A compact CLEFIA algorithm encryption circuit
By designing a compact CLEFIA algorithm encryption circuit and using data flow control unit to realize resource sharing, the problem of redundancy and complex structure of traditional CLEFIA encryption algorithm is solved, and is suitable for IoT devices with resource limitations.
Patent Information
- Application Number
- CN202210994390.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-18
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-08-18
AI Technical Summary
The traditional CLEFIA encryption algorithm has redundant and complex structures and is not suitable for widespread use in resource-constrained IoT devices.
A compact CLEFIA algorithm encryption circuit is designed, including a data flow control unit, a constant operation unit, a key expansion unit and a GFN4,r integration unit. The data flow control unit controls other units to realize resource sharing and reduce hardware resource consumption.
Resource sharing is realized, hardware consumption is reduced, and the problem of redundancy and complex traditional structures is solved, making it suitable for IoT devices with resource-constrained.
Smart Images

Figure CN115361111B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption chips, and more particularly to a compact CLEFIA algorithm encryption circuit. Background Art
[0002] The rapid growth of the number of Internet of Things (IoT) devices and the development of edge computing have brought convenience to daily life while also bringing data security problems. However, a large number of IoT devices are deployed in restricted environments relying on small batteries. How to reduce the hardware overhead while ensuring data security has become one of the urgent problems to be solved in the current development of the IoT. The most core method of data security is to use cryptographic algorithms for data encryption to ensure data confidentiality.
[0003] Traditional encryption algorithm circuit implementations such as the Advanced Encryption Standard (AES) have the problem of large hardware overhead and are difficult to be effectively deployed in resource-constrained environments. The CLEFIA block encryption algorithm was proposed by Sony Corporation of Japan in 2007. However, the traditional CLEFIA encryption algorithm has a redundant and complex structure, which is not conducive to wide application in IoT scenarios. Summary of the Invention
[0004] The present invention is to solve the above-mentioned deficiencies of the prior art, and proposes a compact CLEFIA algorithm encryption circuit, in order to reduce the redundant parts in the circuit structure and achieve resource sharing, thereby reducing the consumption of hardware resources and making it suitable for resource-constrained IoT devices.
[0005] In order to achieve the above object of the invention, the present invention adopts the following technical solutions:
[0006] A compact CLEFIA algorithm encryption circuit of the present invention is characterized by comprising: a data flow control unit, a constant operation unit, a key expansion unit, and a GFN 4,r integration unit;
[0007] The data flow control unit receives an externally input clock signal, a reset signal, and a circuit operation signal, and when the circuit operation signal is valid, raises its own circuit busy signal and sends it to the constant operation unit; the counter inside the data flow control unit starts counting, and generates a low-order counter signal and sends it to the constant operation unit and the GFN 4,r integration unit, and at the same time generates a status signal and sends it to the key expansion unit and the GFN 4,r integration unit;
[0008] The constant operation unit receives the clock signal, the reset signal, the circuit operation signal, the circuit busy signal, and the low-order counter signal, and sends them to the key expansion unit and the GFN 4,rThe integrated unit outputs a set of constants respectively;
[0009] The GFN 4,r The integrated unit receives the plaintext input externally, the clock signal, the reset signal, the key, the low-order signal of the counter, the status signal, and a set of constants, and generates the signal L[127:0] and then sends it to the key expansion unit;
[0010] The key expansion unit receives the key input externally, the clock signal, the reset signal, the status signal, a set of constants, and the signal L[127:0], and generates the white key and the round key and sends them to the GFN 4,r Integrated unit;
[0011] The GFN 4,r The integrated unit generates the ciphertext C[127:0] and outputs it according to the white key and the round key. Meanwhile, the data flow control unit generates an encryption completion signal.
[0012] Another feature of the compact CLEFIA algorithm encryption circuit according to the present invention is that the data flow control unit includes: an adder, a counter, a first comparator, a second comparator, a first flip-flop to a third flip-flop, a first multiplexer to a sixth multiplexer;
[0013] The adder performs a cyclic increment operation on the count value sent by the counter, and sends the accumulated result to the first multiplexer after obtaining it; the first multiplexer selects the accumulated result output by the adder and outputs it to the second multiplexer when the externally input circuit operation signal is at a high level; the second multiplexer selects the accumulated result output by the first multiplexer and sends it to the counter when the encryption completion signal is at a low level;
[0014] The counter starts counting when the circuit operation signal is valid, sends the generated count value to the first comparator, and uses the least significant bit of the count value as an output of the data flow control unit;
[0015] The first comparator receives the count value of the counter and the externally input preset number A, generates a comparison result and sends it to the third multiplexer; the third multiplexer outputs the preset number "1" when the comparison result output by the first comparator is at a high level, and the third multiplexer outputs the preset number "0" when the comparison result output by the first comparator is at a low level, and thus sends the output result to the first flip-flop;
[0016] The first flip-flop receives the externally input clock signal and reset signal, and generates an encryption completion signal and sends it to the second multiplexer and the fifth multiplexer respectively;
[0017] When the circuit operation signal input externally is at a high level, the fourth multiplexer selects the preset number "1" and outputs it to the fifth multiplexer; when the encryption completion signal is at a low level, the fifth multiplexer selects the output value of the fourth multiplexer and sends it to the second flip-flop;
[0018] The second flip-flop receives the clock signal and reset signal input externally and outputs a circuit busy signal;
[0019] The second comparator receives the count value output by the counter, compares it with "1", and sends the obtained result to the sixth multiplexer;
[0020] When the result output by the second comparator is at a high level, the sixth multiplexer selects the externally input preset number B and outputs it to the third flip-flop;
[0021] The third flip-flop receives the clock signal and reset signal input externally and generates a status signal according to the preset number B.
