryptographic algorithm based on the operation result of the current round of operation until the operation result of the last round of operation of the cryptographic algorithm is obtained, thereby directly obtaining the processing result of the data based on the operation result of the last round of operation.

[0073] The data processing method provided by the embodiment of the present application can determine the data to be processed when the cryptographic algorithm is used to process the data; thereby, in the current round of operation of the cryptographic algorithm, the input of the substitution box is determined, wherein the input of the substitution box is an element of a finite field. On this basis, the embodiment of the present application can improve the operation mode of the substitution box, and when the input of the substitution box is an element of a finite field, a redundant basis is used to represent the element of the finite field; further, the embodiment of the present application can perform an inversion operation in the substitution box operation on the elements of the finite field represented by the redundant basis; thereby, the output of the substitution box is determined according to the result of the inversion operation. After obtaining the output of the substitution box, the embodiment of the present application can determine the operation result of the current round of operation according to the output of the substitution, so as to realize each round of operation when the processor executes the cryptographic algorithm. On the basis of realizing each round of operation of the cryptographic algorithm, the embodiment of the present application can determine the processing result of the data according to the operation result of the current round of operation, so as to realize the processing of the data.

[0074] It can be seen that when using a cryptographic algorithm to process data, based on the fact that the input of the substitution box during the execution of the cryptographic algorithm is an element of a finite field, the embodiment of the present application can use a redundant basis to represent the elements of the finite field, so as to perform substitution box operations based on the redundant basis to achieve improvements in substitution box operations in each round of operations of the cryptographic algorithm. Since the redundant basis can balance the characteristics of the normal basis, which is fast in square operations but slow in multiplication operations, and the characteristics of the polynomial basis, which is slow in square operations but fast in multiplication operations, the embodiment of the present application performs inversion operations in substitution box operations based on the redundant basis, which can optimize the performance of substitution box operations (for example, optimize the performance of nonlinear transformations implemented through finite composite fields), thereby improving the operation performance of the cryptographic algorithm, and further improving the performance of processing data using the cryptographic algorithm; and since the substitution box operations are performed based on the redundant basis, the hardware implementation area occupied by the substitution box operations performed through the substitution box lookup table can be reduced, the embodiment of the present application can reduce the hardware implementation area of ​​the cryptographic algorithm. It can be seen that the data processing method provided by the embodiment of the present application can improve the computing performance of the cryptographic algorithm and reduce the hardware implementation area. Therefore, when the processor uses the cryptographic algorithm to process data, the embodiment of the present application can improve the performance of the processor in executing the cryptographic algorithm, thereby improving the processing performance of the data processed by the cryptographic algorithm. At the same time, the embodiment of the present application can also improve the performance of the processor.

[0075] In some embodiments, using a redundant basis to represent an element of a finite field may be a redundant representation, that is, compared with using a normal basis or a polynomial basis to represent an element of a finite field, using a redundant basis to represent an element of a finite field requires more bits; for example, a redundant basis uses 9 bits to represent an element of a finite field, while a normal basis or a polynomial basis uses 8 bits to represent an element of a finite field. Under this redundant representation, when using a redundant basis to represent an element of a finite field, the square operation of the element may be implemented by bit permutation. For example, let a(x) be the finite field GF(2 8 ), then the square operation of a(x) can be expressed as: Wherein, k represents the kth coefficient of the polynomial a, when the redundant basis uses 9 bits to represent an element of the finite field, k is an integer from 0 to 8, and 2·k mod 9 represents the remainder after 2*k is divided by 9.

[0076] It can be seen that when a redundant basis is used to represent the elements of a finite field, the square operation of the elements can be implemented by bit replacement, which can be optionally expressed as the adjustment of metal wires in hardware implementation (for example, each metal wire transmits a 1-bit data). Therefore, when a redundant basis is used to represent the elements of a finite field, the time consumption of the square operation of the elements is extremely small compared to multiplication and can be ignored, which has the same advantages as the normal basis.

[0077] When a redundant basis is used to represent the elements of a finite field, the multiplication of the elements is similar to the multiplication performed when a polynomial basis is used to represent the elements of a finite field, and has similar advantages as a polynomial basis. For example, let a(x) and b(x) be the finite field GF(2 8 ), then the multiplication of a(x) and b(x) can be expressed as:

[0078] It should be noted that j is a variable ranging from 0 to 8, and the subscript of the polynomial b is (jk) mod 8.

