Encryption methods and devices

By recovering the initial key through differential fault attacks and impossible differential paths, and updating the key arrangement algorithm to generate a second key, the security of lightweight encryption algorithms in edge computing scenarios is solved, thereby improving the security of encryption algorithms.

CN116015611BActive Publication Date: 2026-05-26LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LENOVO (BEIJING) LTD
Filing Date
2022-12-19
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing lightweight block cipher algorithms have insufficient security in edge computing scenarios, especially under differential fault attacks, making it difficult to effectively improve the security of encryption algorithms.

Method used

The final key is obtained through a differential fault attack, and the initial key is recovered using an impossible differential path. The original key arrangement algorithm is then updated to generate a second key, thereby enhancing the security of the encryption algorithm.

Benefits of technology

It improves the security of encryption algorithms under differential fault attacks, enhances the protection of multi-round keys, and reduces the risk of key arrangement algorithms being cracked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015611B_ABST
    Figure CN116015611B_ABST
Patent Text Reader

Abstract

This application discloses an encryption method and apparatus. The method includes: obtaining data to be encrypted and a first key; wherein the first key is obtained through a primitive key arrangement algorithm; if the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and a constructed impossible differential path, then the primitive key arrangement algorithm is updated; based on the initial key and the updated primitive key arrangement algorithm, a second key is determined; and the data to be encrypted is encrypted using the second key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security technology, and includes, but is not limited to, an encryption method and apparatus. Background Technology

[0002] Existing lightweight block cipher algorithms all use Advanced Encryption Standard (AES) as a reference or as a variant of AES. Wireless transmission protocols, including WiFi (a wireless network communication technology), Bluetooth, and Zigbee (a low-speed, short-range wireless network protocol), also use AES (Advanced Encryption Standard) as their built-in encryption algorithm. Therefore, researching advanced encryption standards is of great significance for improving data security and efficiency in edge computing scenarios. Summary of the Invention

[0003] In view of this, embodiments of this application provide an encryption method and apparatus.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] In a first aspect, embodiments of this application provide an encryption method, the method comprising:

[0006] Obtain the data to be encrypted and the first key; wherein the first key is obtained through the original key arrangement algorithm;

[0007] If the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and the constructed impossible differential path, then the original key arrangement algorithm is updated.

[0008] Based on the initial key and the updated original key arrangement algorithm, the second key is determined;

[0009] The data to be encrypted is encrypted using the second key.

[0010] Secondly, embodiments of this application provide an encryption device, the device comprising:

[0011] An acquisition unit is used to obtain the data to be encrypted and a first key; wherein the first key is obtained through a raw key arrangement algorithm;

[0012] The update unit is configured to update the original key arrangement algorithm if the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and the constructed impossible differential path.

[0013] The determining unit is used to determine the second key based on the initial key and the updated original key arrangement algorithm;

[0014] An encryption unit is used to encrypt the data to be encrypted using the second key.

[0015] This application provides an encryption method and apparatus, which obtains data to be encrypted and a first key; wherein the first key is obtained through an original key arrangement algorithm; if the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and an impossible differential path is constructed, then the original key arrangement algorithm is updated; based on the initial key and the updated original key arrangement algorithm, a second key is determined; and the data to be encrypted is encrypted using the second key, thereby improving the security of the encryption algorithm. Attached Figure Description

[0016] Figure 1 This is a schematic diagram illustrating the implementation process of the encryption method in the embodiments of this application. Figure 1 ;

[0017] Figure 2 This is a schematic diagram illustrating the implementation process of the encryption method in the embodiments of this application. Figure 2 ;

[0018] Figure 3A This is a schematic diagram of an impossible differential path in six rounds according to an embodiment of this application;

[0019] Figure 3B This is a schematic diagram of the system architecture corresponding to the encryption and decryption methods in the embodiments of this application;

[0020] Figure 4 This is a schematic diagram of the composition structure of the encryption device according to an embodiment of this application;

[0021] Figure 5 This is a schematic diagram of a hardware entity of an encryption device according to an embodiment of this application. Detailed Implementation

[0022] The technical solutions of this application will be further described in detail below with reference to the accompanying drawings and embodiments. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0023] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0024] In the following description, the use of suffixes such as "module," "part," or "unit" to denote elements is solely for the purpose of illustration and has no specific meaning in itself. Therefore, "module," "part," or "unit" may be used interchangeably.

