A method for generating an S-box with high nonlinearity

By introducing finite domain GF(24) multiplication inverse element transformation, affine transformation and nonlinear transformation into the S-box generation method, the existing S-box algebraic structure is solved, and the security strength of encrypted data is improved and hardware resources are saved.

CN115865310BActive Publication Date: 2025-06-2410TH RES INST OF CETC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211217044.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-30
Publication Date
2025-06-24
Estimated Expiration
2042-09-30

AI Technical Summary

Technical Problem

The existing S box has strong algebraic structure, is not universal, and the random generation of S box is long and has poor properties, making it difficult to meet the demand for the security strength of encrypted data in modern cryptography.

Method used

Using a method that includes finite domain GF(24) multiplication inverse element transformation, affine transformation and nonlinear transformation, the 8-bit input is split into two 4-bit packets, the output value is obtained through these transformations, and the final result is obtained through the coupling.

Benefits of technology

It improves the complexity and nonlinearity of the S box, enhances the security strength of encrypted data, and saves hardware resources through integrated encryption and decryption mode.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865310B_ABST
    Figure CN115865310B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for generating an S-box with high nonlinearity, belonging to the technical field of modern cryptography. First, the 8-bit input is split into two 4-bit groups, and then the corresponding output values are obtained through multiplicative inverse transformation, affine transformation, and two nonlinear transformations. Then, the two groups of output values are concatenated to obtain the result. While ensuring the high nonlinearity and balance of the S-box, the complexity of data encryption is improved by fully confusing the plaintext, and the difficulty of breaking data encryption is increased. At the same time, the present invention integrates the encryption and decryption modes in one system, realizes the free replacement of encryption and decryption, and effectively saves hardware resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of modern cryptography, and particularly relates to a method for generating an S-box (Substitution-box) with high nonlinearity. Background Art

[0002] Cryptography has a long history and was initially used to protect the security of military and diplomatic communications. However, with the popularization of communication networks and computer networks, the application of modern cryptography is no longer limited to politics, military, and diplomacy, and its commercial and social values have been widely recognized. Confidentiality is the core of cryptography, and encryption is a practical tool for obtaining information confidentiality.

[0003] Cryptographic algorithms are divided into public-key cryptographic algorithms and private-key cryptographic algorithms. Private-key cryptographic algorithms are further divided into block cipher algorithms and stream cipher algorithms. Block cipher algorithms generally encrypt messages in blocks, and one large message block is encrypted in one run of the algorithm. Stream cipher algorithms generally use a short key and a specific key stream generation algorithm to generate a key stream sequence of a length comparable to the message to be encrypted, and the key stream sequence is exclusive-ored with the plaintext bit by bit to achieve the purpose of encryption. The decryption party generates the same key stream sequence and exclusive-ors it with the ciphertext to obtain the plaintext.

[0004] The S-box is the most core non-linear component of cryptographic algorithms, and its security largely determines the security strength of cryptographic algorithms. Currently, the more popular S-box is an 8×8 S-box. There are mainly two types of methods for generating S-boxes. One is to construct based on mathematical methods. The S-boxes constructed by this type of method usually have guaranteed cryptographic properties, but the algebraic structure is too strong, making the universality of this method not strong. The other is to randomly generate S-boxes. Using this type of method often takes a long time to output an S-box that meets the conditions, and the properties are slightly worse than the first method. Summary of the Invention

[0005] In view of the deficiencies of the prior art, the present invention proposes a method for generating an S-box with high nonlinearity to enhance the complexity of the S-box and further improve the security strength of encrypted data.

[0006] The technical solution adopted by the present invention is as follows:

[0007] A method for generating an S-box with high nonlinearity, the method comprising the following steps:

[0008] Step 1, a control signal register receives and stores the processing commands for encryption and decryption, and an information memory receives and stores the information X to be processed; wherein, the length of the information X is 8 bits;

[0009] Step 2, a splitter reads the information X from the information memory and splits it into two 4-bit groups Lx and Rx on the left and right;

[0010] Step 3, the encryption and decryption controller reads the processing command in the control signal register. If it is in the encryption mode, step 4 is executed; if it is in the decryption mode, step 5 is executed.

[0011] Step 4, perform the arithmetic processing in the encryption mode:

[0012] Through the multiplicative inverse converter in the finite field GF(2 4 ), perform the multiplicative inverse transformation on the 4-bit groups Lx and Rx segmented by the segmenter respectively to obtain the groups L'x and R'x after the multiplicative inverse transformation;

[0013] Then, select the affine transformation f1 or f2 through the affine transformation controller: if the control signal of the affine transformation controller is 1, perform the affine transformation f1 on the group L'x and the affine transformation f2 on the group R'x; if the control signal of the affine transformation controller is 0, it is the opposite.