[0022] The constant operation unit includes: a flip-flop, a GF(2 16 ) multiplier, a seventh multiplexer, and an eighth multiplexer;
[0023] The flip-flop receives the clock signal, reset signal, and the output signal of the seventh multiplexer input externally, obtains the signal ti[15:0], and sends it to the GF(2 16 ) multiplier;
[0024] The GF(2 16 ) multiplier uses the preset number C as one multiplier and ti[15:0] as the other multiplier to perform Galois field multiplication calculation, and sends the obtained multiplication result to the seventh multiplexer;
[0025] After the circuit operation signal and the circuit busy signal pass through an OR gate and then are ANDed with the low-order signal of the counter, the obtained logical value is used as the input of the control terminal of the seventh multiplexer. When the logical value is at a high level, the multiplication result output by the GF(2 16 ) multiplier is sent to the flip-flop;
[0026] The signal ti[15:0] is successively inverted and circularly shifted left by 8 bits to obtain the signal not1[15:0] and the signal sl8[15:0]. The signal ti[15:0] is also exclusive-ORed with the preset number D to obtain the signal xor2[15:0];
[0027] The signal not1[15:0] is exclusive-ORed with the preset number F to obtain the signal xor1[15:0];
[0028] The signal not1[15:0] is circularly shifted left by 1 bit to obtain the signal sl1[15:0];
[0029] The signals xor1[15:0] and sl8[15:0] are bit - concatenated, and the first concatenation result is sent to the eighth multiplexer;
[0030] The signals xor2[15:0] and sl1[15:0] are bit - concatenated, and the second concatenation result is also sent to the eighth multiplexer;
[0031] The eighth multiplexer uses the low - order signal of the counter as the control terminal and receives the first concatenation result and the second concatenation result, thereby outputting the constant signal con[31:0].
[0032] The key expansion unit includes: a flip - flop, an exclusive - OR gate, a ninth multiplexer, and a tenth multiplexer;
[0033] The ninth multiplexer receives the status signal and the signal L[127:0], performs a Σ - function operation on the signal L[127:0] to obtain the signal Ln1[127:0]. When the status signal is high, it selects the signal Ln1[127:0] and sends it to the flip - flop. When the status signal is low, it selects the signal L[127:0] and sends it to the flip - flop;
[0034] The flip - flop receives an externally input clock signal and a reset signal, and outputs the signal Ln2[127:0] and sends it to the exclusive - OR gate;
[0035] The tenth multiplexer uses the status signal as the input of the control terminal and receives the externally input key K[127:0]. When the status signal is high, it selects the key K[127:0] as the output signal key1[127:0]. When the status signal is low, it selects the preset number "0" as the output signal key1[127:0] and sends it to the exclusive - OR gate;
[0036] The constant signal con[31:0] is bit - concatenated to obtain the signal con1[127:0] and sent to the exclusive - OR gate;
[0037] The exclusive - OR gate performs a bit - by - bit exclusive - OR operation on the signals Ln2[127:0], key1[127:0], and con1[127:0] to obtain the round key RK[63:0] and use it as an output signal of the key expansion unit; the key expansion unit uses the key K[127:0] as the white key WK[127:0] and outputs it.