[0025] It should be noted that the terms "first, second, and third" used in the embodiments of this application are merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, and third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0026] Based on this, this application provides an encryption method. The function implemented by this method can be achieved by the processor in the encryption device calling program code. Of course, the program code can be stored in the storage medium of the encryption device. Figure 1 This is a schematic diagram illustrating the implementation process of the encryption method in the embodiments of this application. Figure 1 ,like Figure 1 As shown, the method includes:

[0027] Step S101: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0028] Here, the encryption device can be any type of device with information processing capabilities, such as a navigator, smartphone, tablet, wearable device, laptop, robot vacuum cleaner, smart kitchen and bathroom, smart home, car, server or server cluster, etc.

[0029] The encryption method in this application embodiment can be applied to some advanced encryption standards, such as the AES encryption standard. The encryption method uses a multi-round key, for example, the key corresponding to the AES encryption algorithm. AES encryption is a block cipher, meaning the plaintext is divided into blocks of equal length, and each block is encrypted sequentially until the entire plaintext is encrypted. In the AES standard specification, the block length can only be 128 bits, that is, each block is 16 bytes (each byte is 8 bits). The key length can be 128 bits, 192 bits, or 256 bits. Different key lengths recommend different numbers of encryption rounds. Specifically, AES-128 has a 128-bit key length and 10 encryption rounds. That is, a plaintext block will be encrypted 10 times. Where w[0], w[1], w[2], w[3] are the original keys. Through the key arrangement function, the original keys are expanded into a sequence of 44 words w[0], w[1], ..., w

[43] . This sequence of 44 words is the multi-round key in AES-128. The original keys w[0], w[1], w[2], w[3] are used for the initial key addition in the encryption operation. The following 40 words are divided into 10 groups, and each group of 4 words (128 bits) of round key is used for the round key addition in 10 rounds of encryption operation.

[0030] In other words, the first key is a multi-round key, and it is obtained through a primitive key arrangement algorithm. Here, the primitive key arrangement algorithm refers to existing key arrangement algorithms. For example, if the encryption algorithm is AES-128, the primitive key arrangement algorithm is: if i is not a multiple of 4, then the i-th column is obtained using the formula... Determined; if i is a multiple of 4, then the i-th column is determined by the formula. Confirmed. Here, T is a function consisting of three parts: word loop, byte substitution, and round constant XOR.

[0031] Here, the data to be encrypted can be any type of data, or a file, etc.

[0032] Step S102: If the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and the constructed impossible differential path, then update the original key arrangement algorithm.

[0033] Here, IDA (Impossible Differential Attack) is a variant of differential analysis, which is more effective for low-round encryption algorithms (such as AES-128 with 10 rounds of encryption) and can be used to filter out erroneous keys. However, the huge sample size required for impossible differential analysis limits the physical conditions required to implement this attack. DFA (Differential Fault Attack) is one of the techniques for launching block cipher attacks by inducing computational errors. The attacker's goal is usually to recover the key information of the last round or the last two rounds. By guessing part of the key information of the last round, the attacker calculates the difference between the correct and erroneous ciphertext information. A key discriminator generated by the fault model distinguishes whether the guessed key information is correct, and then uses exhaustive key search to recover the master key of the encryption algorithm. However, under certain assumptions, this method can only recover the last round key. If it is assumed that the details of the key arrangement algorithm are not visible, the master key cannot be obtained. Therefore, this application proposes an impossible differential fault attack method that integrates IDA and DFA technologies. The DFA attack method is used to compensate for the large sample size problem of IDA. The IDA attack method allows the implementation details of the key arrangement algorithm to be ignored when performing DFA analysis, thereby making it easier to obtain the complete multi-round keys and threatening the security of encrypted data.

[0034] Thus, after obtaining the initial key using the impossible differential fault attack, the original key arrangement algorithm needs to be updated so that the multi-round keys determined by the updated original key arrangement algorithm cannot be easily cracked, thereby improving the security of encryption.

[0035] In other words, the process of an impossible differential fault attack is as follows: first, the final key of the multi-round key is obtained through a differential fault attack; then, the initial key of the multi-round key is obtained through the final key and the constructed impossible differential path. If the initial key of the multi-round key is obtained based on the impossible differential fault attack (and the attacker can then obtain the complete multi-round key based on the initial key and the key arrangement algorithm), it indicates that the original key arrangement algorithm has a defect and needs to be updated.