[0014] Select the non-linear transformation Nl1(x) or Nl2(x) through the non-linear transformation controller: if the control signal of the non-linear transformation controller is 1, perform the non-linear transformation Nl1(x) on the result of the affine transformation f1(x) and the non-linear transformation Nl2(x) on the result of the affine transformation f2(x); if the control signal of the non-linear transformation controller is 0, it is the opposite.

[0015] Obtain the output sequences LY and RY based on the outputs of the linear transformations Nl1(x) and Nl2(x), that is, the transformation sequences;

[0016] Step 5, perform the arithmetic processing in the decryption mode:

[0017] Judge the non-linear inverse transformation according to the non-linear inverse transformation controller or If the control signal of the non-linear transformation controller is 1, perform the non-linear inverse transformation on the group Lx segmented by the segmenter Perform the non-linear inverse transformation on the group Rx If the control signal of the non-linear transformation controller is 0, it is the opposite;

[0018] Then, select the affine inverse transformation f1 through the affine inverse transformation controller -1 or If the control signal of the affine transformation controller is 1, perform the affine inverse transformation f1 on the result of the non-linear inverse transformation and perform the affine inverse transformation on the result of the non-linear inverse transformation -1 If the control signal of the affine transformation controller is 0, it is the opposite;

[0019]

[0019] Perform the affine inverse transformation f1 -1and the affine inverse transformation The results of are respectively passed through the multiplicative inverse transformers in the finite field GF(2 4 ) to perform the multiplicative inverse transformation in the finite field GF(2 4 ), and the output sequences LY and RY are obtained;

[0020] Step 6, connect the sequences output in Step 4 or Step 5 through a connector to obtain the information output Y and send it to the information memory for storage;

[0021] Among them, the non-linear transformations Nl1(x) and Nl2(x) are: set the value of the parameter s, different values of the parameter s correspond to different non-linear transformations, and the non-linear transformation Nl1(x) and the non-linear transformation Nl2(x) are respectively obtained based on two different values of the parameter s. Among them, the value range of the parameter s is: 0 ≤ s ≤ 2 n -2, where n is a positive integer.

[0022] Furthermore, the multiplicative inverse transformers in the finite field GF(2 4 ) store 16 inverse byte data of the finite field GF(2 4 ). This byte data is the 16 data obtained by taking the inverse of 16 data on the finite field GF(2 4 ) with m(x) = x 4 + x + 1 as the irreducible polynomial.

[0023] Furthermore, in Step 4, when performing the encryption mode operation processing, the affine inverse transformations f1(x) and f2(x), and the non-linear transformations Nl1(x) and Nl2(x) are respectively set as:

[0024]

[0025] Each branch of the non-linear transformation Nl1(x) = (nl 10 (x), nl 11 (x), nl 12 (x), nl 13 (x)) is respectively:

[0026]

[0027] Each branch of the non-linear transformation Nl2(x) = (nl 20 (x), nl 21 (x), nl 22 (x), nl 23 (x)) is respectively:

[0028]

[0029] Among them, x0, x1, x2, and x3 respectively represent the bits corresponding to the input information X.

[0030] Further, in step 5, when performing the decryption mode operation process, the affine inverse transformation f1 -1 (x) and and the non - linear inverse transformation and are respectively set as:

[0031]

[0032] Among them, each branch of the inverse transformation of the non - linear transformation is respectively:

[0033]

[0034] Each branch of the inverse transformation of the non - linear transformation is respectively:

[0035]

[0036] The technical solution provided by the present invention at least brings the following beneficial effects:

[0037] The present invention first splits the 8 - bit input into two 4 - bit groups, then obtains the corresponding output values through multiplicative inverse transformation, affine transformation, and two non - linear transformations, and then concatenates the two groups of output values to obtain the result. While ensuring the high non - linearity and balance of the S - box, it improves the complexity of data encryption by fully confusing the plaintext, increasing the difficulty of breaking data encryption. At the same time, the present invention integrates the encryption and decryption modes in one system, realizes the free replacement of encryption and decryption, and effectively saves hardware resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0039] Figure 1 is a schematic diagram of the processing process of a method for generating an S - box with high non - linearity provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0040] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will further describe the embodiments of the present invention in detail with reference to the drawings.

[0041] As Figure 1As shown in the figure, a method for generating an S-box with high nonlinearity provided by an embodiment of the present invention realizes the reception, storage, and transmission of information and control signals through an input information memory, a control signal register, and an output information memory; and realizes the dynamic control of the entire S-box transformation through a control module (including an encryption and decryption controller, an affine transformation controller, a non-linear transformation controller, an affine inverse transformation controller, and a non-linear inverse transformation controller).