[0079] As an alternative implementation, we can use a redundant basis to represent the finite field GF(2 8 ), the multiplication result of element a(x)·b(x) can store 9 coefficients in the computer. Where j is a variable from 0 to 8, that is, one value of j corresponds to one coefficient. Due to the parallel nature of hardware implementation, these nine coefficients can be calculated simultaneously. In the first step, based on k values ​​from 0 to 8 and j values ​​from 0 to 8, a 9×9 AND gate matrix can be used to calculate a for all values ​​of k and j. k b (j-k)mod8 ; The second step is to calculate the above 9 coefficients in parallel. Taking one of the coefficients as an example, when j = 8, the corresponding coefficient is where k is from 0 to 8 k b (8-k)mod8 The results have been calculated in the first step. Here we can use these 9 a k b (8-k)mod8 Then, the embodiment of the present application uses four XOR processes to obtain the final calculated value; for example, after the first XOR process, 5 calculated values ​​remain, after the second XOR process, 3 calculated values ​​remain, after the third XOR process, 2 calculated values ​​remain, and after the fourth XOR process, The final calculated value of . In summary, when using redundant basis to represent finite field GF(2 8 ), the latency of the element-wise multiplication is 1 AND and 4 XOR operations.

[0080] When redundant bases are used to represent the elements of a finite field, based on the square operation and multiplication operation of the elements, for the finite field GF(2 8 ), such as element a(x), satisfies (a(x)) 28 =a(x), and the following relationship exists:

[0081]

[0082] Based on this, when using redundant basis to represent finite field GF(28 ), as an alternative implementation, the finite field GF(2 8 ) can be converted into square and multiplication operations, and the inversion operation requires 4 multiplications and 7 squares. On this basis, the permutation box operation can be optionally performed based on the first matrix A 1 and the second matrix A 2 As an optional implementation, when redundant bases are used to represent the elements of a finite field, Figure 4 The flowchart of an optional method for performing substitution box calculation provided by an embodiment of the present application is exemplarily shown. Figure 4 As shown, the method flow may include the following steps.

[0083] In step S410, the elements of the finite field are transformed to a target set corresponding to a redundant basis through a first affine transformation and a first isomorphic mapping.

[0084] In the case of using a redundant basis to represent the elements of a finite field, the embodiment of the present application may process the elements of the finite field through a first affine transformation, and then process the processing result through a first isomorphic mapping, so as to transform it to a target set F corresponding to the redundant basis. In an example, the first affine transformation may be based on a preset first matrix A 1 The first isomorphic mapping can be based on a preset first isomorphic mapping matrix T 1 That is, as an optional implementation, the embodiment of the present application can transform the elements of the finite field by a first matrix A based on a preset 1 The linear transformation and the first isomorphic mapping matrix T based on the preset 1 The nonlinear transformation is transformed to the target set F corresponding to the redundant basis. That is, the embodiment of the present application can perform a linear transformation on the elements of the finite field based on a preset first matrix; and then perform a nonlinear transformation on the linear transformation result based on a preset first isomorphic mapping matrix to transform it to the target set corresponding to the redundant basis.

[0085] As an optional implementation, the preset first matrix A 1 For examples, see Figure 5 As shown in the example. The first isomorphic mapping matrix T 1 The target set F can be isomorphic to the finite field GF(2 8 As an optional implementation, the embodiment of the present application can use the isomorphic mapping of the polynomial basis and the redundant basis to derive the first isomorphic mapping matrix T corresponding to the first isomorphic mapping 1 , thereby realizing the inverse operation in the permutation box operation using the redundant basis.

[0086] As an optional implementation, taking the 8-bit data as an example of the substitution box input of the SM4 algorithm, the 8-bit data can be a finite field GF(2 8 ) is an element in the finite field GF(2 8 ) is isomorphic to GF(2)[x] / (p(x)), where p(x) = x 8 +x 7 +x 6 +x 5 +x 4 +x 3 +x 2 +x+1, so GF(2)[x] / (p(x)) is isomorphic to the target set F corresponding to the redundant basis, F={<(x+1)mod(x 9 +1)>∪{0},+,·}.

[0087] Furthermore, since the generator of non-zero elements in GF(2)[x] / (p(x)) is x mod p(x), and the generator of non-zero elements in the target set F is (x+1) mod(x 9 +1), so the target set F is isomorphic to the finite field GF(2 8 ) can be expressed as: in, Represents a mapping.

[0088] Furthermore, the embodiment of the present application can use the isomorphic mapping of the polynomial basis and the redundant basis to derive the first mapping matrix T corresponding to the first isomorphic mapping: 1 As an optional implementation, the corresponding relationship between the polynomial basis and the redundant basis can be shown in Table 1 below.

