A white box SM4 cryptographic algorithm construction method and device supporting anti-tampering of lookup table

By using the SM3 algorithm in the white boxed SM4 algorithm for data integrity verification of the lookup table, the problem that the lookup table is easily stolen and tampered in the white box environment is solved, and effective protection of key information and the security of the white box algorithm are achieved.

CN115996113BActive Publication Date: 2025-05-06BEIJING ELECTRONICS SCI & TECH INST
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211695716.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-28
Publication Date
2025-05-06
Estimated Expiration
2042-12-28

AI Technical Summary

Technical Problem

In a white box environment, lookup tables are easily stolen and tampered during storage and transmission, resulting in the leakage or tampering of key information, affecting the security of the white box SM4 algorithm.

Method used

The SM3 algorithm is used to verify data integrity. By generating a 256-bit digest value, it is used to determine whether the lookup table has been tampered with, and the lookup table is repeatedly checked during the encryption and decryption process to ensure data integrity.

Benefits of technology

Effectively prevent the key information in the lookup table from being stolen and tampered, enhance the security of the white-boxed SM4 algorithm, ensure the confidentiality and integrity of the key information, and do not affect the algorithm's encryption and decryption operation efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115996113B_ABST
    Figure CN115996113B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for constructing a white-box SM4 cryptographic algorithm that supports anti-tampering of a lookup table. The method white-boxes the domestic block cipher algorithm SM4 with a new lookup table technology, and uses the domestic cryptographic algorithm SM3 to perform integrity verification of the lookup table data to prevent tampering. On the one hand, the present invention improves the overall security of the algorithm by combining two secure cryptographic algorithms; on the other hand, although the lookup table of the white-box cryptography can hide key information, it may face the risk of being tampered with by an adversary during storage and transmission. If the adversary obtains the lookup table and cracks the key information, and then produces a counterfeit lookup table by tampering with key data, it may affect the subsequent encryption and decryption operation process. The present invention can effectively ensure the integrity of the lookup table by checking the integrity of the lookup table data, thereby broadening the application field of white-box cryptography.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security and cryptographic technology, and specifically designs a white box SM4 cryptographic algorithm construction method and device that supports anti-tampering of lookup tables, which can meet the security requirements of the white box environment and have high efficiency. Background Art

[0002] Patent document 1 (publication number: CN113111317A, publication date: July 13, 2021) discloses a software tampering detection method based on the white-box CLEFIA encryption method. By setting the black-box encryption parameters, three types of lookup tables are constructed to update the white-box encryption method to determine whether the software to be detected has been tampered with. This method takes into account the scope of use of white-box cryptographic algorithms in software tamper prevention and has achieved good results.

[0003] Patent document 2 (publication number: CN111741374B, publication date: October 21, 2022) discloses a method, device, electronic device, storage medium and server for obtaining a white-box lookup table. The invention obtains the key-related part of the white-box lookup table through the server, and then sends the key-related part to the client, and then instructs the client to generate a white-box lookup table based on the key-related part and the key-irrelevant part. The amount of data in the white-box lookup table sent to the client can be reduced, thereby saving network resources.

[0004] Through the analysis of the above documents, it can be known that the current block cipher algorithm white-box lookup table technology structure is based on the input-output mapping relationship of the algorithm to confuse and hide the key information in the lookup table. Although white-box cryptography technology can be applied to multiple fields, its lookup table is inevitably at risk of being stolen during storage and transmission, so it is necessary to ensure its data integrity. The present invention uses the SM3 algorithm to verify the data integrity of the lookup table, and can judge whether the lookup table has been tampered with by comparing the 256-bit summary value. On the basis of protecting the key information in the lookup table, it can prevent the information from being tampered with after the lookup table is stolen, thereby enhancing the security of the overall white-box SM4 algorithm, making the SM4 algorithm more confidential, protecting the key information from being leaked to a large extent, and ensuring that the key information therein is not tampered with, and does not affect the overall encryption and decryption operation efficiency of the algorithm and the output result of the original algorithm. Summary of the invention

[0005] The present invention designs a white box SM4 cryptographic algorithm construction method and device that supports anti-tampering of lookup tables. The data integrity verification technology of the SM3 algorithm is combined in the design to prevent key information of the lookup table from being tampered with.