[0042] As Figure 1 shown, the multiplicative inverse converter in the finite field GF(2 4 ) stores 16 binary sequence values of 4 bits in length, and these binary sequence values are 16 values obtained by taking the inverse of 16 elements in the finite field GF(2 4 ) with m(x) = x 4 + x + 1 as the irreducible polynomial.

[0043] As Figure 1 shown, the encryption mode includes affine transformations f1(x) and f2(x) and non-linear transformations Nl1(x) and Nl2(x); the decryption mode includes the affine inverse transformation f1 -1 (x) and and the non-linear inverse transformation and

[0044]

[0045]

[0046] Each branch of the non-linear transformation Nl1(x) = (nl 10 (x), nl 11 (x), nl 12 (x), nl 13 (x)) is respectively:

[0047]

[0048] Each branch of the non-linear transformation Nl2(x) = (nl 20 (x), nl 21 (x), nl 22 (x), nl 23 (x)) is respectively:

[0049]

[0050] Each branch of the inverse transformation of the non-linear transformation is respectively:

[0051]

[0052] Inverse transformation of non - linear transformation Each branch of

[0053]

[0054] where x0, x1, x2, x3 respectively represent the bits corresponding to the input information X.

[0055] As Figure 1 shown, the processing procedure of the present invention is as follows:

[0056] Step S1: The control signal register receives and stores the processing command (encryption mode or decryption mode) for encryption and decryption, and the information memory receives and stores the information X to be processed, where the length of the information X is 8 bits;

[0057] Step S2: The splitter reads the information X from the information memory and splits it into two 4 - bit groups Lx and Rx on the left and right;

[0058] Step S3: The encryption / decryption controller reads the processing command in the control signal register. If it is in the encryption mode, step S4 is executed; if it is in the decryption mode, step S5 is executed;

[0059] Step S4: In the encryption mode, the specific operation process is as follows:

[0060] First, for each 4 - bit input data, the multiplicative inverse transformation over the finite field GF(2 4 ) is performed respectively, that is, the multiplicative inverse transformers over the finite field GF(2 4 ) respectively perform the multiplicative inverse transformation on the 4 - bit groups Lx and Rx split by the splitter to obtain the groups L′x and R′x after the multiplicative inverse transformation;

[0061] Then, the affine transformation controller selects whether to perform the affine transformation f1 or the affine transformation f2: If the signal of the affine transformation controller is 1, the group L′x is subjected to the affine transformation f1, and the group R′x is subjected to the affine transformation f2; if it is 0, the group L′x is subjected to the affine transformation f2, and the group R′x is subjected to the affine transformation f1; of course, the opposite is also true for the affine transformation controller.

[0062] Finally, the non - linear transformation controller selects whether to perform the non - linear transformation Nl1(x) or Nl2(x): If the result of the non - linear transformation controller is 1, the result of the affine transformation f1(x) is subjected to the non - linear transformation Nl1(x), and the result of the affine transformation f2(x) is subjected to the non - linear transformation Nl2(x); if it is 0, it is the opposite, and the sequences LY and RY (transformation sequences) are output respectively.

[0063] Step S5, in the decryption mode, the specific operation process is as follows:

[0064] First, determine the non - linear inverse transformation according to the non - linear inverse transformation controller Or If the result of the non - linear transformation controller is 1, perform non - linear inverse transformation on the packet Lx segmented by the splitter Perform non - linear inverse transformation on the packet Rx If the control signal is 0, perform non - linear inverse transformation on the packet Lx Perform non - linear inverse transformation on the packet Rx

[0065] Then, select the affine inverse transformation f1 according to the affine inverse transformation controller -1 Or If the affine transform signal is 1, perform affine inverse transformation on the result of the non - linear inverse transformation by f1 -1 , for the result of the non - linear inverse transformation perform affine inverse transformation If it is 0, do the opposite;

[0066] Finally, perform multiplicative inverse transformation over the finite field GF(2 -1 and the result of the affine inverse transformation ) on the results of the affine inverse transformation f1 and the affine inverse transformation respectively through the multiplicative inverse element transformers over the finite field GF(2 4 ), and obtain the output sequences LY and RY respectively. 4 )

[0067] Step S6: Connect the sequences output in step S4 or step S5 through a connector to obtain the information output Y and send it to the information memory for storage.

[0068] In this embodiment, the encryption mode is adopted. The value of the affine transformation controller is 1, and the value of the non - linear transformation controller is 1. That is, Lx undergoes the affine transformation f1(x), and Rx undergoes the affine transformation f2(x). Their corresponding results then respectively undergo the non - linear transformations Nl1(x) and Nl2(x). Finally, by traversing all the corresponding S - box can be obtained:

[0069] Table 1 Correspondence table of input - output of S - box

[0070]

[0071]

[0072] In Table 1, the row represents the hexadecimal number corresponding to the first four bits of the 8 - bit input information, and the column represents the hexadecimal number corresponding to the last four bits of the 8 - bit input information.

