An Encryption and Decryption Method for a Controllable Parallel CBC Block Cipher Mode
The CP-CBC encryption method addresses the speed limitations of CBC mode by enabling parallel processing with controlled parallelism, achieving nearly linear speedup and improved security against specific attacks.
Patent Information
- Application Number
- CN202211175958.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-26
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-09-26
AI Technical Summary
The encryption speed of the traditional CBC mode is limited by serial iteration, which is difficult to meet the encryption needs of the big data era, and the existing improvement solutions have not effectively improved the encryption speed.
A controllable parallel CBC packet cipher working mode is proposed. By setting the parallelism degree n, the encryption process is divided into an expansion stage and a parallel encryption stage. Part of the ciphertext is used as the initialization vector to open the parallel encryption chain, maintain the security of the CBC mode and improve the encryption speed.
It realizes an approximate linear acceleration ratio, can freely control the parallelism, improves encryption speed, and maintains security under the LOR-CPA model, and has higher anti-byte inversion and padding attack capabilities.
Smart Images

Figure CN115580395B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and in particular to an encryption and decryption method for a controllable parallel CBC block cipher mode of operation. Background Art
[0002] The perception of data by the Internet of Things and the storage and utilization of data by cloud computing have promoted the arrival of the big data era in which valuable judgment capabilities are provided by quickly analyzing data. The analysis technology of massive data has received widespread attention from people. The data shows a growth trend of TB-level scale, and high-value data has gradually become the core competitive asset. At the same time, the security and availability of data also face new challenges. It is urgent to develop high-speed massive data encryption technology to ensure data confidentiality and anti-tampering.
[0003] At present, the mainstream solution for big data encryption is a solution that combines a block cipher system and a public key cipher system, that is, first use a block cipher to encrypt big data, and then use a public key cipher to encrypt and protect the key of the block cipher. In 1980, the US National Bureau of Standards (now NIST) announced 4 block cipher modes of operation, which are ECB (Electronic Codebook), CBC (CipherBlockChaining), CFB (Cipher Feedback), and OFB (Output Feedback). On this basis, a large amount of work has been done, and a series of modes of operation have been proposed one after another, such as OCB (Offset Codebook), IAPM (Integrity Aware Parallelizable Mode), EAX, etc. Among them, the CBC mode is simple and easy to implement, has security under chosen-plaintext attack, has better security than other modes, and repeated plaintext blocks will not expose this repetition relationship in the ciphertext, avoiding some defects of the ECB mode. Therefore, the CBC mode is the most widely used, and the current big data encryption also often uses the CBC mode.
[0004] The CBC mode is as Figure 1 shown. It encrypts one plaintext block at a time, uses the same key k each time for encryption, the input of the encryption algorithm is the exclusive OR of the current plaintext block and the previous ciphertext block, and the first plaintext block is exclusive ORed with a random initialization vector IV.
[0005] The plaintext block of the CBC mode is denoted as m i , and the corresponding ciphertext block is c i (1 ≤ i ≤ s), where s is the total number of groups, then the encryption equation of the CBC mode is:
[0006]
[0007] The decryption equation is:
[0008]
[0009] From Figure 1 It can be seen that there is an iterative feedback form in the CBC working mode, which belongs to serial encryption and restricts the data encryption speed. In the era of big data, data has characteristics such as large data volume and diverse data types. Traditional encryption technologies already have constraints in terms of encryption speed. Therefore, it is necessary to construct a parallel cryptosystem and combine parallel computing theory to cope with the encryption of massive data and ensure the security of core data. Feng Xiao et al. gave a parallel processing architecture for block ciphers at the hardware level; Shi Jingang et al. explored the parallel block cipher system for massive data in the cloud environment, but only relied on the MapReduce parallel framework and did not transform the mode itself.
[0010] At present, there are not many improvements to the CBC mode. Wen Fengtong enhanced the security of the CBC mode, but the encryption speed did not increase; Fan Lingyan et al. gave a chip-level implementation of the SM4 algorithm in the CBC mode, but did not improve the mode itself. Summary of the Invention
[0011] To improve the encryption speed of the CBC mode, the present invention provides an encryption and decryption method for a controllable parallel CBC block cipher working mode, which can not only freely control the parallelism as needed, but also almost achieve a linear speedup ratio on the premise of not changing the cryptographic characteristics of the original block cipher operation mode.