[0006] The technical solution of the present invention is as follows:

[0007] A white box SM4 cryptographic algorithm construction method and device supporting anti-tampering of lookup tables, the encryption steps are as follows:

[0008] Step S1: SM4 block cipher algorithm round function encryption process. Before encryption, the plaintext data is preprocessed, and the 128-bit plaintext data is split into 4 groups of data by bit, each group is 32 bits long, that is, X = (X0, X1, X2, X3); part of the plaintext data and the key rk i XOR is performed and the result is used as the input data of the S box, that is, S in =X i+1 ⊕X i+2 ⊕X i+3 ⊕rk i The 4 8-bit data after the 32-bit data is split enters 4 S-boxes for operation respectively. The output data of the 4 S-boxes after the operation are combined into 32-bit data S out ; S out Perform multiple circular shifts and then XOR, and we get

[0009] X i+4 =S out ⊕(S out <<<2)⊕(S out <<<10)⊕(S out <<<18)⊕(S out <<<24)⊕X i ;

[0010] Step S2: The key generation method is similar to round function encryption. First, the master key Mk = (K0, K1, K2, K3) is still 128-bit data. The 4 groups of 32-bit data after splitting are XORed with system parameters FK0, FK1, FK2, FK3, respectively.

[0011] k0=K0⊕FK0;k1=K1⊕FK1;k2=K2⊕FK2;k3=K3⊕FK3;the obtained k0-k3 is used to generate the subsequent round of keys. in =k i+1 ⊕k i+2 ⊕k i+3 ⊕ck i , the 4 8-bit data after the 32-bit data is split enters 4 S-boxes respectively for operation, and the output data of the 4 S-boxes after the operation are combined into 32-bit data S out ; S out Perform 2 circular shifts and then XOR, and we get

[0012] rk i =k i+4 =S out ⊕(S out <<<13)⊕(S out <<<23)⊕ki ;

[0013] where ck i Different in each round, with fixed parameters, i = 0, 1, 2, ..., 31;

[0014] Step S3: The input and output of each round of the SM4 algorithm are converted into a lookup table using a new lookup table theory to protect and hide the key information so that it cannot be obtained by the adversary;

[0015] Step S4: Use the SM3 algorithm to iterate the data of the expanded lookup table to generate a summary value, calculate again before looking up the table, and compare the two summary values. If they are consistent, it means that the lookup table data has not been tampered with.

[0016] A white box SM4 cryptographic algorithm construction method and device supporting anti-tampering of the lookup table, using the SM3 algorithm to perform integrity verification of the lookup table as follows:

[0017] Step S1: The lookup table T generated in the 16th and 32nd rounds A Expand the data, convert it into binary data in row and column order, and then use the padding step of the SM3 algorithm, with each data group being 512 bits;

[0018] Step S2: grouping the expanded bit string and then performing an iterative data compression process, wherein the compression function includes a message extension part and a status update part;

[0019] Step S3: Lookup table T A After multiple rounds of data compression iterations, the data generates a hash value (digest) of the SM3 algorithm. The hash value is 256 bits and can be made public together with the lookup table.

[0020] Step S4: Before the table lookup operation in the subsequent encryption and decryption process, the corresponding lookup table is first expanded according to the method in step S1, and then the SM3 algorithm is used to generate a summary value. The summary values ​​generated twice by the same lookup table are compared to see if they are the same. If they are the same, it means that the lookup table data has not been tampered with.

[0021] A method and device for constructing a white-box SM4 cryptographic algorithm that supports anti-tampering of a lookup table. The steps for making the lookup table are as follows:

[0022] Step S1: X in the SM4 algorithm encryption process i+4 The partial XOR and linear cyclic shift operations in the generation step are made into a lookup table T A With the lookup table T B ,The two types of lookup tables are respectively used to query the mapping values ​​of operations such as linear transformation, which can fully obfuscate the specific key information into the lookup table;

[0023] Step S2: At the output position of the round function of each round, the internal state of the output data is first obfuscated using a reversible affine transformation. The obfuscation method is a 32-order reversible transformation matrix. The transformed data and all possible input and output values ​​are made into a lookup table;

[0024] Step S3: Before the next round of iteration begins, a table lookup operation is performed to obtain the corresponding input value, and then the data is restored through the inverse transformation of the previous round of reversible affine transformation to enter the next round of iteration.

[0025] Compared with the prior art, the present invention has the following beneficial effects:

[0026] First, the original SM4 block cipher algorithm is white-boxed, which improves its applicability in white-box attack environments and enhances overall security performance.