[0036] Step S103: Determine the second key based on the initial key and the updated original key arrangement algorithm;

[0037] In this embodiment, the initial key can be expanded based on the updated original key arrangement algorithm to obtain the second key; wherein the second key cannot be obtained through the aforementioned impossible differential fault attack. For example, for the AES-128 encryption algorithm, the initial key w[0], w[1], w[2], w[3] can be expanded by the updated original key arrangement algorithm into a sequence of 44 words w[0], w[1], ..., w

[43] , which is the second key corresponding to the AES-128 encryption algorithm.

[0038] Step S104: Encrypt the data to be encrypted using the second key.

[0039] In this embodiment of the application, an enhanced encryption key (i.e., a second key) can be obtained based on the updated original key arrangement algorithm, and then the enhanced encryption key can be used to encrypt the data to be encrypted.

[0040] Here, through the above steps S101 to S104, an enhanced encryption key can be provided even when the first key is obtained using an impossible differential fault attack, thereby improving the security of the encryption algorithm.

[0041] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device, and the method includes:

[0042] Step S111: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0043] Step S112: Construct an impossible differential path;

[0044] In this embodiment, an impossible differential distinguisher can be selected, and then an impossible differential path can be constructed using this impossible differential distinguisher. Furthermore, input plaintext-ciphertext pairs with specific differential values ​​are selected. According to the impossible differential path, the output differential values ​​of these plaintext-ciphertext pairs do not satisfy specific conditions, thereby eliminating erroneous keys.

[0045] Step S113: Based on the impossible differential path, determine multiple plaintext pairs from several plaintexts;

[0046] For example, you can choose 2. 49 Each plaintext group is traversed by the 8 bytes at positions (1,3,4,6,9,11,12,14). The remaining bytes are fixed constants, with each plaintext group having 2 bytes. 64 There are 2 in total. 127 The plaintext is correct.

[0047] Step S114: Encrypt the multiple plaintext pairs based on the first key to obtain multiple first ciphertext pairs;

[0048] For example, select 2 49 Each plaintext group is traversed by the 8 bytes at positions (1,3,4,6,9,11,12,14). The remaining bytes are fixed constants, with each plaintext group having 2 bytes. 64 There are 2 in total. 127 Plaintext pair, pair 2 49 After 6 rounds of encryption, the plaintext structure can be obtained as 2 127+49 Encrypt all plaintext pairs to obtain the corresponding ciphertext pairs.

[0049] Step S115: Perform a differential fault attack on the encryption process to obtain multiple erroneous final round keys;

[0050] In this embodiment, a single-byte random fault can be injected into a byte in the penultimate round to obtain multiple erroneous final round keys. For example, a random single-byte fault can be injected into the column obfuscation input in the (r-1)th round of an impossible differential path in round r. The corresponding bytes of the round keys in the last round on the impossible differential path can be filtered out by differential fault injection, and these filtered-out last round keys can be added to a filtering list.

[0051] Step S116: If the multiple sets of first ciphertext pairs are processed based on the impossible differential path and the multiple erroneous final round keys to obtain the initial key of the first key, then the original key arrangement algorithm is updated.

[0052] In this embodiment of the application, if the ciphertext satisfies that the differential value after decryption of all erroneous keys in the elimination list is not on an impossible differential path, the erroneous key that satisfies this condition is called a completely wrong key. Then, the guessed key value corresponding to the input differential value of the plaintext that satisfies an impossible differential path in the first round of encryption is simultaneously eliminated. By combining the two differentials, the candidate space of the round keys required by the guessing algorithm can be greatly reduced, so that the initial key of the first key can be obtained more easily.

[0053] Step S117: Determine the second key based on the initial key and the updated original key arrangement algorithm;

[0054] Step S118: Encrypt the data to be encrypted using the second key.

[0055] Here, through the above steps S111 to S118, the key candidate space of the round keys required by the impossible differential attack algorithm can be greatly reduced. The erroneous key candidate space of the first two rounds can be directly eliminated by the last round key until the master key is found. It is not necessary to derive the intermediate round keys sequentially according to the key arrangement algorithm. This means that the key arrangement algorithm is designed so that the round key arrangement in the middle position fails, thereby obtaining the encryption key. In this way, the encryption key arrangement algorithm can be improved to enhance the security of the encryption algorithm.