[0089] Polynomial basis Redundant Base <![CDATA[α 0 =0000 0010]]> <![CDATA[β 0 =0 0000 0011]]> <![CDATA[α 1 =0000 0100]]> <![CDATA[β 1 =0 0000 0101]]> <![CDATA[α 2 =0000 1000]]> <![CDATA[β 2 =0 0000 1111]]> <![CDATA[α 3 =0001 0000]]> <![CDATA[β 3 =0 0001 0001]]> <![CDATA[α 4 =0010 0000]]> <![CDATA[β 4 =0 0011 0011]]> <![CDATA[α 5 =0100 0000]]> <![CDATA[β 5 =0 0101 0101]]> <![CDATA[α 6 =1000 0000]]> <![CDATA[β 6 =0 1111 1111]]> <![CDATA[α 7 =0000 0001]]> <![CDATA[β 7 =1 0000 0001]]>

[0090] Table 1

[0091] Based on the corresponding relationship in Table 1, the embodiment of the present application can derive the first isomorphic mapping matrix T corresponding to the first isomorphic mapping. 1 In matrix form, the preset first isomorphic mapping matrix T is realized 1 In one implementation example, the first isomorphic mapping matrix T 1 The matrix form can be, for example, Fig. 6A shown.

[0092] In a further optional implementation, the embodiment of the present application may multiply the elements of the finite field by the first matrix A 1 and the first isomorphism mapping matrix T 1 , thereby transforming the elements of the finite field to the target set F corresponding to the redundant basis. For example, let the input of the box-changing be e, and e be a finite field GF(28 ) elements, then through e·A 1 ·T 1 , e can be transformed to the target set F corresponding to the redundant basis.

[0093] In step S411, an inversion operation is performed in the target set.

[0094] As an optional implementation, the embodiment of the present application can transform the elements of the finite field to the target set F, as well as the preset constant matrix and the first isomorphic mapping matrix T 1 An inverse operation is performed, thereby performing an inverse operation in the target set F and obtaining an inverse operation result. As an implementation example, an example formula for performing an inverse operation in the target set F may be, for example: I(e·A 1 ·T 1 +C·T 1 ). That is, in the implementation example, the embodiment of the present application can transform the elements of the finite field into the result e·A of the target set F. 1 ·T 1 , with the constant matrix C and the first isomorphic mapping matrix T 1 The multiplication results are added; and the addition result is then inverted to obtain the inversion operation result. As an optional implementation, the constant matrix C can be preset, and its matrix form can be, for example, (11001011).

[0095] In step S412, the inverse operation result is transformed back to the finite field through the second isomorphic mapping and the second affine transformation to obtain the output of the substitution box.

[0096] After obtaining the inverse operation result, the embodiment of the present application can process the inverse operation result through the second isomorphic mapping, and then process the processing result through the second affine transformation, so as to transform it back to the finite field GF(2 8 ), and obtain the output of the substitution box. In an implementation example, the second isomorphic mapping can be based on a preset second isomorphic mapping matrix T 2 The nonlinear transformation, the second isomorphism mapping matrix T 2 Through the first isomorphism mapping matrix T 1 Determine; the second affine transformation can be based on a preset second matrix A 2 The linear transformation of the first matrix A 1 With the second matrix A 2 That is to say, as an optional implementation, the embodiment of the present application can convert the inverse operation result into the same matrix based on the preset second isomorphic mapping matrix T 2 The nonlinear transformation and the second matrix A based on the preset 2 The linear transformation of GF(2 8), thereby obtaining the output of the substitution box. For example, in the embodiment of the present application, the inverse operation result can be based on the second isomorphic mapping matrix T 2 Perform nonlinear transformation; then use the nonlinear transformation result based on the second matrix A 2 Perform a linear transformation to transform back to the finite field GF(2 8 ) to get the output of the substitution box.

[0097] As an optional implementation, the embodiment of the present application can be based on Fig. 6A The first isomorphism mapping matrix T shown 1 Determine the second isomorphic mapping matrix T 2 In matrix form, the second isomorphism mapping matrix T 2 An example of a matrix form of can be, for example Figure 6B shown.