[0038] The GFN 4,rThe integration unit includes: an F function, an iteration module, and a multiplexer from the 11th to the 22nd;
[0039] The 11th multiplexer uses the status signal as the control terminal, receives the partial plaintext P[127:96] and the partial key K[127:96] input externally, and outputs the selection result 1 to the 15th multiplexer;
[0040] The 12th multiplexer uses the status signal as the control terminal, receives the partial plaintext P[63:32] and the partial key K[63:32] input externally, and outputs the selection result 2 to the 15th multiplexer;
[0041] The 13th multiplexer uses the status signal as the control terminal, receives the partial plaintext P[95:64] and the partial key K[95:64] input externally, and outputs the selection result 3 to the 16th multiplexer;
[0042] The 14th multiplexer uses the status signal as the control terminal, receives the partial plaintext P[31:0] and the partial key K[31:0] input externally, and outputs the selection result 4 to the 16th multiplexer;
[0043] The 15th multiplexer uses the low-order signal of the counter as the control terminal and receives the selection result 1 and the selection result 2, so as to output the signal u0[31:0] to the F function and the iteration module respectively;
[0044] The 16th multiplexer uses the low-order signal of the counter as the control terminal and receives the selection result 3 and the selection result 4, so as to output the signal u1[31:0];
[0045] The 17th multiplexer uses the low-order signal of the counter as the control terminal and receives the white key WK[127:64], so as to output the selection result 5 to the 18th multiplexer;
[0046] The 18th multiplexer uses the status signal as the control terminal, receives the selection result 5 and the preset number "0", and outputs the selection result 6, and then performs a bitwise exclusive OR operation with the signal u1[31:0] to obtain the signal u2[31:0];
[0047] The 19th multiplexer uses the low-order signal of the counter as the control terminal and receives the round key RK[63:0], so as to output the selection signal 7 to the 20th multiplexer;
[0048] The 20th multiplexer uses the status signal as the control terminal, receives the selection signal 7 and the constant con[31:0], so as to output the selection signal 8 to the F function;
[0049] The F function receives the low - order signal of the counter, the signal u0[31:0], and the selection signal 8, and thus outputs the signal f1[31:0];
[0050] After performing a bit - by - bit exclusive - OR operation on the signal f1[31:0] and the signal u2[31:0], the signal u3[31:0] is obtained and sent to the iterative module;
[0051] The twenty - first multiplexer uses the low - order signal of the counter as the control terminal and receives the white key WK[63:0], and thus outputs the selection result 9 to the twenty - second multiplexer;
[0052] The iterative module uses the low - order signal of the counter as the control signal and receives the signal u0[31:0] and the signal u3[31:0], and thus generates the signal m1[31:0] and the signal m2[31:0], where the signal m1[31:0] is used as an output signal of the GFN 4,r integrated unit to generate the signal L[127:96] or the signal L[63:32] or the ciphertext C[127:96] or the ciphertext C[63:32]. The signal m2[31:0] and the signal f1[31:0] are subjected to a bit - by - bit exclusive - OR operation to obtain the signal d1[31:0];
[0053] The twenty - second multiplexer uses the status signal as the control terminal, receives the selection result 9 and the preset number "0", and outputs the selection result 10, and then performs a bit - by - bit exclusive - OR operation with the signal d1[31:0] to obtain the signal L[95:64] or L[31:0] or the ciphertext C[95:64] or the ciphertext C[31:0], and serves as another output signal of the GFN 4,r integrated unit.
[0054] The iterative module includes 4 groups of registers L0, L1, R0, and R1;
[0055] The registers L0 and R0 successively receive the signal u0[31:0] as the initial value, and the registers L1 and R1 successively receive the signal u3[31:0] as the initial value;
[0056] When the low - order signal of the counter is 0, the register L0 remains unchanged, the register L1 receives the value of the register R1, the register R0 receives the value of the register L1, and the register R1 receives the value obtained by performing the F function on the register L1 and then exclusive - ORing with R0;
[0057] When the low - order signal of the counter is 1, the register L0 receives the value of the register R0, the register L1 receives the value of the register R1, the register R0 receives the value of the register L1, and the register R1 receives the value obtained by performing the F function on the register L1 and then exclusive - ORing with L0.
[0058] The GFN mentioned above 4,r When the integrated unit outputs the signal L[127:0], the eleventh to fourteenth multiplexers select the key K[127:0] as the output, the eighteenth multiplexer selects the preset number "0" as the output, the twentieth multiplexer selects the constant con[31:0] as the output, and the twenty-second multiplexer selects the preset number "0" as the output;
[0059] The GFN mentioned above 4,r When the integrated unit outputs the ciphertext C[127:0], the eleventh to fourteenth multiplexers select the plaintext P[127:0] as the output, the eighteenth multiplexer selects the white key WK[127:64] as the output, the twentieth multiplexer selects the round key RK[63:0] as the output, and the twenty-second multiplexer selects the white key WK[63:0] as the output.
[0060] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0061] 1. The present invention makes full use of the data path after the hardware implementation of the CLEFIA encryption algorithm. The data flow control unit controls the constant operation unit and the key expansion unit. The data flow control unit generates control logic based on the counter signal and performs data transmission in the corresponding state, solving the problem of complex control and operation logic design. The structure is clear and simple, and the area is compact, which is conducive to wide use in the Internet of Things scenario.
[0062] 2. The present invention implements the CLEFIA encryption algorithm with a key length of 128-bit. The same circuit structure, namely the GFN 4,r structure, is used to calculate L[127:0] and the ciphertext. In the traditional hardware implementation, two units are required to calculate L[127:0] and the ciphertext respectively. The present invention combines the data paths for calculating L[127:0] and the ciphertext into one through a multiplexer, achieving resource sharing, increasing resource utilization rate, and reducing hardware consumption.