[0056] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device, and the method includes:

[0057] Step S121: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0058] Step S122: Construct an impossible differential path;

[0059] Step S123: Based on the impossible differential path, determine multiple plaintext pairs from several plaintexts;

[0060] Step S124: Encrypt the multiple plaintext pairs based on the first key to obtain multiple first ciphertext pairs;

[0061] For example, it is possible to use 2 49 After 6 rounds of encryption, the plaintext structure can be obtained as 2 127+49 Given a set of plaintext pairs, encrypt all plaintext pairs to obtain corresponding ciphertext pairs, i.e., multiple sets of first ciphertext pairs. Select ciphertext pairs that satisfy the difference ΔC in ΔC3, ΔC6, ΔC9, ΔC... 12 Ciphertext pairs with a non-zero difference value but zero difference values ​​at other byte positions have a filtering probability of 2. -96 Leave behind the corresponding plaintext and ciphertext pairs, totaling approximately 2 80 right.

[0062] Step S125: Determine the final round key from multiple guesses;

[0063] For example, for a 6-round impossible differential path, let the four distinct positions (0,7,10,13), (1,4,11,14), (2,5,8,15), and (3,6,9,12) in each column of the ciphertext pair be i,j,k,l. Then, guess the values ​​of the bytes at positions i,j,k,l of the round key k6 in the 6th round. The guessed values ​​of the bytes at positions i, j, k, l of the round key k6 in round 6. That is, the guessed key for the final round.

[0064] Step S126: Perform single-byte fault injection on the encryption process to obtain multiple possible differential values ​​corresponding to the fault injection;

[0065] Here, if it is a 6-round impossible differential path, a single-byte random fault δ can be injected into a byte after the column obfuscation input in the 5th round of the encryption process with a preset number of iterations. This fault, after being obfuscated, spreads to 4 bytes and participates in the final round of encryption along with the round key of that round. Then, a list θ of all possible differential values ​​of a column output is calculated when only one byte of the column obfuscation input is injected with a random single-byte fault. This list contains a total of 1020 four-byte elements.

[0066] Among them, the multiple possible difference values ​​are difference values ​​of an intermediate state. That is, if the injected fault is random, then the difference value between this random fault and the intermediate state is obtained. These multiple possible difference values ​​are obtained based on the principle of column-mixed calculation.

[0067] Step S127: Match the multiple guessed final round keys with the multiple possible difference values ​​to obtain multiple incorrect final round keys;

[0068] Here, the final round key can be directly calculated through a differential fault attack. The erroneous final round key described in this embodiment refers to the erroneous final round key whose corresponding bytes can be determined through the properties of differentials, and thus the round keys of other rounds can be excluded through the erroneous bytes. Based on this principle, the essence of enhancing the security of the final round key is to change the original differential characteristics.

[0069] For example, after injecting a single-byte random fault, the preset group fault ciphertext C is obtained. * The ciphertext pair (C,C) consisting of the correct ciphertext C and the correct ciphertext C * At this point, the following formula can be used to calculate △. i :

[0070]

[0071] And calculate (2△) i ,△ i ,△ i ,3△ i ,), (3△ i ,3△ i ,△ i ,△ i ,), (△ i ,3△ i ,2△ i ,△ i ,), (△ i ,△ i ,3△ i ,2△i The value of ,) matches the list θ, and the key that fails to match. Save to list In this context, fault injection can be used to obtain... List of all candidate values ​​for error keys

[0072] Step S128: If the multiple sets of first ciphertext pairs are processed based on the impossible differential path and the multiple erroneous final round keys to obtain the initial key of the first key, then the original key arrangement algorithm is updated.

[0073] Step S129: Determine the second key based on the initial key and the updated original key arrangement algorithm;

[0074] Step S128: Encrypt the data to be encrypted using the second key.

[0075] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device, and the method includes:

[0076] Step S131: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0077] Step S132: Construct an impossible differential path;

[0078] Step S133: Based on the impossible differential path, determine multiple plaintext pairs from several plaintexts;

[0079] Step S134: Encrypt the multiple plaintext pairs based on the first key to obtain multiple first ciphertext pairs;

[0080] Step S135: Perform a differential fault attack on the encryption process to obtain multiple erroneous final round keys;

[0081] Step S136: Determine the initial key for multiple guesses;

[0082] For example, one can guess k0. An 8-byte value.