[0098] In a further optional implementation, the embodiment of the present application can be based on the inverse operation result, the second isomorphic mapping matrix T 2 , the second matrix A 2 and constant matrix, transform the inverse operation result back to the finite field to obtain the output of the substitution box. As an implementation example, set the input of the substitution box to e, e is the finite field GF(2 8 ) and represented using a redundant basis, the output of the substitution box Sbox(e) can be expressed as:

[0099] Sbox(e)=I(e·A 1 ·T 1 +C·T 1 )·T 2 ·A 2 +C.

[0100] Where I represents the inverse operation, C is a constant matrix, and C can be expressed as (11001011). The first matrix A 1 can be compared with the second matrix A 2 Equal, the first matrix A 1 and the second matrix A 2 An example can be Figure 5 Example shown.

[0101] In this implementation example, the embodiment of the present application can convert the inverse operation result I(e·A 1 ·T 1 +C·T 1 ) and the second isomorphic mapping matrix T 2 and the second matrix A 2 Multiply them; then perform matrix addition on the multiplication result and the constant matrix C to obtain the output of the substitution box.

[0102] For ease of understanding, Figure 7The following is an example diagram showing the operation process of the substitution box. When the input of the substitution box is a finite field GF(2 8 ) and use redundant basis to represent the finite field GF(2 8 ), the present embodiment can convert the input of the permutation box (i.e., the finite field GF(2 8 ) elements), based on the preset first matrix A 1 Perform an affine transformation (e.g. e·A 1 );The affine transformation result is based on the first isomorphic mapping matrix T 1 Perform isomorphic mapping (e.g. e·A 1 ·T 1 ) to transform the elements of the finite field to the target set F; thus, the embodiment of the present application can perform an inverse operation in the target set F (for example, I(e·A 1 ·T 1 +C·T 1 )) to obtain the inverse operation result; further, the embodiment of the present application can obtain the inverse operation result based on the second isomorphic mapping matrix T 2 Perform isomorphic mapping (for example, I(e·A 1 ·T 1 +C·T 1 )·T 2 ); The isomorphic mapping result is based on the second matrix A 2 Perform an affine transformation (e.g. I(e·A 1 ·T 1 +C·T 1 )·T 2 ·A 2 +C), to transform back to the finite field GF(2 8 ), thus obtaining the output of the substitution box.

[0103] In a further optional implementation, based on the expression of the substitution box output, the embodiment of the present application can convert the first matrix A into 1 and the first isomorphism mapping matrix T 1 Merge to get the first merge matrix B 1 For example, the first matrix A 1 and the first isomorphic mapping matrix T 1 Multiply to get the first merge matrix B 1 , that is, B 1 =A 1 ·T 1 Thus, when the elements of the finite field are transformed to the target set through the first affine transformation and the first isomorphic mapping, the embodiment of the present application can transform the elements of the finite field based on the first merge matrix B 1 Perform a linear transformation (e.g. e·B 1), to transform to the target set corresponding to the redundant basis. In an implementation example, the first merge matrix B 1 The matrix form can be Fig. 8A Example shown.

[0104] Furthermore, in the embodiment of the present application, the constant matrix C and the first isomorphic mapping matrix T 1 Merge to obtain the second merge matrix B 2 For example, the constant matrix C is combined with the first isomorphic mapping matrix T 1 Multiply them to get the second merge matrix B 2 , that is, B 2 =C·T 1 Thus, when performing an inverse operation in the target set, the embodiment of the present application can transform the elements of the finite field into the result of the target set (e.g., e·B 1 ), and the second merge matrix B 2 Perform an inverse operation to obtain an inverse operation result (for example, I(e·B 1 +B 2 )). In one implementation example, the second merge matrix B 2 The matrix form can be, for example, 2 =(110100111).

[0105] Furthermore, in the embodiment of the present application, the second isomorphic mapping matrix T 2 and the second matrix A 2 Merge to get the third merge matrix B 3 ; For example, the second isomorphic mapping matrix T 2 With the second matrix A 2 Multiply them to get the third merge matrix B 3 , that is, B 3 =T 2 ·A 2 Thus, when the inverse operation result is transformed back to the finite field through the second isomorphic mapping and the second affine transformation to obtain the output of the substitution box, the embodiment of the present application can convert the inverse operation result (for example, I(e·B)) into 1 +B 2 )), based on the third merge matrix B 3 Perform a linear transformation (e.g. I(e·B 1 +B 2 )·B 3 ); then based on the linear transformation result and the constant matrix C, the output of the substitution box is obtained (for example, I(e·B 1 +B 2 )·B 3 In one implementation example, the third merge matrix B 3 The matrix form can be Figure 8B Example shown.