[0063] 3. The GFN of the present invention 4,r The GFN in the integrated unit 4,r The GFN 4,r structure has four data paths, and the four data paths are transmitted regularly to calculate the required values. However, this structure has redundant parts, and the repeated and redundant structure increases the number of registers. The present invention reduces the four data paths to two, and only four registers are required to implement the GFN Description of the Drawings
[0064] Figure 1 This is the top - level structure block diagram of a compact CLEFIA algorithm encryption circuit of the present invention;
[0065] Figure 2 This is the internal structure block diagram of the data flow control unit of the present invention;
[0066] Figure 3 This is the internal structure block diagram of the constant operation unit of the present invention;
[0067] Figure 4 This is the internal structure block diagram of the key expansion unit of the present invention;
[0068] Figure 5 This is the schematic diagram of the operation mode of the Σ function of the present invention;
[0069] Figure 6 This is the GFN 4,r Internal structure block diagram of the integration unit;
[0070] Figure 7 This is the data transmission schematic diagram of the iterative module of the present invention. Detailed implementation manners
[0071] In this embodiment, a compact CLEFIA algorithm encryption circuit, as Figure 1 shown, includes: a data flow control unit, a constant operation unit, a key expansion unit, and a GFN 4,r integration unit;
[0072] The data flow control unit receives the externally input clock signal clk, reset signal rst, and circuit operation signal run, and when the circuit operation signal run is valid, raises its own circuit busy signal busy and sends it to the constant operation unit; the counter inside the data flow control unit starts counting and generates the least - significant bit signal LSB of the counter, which is sent to the constant operation unit and the GFN 4,r integration unit respectively, and at the same time generates a status signal state and sends it to the key expansion unit and the GFN 4,r integration unit respectively;
[0073] The constant operation unit receives the clock signal clk, reset signal rst, circuit operation signal run, circuit busy signal busy, and the least - significant bit signal LSB of the counter, and outputs a group of constant signals con[31:0] to the key expansion unit and the GFN 4,r integration unit respectively;
[0074] GFN 4,rThe integration unit receives the plaintext P[127:0], clock signal clk, reset signal rst, key K[127:0], least significant bit signal LSB, status signal state, and constant signal con[31:0] input externally, generates the signal L[127:0], and then sends it to the key expansion unit.
[0075] The key expansion unit receives the key K[127:0], clock signal clk, reset signal rst, status signal state, constant signal con[31:0], and signal L[127:0] input externally, generates the white key WK[127:0] and round key RK[63:0], and sends them together to the GFN 4,r integration unit;
[0076] GFN 4,r The integration unit generates the ciphertext C[127:0] and outputs it according to the white key WK[127:0] and round key RK[63:0]. Meanwhile, the data flow control unit generates the encryption completion signal done.
[0077] As Figure 2 shown, the data flow control unit includes: an adder, a counter, a first comparator, a second comparator, a first flip-flop to a third flip-flop, a first multiplexer to a sixth multiplexer;
[0078] The adder performs a cyclic increment-by-1 operation after receiving the count value sent by the counter, obtains the accumulated result, and sends it to the first multiplexer; when the externally input circuit operation signal run is at a high level, the first multiplexer selects the accumulated result output by the adder and outputs it to the second multiplexer; when the encryption completion signal done is at a low level, the second multiplexer selects the accumulated result output by the first multiplexer and sends it to the counter.
[0079] The counter starts counting when the circuit operation signal run is valid, sends the generated count value to the first comparator, and at the same time uses the least significant bit of the count value as an output of the data flow control unit.
[0080] The first comparator receives the count value of the counter and the preset number A of clock cycles required for the entire circuit stored in advance, generates a comparison result, and sends it to the third multiplexer. When the count value is equal to the preset number A of clock cycles required for the entire circuit stored in advance, the first comparator outputs a high level, and in other cases, it outputs a low level; when the comparison result output by the first comparator is at a high level, the third multiplexer selects the preset number "1" for output, and when the comparison result output by the first comparator is at a low level, the third multiplexer selects the preset number "0" for output, and thus sends the output result to the first flip-flop.
[0081] The first flip-flop receives the externally input clock signal clk and reset signal rst, and generates an encryption completion signal done, which is then sent to the second multiplexer and the fifth multiplexer respectively. When the third multiplexer outputs '1', the encryption completion signal is pulled high, thus completing a complete encryption operation;
[0082] When the externally input circuit operation signal run is at a high level, the fourth multiplexer selects the preset number '1' and outputs it to the fifth multiplexer; when the encryption completion signal done is at a low level, the fifth multiplexer selects the output value of the fourth multiplexer and sends it to the second flip-flop;
[0083] The second flip-flop receives the externally input clock signal clk, reset signal rst and outputs a circuit busy signal busy. When the circuit operation signal run is at a high level and the encryption completion signal done is at a low level, the circuit busy signal busy is pulled high until the encryption completion signal done becomes high and then pulled low;
[0084] The second comparator receives the count value output by the counter, compares it with '1', and sends the result to the sixth multiplexer;
[0085] When the result output by the second comparator is at a high level, the sixth multiplexer selects the externally input preset number B and outputs it to the third flip-flop;
[0086] The third flip-flop receives the externally input clock signal clk and reset signal rst, and generates a status signal state according to the preset number B.