[0012] On the one hand, the present invention provides an encryption method for a controllable parallel CBC block cipher working mode, including the following steps:
[0013] Step 1: Set the parallelism n, and determine the row number i and column number j in the plaintext block and ciphertext block in the CP-CBC mode according to the mark x of the x-th plaintext block in the original CBC mode and the parallelism n; where the CP-CBC mode is a controllable parallel CBC block cipher working mode; 1 ≤ x ≤ s, |m| represents the plaintext length, and l represents the block size;
[0014] Step 2: In the CP-CBC mode, set the case when i = 1 as the expansion stage; for the plaintext block and in the expansion stage, call the precursor block of , and the successor block of
[0015] Set the parallel encryption phase when i≥2; for the plaintext blocks in the parallel encryption phase and is called as the predecessor block of is the successor block of; where, 1≤j≤n;
[0016] Step 3: In the expansion phase, serially encrypt the n plaintext blocks according to the original CBC mode to obtain the corresponding n ciphertext blocks where, 1≤j≤n;
[0017] Step 4: Respectively use the n ciphertext blocks generated in the expansion phase as the initialization vectors of the parallel encryption phase, and start n parallel encryption chains; where, in the same encryption chain, serially encrypt according to the original CBC mode.
[0018] Furthermore, Step 1 specifically includes:
[0019]
[0020]
[0021] Furthermore, in Step 3, the encryption equation in the expansion phase is specifically:
[0022]
[0023] where, E k represents the encryption algorithm.
[0024] Furthermore, in Step 4, the encryption equation in the parallel encryption phase is specifically:
[0025]
[0026] where, E k represents the encryption algorithm.
[0027] Furthermore, it also includes: before encryption, pad the plaintext using the PKCS7 padding algorithm.
[0028] On the other hand, the present invention also provides a decryption method for a controllable parallel CBC block cipher working mode, including:
[0029] Step 1: Obtain the parallelism n, and group the ciphertext according to the parallelism n to obtain ciphertext blocks;
[0030] Step 2: In the CP-CBC mode, set the expansion phase when i = 1; for the ciphertext blocks in the expansion phase and It is called the predecessor block of and is called the successor block of
[0031] where 2 ≤ j ≤ n; and It is called the predecessor block of and is called the successor block of
[0032] Step 3: In the expansion stage, decrypt the n ciphertext blocks according to the original CBC mode to obtain the corresponding n plaintext blocks where 1 ≤ j ≤ n;
[0033] Step 4: Use the n ciphertext blocks in the expansion stage as the initialization vectors for the parallel decryption stage, and start n parallel decryption chains; in the same decryption chain, decrypt according to the original CBC mode.
[0034] Furthermore, in Step 3, the decryption equation in the expansion stage is specifically:
[0035]
[0036] where D k represents the decryption algorithm.
[0037] Furthermore, in Step 4, the decryption equation in the parallel decryption stage is specifically:
[0038]
[0039] where D k represents the decryption algorithm.
[0040] Advantages of the present invention:
[0041] The encryption and decryption method of a controllable parallel CBC block cipher working mode proposed by the present invention can achieve an approximate linear speedup ratio, and can freely control the parallelism degree n, while maintaining the security characteristics of the traditional CBC mode, that is, it is provably secure under the LOR-CPA model. For byte-reversal attacks and padding attacks, the solution of the present invention is more resistant to attacks without disclosing the parallelism degree n, and the security has a certain improvement compared with the traditional CBC mode. Description of the Drawings
[0042] Figure 1Flow diagram of the encryption and decryption method for the CBC working mode: (a) is the encryption process; (b) is the decryption process;
[0043] Figure 2 Flow diagram of the encryption method for a controllable parallel CBC block cipher working mode provided by an embodiment of the present invention;
[0044] Figure 3 Flow diagram of the decryption method for a controllable parallel CBC block cipher working mode provided by an embodiment of the present invention. Detailed implementation manners
[0045] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0046] For the convenience of description, some symbol conventions in this article are as follows:
[0047] Table 1 Symbol table
[0048]
[0049]
[0050] Among them, the plaintext block and the ciphertext block The superscript i and subscript j determine the row and column where the block is located.