[0083] Step S137: Decrypt the multiple sets of first ciphertext pairs using the multiple erroneous last-round keys to obtain the decryption result;

[0084] For example, you can use a list. Each key For the ciphertext pair (C,C) in round 6 * Perform a round of decryption and calculate and Here, MC-1 This refers to the inverse operation of the column mixing operation in the AES encryption algorithm, SB. -1 This refers to the inverse operation of the byte substitution operation in the AES encryption algorithm, SR -1 ARK refers to the inverse operation of the row shift operation in the AES encryption algorithm. -1 This refers to the inverse operation of the round key addition operation in the AES encryption algorithm.

[0085] Step S138: Based on the decryption result and preset conditions, filter the multiple sets of first ciphertext pairs to obtain filtered ciphertext pairs;

[0086] For example, if the difference value ΔC of the decrypted ciphertext is zero at any of the byte positions in the combinations (0,7,10,13), (1,4,11,14), (2,5,8,15), and (3,6,9,12), and the differences are non-zero at the remaining byte positions, then for each... After decryption, the difference values ​​all have: ΔC≠β; keep only such plaintext-ciphertext pairs and discard the rest. The filtering probability here is 2. -32 ×2 -32 =2 -64 Such pairs are approximately 2 16 right.

[0087] In this embodiment, filtering ciphertext pairs can gradually reduce the complexity of the scheme, reduce the number of ciphertext pairs processed, and thus reduce the total number of keys to be guessed. Therefore, the corresponding bytes of the initial key can be calculated based on this differential characteristic, and the details of the key arrangement algorithm can be ignored.

[0088] Step S139: If the initial keys of the first key are obtained by eliminating the multiple guessed initial keys based on the filtered ciphertext pairs and the impossible differential paths, then the original key arrangement algorithm is updated.

[0089] Step S140: Determine the second key based on the initial key and the updated original key arrangement algorithm;

[0090] Step S141: Encrypt the data to be encrypted using the second key.

[0091] Here, using the methods in steps S121 to S141 above, based on the properties of impossible differential paths, the analysis method can recover the initial key without guessing the key of subsequent rounds based on the key expansion function. The properties of the first round key expansion are known from the original expansion algorithm. Any improved key arrangement scheme generates the same properties for the first round key. The four words of the first round key need to be used in the operation with the four words of all the initial keys, and each word can only be XORed once. All the byte information of the first round key comes from the initial key. Therefore, this method can pose a significant threat to the key arrangement scheme of the AES algorithm. At the same time, this scheme can analyze higher rounds of the AES algorithm. Combined with the existing impossible differential analysis of 7 rounds, 8 rounds, and 9 rounds, the analysis can be achieved by satisfying that the encryption two rounds reach the impossible differential path.

[0092] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device, and the method includes:

[0093] Step S151: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0094] Step S152: Construct an impossible differential path;

[0095] Step S153: Based on the impossible differential path, determine multiple plaintext pairs from several plaintexts;

[0096] Step S154: Encrypt the multiple plaintext pairs based on the first key to obtain multiple first ciphertext pairs;

[0097] Step S155: Perform a differential fault attack on the encryption process to obtain multiple erroneous final round keys;

[0098] Step S156: Determine the initial key for multiple guesses;

[0099] Step S157: Perform single-byte fault injection on the penultimate round of encryption to obtain the state matrix of injected faults;

[0100] Step S158: Based on the first key, the state matrix of the injected fault is further encrypted to obtain multiple sets of second ciphertext pairs;

[0101] For example, in the fifth round of the pre-defined encryption process, after column obfuscation of the input, a single-byte random fault δ is injected into a certain byte. After column obfuscation, this fault is spread to 4 bytes and participates in the final round of encryption along with the round key of that round. At this point, the attacker obtains the pre-defined fault ciphertext C. * The ciphertext pair (C,C) consisting of the correct ciphertext C and the correct ciphertext C *The fault ciphertext C * That is, the second ciphertext pair.

[0102] Step S159: Use the multiple erroneous final round keys to decrypt the multiple sets of first ciphertext pairs and the multiple sets of second ciphertext pairs to obtain the decryption results of the first ciphertext pairs and the decryption results of the second ciphertext pairs;

[0103] In this embodiment of the application, the first ciphertext pair C and the corresponding second ciphertext pair C can be... * Combine them to form a ciphertext pair (C,C) * Then, for the ciphertext pair (C,C), * Decrypt the ciphertext to obtain the ciphertext pair (C,C). * The ciphertext pair difference value ΔC.