[0106] The first merged matrix B obtained by merging based on the embodiment of the present application 1 , the second merge matrix B 2 and the third merge matrix B 3 , the embodiment of the present application can convert the expression of the output Sbox(e) of the substitution box into:

[0107] Sbox(e)=I(e·B 1 +B 2 )·B 3 +C.

[0108] That is, the permutation box operation can be simplified to be based on the first merge matrix B 1 and the third merge matrix B 3 The inverse operation is performed in the target set F, which requires only 4 multiplications and 7 squarings. Furthermore, by utilizing the characteristics of the redundant basis, since the delay of the squaring operation can be ignored, and the delay of the multiplication operation is 1 AND (AND operation) plus 3 XOR (exclusive OR operation), the delay of the inverse operation is 4 ANDs and 12 XORs, thereby improving the operation speed and performance of the substitution box operation. In other words, the substitution box operation based on the redundant basis of the embodiment of the present application can reduce the hardware implementation area compared to the substitution box operation through the substitution box lookup table, and has a faster operation speed compared to the substitution box operation using the normal basis and the polynomial basis.

[0109] Furthermore, in the process of performing substitution box operations based on redundant bases, the embodiment of the present application uses isomorphic mappings of polynomial bases and redundant bases to derive an isomorphic mapping matrix (e.g., the first isomorphic mapping matrix T 1 and the second isomorphism mapping matrix T 2 ), so that the inverse operation of the substitution box operation in the SM4 algorithm can be performed using a redundant basis, and the embodiment of the present application further utilizes the characteristics of the square operation and multiplication operation of the redundant basis to optimize the inverse operation and increase the operation speed, thereby improving the operation performance of the SM4 algorithm.

[0110] Furthermore, the data processing scheme provided by the embodiment of the present application is applicable not only to the SM4 algorithm, but also to cryptographic algorithms with substitution box operations such as AES. That is to say, in any cryptographic algorithm with substitution box operations, the embodiment of the present application can map the inversion operation involved in the substitution box operation to the redundant basis in each round of operation of the cryptographic algorithm (for example, each round of encryption operation or each round of decryption operation), and optimize the performance of the substitution box operation by utilizing the characteristics of the square operation and multiplication operation of the redundant basis, so as to achieve the effect of reducing the hardware implementation area and improving the operation speed; thus, when the processor executes the cryptographic algorithm, the embodiment of the present application can improve the performance of the processor in executing the cryptographic algorithm and improve the performance of the processor.

[0111] The data processing scheme provided by the embodiment of the present application can be applied to data encryption or data decryption scenarios. For example, based on the data processing scheme provided by the embodiment of the present application, when using a cryptographic algorithm to encrypt or decrypt data, the input of the substitution box can be regarded as an element of a finite field in each round of operation of the cryptographic algorithm, and the elements of the finite field can be represented by a redundant basis, so that in each round of operation of the cryptographic algorithm, the output of the substitution box is determined to determine the operation result of each round of operation of the cryptographic algorithm; further, based on the operation result of the last round of the cryptographic algorithm, the embodiment of the present application can determine the ciphertext data after the data is encrypted, or the plaintext data after the data is decrypted; in the data encryption or data decryption scenario, the data processing scheme provided by the embodiment of the present application is applied to improve data processing performance.

[0112] The data processing device provided in the embodiment of the present application is introduced below. The data processing device can be a processor such as a CPU, a cryptographic coprocessor, etc., which is a functional device required to implement the data processing method provided in the embodiment of the present application. In some embodiments, the data processing device can be a hardware circuit device in a processor such as a CPU, a cryptographic coprocessor, etc.

[0113] As an optional implementation, Fig. 9 An optional block diagram of a data processing device provided in an embodiment of the present application is shown as an example. Fig. 9 As shown, the data processing device may include: a key expansion unit 910 and a round calculation unit 920. The key expansion unit 910 is used to provide a round key in each round of operation of a cryptographic algorithm such as the SM4 algorithm.

[0114] The round calculation unit 920 is used to implement each round of operations of a cryptographic algorithm such as the SM4 algorithm. In an embodiment of the present application, the round calculation unit 920 can be used to: determine the data to be processed, the data is processed using a cryptographic algorithm, wherein the cryptographic algorithm includes multiple rounds of iterative operations; in the current round of operations of the cryptographic algorithm, determine the input of the substitution box of the current round of operations; the input of the substitution box is an element of a finite field; the elements of the finite field are represented by a redundant basis; the elements of the finite field represented by the redundant basis are inverted; according to the inverted operation result, the output of the substitution box is determined; according to the output of the substitution box, the operation result of the current round of operations is determined; according to the operation result, the processing result of the data is determined.

