A Resource Optimization Implementation Method for ZUC-256 Algorithm in a Multi-Channel Scenario

By adopting the multi-channel ZUC-256 composite algorithm core in multi-channel scenarios, the resource optimization of the ZUC-256 algorithm is solved, and the high demand for hardware resources of the ZUC-256 algorithm in multi-channel scenarios is solved, which reduces resource occupation and supports the encryption, decryption and expansion of multiple channels.

CN115550914BActive Publication Date: 2025-05-27HANGZHOU XINXIAO INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210992790.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-18
Publication Date
2025-05-27
Estimated Expiration
2042-08-18

AI Technical Summary

Technical Problem

In multi-channel scenarios, the ZUC-256 algorithm has a high demand for hardware resources, and it is difficult to meet the encryption and decryption needs of multi-channel data in scenarios with resource limitations, and it is difficult to achieve convenient expansion of multiple channels.

Method used

The multi-channel ZUC-256 composite algorithm core is adopted, including the ZUC256_integer module and multiple ZUC256_atom algorithm cores. By building multi-channel external interfaces and public resource deployment, resource optimization of the ZUC-256 algorithm is realized. Specific measures include: defining multiple encryption and decryption paths and initial keys/vectors, adopting time-division multiplexing strategy, fixed timing time-division time-division distribution of S-box parameter data, and multiplexing MDS matrices L1 and L2.

Benefits of technology

The system's resource occupation is greatly reduced. In a typical 8-channel scenario, the resource occupation is reduced by about 42%, and in a 16-channel scenario, it also supports the encryption and decryption of multiple channels, and is convenient for expansion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115550914B_ABST
    Figure CN115550914B_ABST
Patent Text Reader

Abstract

The present invention discloses a resource optimization implementation method for the ZUC-256 algorithm in a multi-channel scenario. The present invention first constructs a multi-channel ZUC-256 composite algorithm core, which specifically includes two parts: a ZUC256_integer module and multiple ZUC256_atom algorithm cores; the ZUC256_integer module is used to complete the interface definition for multiple channels and the deployment of common resources; the ZUC256_atom algorithm core is used to implement the basic operations of the ZUC-256 algorithm, that is, the basic combinational logic and multi-round timing logic required for the independent operation of the algorithm core, and one ZUC256_atom algorithm core independently is responsible for the data encryption or decryption of one channel. The present invention can meet the encryption and decryption requirements for multi-channel data in a scenario where hardware resources are limited, and can conveniently realize the expansion of multiple channels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security and relates to a resource optimization implementation method of the ZUC-256 algorithm in a multi-channel scenario. Specifically, it is a resource optimization method for the hardware implementation of the ZUC (Zu Chongzhi)-256 algorithm. Background Art

[0002] The ZUC encryption algorithm independently designed by China was approved as a candidate encryption algorithm for 4G wireless communication at the 53rd 3GPP System Architecture Group meeting in 2011. This is the first time that China's commercial cipher algorithm has gone abroad to participate in the competition of international standards, proving the reliability of domestic commercial cipher algorithms. At the same time, in order to meet the needs of the popularization of 5G wireless communication, the ZUC-256 encryption algorithm was subsequently proposed to provide data security in the 5G application environment and became an ISO / IEC international standard in 2020.

[0003] In the customized design of communication system products with multi-channel requirements such as actual satellite communication and data access, it is of great significance to reduce the hardware resource requirements of ZUC-256 and facilitate the expansion of multiple channels while meeting the encryption and decryption speed. Summary of the Invention

[0004] The object of the present invention is to overcome the deficiencies of the prior art and propose a resource optimization implementation method of the ZUC-256 algorithm in a multi-channel scenario. The present invention can meet the encryption and decryption requirements of multi-channel data in a scenario with limited hardware resources and can conveniently implement the expansion of multiple channels.

[0005] To achieve the above invention object, the technical solution adopted by the present invention is:

[0006] First, a multi-channel ZUC-256 composite algorithm core is constructed, which specifically includes two parts: the ZUC256_integer module and multiple ZUC256_atom algorithm cores. The ZUC256_integer module is used to complete the interface definition for multiple channels and the deployment of common resources. The ZUC256_atom algorithm core is used to implement the basic operations of the ZUC-256 algorithm, that is, the basic combinational logic and multi-round sequential logic required for the independent operation of the algorithm core. One ZUC256_atom algorithm core independently is responsible for the data encryption or decryption of one channel.