[0051] Embodiment 1
[0052] As Figure 2 shown, an embodiment of the present invention provides an encryption method for a controllable parallel CBC block cipher working mode, including the following steps:
[0053] S101: Pad the plaintext;
[0054] Specifically, the block cipher system requires that the length of the plaintext to be encrypted is an integer multiple of the block length. For the last plaintext block, it is often difficult to exactly form a complete plaintext block, and padding is required at this time.
[0055] The PKCS7 padding algorithm is a commonly used padding algorithm at present. This padding algorithm needs to append a series of pad bytes at the end of the original data. The value of the pad is both the byte to be padded and the number of bytes to be padded. Specifically:
[0056] pad = l - (|m| mod l)
[0057] Where l is the block size, |m| represents the length of the plaintext, and 1 ≤ l ≤ 255.
[0058] Taking AES as an example, the padding example is shown in Table 2.
[0059] Table 2 PKCS7 Padding Format
[0060]
[0061] S102: Set the parallelism n. Determine the row number i and column number j of the plaintext block and ciphertext block in the CP-CBC mode according to the notation x of the x-th plaintext block and the parallelism n in the original CBC mode; where the CP-CBC (Controlled Parallel Cipher Block Chaining) mode is a controlled parallel CBC block cipher working mode; 1 ≤ x ≤ s, and the ciphertext block |m| represents the length of the plaintext, and l represents the block size; Specifically, determine the parallelism n according to the number of processors and the encryption requirements in the actual encryption scenario. The calculation process of the row number i and column number j is as follows:
[0062] Specifically, determine the parallelism n according to the number of processors and the encryption requirements in the actual encryption scenario. The calculation process of the row number i and column number j is as follows:
[0063]
[0064]
[0065] S103: In the CP-CBC mode, set the expansion stage when i = 1; for the plaintext block and call as the predecessor block of, as the successor block of; where 2 ≤ j ≤ n;
[0066] Set the parallel encryption stage when i ≥ 2; for the plaintext block and call as the predecessor block of, as the successor block of; where 1 ≤ j ≤ n;
[0067] Specifically, according to the arrangement of n blocks per row, the total number of rows of the blocks can be determined Since the arrangement of the plaintext and ciphertext is divided by rows, the predecessor group and successor group in the parallel encryption stage differ by n groups in the combined ciphertext.
[0068] S104: In the expansion stage, perform serial encryption on n plaintext groups according to the original CBC mode to obtain the corresponding n ciphertext groups where 1 ≤ j ≤ n;
[0069] Specifically, the encryption equation in the expansion stage, that is, the encryption equation for the n groups in the first row, is specifically:
[0070]
[0071] where E k represents the encryption algorithm.
[0072] S105: Use the n ciphertext groups generated in the expansion stage as the initialization vectors for the parallel encryption stage respectively, and start n parallel encryption chains; among them, in the same encryption chain, perform serial encryption according to the original CBC mode, that is, perform encryption after XOR with the predecessor group.
[0073] Specifically, each encryption chain is independent of each other and presents a parallel relationship. The encryption equation in the parallel encryption stage is specifically:
[0074]
[0075] where E k represents the encryption algorithm.
[0076] The core idea of the encryption method of the controllable parallel CBC block cipher working mode provided by the embodiments of the present invention is to use some of the generated ciphertext as the initialization vector to start a new encryption chain.
[0077] It should be noted that for the last row in the encryption method, Figure 2 the ideal situation given is that the parallelism n can exactly divide the number of plaintext groups.