[0087] As Figure 3 shown, the constant operation unit includes: a flip-flop, a GF(2 16 ) multiplier, a seventh multiplexer and an eighth multiplexer;
[0088] The flip-flop receives the externally input clock signal clk, reset signal rst and the output signal of the seventh multiplexer, obtains the signal ti[15:0] and sends it to the GF(2 16 ) multiplier;
[0089] GF(2 16 ) multiplier uses the preset number C as one multiplier and the signal ti[15:0] as the other multiplier to perform Galois field multiplication calculation. The multiplication result obtained is sent to the seventh multiplexer. The initial value of the signal ti[15:0] is selected according to the key length. In this embodiment, a 128-bit CLEFIA encryption circuit is implemented. The initial value of the signal ti[15:0] corresponding to the 128-bit key length is 0x428a; GF(2 16 ) multiplier uses GF(2 16) The multiplication operation on it is the core. Based on the primitive polynomial z 16 +z 15 +z 13 +z 11 +z 5 +z 4 +1 for operation. In this embodiment, the preset number C is 0x0002 -2 , the signal ti[15:0] and 0x0002 -2 perform a multiplication operation in GF(2 16 ). It is equivalent to shifting ti[15:0] one bit to the right in GF(2 16 ), and then obtaining the result after the right shift according to the primitive polynomial, which is the multiplication result;
[0090] After the circuit operation signal run and the circuit busy signal busy pass through an OR gate, they are then ANDed with the least significant bit signal LSB of the counter, and the obtained logical value is used as the input of the control terminal of the seventh multiplexer. When the logical value is high, the multiplication result output by the GF(2 16 ) multiplier is sent to the flip-flop;
[0091] After the signal ti[15:0] is successively inverted and circularly shifted left by 8 bits, the signals not1[15:0] and sl8[15:0] are obtained. The signal ti[15:0] is also XORed with the preset number D bit by bit to obtain the signal xor2[15:0]. In this embodiment, the preset number D is 0xb7e1;
[0092] The signal not1[15:0] is XORed with the preset number F bit by bit to obtain the signal xor1[15:0]. In this embodiment, the preset number F is 0x243f;
[0093] The signal not1[15:0] is circularly shifted left by 1 bit to obtain the signal sl1[15:0];
[0094] The signals xor1[15:0] and sl8[15:0] are bit-concatenated, and the obtained first concatenation result is sent to the eighth multiplexer;
[0095] The signals xor2[15:0] and sl1[15:0] are bit-concatenated, and the obtained second concatenation result is also sent to the eighth multiplexer;
[0096] The eighth multiplexer uses the least significant bit signal LSB of the counter as the control terminal and receives the first concatenation result and the second concatenation result, thereby outputting the constant signal con[31:0].
[0097] Such as Figure 4As shown in the figure, the key expansion unit includes: a flip-flop, an exclusive-OR gate, a ninth multiplexer, and a tenth multiplexer;
[0098] The ninth multiplexer receives the state signal state and the signal L[127:0], and performs a Σ function operation on the signal L[127:0] to obtain the signal Ln1[127:0]. As Figure 5 shown in the schematic diagram of the Σ function operation method, that is, Ln1[127:71] is L[120:64], Ln1[70:64] is L[6:0], Ln1[63:57] is L[127:121], and Ln1[56:0] is L[63:7]. When the state signal state is high, the selected signal Ln1[127:0] is sent to the flip-flop. When the state signal state is low, the selected signal L[127:0] is sent to the flip-flop;
[0099] The flip-flop receives the externally input clock signal clk and reset signal rst, and outputs the signal Ln2[127:0] to the exclusive-OR gate;
[0100] The tenth multiplexer uses the state signal state as the input of the control terminal and receives the externally input key K[127:0]. When the state signal state is high, it selects the key K[127:0] as the output signal key1[127:0] and sends it to the exclusive-OR gate. At this time, the exclusive-OR gate has three inputs. When the state signal state is low, it selects the preset number "0" as the output signal key1[127:0] and sends it to the exclusive-OR gate. At this time, the three-input exclusive-OR gate is equivalent to a two-input exclusive-OR gate;
[0101] Perform a bit concatenation operation on four groups of constant signals con[31:0] to obtain the signal con1[127:0] and send it to the exclusive-OR gate;
[0102] The exclusive-OR gate performs a bitwise exclusive-OR operation on the signal Ln2[127:0], the signal key1[127:0], and the signal con1[127:0] to obtain the round key RK[63:0] and use it as an output signal of the key expansion unit; the key expansion unit uses the key K[127:0] as the white key WK[127:0] and outputs it.