[0007] The ZUC256_integer module defines n 32-bit encryption and decryption channels, n initial keys iK, and n initial vectors iV according to actual application requirements, and takes the encryption and decryption channels, the initial key iK, and the initial vector iV as external data interfaces and corresponding control signals.

[0008] The ZUC256_integer module is used to perform the following logical functions:

[0009] Function 1: According to the control signals of the external control module and the n internally instantiated (depending on the specific number of channels in the actual application scenario) ZUC256_atom algorithm cores, the initial key iK and the initial vector iV information of each path are respectively sent to each internally instantiated ZUC256_atom algorithm core.

[0010] The external control module mentioned above refers to an external control interface that needs to apply the algorithm of the present invention.

[0011] Function 2: Perform data flow control according to the control signals of the external control module and the n internally instantiated ZUC256_atom algorithm cores.

[0012] Function 3: Provide two S-boxes: S0_BOX resource and S1_BOX resource; provide two MDS matrices L1, L2.

[0013] The S0_BOX resource and S1_BOX resource are used to perform non-linear substitution on the input 8-bit data, which is specifically implemented using a ROM based on a lookup table. The input is an 8-bit address (each 8-bit address corresponds to an 8-bit data), and the output 8-bit data is the value after non-linear substitution. Therefore, 256 bytes (8×256 = 2048-bit) of data need to be stored in the ROM.

[0014] Furthermore, in the process of implementing the ZUC-256 algorithm, it is necessary to use the S-box to replace the 32-bit data generated by the MDS matrix and then update the values of the registers R1 and R2 in the FMS. Before optimizing the ZUC-256 algorithm, using a parallel method to replace the 32-bit data requires 4 S0_BOXes and 4 S1_BOX resources, as Figure 2 shown.

[0015] The optimization scheme of this design takes into account both the convenience of processing and the performance of the algorithm, and plans the S-box resources into 4 fixed control time slots and 4n data time slots as a time-sharing processing strategy. Using this strategy can support data encryption and decryption of n channels simultaneously at most.

[0016] The time slot number is x-bit (x represents the data bit width, and its length needs to be able to represent all the time sequences), and a total of 4(n + 1) time slots are set, where the 0 to 3 time slots are control fields, and the 4 to 4n + 3 time slots are data fields.

[0017] Further, the time slot serial number x-bit is generated by an 8-bit counter. The counter increments by 1 at each rising edge of the clock. After power-on reset, it starts counting from 0, and after counting to 4n + 3, it resets to 0 and starts counting again.

[0018] Among the time slot serial numbers, the data represented by the high (x - 2) bits is the channel identifier of the algorithm core, and the data represented by the low 2 bits is the internal timing when the ZUC256_atom algorithm core is in the channel.

[0019] Among the time slot serial numbers, the data represented by the high (x - 2) bits is the channel identifier of the ZUC256_atom algorithm core, which is used to indicate that the current S-box parameter data (representing the data output after looking up the L1 and L2 matrices) is distributed to the ZUC256_atom algorithm core in the corresponding channel.

[0020] The internal timing of the algorithm for the low 2 bits is an optimization strategy to achieve the minimum resource consumption. Specifically, the look-up table replacement of 32-bit data is planned and divided into 4 times of 8-bit look-up table replacement processes. In this way, each ZUC256_atom algorithm core needs 4 timing cycles to complete a 32-bit data look-up table replacement process.

[0021] For the ZUC256_atom algorithm core, in terms of external interfaces, it includes all the interfaces in the original algorithm architecture, and newly adds a 32-bit output and a 32-bit input interface for S-box look-up table, as well as a control interface that is compatible with the control processing of the previous 4 + 4n time slots.

[0022] The ZUC256_atom algorithm core supports the following logical functions:

[0023] Function 1: Data initialization involved in algorithm initial startup or key update;

[0024] Function 2: LFSR update in the first 33 rounds;

[0025] Function 3: Encryption and decryption process of data after key initialization;

[0026] Function 4: Combinational logic required for generating various algorithm parameters;

[0027] Function 5: Data flow control processing and time-division multiplexing S-box look-up table logic.

[0028] The specific implementation of Function 5 includes:

[0029] The described ZUC256_atom algorithm core supports four states: halt, idle, wait, and valid, and can dynamically adjust the operating power consumption and data flow control. Among them, halt means that the ZUC256_atom algorithm core stops running, wait means data flow control waiting, valid means that the current S-box lookup table data is valid, and idle means that the algorithm core pauses logic inversion.