[0027] Second, the constructed lookup table can be verified by generating a summary value using the SM3 algorithm, which prevents the hidden key information in the lookup table from being stolen and tampered with, and effectively protects the integrity of the lookup table data in a public environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 It is the overall encryption and decryption flow chart of the method proposed in the present invention;

[0029] Figure 2 It is the encryption structure diagram of SM4 algorithm;

[0030] Figure 3 It is a schematic diagram of the SM3 algorithm verifying the lookup table;

[0031] Figure 4 This is a flow chart of making a white-box lookup table according to the method proposed in the present invention. DETAILED DESCRIPTION

[0032] The implementation process of the present invention is further described below with reference to the accompanying drawings and examples, but the application scope of the present invention is not limited in any way.

[0033] Reference Figure 1 and Figure 2 , the implementation ideas of the present invention are further described.

[0034] Step S1: SM4 block cipher algorithm round function encryption process. Before encryption, the plaintext data is preprocessed, and the 128-bit plaintext data is split into 4 groups of data by bit, each group is 32 bits long, that is, X = (X0, X1, X2, X3); part of the plaintext data and the key rk i XOR is performed and the result is used as the input data of the S box, that is, S in =X i+1 ⊕X i+2 ⊕Xi+3 ⊕rk i The 4 8-bit data after the 32-bit data is split enters 4 S-boxes for operation respectively. The output data of the 4 S-boxes after the operation are combined into 32-bit data S out ; S out Perform multiple circular shifts and then XOR, and we get

[0035] X i+4 =S out ⊕(S out <<<2)⊕(S out <<<10)⊕(S out <<<18)⊕(S out <<<24)⊕X i ;

[0036] Step S2: The key generation method is similar to round function encryption. First, the master key Mk = (K0, K1, K2, K3) is still 128-bit data. The 4 groups of 32-bit data after splitting are XORed with system parameters FK0, FK1, FK2, FK3, respectively.

[0037] k0=K0⊕FK0;k1=K1⊕FK1;k2=K2⊕FK2;k3=K3⊕FK3;the obtained k0-k3 is used to generate the subsequent round of keys. in =k i+1 ⊕k i+2 ⊕k i+3 ⊕ck i , the 4 8-bit data after the 32-bit data is split enters 4 S-boxes respectively for operation, and the output data of the 4 S-boxes after the operation are combined into 32-bit data S out ; S out Perform 2 circular shifts and then XOR, and we get

[0038] rk i =k i+4 =S out ⊕(S out <<<13)⊕(S out <<<23)⊕k i ;

[0039] where ck i Different in each round, with fixed parameters, i = 0, 1, 2, ..., 31;

[0040] Step S3: The input and output of each round of the SM4 algorithm are converted into a lookup table using a new lookup table theory to protect and hide the key information so that it cannot be obtained by the adversary;

[0041] Step S4: Use the SM3 algorithm to iterate the data of the expanded lookup table to generate a summary value, calculate again before looking up the table, and compare the two summary values. If they are consistent, it means that the lookup table data has not been tampered with.

[0042] Reference Figure 3 , the implementation idea of ​​the present invention is further described, and the steps of applying the SM3 algorithm to perform integrity check of the lookup table are as follows:

[0043] Step S1: The lookup table T generated in the 16th and 32nd rounds A Expand the data, convert it into binary data in row and column order, and then use the padding step of the SM3 algorithm, with each data group being 512 bits;

[0044] Step S2: grouping the expanded bit string and then performing an iterative data compression process, wherein the compression function includes a message extension part and a status update part;

[0045] Step S3: Lookup table T A After multiple rounds of data compression iterations, the data generates a hash value (digest) of the SM3 algorithm. The hash value is 256 bits and can be made public together with the lookup table.

[0046] Step S4: Before the table lookup operation in the subsequent encryption and decryption process, the corresponding lookup table is first expanded according to the method in step S1, and then the SM3 algorithm is used to generate a summary value. The summary values ​​generated twice by the same lookup table are compared to see if they are the same. If they are the same, it means that the lookup table data has not been tampered with.

[0047] Reference Figure 4 , the implementation ideas of the present invention are further described.