[0103] As Figure 6 shown, the GFN 4,r The integration unit includes: an F function, an iterative module, an eleventh multiplexer to a twenty-second multiplexer;
[0104] The eleventh multiplexer uses the state signal state as the control terminal, receives the externally input partial plaintext P[127:96] and partial key K[127:96], and outputs the selection result 1 to the fifteenth multiplexer;
[0105] The twelfth multiplexer uses the state signal state as the control terminal, receives the partial plaintext P[63:32] and the partial key K[63:32] input externally, and outputs the selection result 2 to the fifteenth multiplexer;
[0106] The thirteenth multiplexer uses the state signal state as the control terminal, receives the partial plaintext P[95:64] and the partial key K[95:64] input externally, and outputs the selection result 3 to be sent to the sixteenth multiplexer;
[0107] The fourteenth multiplexer uses the state signal state as the control terminal, receives the partial plaintext P[31:0] and the partial key K[31:0] input externally, and outputs the selection result 4 to the sixteenth multiplexer;
[0108] The fifteenth multiplexer uses the least significant bit signal LSB of the counter as the control terminal and receives the selection result 1 and the selection result 2, thereby outputting the signal u0[31:0] to the F function and the iterative module respectively;
[0109] The sixteenth multiplexer uses the least significant bit signal LSB of the counter as the control terminal and receives the selection result 3 and the selection result 4, thereby outputting the signal u1[31:0];
[0110] The seventeenth multiplexer uses the least significant bit signal LSB of the counter as the control terminal and receives the white key WK[127:64], thereby outputting the selection result 5 to the eighteenth multiplexer;
[0111] The eighteenth multiplexer uses the state signal state as the control terminal, receives the selection result 5 and the preset number "0", and outputs the selection result 6, and then performs a bitwise exclusive OR operation with the signal u1[31:0] to obtain the signal u2[31:0];
[0112] The nineteenth multiplexer uses the least significant bit signal LSB of the counter as the control terminal and receives the round key RK[63:0], thereby outputting the selection signal 7 to the twentieth multiplexer;
[0113] The twentieth multiplexer uses the state signal state as the control terminal, receives the selection signal 7 and the constant signal con[31:0], thereby outputting the selection signal 8 to be sent to the F function;
[0114] The F function receives the least significant bit signal LSB of the counter, the signal u0[31:0] and the selection signal 8, thereby outputting the signal f1[31:0];
[0115] Perform a bitwise exclusive OR operation on the signal f1[31:0] and the signal u2[31:0] to obtain the signal u3[31:0] and send it to the iterative module;
[0116] The twenty - first multiplexer uses the least - significant bit (LSB) of the counter as the control terminal and receives the white key WK[63:0], thereby outputting the selection result 9 to the twenty - second multiplexer;
[0117] The iterative module uses the least - significant bit (LSB) of the counter as the control signal and receives the signal u0[31:0] and the signal u3[31:0], thereby generating the signal m1[31:0] and the signal m2[31:0]. The signal m1[31:0] serves as GFN 4,r An output signal of the integration unit generates the signal L[127:96] or the signal L[63:32] or the ciphertext C[127:96] or the ciphertext C[63:32]. The signal m2[31:0] and the signal f1[31:0] are XOR - ed bit - by - bit to obtain the signal d1[31:0];
[0118] The twenty - second multiplexer uses the state signal state as the control terminal, receives the selection result 9 and the preset number "0", and outputs the selection result 10. Then, after XOR - ing with the signal d1[31:0], it obtains the signal L[95:64] or the signal L[31:0] or the ciphertext C[95:64] or the ciphertext C[31:0], and serves as GFN 4,r Another output signal of the integration unit.
[0119] In the specific implementation, GFN 4,r When the integration unit outputs the signal L[127:0], the eleventh to fourteenth multiplexers select the key K[127:0] as the output, the eighteenth multiplexer selects the preset number "0" as the output, the twentieth multiplexer selects the constant con[31:0] as the output, and the twenty - second multiplexer selects the preset number "0" as the output;
[0120] GFN 4,r When the integration unit outputs the ciphertext C[127:0], the eleventh to fourteenth multiplexers select the plaintext P[127:0] as the output, the eighteenth multiplexer selects the white key WK[127:64] as the output, the twentieth multiplexer selects the round key RK[63:0] as the output, and the twenty - second multiplexer selects the white key WK[63:0] as the output.
[0121] As Figure 7 shown, the iterative module includes 4 groups of registers L0, L1, R0, and R1;
[0122] The registers L0 and R0 successively receive the signal u0[31:0] as the initial value, and the registers L1 and R1 successively receive the signal u3[31:0] as the initial value;
[0123] When the least significant bit signal LSB of the counter is 0, register L0 remains unchanged, register L1 receives the value of register R1, register R0 receives the value of register L1, and register R1 receives the value obtained by XORing the value of register L1 after passing through the F function with R0;
[0124] When the least significant bit signal LSB of the counter is 1, register L0 receives the value of register R0, register L1 receives the value of register R1, register R0 receives the value of register L1, and register R1 receives the value obtained by XORing the value of register L1 after passing through the F function with L0.