[0030] Furthermore, two MDS matrices L1 and L2 in the ZUC-256 algorithm resources are extracted into the ZUC256_integer module as common resources for time-division multiplexing. At this time, the input and output interface methods are compatible with the aforementioned S-box resource optimization operations.

[0031] The two MDS matrices L1 and L2 are used to perform a linear transformation on the input 32-bit data X. The specific operation is as shown in the following formula:

[0032]

[0033]

[0034] Among them, <<< represents a cyclic left shift, represents an exclusive OR operation.

[0035] The beneficial effects of the present invention are as follows:

[0036] (1) The method of the present invention distributes S-box parameter data in a fixed time sequence and time-division manner, and on this basis, multiplexes the MDS matrices L1 and L2, greatly reducing the resource occupation of the system. Compared with the method without resource optimization, the total resource occupation (including top-level processing) is reduced by about 42% in the current typical 8-channel scenario and about 55% in the 16-channel scenario.

[0037] (2) The present invention realizes an optimization strategy with the least resource consumption through the internal timing of the lower 2 bits of the algorithm.

[0038] (3) The present invention takes into account both the convenience of processing and the performance of the algorithm, and uses 4 control time slots and 4n data time slots with fixed S-box resource planning as a time-division processing strategy, so as to support data encryption and decryption of n channels at most simultaneously.

[0039] (4) The present invention can meet the requirements for encryption and decryption of multi-channel data in scenarios with limited hardware resources, and can conveniently realize the expansion of multiple channels. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is the overall architecture of the resource optimization implementation scheme of the ZUC-256 algorithm in a multi-channel scenario described in the embodiments of the present invention.

[0041] Figure 2 This is a schematic diagram showing the specific use of the S-box of the ZUC-256 algorithm in the embodiments of the present invention.

[0042] Figure 3 This is a schematic diagram of the internal structure of the ZUC256_atom algorithm core in the embodiments of the present invention.

[0043] Figure 4 This is a schematic diagram of the look-up table logic of the ZUC256_atom algorithm core in the embodiments of the present invention.

[0044] Figure 5 This is a schematic diagram of the state transition of the ZUC256_atom algorithm core in the embodiments of the present invention.

[0045] Figure 6 This is a diagram of the resource optimization result in the embodiments of the present invention. Detailed implementation manners

[0046] The present invention will be further described in detail below in conjunction with embodiments and the accompanying drawings, but the implementation manners of the present invention are not limited thereto.

[0047] As Figure 1 shown, a method for realizing resource optimization of the ZUC-256 algorithm in a multi-channel scenario first constructs a multi-channel ZUC-256 composite algorithm core, which specifically includes two parts: a ZUC256_integer module and multiple ZUC256_atom algorithm cores. The ZUC256_integer module is used to complete the definition of the external interfaces for multiple channels (i.e., responsible for communicating with the outside through the defined interfaces) and the deployment of common resources. The ZUC256_atom algorithm core is used to implement the encryption and decryption algorithms of the ZUC-256 algorithm, that is, the basic combinational logic and multi-round timing logic required for the operation of an independent algorithm core. One ZUC256_atom algorithm core independently is responsible for data encryption or decryption of one channel.

[0048] The ZUC256_integer module defines n 32-bit encryption / decryption channels, n initial keys iK, and n initial vectors iV according to actual application requirements, and uses the encryption / decryption channels, initial keys iK, and initial vectors iV as external data interfaces and corresponding control signals. According to the external control signals, the initial keys iK and initial vectors iV data are sent to the corresponding ZUC256_atom algorithm cores for initialization. At the same time, the ciphertext / plaintext is sent to the corresponding ZUC256_atom algorithm cores for encryption or decryption and then the corresponding plaintext / ciphertext output is received.

[0049] The ZUC256_integer module is used to complete the following logical functions:

[0050] Function 1: According to the control signals corresponding to the external control module and the n internally instantiated (depending on the specific number of channels in the actual application scenario) ZUC256_atom algorithm cores, the initial key iK and the initial vector iV information of each path are respectively sent to each internally instantiated ZUC256_atom algorithm core.

[0051] The external control module mentioned above refers to an external control interface that needs to apply the algorithm of the present invention.

[0052] Function 2: Perform data flow control according to the control signals corresponding to the external control module and the n internally instantiated ZUC256_atom algorithm cores.