[0115] In some embodiments, the round calculation unit 920 for representing the elements of the finite field using a redundant basis includes:

[0116] Elements of the finite field are represented by elements in a target set corresponding to a redundant basis; wherein an element of a finite field is represented by a plurality of redundant bits, and the target set is isomorphic to the finite field.

[0117] In some embodiments, the round calculation unit 920, for performing an inverse operation on the elements of the finite field represented by the redundant basis, comprises:

[0118] In the case where a redundant basis is used to represent the elements of the finite field, transforming the elements of the finite field to the target set through a first affine transformation and a first isomorphic mapping;

[0119] An inversion operation is performed in the target set.

[0120] In some embodiments, the round calculation unit 920 is used to determine the output of the substitution box according to the inversion operation result, including:

[0121] The inversion operation result is transformed back to a finite field through a second isomorphic mapping and a second affine transformation to obtain the output of the substitution box.

[0122] In some embodiments, the first affine transformation is a linear transformation based on a preset first matrix; the first isomorphic mapping is a nonlinear transformation based on a preset first isomorphic mapping matrix, and the first isomorphic mapping matrix is ​​a mapping matrix of the target set isomorphic to the finite field; the second isomorphic mapping is a nonlinear transformation based on a preset second isomorphic mapping matrix, and the second isomorphic mapping matrix is ​​determined by the first isomorphic mapping matrix; the second affine transformation is a linear transformation based on a preset second matrix, and the first matrix is ​​the same as the second matrix.

[0123] In some embodiments, the first isomorphic mapping matrix is ​​derived by using isomorphic mapping of a polynomial basis and a redundant basis.

[0124] On the one hand, as an optional implementation, the round calculation unit 920, for transforming the elements of the finite field to the target set through a first affine transformation and a first isomorphic mapping, comprises:

[0125] The elements of the finite field are linearly transformed based on the first matrix; the linear transformation result is nonlinearly transformed based on the first isomorphic mapping matrix to transform it to a target set corresponding to a redundant basis.

[0126] As an optional implementation, the round calculation unit 920 is used to transform the inversion operation result back to the finite field through the second isomorphic mapping and the second affine transformation to obtain the output of the substitution box, including:

[0127] The inversion operation result is subjected to nonlinear transformation based on the second isomorphic mapping matrix; the nonlinear transformation result is subjected to linear transformation based on the second matrix to transform back to the finite field, thereby obtaining the output of the substitution box.

[0128] As an optional implementation, the round calculation unit 920, configured to perform an inversion operation in the target set, includes:

[0129] An inverse operation is performed based on the result of transforming the elements of the finite field to the target set, a preset constant matrix and a first isomorphic mapping matrix to obtain an inverse operation result.

[0130] As an optional implementation, the round calculation unit 920 is used to perform a linear transformation on the nonlinear transformation result based on the second matrix to transform it back to the finite field, and the output of the substitution box includes:

[0131] According to the nonlinear transformation result, the second matrix and the constant matrix, the inverse operation result is transformed back to the finite field to obtain the output of the substitution box.

[0132] As an optional implementation, the output of the substitution box is represented as Sbox(e), which is expressed as: Sbox(e) = I(e·A 1 ·T 1 +C·T 1 )·T 2 ·A 2 +C;

[0133] Where, I represents the inverse operation, e represents the input of the substitution box, A 1 Denotes the first matrix, T 1 represents the first isomorphic mapping matrix, C is the constant matrix, T 2 Denotes the second isomorphism mapping matrix, A2 Denotes the second matrix.

[0134] On the other hand, as an optional implementation, the embodiment of the present application may also merge the first matrix and the first isomorphic mapping matrix to obtain a first merged matrix; merge the preset constant matrix and the first isomorphic mapping matrix to obtain a second merged matrix; merge the second isomorphic mapping matrix and the second matrix to obtain a third merged matrix.

[0135] As an optional implementation, the round calculation unit 920 is used to transform the elements of the finite field to the target set through the first affine transformation and the first isomorphic mapping, including:

[0136] The elements of the finite field are linearly transformed based on the first merging matrix to transform them into a target set corresponding to a redundant basis.

[0137] As an optional implementation, the round calculation unit 920, for performing an inversion operation in the target set, includes:

[0138] An inverse operation is performed based on the result of transforming the elements of the finite field to the target set and the second merged matrix to obtain an inverse operation result.