Claims
1. A compact CLEFIA algorithm encryption circuit, characterized in that, it includes: Data flow control unit, constant operation unit, key expansion unit, and GFN 4,r Integration unit; The data flow control unit receives an externally input clock signal, a reset signal, and a circuit operation signal. When the circuit operation signal is valid, it raises its own circuit busy signal and sends it to the constant operation unit; the counter inside the data flow control unit starts counting and generates a low-order counter signal, which is sent to the constant operation unit and the GFN 4,r integration unit respectively, and at the same time generates a status signal and sends it to the key expansion unit and the GFN 4,r integration unit; The data flow control unit includes: an adder, a counter, a first comparator, a second comparator, a first flip-flop to a third flip-flop, a first multiplexer to a sixth multiplexer; After receiving the count value sent by the counter, the adder performs a cyclic increment-by-1 operation and sends the accumulated result to the first multiplexer after obtaining it; when the externally input circuit operation signal is high, the first multiplexer selects the accumulated result output by the adder and outputs it to the second multiplexer; when the encryption completion signal is low, the second multiplexer selects the accumulated result output by the first multiplexer and sends it to the counter; The counter starts counting when the circuit operation signal is valid, sends the generated count value to the first comparator, and at the same time takes the least significant bit of the count value as an output of the data flow control unit; After receiving the count value of the counter and the externally input preset number A, the first comparator generates a comparison result and sends it to the third multiplexer; when the comparison result output by the first comparator is high, the third multiplexer selects the preset number "1" for output, and when the comparison result output by the first comparator is low, the third multiplexer selects the preset number "0" for output, and thus sends the output result to the first flip-flop; The first flip-flop receives the externally input clock signal and reset signal, and generates an encryption completion signal and sends it to the second multiplexer and the fifth multiplexer respectively; When the externally input circuit operation signal is high, the fourth multiplexer selects the preset number "1" and outputs it to the fifth multiplexer; when the encryption completion signal is low, the fifth multiplexer selects the output value of the fourth multiplexer and sends it to the second flip-flop; The second flip-flop receives the externally input clock signal, reset signal and outputs a circuit busy signal; The second comparator receives the count value output by the counter, compares it with "1", and sends the obtained result to the sixth multiplexer; When the result output by the second comparator is high, the sixth multiplexer selects the externally input preset number B and outputs it to the third flip-flop; The third flip-flop receives the externally input clock signal and reset signal, and generates a status signal according to the preset number B; The constant operation unit receives the clock signal, the reset signal, the circuit operation signal, the circuit busy signal, and the lower bit signal of the counter, and outputs a set of constants to the key expansion unit and the GFN 4,r integration unit respectively; The GFN 4,r The integration unit receives the plaintext, the clock signal, the reset signal, the key, the low-order counter signal, the status signal, and a set of constants input externally, generates the signal L[127:0], and sends it to the key expansion unit; The key expansion unit receives an externally input key, the clock signal, a reset signal, the status signal, a set of constants, and the signal L[127:0], and generates a white key and round keys and sends them together to the GFN 4,r Integration unit; The GFN 4,r The integration unit generates and outputs ciphertext C[127:0] according to the white key and the round key. Meanwhile, the data stream control unit generates an encryption completion signal.
2. The compact CLEFIA algorithm encryption circuit according to claim 1, characterized in that, The constant operation unit includes: a flip-flop, a GF(2 16 ) multiplier, a seventh multiplexer, and an eighth multiplexer; The trigger receives an externally input clock signal, a reset signal, and an output signal of a seventh multiplexer, obtains a signal ti[15:0], and sends it to a GF(2 16 ) multiplier; The GF(2 16 ) multiplier uses the preset number C as one multiplier and ti[15:0] as the other multiplier to perform Galois field multiplication calculation, and sends the multiplication result to the seventh multiplexer; After the circuit operation signal and the circuit busy signal pass through an OR gate and then are ANDed with the low-order signal of the counter, the obtained logical value is used as the input of the control terminal of the seventh multiplexer. When the logical value is at a high level, the multiplication result output by the GF(2 16 ) multiplier is sent to the flip-flop; The signal ti[15:0] is successively inverted and circularly left-shifted by 8 bits to obtain the signal not1[15:0] and the signal sl8[15:0], and the signal ti[15:0] is also exclusive-ORed with the preset number D to obtain the signal xor2[15:0]; The signal not1[15:0] is exclusive-ORed with the preset number F to obtain the signal xor1[15:0]; The signal not1[15:0] is circularly left-shifted by 1 bit to obtain the signal sl1[15:0]; Perform a bit concatenation operation on the signal xor1[15:0] and the signal sl8[15:0], and send the obtained first concatenation result to the eighth multiplexer; Perform a bit concatenation operation on the signal xor2[15:0] and the signal sl1[15:0], and also send the obtained second concatenation result to the eighth multiplexer; The eighth multiplexer uses the low-order signal of the counter as the control terminal, and receives the first concatenation result and the second concatenation result, thereby outputting the constant signal con[31:0].
3. A compact CLEFIA algorithm encryption circuit according to claim 2, characterized in that, The key expansion unit includes: a flip-flop, an exclusive-OR gate, a ninth multiplexer, and a tenth multiplexer; The ninth multiplexer receives the status signal and the signal L[127:0], performs a Σ function operation on the signal L[127:0] to obtain the signal Ln1[127:0], and when the status signal is at a high level, selects the signal Ln1[127:0] and sends it to the flip-flop, and when the status signal is at a low level, selects the signal L[127:0] and sends it to the flip-flop; The flip-flop receives an externally input clock signal and a reset signal, and outputs the signal Ln2[127:0] and sends it to the exclusive-OR gate; The tenth multiplexer uses the status signal as the input of the control terminal and receives the externally input key K[127:0]. When the status signal is at a high level, it selects the key K[127:0] as the output signal key1[127:0], and when the status signal is at a low level, it selects the preset number "0" as the output signal key1[127:0] and sends it to the exclusive-OR gate; Perform a bit concatenation operation on the constant signal con[31:0] to obtain the signal con1[127:0] and send it to the exclusive-OR gate; The exclusive-OR gate performs a bitwise exclusive-OR operation on the signal Ln2[127:0], the signal key1[127:0], and the signal con1[127:0] to obtain the round key RK[63:0] and use it as an output signal of the key expansion unit; the key expansion unit uses the key K[127:0] as the white key WK[127:0] and outputs it.