[0073] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

[0074] The above are only some embodiments of the present invention. For those of ordinary skill in the art, without departing from the creative concept of the present invention, several deformations and improvements can still be made, and these all belong to the protection scope of the present invention.

Claims

1. A method for generating an S-box with high non-linearity, characterized in that, It includes the following steps: Step 1, the control signal register receives and stores the processing commands for encryption and decryption, and the information memory receives and stores the information X to be processed; wherein, the length of the information X is 8 bits; Step 2, the splitter reads the information X from the information memory and splits it into two 4-bit groups Lx and Rx on the left and right; Step 3, the encryption and decryption controller reads the processing commands in the control signal register. If it is in the encryption mode, step 4 is executed; if it is in the decryption mode, step 5 is executed; Step 4, perform the arithmetic processing in the encryption mode: Through the multiplicative inverse transformers in the finite field GF(2 4 ), perform multiplicative inverse transforms on the 4-bit groups Lx and Rx respectively segmented by the segmenter to obtain the groups L'x and R'x after the multiplicative inverse transform; Then, the affine transformation controller selects the affine transformation f1 or f2: if the control signal of the affine transformation controller is 1, perform the affine transformation f1 on the group L′x and the affine transformation f2 on the group R′x; if the control signal of the affine transformation controller is 0, it is the opposite; The non-linear transformation controller selects the non-linear transformation Nl1(x) or Nl2(x): if the control signal of the non-linear transformation controller is 1, perform the non-linear transformation Nl1(x) on the result of the affine transformation f1(x) and the non-linear transformation Nl2(x) on the result of the affine transformation f2(x); if the control signal of the non-linear transformation controller is 0, it is the opposite; Based on the outputs of the linear transformations Nl1(x) and Nl2(x), obtain the output sequences LY and RY, that is, the transformation sequences; Step 5, perform the arithmetic processing in the decryption mode: Judging the non - linear inverse transformation according to the non - linear inverse transformation controller Or If the control signal of the non - linear transformation controller is 1, perform a non - linear inverse transformation on the packet Lx segmented by the splitter Perform a non - linear inverse transformation on the packet Rx If the control signal of the non - linear transformation controller is 0, vice versa; Then, an affine inverse transformation controller is used to select the affine inverse transformation f1 -1 or If the control signal of the affine converter is 1, then the affine inverse transformation is performed on the result of the non-linear inverse transformation f1 -1 , and the affine inverse transformation is performed on the result of the non-linear inverse transformation ; if the control signal of the affine converter is 0, then the opposite is true ​ Apply the affine inverse transformation f1 -1 and the affine inverse transformation respectively pass the results through a multiplicative inverse transformer in the finite field GF(2 4 ) to perform a multiplicative inverse transformation over the finite field GF(2 4 ), obtaining the output sequences LY and RY; Step 6, connect the sequences output in step 4 or step 5 through a connector to obtain the information output Y and send it to the information memory for storage; Among them, the non-linear transformations Nl1(x) and Nl2(x) are as follows: Set the value of parameter s. Different values of parameter s correspond to different non-linear transformations. Based on two different values of parameter s, the non-linear transformation Nl1(x) and the non-linear transformation Nl2(x) are obtained respectively. Among them, the value range of parameter s is: 0 ≤ s ≤ 2 n -2.

2. The method according to claim 1, wherein Finite field GF(2 4 ) The multiplicative inverse converter stores 16 bytes of inverse element data of the finite field GF(2 4 ). The byte data is obtained by taking the inverse of 16 data on the finite field GF(2 4 ) with m(x) = x 4 + x + 1 as the irreducible polynomial for 16 data.

3. The method according to claim 1, characterized in that, In step 4, when performing the arithmetic processing in the encryption mode, the inverse affine transformations f1(x) and f2(x), and the non-linear transformations Nl1(x) and Nl2(x) are respectively set as: The non-linear transformation Nl1(x) = (nl 10 (x), nl 11 (x), nl 12 (x), nl 13 (x)) includes four branches, and each branch is respectively: The non-linear transformation Nl2(x) = (nl 20 (x), nl 21 (x), nl 22 (x), nl 23 (x)) includes four branches, and each branch is respectively: wherein, x0, x1, x2, x3 respectively represent the bits corresponding to the input information X.

4. The method according to claim 1, wherein In step 5, when performing the decryption mode operation process, the affine inverse transformation f1 -1 (x) and and the non-linear inverse transformation and are respectively set to: Among them, the inverse transformation of the non-linear transformation includes four branches, and each branch is respectively: Inverse transformation of non-linear transformation It includes four branches, and each branch is respectively: wherein, x0, x1, x2, x3 respectively represent the bits corresponding to the input information X.