[0078] Embodiment 2
[0079] Corresponding to the above encryption method, as Figure 3 shown, the embodiments of the present invention provide a decryption method for the controllable parallel CBC block cipher working mode, including the following steps:
[0080] S201: Obtain the parallelism n, and group the ciphertext according to the parallelism n to obtain ciphertext groups;
[0081] Specifically, the ciphertext c obtained by the encryption method is formed by connecting several ciphertext groups. For example, specifically:
[0082]
[0083] Among them, d represents the number of plaintext or ciphertext groups in the last row, and there exists
[0084] Therefore, for the subsequent decryption process, it is first necessary to group the entire ciphertext. Specifically, the ciphertext c is divided into:
[0085] S202: In the CP-CBC mode, it is set that when i = 1, it is the expansion stage; for the ciphertext group in the expansion stage and is called as the precursor group of is the successor group of
[0086] It is set that when i ≥ 2, it is the parallel decryption stage; for the ciphertext group in the parallel decryption stage and is called as the precursor group of is the successor group of
[0087] S203: In the expansion stage, decrypt the n ciphertext groups according to the original CBC mode to obtain the corresponding n plaintext groups where 1 ≤ j ≤ n;
[0088] Specifically, the decryption equation in the expansion stage is specifically:
[0089]
[0090] where D k represents the decryption algorithm.
[0091] S204: Use the n ciphertext groups in the expansion stage as the initialization vectors in the parallel decryption stage respectively, and start n parallel decryption chains; among them, in the same decryption chain, decrypt according to the original CBC mode.
[0092] Specifically, the decryption equation in the parallel decryption stage is specifically:
[0093]
[0094] where D k represents the decryption algorithm.
[0095] Finally, the plaintext m can be obtained, specifically:
[0096]
[0097] The security of the encryption method provided by the present invention will be specifically analyzed below.
[0098] The two stages of the solution of the present invention - the expansion stage and the parallel encryption stage - are essentially still in the CBC mode. In the expansion stage, ciphertexts are generated serially Since the ciphertext has good randomness, and the encryption result is different with different plaintext m and initialization vector IV, and has unpredictability, the ciphertexts generated by these n groups are respectively used as the initialization vectors to start n parallel CBC encryption chains in the parallel encryption stage. Therefore, the solution of the present invention maintains the security characteristics of the traditional CBC mode, that is, it is provably secure under the LOR-CPA model.
[0099] Therefore, the security of the solution of the present invention will not be proved from the perspective of provable security, but will be analyzed from the perspective of the attack route. At present, the more effective attack schemes against the CBC mode include: byte-flipping attack and padding attack. The security of the CP-CBC mode will be analyzed from these two attacks respectively below.
[0100] According to the above embodiments, the encryption process (such as formula (1)) and decryption process (such as formula (2)) of the present invention can be respectively summarized as:
[0101]
[0102]
[0103] (1) Byte-flipping attack
[0104] The core idea of the byte-flipping attack (Byte-Flipping Attack, BFA) is to use the influence of the previous ciphertext block on the next plaintext block to achieve tampering of the plaintext at a specific position. According to the decryption equation of the above CP-CBC mode, that is, formula (2), the first plaintext block needs to be XORed with the initialization vector IV before encryption, and the subsequent plaintext blocks need to be XORed with the ciphertext of the previous block before encryption.
[0105] There is conclusion 1: Under the condition that the parallelism degree n is not public, the idea of the byte-flipping attack can still attack the CP-CBC mode, and the attack cost is proportional to n; the verification process of this conclusion is as follows:
[0106] Since the byte-flipping attack only considers the relationship between the previous block and the subsequent block, the previous block and the subsequent block are simply denoted as the (N - 1)-th and N-th blocks. According to the value A of a certain bit of the ciphertext of the (N - 1)-th group, and the value B of the same position of the ciphertext of the N-th group after decryption, it is easy to obtain the plaintext C at this position of the N-th group of plaintext
[0107]
[0108] If the ciphertext A of the (N - 1)-th group is modified and XORed with the plaintext C, we get Continuing the above operation, the following formula is obtained from the XOR property
[0109]
[0110] It can be seen that the calculated plaintext is tampered with to 0. Further, the plaintext can be arbitrarily changed to any character X. Just XOR X on the basis of A' to get Similarly, we can get
[0111]
[0112] At this time, we have changed the plaintext to any desired character by modifying the ciphertext. For the first block, the IV can be changed using this principle. In particular, in the expansion stage of the CP-CBC mode, i.e., when i = 1, is not only used for XOR with but also for XOR with If an adversary wants to tamper with the plaintext at both of these places simultaneously, it will cause trouble to the adversary.