[0139] As an optional implementation, the round calculation unit 920 is used to transform the inversion operation result back to the finite field through the second isomorphic mapping and the second affine transformation to obtain the output of the substitution box, including:

[0140] The inverse operation result is linearly transformed based on the third merge matrix; and the output of the substitution box is obtained based on the linear transformation result and the constant matrix.

[0141] As an optional implementation, the output of the substitution box is represented as Sbox(e), which is expressed as: Sbox(e) = I(e·B 1 +B 2 )·B 3 +C;

[0142] Where I represents the inverse operation, e represents the input of the substitution box, and B 1 represents the first merge matrix, B 2 Denotes the second merge matrix, B 3 represents the third merged matrix, and C is the constant matrix.

[0143] In some embodiments, taking the SM4 algorithm as an example, the round calculation unit 920 is used to determine the input of the substitution box of the current round operation, including: determining the input of the nonlinear transformation of the current round operation, the nonlinear transformation including parallel operation of multiple substitution boxes; determining the input of each substitution box from the input of the nonlinear transformation.

[0144] The data processing device provided in the embodiment of the present application can be applied to cryptographic algorithms with substitution box operations such as the SM4 algorithm and the AES algorithm, and can be applied to scenarios of data encryption or data decryption.

[0145] The present application also provides a processor, such as a CPU, a cryptographic coprocessor, etc., which can be configured with a data processing device provided in the present application. As an optional implementation, the processor provided in the present application can be configured to execute the data processing method provided in the present application.

[0146] An embodiment of the present application also provides a chip, which may include the processor provided in the embodiment of the present application.

[0147] An embodiment of the present application also provides an electronic device, such as a terminal device or a server device, etc., which may include the chip provided by the embodiment of the present application.

[0148] The above describes multiple implementation schemes provided by the embodiments of the present application. The various optional methods introduced in each implementation scheme can be combined and cross-referenced with each other without conflict, thereby extending a variety of possible implementation schemes, which can all be considered as implementation schemes disclosed and open in the embodiments of the present application.

[0149] Although the embodiments of the present application are disclosed above, the present application is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be subject to the scope defined by the claims.

Claims

1. A data processing method, It is characterized in that include: Determining data to be processed, wherein the data is processed using a cryptographic algorithm, wherein the cryptographic algorithm includes multiple rounds of iterative operations; In a current round of operation of the cryptographic algorithm, an input of a substitution box of the current round of operation is determined; the input of the substitution box is an element of a finite field; Using a redundant basis to represent the elements of the finite field corresponding to the input of the permutation box; Performing an inverse operation on the elements of the finite field represented by the redundant basis; determining the output of the substitution box according to the inverse operation result; Determine the result of the current round of operation according to the output of the substitution box; The processing result of the data is determined according to the operation result.

2. The method according to claim 1, It is characterized in that The elements of the finite field corresponding to the input of the substitution box represented by the redundant basis include: Elements of the finite field are represented by elements in a target set corresponding to a redundant basis; wherein an element of a finite field is represented by a plurality of redundant bits, and the target set is isomorphic to the finite field.

3. The method according to claim 2, It is characterized in that The performing an inverse operation on the elements of the finite field represented by the redundant basis comprises: In the case where a redundant basis is used to represent the elements of the finite field, transforming the elements of the finite field to the target set through a first affine transformation and a first isomorphic mapping; Performing an inversion operation in the target set; Determining the output of the substitution box according to the inverse operation result includes: The inversion operation result is transformed back to a finite field through a second isomorphic mapping and a second affine transformation to obtain the output of the substitution box.

4. The method according to claim 3, It is characterized in that The first affine transformation is a linear transformation based on a preset first matrix; the first isomorphic mapping is a nonlinear transformation based on a preset first isomorphic mapping matrix, and the first isomorphic mapping matrix is ​​a mapping matrix of the target set isomorphic to the finite field; the second isomorphic mapping is a nonlinear transformation based on a preset second isomorphic mapping matrix, and the second isomorphic mapping matrix is ​​determined by the first isomorphic mapping matrix; the second affine transformation is a linear transformation based on a preset second matrix, and the first matrix is ​​the same as the second matrix.

5. The method according to claim 4, It is characterized in that The first isomorphic mapping matrix is ​​derived by using isomorphic mapping of a polynomial basis and a redundant basis.