[0104] Step S160: Determine the ciphertext pair difference value based on the decryption results of the first ciphertext pair and the second ciphertext pair;

[0105] Step S161: Based on the difference value of the ciphertext pair and the preset conditions, filter the multiple sets of first ciphertext pairs to obtain filtered ciphertext pairs;

[0106] In this embodiment of the application, the preset condition can be: if the difference value ΔC of the decrypted ciphertext is zero at any byte position in the byte combination positions (0,7,10,13), (1,4,11,14), (2,5,8,15), (3,6,9,12), and the remaining differences are non-zero, that is, for each After decryption, the difference values ​​all have: ΔC≠β; keep such plaintext-ciphertext pairs and discard the rest.

[0107] Step S162: If the initial keys of the first key are obtained by excluding the multiple guessed initial keys based on the filtered ciphertext pairs and the impossible differential paths, then the original key arrangement algorithm is updated.

[0108] For example, based on the impossible difference path in 6 rounds, guess the value of k0. The 8-byte value is used to encrypt the plaintext pair once using a guessed value. Finally, without performing an ARK, the difference ΔC is calculated, and the pairs that satisfy ΔC are selected from ΔC1, ΔC3, ΔC5, ΔC7, ΔC9, and ΔC1. 11 ,△C 13 ,△C 15 Ciphertext pairs where the difference value is non-zero and the difference of the remaining bytes is zero; the filtering probability here is approximately 1, leaving approximately 2 such ciphertext pairs. 16 right.

[0109] As can be seen from the key arrangement algorithm, based on guessing k0... 4 bytes can be used to obtain k1 2 bytes, then guess k0 Two bytes can be used to obtain k1. A 2-byte value, for k1 Take the two-byte values ​​from two different columns (one byte per column), use the guessed values ​​to encrypt the above ciphertext pair once, and calculate the difference ΔC of the resulting ciphertext pair. If the difference ΔC is in ΔC1, ΔC5, ΔC7, ΔC... 11 ,△C 13 ,△C 15 If the difference value of one byte is non-zero while the difference value of the other bytes is zero, then the two bytes of the guessed k1 are incorrect. The filtering probability here is approximately (2). 16 -1) / 2 16 =0.9999847412≈99.99985%, meaning the filtering probability is approximately 1, then there are approximately 2 pairs that satisfy this condition. 16 Yes, it covers the entire two-byte space; inject 6 more faults, and using the same method, k1 can be obtained through 8 faults. 8 bytes and k0 With 6 bytes, by changing the impossible differential path in the opposite direction, injecting 8 faults can obtain the value of another 8 bytes of k1 and the corresponding 6 bytes of k0. With all the known byte information of k1, the value of the remaining bytes of the master key can be deduced, and thus the entire master key can be recovered; at this time, with 2 faults, all 4 bytes of k6 and 2 bytes of k1 can be obtained; with 8 fault injections, all bytes of k6, 8 bytes of k1, and 6 bytes of k0 can be obtained; with 16 fault injections, the entire value of k0 can be obtained.

[0110] Step S163: Determine the second key based on the initial key and the updated original key arrangement algorithm;

[0111] Step S164: Encrypt the data to be encrypted using the second key.

[0112] In some embodiments, step S157, injecting a single-byte fault into the penultimate round of encryption to obtain a state matrix with injected faults, includes:

[0113] Step S1571: Determine the number of rounds for constructing the impossible differential path;

[0114] Step S1572: Determine the number of attacks for the differential fault attack based on the number of rounds of the impossible differential path;

[0115] Here, performing a differential fault attack on the encryption process of a plaintext pair is called a differential fault attack.

[0116] Step S1573: During the encryption process of the number of attacks, a single-byte fault injection is performed on the penultimate round of encryption to obtain the state matrix of injected faults.

[0117] Here, through the methods in steps S152 to S162 above, it can be proven that the design of certain key arrangement algorithms has defects in implementation. The final key of the algorithm is contained in the ciphertext, which is very easy for attackers to obtain and is also the easiest to ignore.

[0118] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device. Figure 2 This is a schematic diagram illustrating the implementation process of the encryption method in the embodiments of this application. Figure 2 ,like Figure 2 As shown, the method includes:

[0119] Step S201: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0120] Step S202: If the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and the constructed impossible differential path, then update the original key arrangement algorithm.