[0113] Under the condition of knowing part of the plaintext and ciphertext and being able to locate the previous ciphertext block of the block where the plaintext is located, the byte-reversal attack can achieve the tampering of the plaintext at a specific position. According to the ciphertext arrangement of the CP-CBC mode (as shown in Figure 2 ), there are n blocks between in the parallel encryption stage and its previous block . If the parallelism n is not public, in addition to the above operations, an attacker needs to try different values of n to achieve the tampering of the plaintext. Moreover, the larger the value of n, the higher the cracking difficulty for the attacker, and the average attack time is proportional to n.
[0114] Therefore, compared with the traditional CBC mode, the CP-CBC mode proposed in the present invention has higher resistance to byte-reversal attacks and certain improvement in security.
[0115] (2) Padding attack
[0116] In the padding oracle attack (POA), there is a receiver that decrypts the received ciphertext and checks whether the decrypted result satisfies the padding rule. If it is satisfied, it returns Valid; otherwise, it returns Invalid. Serge Vaudenay et al. invented this method of using the ciphertext padding verification response message to attack the CBC mode. Based on this idea, the padding attack against the CP-CBC mode is introduced below.
[0117] There is Conclusion 2: Under the condition that the parallelism degree n is not public, the idea of the padding attack in the CBC mode can still attack the CP-CBC mode, but the attack cost of step (1) (see the following attack process) is proportional to n. The verification process of this conclusion is as follows:
[0118] Let the last plaintext block of the CP-CBC mode be Then its precursor block is The corresponding ciphertext blocks are respectively Denote the intermediate result after decrypting the ciphertext block using the symmetric key k as That is The precursor block of is Then equation (3) becomes:
[0119]
[0120] When r = 1 or n = 1, the CP-CBC mode degenerates into the CBC mode, and the attack method is the method of using ciphertext padding to verify the response message to attack the CBC mode proposed by Serge Vaudenay et al. Therefore, the following discussion is based on r ≥ 2 and n ≥ 2.
[0121] If the parallelism degree n is public, then from the plaintext block it is easy to locate its precursor block by pushing back n blocks. The specific attack process is as follows:
[0122] Step (1) Determine the padding length of the last block: The last block must contain padding, at least one 0x01 and at most 16 0x10s (taking AES as an example, see Table 2 above). The attacker starts from the first byte on the left of its precursor block and modifies it to
[0123]
[0124] Then the modified ciphertext is sent to the receiver, and the receiver executes the decryption process to obtain the first byte on the left as
[0125]
[0126] At this time, if the receiver returns Invalid, it indicates that is part of the padding and the padding length is 16. If it returns Valid, then the change of does not affect the padding verification, and the padding length must be less than 16. The attacker then modifies the second byte following equation (4), subtracts one from the XOR number, and sends it to the receiver again. Repeating the above operation can obtain the padding length L.
[0127] Step (2) Decrypt the plaintext of the last block: After obtaining the padding length, the attacker can decrypt the plaintext one by one from right to left. According to the PKCS#7 standard, the last L bytes of the last block are all L, that is The attacker first modifies the last L bytes of
[0128]
[0129] where 16 - L ≤ i < 16. In this way, when the receiver executes the decryption process, the last L bytes obtained are
[0130]
[0131] Therefore, the effect of equation (5) is equivalent to changing the last L bytes of the last plaintext block after decryption to L + 1. Then the attacker tries to execute
[0132]
[0133] the following is the effect after the receiver executes
[0134]
[0135] where the value range of X is 0x00 - 0xFF. There is exactly one X in this range such that that is, the penultimate L + 1 byte is also L + 1. At this time, the whole block ends with L + 1 L + 1s, which is the only case that will not produce Invalid. Derived from equation (7)
[0136]
[0137] Therefore, as long as X is cracked, the attacker can calculate that the penultimate L + 1 byte of the plaintext is Next, the attacker increments L and repeats this process to obtain the plaintext of the last block. It can be seen that in this attack method, on average, 128 modified ciphertexts need to be sent to crack each byte of the plaintext.