6. The method according to claim 4 or 5, It is characterized in that The transforming the elements of the finite field to the target set through a first affine transformation and a first isomorphic mapping comprises: Performing a linear transformation on the elements of the finite field based on the first matrix; performing a nonlinear transformation on the linear transformation result based on the first isomorphic mapping matrix to transform it to a target set corresponding to a redundant basis; The step of transforming the inverse operation result back to a finite field through a second isomorphic mapping and a second affine transformation to obtain the output of the substitution box comprises: The inversion operation result is subjected to nonlinear transformation based on the second isomorphic mapping matrix; the nonlinear transformation result is subjected to linear transformation based on the second matrix to transform back to the finite field, thereby obtaining the output of the substitution box.

7. The method according to claim 6, It is characterized in that The performing of the inverse operation in the target set comprises: Performing an inverse operation according to the result of transforming the elements of the finite field to the target set, a preset constant matrix and a first isomorphic mapping matrix to obtain an inverse operation result; The step of performing a linear transformation on the nonlinear transformation result based on the second matrix to transform it back into the finite field to obtain the output of the substitution box comprises: According to the nonlinear transformation result, the second matrix and the constant matrix, the inverse operation result is transformed back to the finite field to obtain the output of the substitution box.

8. The method according to claim 7, It is characterized in that The output of the substitution box is represented as Sbox(e), which is expressed as: Sbox(e)=I(e·A 1 ·T 1 +C·T 1 )·T 2 ·A 2 +C; Where, I represents the inverse operation, e represents the input of the substitution box, A 1 Denotes the first matrix, T 1 represents the first isomorphic mapping matrix, C is the constant matrix, T 2 Denotes the second isomorphism mapping matrix, A 2 Denotes the second matrix.

9. The method according to claim 4 or 5, It is characterized in that Also includes: Merging the first matrix and the first isomorphic mapping matrix to obtain a first merged matrix; Merging a preset constant matrix and the first isomorphic mapping matrix to obtain a second merged matrix; The second isomorphic mapping matrix and the second matrix are combined to obtain a third combined matrix.

10. The method according to claim 9, It is characterized in that The transforming the elements of the finite field to the target set through a first affine transformation and a first isomorphic mapping comprises: Performing a linear transformation on the elements of the finite field based on the first merging matrix to transform them into a target set corresponding to a redundant basis; The performing of the inverse operation in the target set comprises: Performing an inverse operation on the result of transforming the elements of the finite field to the target set and the second merged matrix to obtain an inverse operation result; The step of transforming the inverse operation result back to a finite field through a second isomorphic mapping and a second affine transformation to obtain the output of the substitution box comprises: The inverse operation result is linearly transformed based on the third merge matrix; and the output of the substitution box is obtained based on the linear transformation result and the constant matrix.

11. The method according to claim 10, It is characterized in that The output of the substitution box is represented as Sbox(e), which is expressed as: Sbox(e) = I(e·B 1 +B 2 )·B 3 +C; Where I represents the inverse operation, e represents the input of the substitution box, and B 1 represents the first merge matrix, B 2 Denotes the second merge matrix, B 3 represents the third merged matrix, and C is the constant matrix.

12. The method according to claim 1, It is characterized in that The input of determining the substitution box of the current round of operation includes: Determining an input of a nonlinear transformation of a current round of operations, wherein the nonlinear transformation includes parallel operations of a plurality of substitution boxes; The input to each displacement box is determined from the input to the nonlinear transformation.

13. A data processing device, It is characterized in that include: A round calculation unit is used to determine data to be processed, the data is processed using a cryptographic algorithm, wherein the cryptographic algorithm includes multiple rounds of iterative operations; in a current round of operations of the cryptographic algorithm, determine the input of a substitution box of the current round of operations, the input of the substitution box is an element of a finite field; use a redundant basis to represent the element of the finite field corresponding to the input of the substitution box; perform an inverse operation on the elements of the finite field represented by the redundant basis; determine the output of the substitution box according to the inverse operation result; determine the operation result of the current round of operations according to the output of the substitution box; and determine the processing result of the data according to the operation result; The key expansion unit is used to provide round keys in each round of cryptographic algorithms.

14. A processor, It is characterized in that The processor is configured to execute the data processing method according to any one of claims 1 to 12.

15. A chip, It is characterized in that Comprising a processor as claimed in claim 14.

16. An electronic device, It is characterized in that Comprising the chip as claimed in claim 15.

Citation Information

Patent Citations

  • Method and device for realizing S box in SM4 algorithm

    CN110278070A

  • Data processing method, secret key expansion method and device, equipment and storage medium

    CN116614217A