[0048] Step S1: X in the SM4 algorithm encryption process i+4 The partial XOR and linear cyclic shift operations in the generation step are made into a lookup table T A With the lookup table T B ,The two types of lookup tables are respectively used to query the mapping values ​​of operations such as linear transformation, which can fully obfuscate the specific key information into the lookup table;

[0049] Step S2: At the output position of the round function of each round, the internal state of the output data is first obfuscated using a reversible affine transformation. The obfuscation method is a 32-order reversible transformation matrix. The transformed data and all possible input and output values ​​are made into a lookup table;

[0050] Step S3: Before the next round of iteration begins, a table lookup operation is performed to obtain the corresponding input value, and then the data is restored through the inverse transformation of the previous round of reversible affine transformation to enter the next round of iteration.

[0051] The above description in combination with the pictures is a specific example of the present invention and does not constitute any limitation to the present invention. After understanding the technical principle of the present invention, professionals in this field may make deformation or improvement on the method proposed in the present invention in details or form, which still fall within the scope of protection of the present invention.

Claims

1. A method for constructing a white-box SM4 cryptographic algorithm that supports tamper-proof lookup tables, characterized in that: The encryption steps are as follows: Step S1: SM4 block cipher algorithm round function encryption process, before encryption, the plaintext data is preprocessed, the 128-bit plaintext data is split into 4 groups of data by bit, each group is 32 bits long, that is, X = (X0, X1, X2, X3); part of the plaintext data and the key rk i XOR is performed and the result is used as the input data of the S box, that is, The 4 8-bit data after the 32-bit data is split enters 4 S-boxes for operation respectively. The output data of the 4 S-boxes after the operation are combined into 32-bit data S out1 ; S out1 Perform multiple circular shifts and then XOR, and we get Step S2: The key generation method is similar to round function encryption. First, the master key Mk = (K0, K1, K2, K3) is still 128-bit data. The 4 groups of 32-bit data after splitting are XORed with system parameters FK0, FK1, FK2, FK3, respectively. The obtained k0-k3 is used to generate the keys for the subsequent rounds. The 4 8-bit data after the 32-bit data is split enters 4 S-boxes for operation respectively. The output data of the 4 S-boxes after the operation are combined into 32-bit data S out2 ; S out2 Perform 2 circular shifts and then XOR, and we get where ck i Different in each round, with fixed parameters, i = 0, 1, 2, ..., 31; Step S3: Each round of input and output of the SM4 algorithm is converted into a lookup table using a new lookup table theory to protect and hide the key information so that it cannot be obtained by the adversary. The steps for making the lookup table are as follows: Step S31: X in the SM4 algorithm encryption process i+4 The partial XOR and linear cyclic shift operations in the generation step are made into a lookup table T A With the lookup table T B ,The two types of lookup tables are respectively used to query the mapping values ​​of the linear transformation operation, which can fully obfuscate the specific key information into the lookup table; Step S32: At the output position of the round function of each round, the internal state of the output data is first obfuscated using a reversible affine transformation, and the obfuscation method is a 32-order reversible transformation matrix. The transformed data and all possible input and output values ​​are made into a lookup table; Step S33: before the next round of iteration begins, a table lookup operation is performed to obtain the corresponding input value, and then the data is restored by the inverse transformation of the previous round of reversible affine transformation to enter the next round of iteration; Step S4: Use the SM3 algorithm to iterate the data of the expanded lookup table, generate a summary value, calculate again before looking up the table, and compare the two summary values. If they are consistent, it means that the lookup table data has not been tampered with; the steps of using the SM3 algorithm to perform integrity verification on the lookup table are as follows: Step S41: The lookup table T generated in the 16th and 32nd rounds A Expand the data, convert it into binary data in row and column order, and then use the padding step of the SM3 algorithm, with each data group being 512 bits; Step S42: grouping the expanded bit string and then performing a data iterative compression process, wherein the compression function includes a message extension part and a status update part; Step S43: Lookup table T A After multiple rounds of data compression iterations, the data generates a summary value of the SM3 algorithm. The summary value is 256 bits and can be made public together with the lookup table. Step S44: Before the table lookup operation in the subsequent encryption and decryption process, the corresponding lookup table is first expanded according to the method in step S41, and then the summary value is generated using the SM3 algorithm. The summary values ​​generated twice from the same lookup table are compared to see if they are the same. If they are the same, it means that the lookup table data has not been tampered with.

Citation Information

Patent Citations

  • Methods, devices, electronic equipment, storage media, and servers for obtaining white-box lookup tables

    CN111741374B

  • Software tampering detection method based on white box CLEFIA encryption method

    CN113111317A

  • Dynamic white box library generation and use method suitable for block cipher white box

    CN111800255A

  • Implementation method of SM4-GCM network encryption transmission system based on FPGA

    CN112769551A