[0138] Step (3) Decrypt the plaintext of non-tail blocks: For non-tail blocks, the attack method is not essentially different. The attacker removes the last block that has just been decrypted. At this time becomes the last block, is its predecessor block, and modifies the last byte of ) and then send it to the receiver. When receiving an Invalid message, the attacker tries the next X. When receiving a Valid message, the following two cases need to be distinguished:
[0139] ① If the last byte after decryption is 0x01, the receiver will surely return Valid. Because padding must exist, and 0x01 is the only single-byte padding case that can pass the verification. Obtained from Equation (8)
[0140]
[0141] ② If the last byte after decryption is a value between 0x02 and 0x10, and the plaintext data happens to be one of the following 15 cases, the receiver will also return Valid.
[0142] Table 3 Plaintext Patterns
[0143]
[0144]
[0145] To distinguish these two cases, after receiving Valid, the attacker modifies the second-to-last byte and resends it to the receiver. If it is Case ①, the receiver still returns Valid because the change of the second-to-last byte has no impact on the format; if it is Case ②, the change of the second-to-last byte destroys the format and the receiver returns Invalid. Thus, the two cases are identified, and then Equation (8) can be applied.
[0146] Next, for the cracking of other plaintext bytes in non-tail blocks, repeat the same processing in step (2) above, and crack byte by byte from right to left referring to Equations (5)-(8).
[0147] Through steps (1)(2)(3), the attack on the parallel encryption stage of the CP-CBC mode can be completed. The attacker removes the cracked blocks, and the remaining expansion stage degenerates into the CBC mode. The attack method is like the method of using ciphertext padding to verify the response message to attack the CBC mode proposed by Serge Vaudenay et al.
[0148] If the parallelism degree n is not public, the attacker locates its predecessor block from the block It is necessary to gradually explore the value of n. The larger the value of n, the higher the cracking difficulty for the attacker. To ensure the smooth progress of the attack, the attacker will explore the value of n while determining the padding length of the last block in step (1). If, for a certain exploration of n by the attacker, the feedback received for modifying all bytes of the previous block is Valid, it indicates that the modification of the previous block has not affected the last block, that is, the value of n is incorrect. The attacker increments n by 1 and continues the exploration until an Invalid feedback is received. During this process, the number of times the attacker needs to modify the ciphertext is proportional to n.
[0149] Therefore, compared with the traditional CBC mode, the CP-CBC mode has stronger resistance to this attack and its security has been improved to a certain extent. In addition, the emergence of this attack is due to the improper use scenario of the design, resulting in being cracked through "side-channel attack", rather than cracking the algorithm itself.
[0150] An important indicator for measuring the performance of block cipher modes of operation is the encryption speed. The following compares the encryption times of the same plaintext by CBC and CP-CBC to analyze the performance of the CP-CBC mode.
[0151] There is Conclusion 3: Compared with the CBC mode, the CP-CBC mode has an approximate linear speedup ratio of n. The verification process of this conclusion is as follows:
[0152] Let m be the plaintext bit string to be encrypted, |m| be the length of the bit string m, and l be the number of bits of the selected encryption algorithm, that is, the block size. Using the PKCS7 padding scheme, the total number of blocks Denote the processing time of a single block as t, which includes the time used for XOR operation and encryption operation. Then, in the case of the traditional CBC mode with the input plaintext being m, the total encryption time is:
[0153]
[0154] The number of plaintext blocks in the expansion stage of the CP-CBC mode is the parallelism n. Substituting n into formula (10), the encryption time T1 = tn in the expansion stage is obtained. The time used in the parallel encryption stage is determined by the maximum time among the n encryption chains, that is, determined by the maximum number of plaintext blocks. The maximum number of plaintext blocks in this stage (excluding the one plaintext block in the expansion stage), substituting into formula (10) to obtain the time used in the parallel encryption stage Then, in the case of the CP-CBC mode with the input plaintext being m, the total encryption time is:
[0155]
[0156] Define the speedup ratio:
[0157]
[0158] where T CBC is the encryption time required for the traditional CBC mode, and T CP-CBC is the encryption time required for the controllable parallel CBC mode. Substituting equations (10) and (11) gives the speedup ratio as
[0159]
[0160] where Approximating equation (12) gives the speedup ratio as
[0161]
[0162] For common symmetric encryption algorithms, the value of l is not too large. For example, the block length of the SM4 algorithm is 128 bits, and the block length of the AES algorithm can be 128, 192, or 256 bits. For the degree of parallelism n, due to the actual processor cost, the value of n cannot be too large. For the encryption of a large amount of data, |m| is much larger than l and n. Therefore That is to say, when |m| approaches infinity, the speedup ratio approaches n.