[0053] Function 3: Provide the common resources required by the ZUC256_atom algorithm core, including two S-boxes: S0_BOX resource and S1_BOX resource; two MDS matrices L1 and L2.

[0054] Furthermore, in Function 1, the initial key iK and the initial vector iV data of each path are based on the corresponding control signal ch of the external channel selection. The key data valid signal key_enable writes the externally input initial key iK and the initial vector iV data into the key data register of the corresponding ZUC256_atom algorithm core. When the ZUC256_atom algorithm core performs an initialization operation or a key update operation, the updated data is read from the key data register.

[0055] Furthermore, the data flow control in Function 2 distributes the data transmitted to each channel to the corresponding ZUC256_atom algorithm core for encryption and decryption processing in sequence, and then returns the data obtained after encryption and decryption in sequence.

[0056] Furthermore, the S0_BOX and S1_BOX resources mentioned in Function 3 are used for non-linear substitution of the input 8-bit data. Specifically: it is implemented using a ROM based on a lookup table. The input is an 8-bit address (i.e., the value before substitution), and the output 8-bit data is the value after non-linear substitution. Therefore, 256 bytes (8×256 = 2048-bit) of data need to be stored in the ROM.

[0057] In this embodiment, the selected FPGA chip is the CycloneIV series EP4CE115F17C8 of Altera Corporation, and this chip has more than 115K logic units. A ROM can be quickly generated through the wizard tool of Altera's QuartusⅡ development software. The ROM in this example is set to have a length of 8 bits and a depth of 8 bits, and then the corresponding data of the S-box is written in advance internally.

[0058] As Figure 2 shown, in the process of implementing the ZUC-256 algorithm, the S-box is needed to replace the 32-bit data generated by the MDS matrix and then update the values of registers R1 and R2 in the FMS. Before optimizing the ZUC-256 algorithm, using a parallel method to replace the 32-bit data requires 4 S0_BOX and 4 S1_BOX resources.

[0059] The optimization scheme in this embodiment takes into account both the convenience of processing and the performance of the algorithm. When n = 16, that is, 16 channels, the present invention plans 4 fixed control time slots + 64 data time slots for the S-box resources as a time-sharing processing strategy; this strategy can support data encryption and decryption of up to 16 channels simultaneously.

[0060] Further, the time slot number is 7 bits, and a total of 68 time slots are set (4 control time slots + 64 data time slots), where time slots 0-3 are control fields and time slots 4-67 are data fields.

[0061] Further, the time slot number is generated by an 8-bit counter. The counter increments by 1 at each rising edge of the clock. After power-on reset, it starts counting from 0, and after counting to 67, it resets to 0 and starts counting again.

[0062] Among the 7 bits of the time slot number, the high 5 bits represent the channel identifier of the algorithm core, and the low 2 bits represent the internal timing when it is the channel of the ZUC256_atom algorithm core.

[0063] The data represented by the high 5 bits of the time slot number is the channel identifier of the ZUC256_atom algorithm core, which is used to indicate that the current S-box parameter data is distributed to the ZUC256_atom algorithm core in the corresponding channel. For example, when the high bit of the serial number is 1, it means that the S-box parameter data is distributed to the ZUC256_atom algorithm core in channel 1, and when it is 16, it means that the S-box parameter data is distributed to the ZUC256_atom algorithm core in channel 16, and so on. The high bit part of the time slot number can be adjusted according to the required number of channels. When more channels need to be implemented, the high bit of the time slot number is extended, and when the number of channels needs to be reduced, the high bit of the extended time slot number is reduced. As long as the time slot number can represent the number of channels.

[0064] The internal timing of the algorithm for the low 2 bits is an optimization strategy to achieve the minimum resource consumption. Specifically, the look-up table replacement of 32-bit data is planned and divided into 4 8-bit look-up table replacement processes. In this way, each ZUC256_atom algorithm core needs 4 timing cycles to complete a 32-bit data look-up table replacement process. The specific steps are as follows:

[0065] Taking the time slot sequence number 7’b0000101 (in binary representation) as an example, it means that at this time, the S-box parameter data is distributed to the ZUC256_atom algorithm core of channel 0 for the second table lookup and replacement; when the time slot sequence number is 7’b1000011, it means that at this time, the S-box parameter data is distributed to the ZUC256_atom algorithm core of channel 15 for the fourth table lookup and replacement. And so on for other cases.

[0066] Furthermore, for the ZUC256_atom algorithm core, in terms of external interfaces, it includes all the interfaces in the original algorithm architecture, and newly adds a 32-bit output and a 32-bit input interface for S-box table lookup, as well as a control interface that is compatible with the control processing of the aforementioned 68 time slots.