4. A compact CLEFIA algorithm encryption circuit according to claim 3, characterized in that, The GFN 4,r The integration unit includes: an F function, an iteration module, a multiplexer from the eleventh to the twenty-second The eleventh multiplexer uses the status signal as the control terminal, receives the externally input partial plaintext P[127:96] and partial key K[127:96], and outputs the selection result 1 to the fifteenth multiplexer; The twelfth multiplexer uses the status signal as the control terminal, receives the externally input partial plaintext P[63:32] and partial key K[63:32], and outputs the selection result 2 to the fifteenth multiplexer; The thirteenth multiplexer uses the status signal as the control terminal, receives the externally input partial plaintext P[95:64] and partial key K[95:64], and outputs the selection result 3 and sends it to the sixteenth multiplexer; The fourteenth multiplexer uses the status signal as the control terminal, receives the partial plaintext P[31:0] and the partial key K[31:0] input externally, and outputs the selection result 4 to the sixteenth multiplexer; The fifteenth multiplexer uses the low-order signal of the counter as the control terminal, and receives the selection result 1 and the selection result 2, so as to output the signal u0[31:0] to the F function and the iteration module respectively; The sixteenth multiplexer uses the low-order signal of the counter as the control terminal, and receives the selection result 3 and the selection result 4, so as to output the signal u1[31:0]; The seventeenth multiplexer uses the low-order signal of the counter as the control terminal, and receives the white key WK[127:64], so as to output the selection result 5 to the eighteenth multiplexer; The eighteenth multiplexer uses the status signal as the control terminal, receives the selection result 5 and the preset number "0", and outputs the selection result 6, and then performs a bitwise exclusive OR operation with the signal u1[31:0] to obtain the signal u2[31:0]; The nineteenth multiplexer uses the low-order signal of the counter as the control terminal, and receives the round key RK[63:0], so as to output the selection signal 7 to the twentieth multiplexer; The twentieth multiplexer uses the status signal as the control terminal, receives the selection signal 7 and the constant con[31:0], so as to output the selection signal 8 and send it to the F function; The F function receives the low-order signal of the counter, the signal u0[31:0] and the selection signal 8, so as to output the signal f1[31:0]; After performing a bitwise exclusive OR operation on the signal f1[31:0] and the signal u2[31:0], the signal u3[31:0] is obtained and sent to the iteration module; The twenty-first multiplexer uses the low-order signal of the counter as the control terminal, and receives the white key WK[63:0], so as to output the selection result 9 to the twenty-second multiplexer; The iteration module uses the low-order signal of the counter as a control signal and receives signals u0[31:0] and u3[31:0], thereby generating signals m1[31:0] and m2[31:0], where the signal m1[31:0] serves as GFN 4,r An output signal of the integration unit generates signal L[127:96] or signal L[63:32] or ciphertext C[127:96] or ciphertext C[63:32]. The signal m2[31:0] and the signal f1[31:0] are subjected to a bitwise exclusive OR operation to obtain the signal d1[31:0]; The twenty-second multiplexer uses the status signal as the control terminal, receives the selection result 9 and the preset number "0", and outputs the selection result 10. Then, after performing a bitwise exclusive OR operation with the signal d1[31:0], it obtains the signal L[95:64] or L[31:0] or the ciphertext C[95:64] or the ciphertext C[31:0], which is used as GFN 4,r Another output signal of the integrated unit.
5. A compact CLEFIA algorithm encryption circuit according to claim 4, wherein, the iteration module includes 4 groups of registers L0, L1, R0, R1; The registers L0 and R0 successively receive the signal u0[31:0] as the initial value, and the registers L1 and R1 successively receive the signal u3[31:0] as the initial value; When the low-order signal of the counter is 0, the register L0 remains unchanged, the register L1 receives the value of the register R1, the register R0 receives the value of the register L1, and the register R1 receives the value obtained after the register L1 passes through the F function and then is XORed with R0; When the low-order signal of the counter is 1, the register L0 receives the value of the register R0, the register L1 receives the value of the register R1, the register R0 receives the value of the register L1, and the register R1 receives the value obtained after the register L1 passes through the F function and then is XORed with L0.
6. A compact CLEFIA algorithm encryption circuit according to claim 5, wherein, The GFN 4,r When the integrated unit outputs the signal L[127:0], the eleventh multiplexer to the fourteenth multiplexer select the key K[127:0] as the output, the eighteenth multiplexer selects the preset number "0" as the output, the twentieth multiplexer selects the constant con[31:0] as the output, and the twenty-second multiplexer selects the preset number "0" as the output; The GFN 4,r When the integrated unit outputs the ciphertext C[127:0], the eleventh multiplexer to the fourteenth multiplexer select the plaintext P[127:0] as the output, the eighteenth multiplexer selects the white key WK[127:64] as the output, the twentieth multiplexer selects the round key RK[63:0] as the output, and the twenty-second multiplexer selects the white key WK[63:0] as the output.
Citation Information
Patent Citations
Block encryption apparatus, block encryption method and program
CN102598574A
Code processing device, code processing method, and program
CN103238291A