[0163] During the decryption of the CP-CBC mode, since the receiving party knows all the ciphertext blocks and the initialization vector IV, there is no dependency between the decryption and other blocks, that is, the high efficiency of the decryption of the traditional CBC mode is still retained. Table 4 gives a comparative analysis of the CP-CBC mode and some common modes:
[0164] Table 4 CP-CBC mode and some common modes
[0165]
[0166]
[0167] Therefore, the solution of the present invention has almost a linear speedup ratio for the encryption of a large amount of data. Compared with the traditional CBC mode, the encryption speed has been greatly improved.
[0168] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. An encryption method for a controllable parallel CBC block cipher mode of operation, characterized in that, Including: Step 1: Set the parallelism degree n. Determine the line number i and column number j in the plaintext block and ciphertext block in the CP-CBC mode according to the notation x of the x-th plaintext block in the original CBC mode and the parallelism degree n. Here, the CP-CBC mode is a controllable parallel CBC block cipher working mode; 1 ≤ x ≤ s, and the ciphertext block where |m| represents the plaintext length and l represents the block size; |m| represents the plaintext length and l represents the block size; Step 2: In the CP-CBC mode, when i = 1, it is the expansion phase; for the plaintext block in the expansion phase and is called the predecessor block of and is called the successor block of; where, 2 ≤ j ≤ n; Set the parallel encryption phase when \(i\geq2\); for the plaintext blocks in the parallel encryption phase and is called as the predecessor block of, is the successor block of; where, \(1\leq j\leq n\); Step 3: In the expansion phase, n plaintext blocks are serially encrypted according to the original CBC mode to obtain the corresponding n ciphertext blocks where 1 ≤ j ≤ n; Step 4: Use the n ciphertext groups generated in the expansion stage as the initialization vectors for the parallel encryption stage respectively, and start n parallel encryption chains; among them, in the same encryption chain, serial encryption is performed according to the original CBC mode.
2. The encryption method of a controllable parallel CBC block cipher working mode according to claim 1, characterized in that, Step 1 specifically includes:
3. The encryption method of a controllable parallel CBC block cipher working mode according to claim 1, characterized in that, In Step 3, the encryption equation in the expansion stage is specifically: Among them, E k represents an encryption algorithm.
4. The encryption method of a controllable parallel CBC block cipher working mode according to claim 1, characterized in that, In Step 4, the encryption equation in the parallel encryption stage is specifically: Among them, E k represents an encryption algorithm.
5. The encryption method of a controllable parallel CBC block cipher working mode according to claim 1, characterized in that, Also including: Before encryption, the plaintext is padded using the PKCS7 padding algorithm.
6. A decryption method for a controllable parallel CBC block cipher mode of operation, characterized in that, Including: Step 1: Obtain the parallelism degree n, group the ciphertext according to the parallelism degree n to obtain ciphertext groups; Step 2: In the CP-CBC mode, set the expansion phase when i = 1; for the ciphertext block in the expansion phase and is called the predecessor block of and is called the successor block of; where 2 ≤ j ≤ n; Set the parallel decryption phase when \(i\geq2\); for the ciphertext blocks in the parallel decryption phase and are called the predecessor block of , and is called the successor block of; where, \(1\leq j\leq n\). Step 3: In the expansion phase, decrypt the n ciphertext groups according to the original CBC mode to obtain the corresponding n plaintext groups where 1 ≤ j ≤ n; Step 4: Use the n ciphertext groups generated in the expansion stage as the initialization vectors for the parallel decryption stage respectively, and start n parallel decryption chains; among them, in the same decryption chain, decryption is performed according to the original CBC mode.
7. The decryption method of a controllable parallel CBC block cipher working mode according to claim 6, characterized in that, In Step 3, the decryption equation in the expansion stage is specifically: Among them, D k represents the decryption algorithm.
8. The decryption method of a controllable parallel CBC block cipher working mode according to claim 6, characterized in that, In Step 4, the decryption equation in the parallel decryption stage is specifically: Among them, D k represents the decryption algorithm.