[0067] The ZUC256_atom algorithm core supports the following logical functions:

[0068] Function 1: Data initialization involved in algorithm initial startup or key update;

[0069] Function 2: Update of LFSR in the first 33 rounds;

[0070] Function 3: Encryption and decryption process of data after key initialization;

[0071] Function 4: Combinational logic required for generating various algorithm parameters;

[0072] Function 5: Data flow control and time-division multiplexing S-box table lookup logic;

[0073] The specific operation in Function 1 is: after detecting the key update signal, load KEY and IV into the LFSR register according to the algorithm rules, and at the same time set the two registers R1 and R2 in the FSM to zero. After completion, jump to execute Function 2.

[0074] The specific operation in Function 2 is: calculate the u and v parameters according to the algorithm, and thus calculate the value of s16 to update the LFSR register. After 32 rounds of cyclic update, only calculate the value of s16 according to the v parameter to update the LFSR register, and complete the update of the LFSR register in the 33rd round.

[0075] The specific operation in Function 3 is: perform an exclusive OR operation on the input 32-bit plaintext / ciphertext and the 32-bit key stream generated by the ZUC-256 algorithm to obtain the encrypted / decrypted ciphertext / plaintext.

[0076] The overall internal implementation structure of the ZUC256_atom algorithm core in Function 4 is as Figure 3 shown, including an LFSR module, a BR module, an FSM module, and an FSM_TOP module.

[0077] The S-box look-up table logic in Function Five is specifically as follows Figure 4 as shown. The operation steps are as follows:

[0078] When T = 0, the look-up table replacement of L1[23:16] and L1[31:24] is completed; when T = 1, the look-up table replacement of L1[7:0] and L1[15:8] is completed; when T = 2, the look-up table replacement of L2[23:16] and L2[31:24] is completed; when T = 3, the look-up table replacement of L2[7:0] and L2[15:8] is completed.

[0079] The ZUC256_atom algorithm core supports four states: halt, idle, wait, and valid, and can be used to dynamically adjust the operating power consumption and data flow control. Among them, halt means that the algorithm core stops running, wait means that the data flow control is waiting, valid means that the current S-box look-up table data is valid, and idle means that the algorithm core pauses the logic flip.

[0080] The jumps of the above-mentioned various states are as follows Figure 5 as shown. When T < 0 and the algorithm core is not enabled, it is in the halt state; during the process of S-box look-up table after the algorithm core is enabled, it is in the wait state; after completing the four-cycle look-up table of the current algorithm core, it is in the valid state; then when the algorithm core is not allocated S-box data, it is in the idle state.

[0081] Furthermore, two MDS matrices L1 and L2 in the ZUC-256 algorithm resources are extracted into the ZUC256_integer module as common resources for time-division multiplexing. At this time, the input / output interface method is compatible with the aforementioned S-box resource optimization operation.

[0082] The MDS matrices L1 and L2 are used to perform a linear transformation on the input 32-bit data X. The specific operation is as shown in the following formula:

[0083]

[0084]

[0085] Specific operation steps: The combined logic implementation part of the two MDS matrices L1 and L2 is extracted into the ZUC256_integer module. The algorithm core no longer directly outputs the 32-bit data after MDS matrix transformation. Instead, when the algorithm core is allocated S-box parameter data, it first performs MDS matrix transformation in the ZUC256_integer module and then performs S-box replacement operation, so that the original input / output interface of the algorithm core can be unchanged.

Claims

1. A resource optimization implementation method of the ZUC-256 algorithm in a multi-channel scenario, characterized in that firstly, a multi-channel ZUC-256 composite algorithm core is constructed, which specifically includes two parts: the ZUC256_integer module and multiple ZUC256_atom algorithm cores; the ZUC256_integer module is used to complete the interface definition for the multi-channel and the deployment of common resources; the ZUC256_atom algorithm core is used to implement the basic operations of the ZUC-256 algorithm, that is, the basic combinational logic and multi-round sequential logic required for the independent operation of the algorithm core, and one ZUC256_atom algorithm core independently is responsible for data encryption or decryption of one channel; The ZUC256_integer module can complete the following logical functions: Function 1: According to the control signals of the external control module and the corresponding n ZUC256_atom algorithm cores instantiated internally, the initial key iK and the initial vector iV of each path are respectively sent to each ZUC256_atom algorithm core instantiated internally; Function 2: According to the control signals of the external control module and the corresponding n ZUC256_atom algorithm cores instantiated internally, data flow control is performed; Function 3: Provide the common resources required by the ZUC256_atom algorithm core, including two S-boxes: the S0_BOX resource and the S1_BOX resource; two MDS matrices L1 and L2; The S0_BOX resource and the S1_BOX resource are used for non-linear substitution of the input 8-bit data, and are specifically implemented using a ROM based on a lookup table: the input is an 8-bit address, and the output 8-bit data is the value after non-linear substitution; The S-box resource is planned with 4 fixed control time slots and 4n data time slots as a time-sharing processing strategy, and using this strategy can support data encryption and decryption of n channels simultaneously; The time slot number is x-bit, where x represents the data bit width, and its length needs to be able to represent all the time sequences, 4(n + 1) time slots, where the 0th to 3rd time slots are control fields, and the 4th to 4n + 3rd time slots are data fields; In the time slot number, the data represented by the high (x - 2) bits is the channel identifier of the algorithm core, and the data represented by the low 2 bits is the internal time sequence of the ZUC256_atom algorithm core channel; The data represented by the high (x - 2) bits is used to indicate that the current S-box parameter data is distributed to the ZUC256_atom algorithm core in the corresponding channel; The internal algorithm time sequence of the low 2 bits is an optimization strategy for realizing the minimum resource consumption. Specifically, the look-up table substitution of 32-bit data is planned and divided into 4 8-bit look-up table substitution processes. In this way, each ZUC256_atom algorithm core needs 4 time sequence cycles to complete a 32-bit data look-up table substitution process.

2. The resource optimization implementation method of the ZUC-256 algorithm in a multi-channel scenario according to claim 1, characterized in that The ZUC256_integer module defines n 32-bit encryption / decryption channels, n initial keys iK, and n initial vectors iV according to actual application requirements, and takes the encryption / decryption channels, initial keys iK, and initial vectors iV as external data interfaces and corresponding control signals.

3. The method for optimizing the implementation of the ZUC-256 algorithm in a multi-channel scenario according to claim 1 or 2, characterized in that the time slot sequence number x-bit is generated by an 8-bit counter, the counter increments by 1 at each rising edge of the clock, starts counting from 0 after power-on reset, and resets to 0 after counting to 4n + 3 and starts counting again.

4. The method for optimizing the implementation of the ZUC-256 algorithm in a multi-channel scenario according to claim 3, characterized in that for the ZUC256_atom algorithm core, a new 32-bit output and 32-bit input interface for S-box look-up table and a control interface compatible with the control processing of the 4 + 4n time slots described above are added to the external interface.

5. The method for optimizing the implementation of the ZUC-256 algorithm in a multi-channel scenario according to claim 4, characterized in that the ZUC256_atom algorithm core supports the following logical functions: Function 1: Data initialization involved in the initial startup of the algorithm or key update; Function 2: LFSR update in the first 33 rounds; Function 3: Encryption / decryption process of data after key initialization; Function 4: Combinational logic required for generating various algorithm parameters; Function 5: Data flow control processing and time-division multiplexing S-box look-up table logic.

6. The method for optimizing the implementation of the ZUC-256 algorithm in a multi-channel scenario according to claim 5, characterized in that the implementation of Function 5 includes: the ZUC256_atom algorithm core supports four states: halt, idle, wait, and valid, and can dynamically adjust the operating power consumption and data flow control; where halt means the ZUC256_atom algorithm core stops running, wait means data flow control waiting, valid means the current S-box look-up table data is valid, and idle means the algorithm core pauses logic inversion.

7. The method for optimizing the implementation of the ZUC-256 algorithm in a multi-channel scenario according to claim 6, characterized in that two MDS matrices L1 and L2 in the ZUC-256 algorithm resources are extracted into the ZUC256_integer module as common resources for time-division multiplexing, and the input / output interface method is compatible with the aforementioned S-box resource optimization operation at this time; the two MDS matrices L1 and L2 are used to perform a linear transformation on the input 32-bit data X, and the specific operation is shown in the following formula: wherein, <<< represents a cyclic left shift, represents an exclusive OR operation.

Citation Information

Patent Citations

  • Initialization method and device of ZUC-256 stream cryptographic algorithm and communication method

    CN110011798A

  • Zu-Chongzhi encryption algorithm acceleration method, system, storage medium and computer equipment

    CN110445601A