[0121] Step S203: Obtain a random number;

[0122] Step S204: Using the random number, the initial key, and the updated original key arrangement algorithm, obtain the penultimate round key;

[0123] In this embodiment, a random number generator can be added. After the random number generator is integerized, it participates in the key expansion operation and participates in the generation of the second-to-last round key of the key arrangement algorithm, thereby achieving security enhancement for the last two round keys of the encryption algorithm.

[0124] Step S205: Determine the second key based on the penultimate round key;

[0125] Here, the final round key can be generated based on the penultimate round key and the original key arrangement algorithm; and the round keys for other rounds besides the penultimate and final rounds can be generated based on the initial key and the original key arrangement algorithm, thus obtaining the complete encryption key, i.e., the second key.

[0126] Step S206: Encrypt the data to be encrypted using the second key.

[0127] Here, through the methods described in steps S201 to S206 above, the key generation method for the last two rounds of the key arrangement algorithm can be reasonably improved, thereby enhancing the security of the last two rounds of keys, resisting differential fault attacks, and achieving enhanced security of the encryption algorithm. Furthermore, this method only adds a simple XOR operation, which does not affect the algorithm's performance. It also reduces the number of decryption steps during data decryption, sacrificing storage but improving the execution efficiency of the decryption algorithm.

[0128] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device, and the method includes:

[0129] Step S211: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0130] Step S212: If the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and the constructed impossible differential path, then update the original key arrangement algorithm.

[0131] Step S213: Obtain a random number;

[0132] Step S214: Using the initial key and the original key arrangement algorithm, obtain the preset round key;

[0133] Here, if a single-byte random fault is injected in the penultimate round, the key arrangement algorithm for the penultimate round is updated, while the key arrangement algorithms for other rounds remain unchanged. Furthermore, the key for the preset round is the key for the third-to-last round. For example, if the encryption algorithm is AES-128, and w[0], w[1], w[2], w[3] are the initial keys, the original keys are expanded into a sequence of 44 words w[0], w[1], ..., w

[43] through the key arrangement algorithm. Then, the key for the preset round is w

[32] , w

[33] , w

[34] , w

[35] . The key for the preset round w

[32] , w

[33] , w

[34] , w

[35] can be obtained from the initial keys w[0], w[1], w[2], w[3] and the original key arrangement algorithm.

[0134] Step S215: Based on the updated original key arrangement algorithm, perform an XOR operation on the random number and the preset round key to obtain the penultimate round key;

[0135] In this embodiment of the application, if the differential fault attack injects a single-byte random fault in the penultimate round, the random number is applied to the penultimate round key arrangement algorithm. That is, the penultimate round key is obtained by XORing the random number and the preset round key. For example, if the encryption algorithm is AES-128, w[0], w[1], w[2], w[3] are the initial keys. The original key is expanded into a sequence of 44 words w[0], w[1], ..., w

[43] through the key arrangement algorithm. Then the penultimate round key is w

[36] , w

[37] , w

[38] , w

[39] . Assuming the obtained random number is R = (r[0], r[1], r[2], r[3]), the penultimate round key is generated in the updated original key arrangement algorithm as follows:

[0136]

[0137] Step S216: Determine the second key based on the round key of the penultimate round;

[0138] Here, the final round key can be generated based on the penultimate round key. Then, based on the penultimate round key, the final round key, and the round keys of the other rounds, the second key, i.e., the complete encryption key, is determined. In this embodiment, by strengthening the keys of the last two rounds, it becomes difficult for differential fault injection to obtain the bytes corresponding to the final round key, thereby rendering impossible differential fault attacks ineffective.

[0139] Step S217: Encrypt the data to be encrypted using the second key.

[0140] In this embodiment, the plaintext to be encrypted (i.e., the data to be encrypted) can be divided into groups of equal length, and one group of data is encrypted at a time until the entire plaintext is encrypted. Specifically, each group of data is first encrypted using an initial key, and then multiple rounds of key addition are performed using subsequent round keys.

[0141] Based on the foregoing embodiments, this application further provides an encryption method, which is applied to an encryption device, and the method includes:

[0142] Step S221: Obtain the data to be encrypted and the first key; wherein, the first key is obtained through the original key arrangement algorithm;

[0143] Step S222: If the final key of the first key is obtained through a differential fault attack, and the initial key of the first key is obtained through the final key and the constructed impossible differential path, then update the original key arrangement algorithm.

[0144] Step S223: Obtain a random number;

[0145] Step S224: Using the random number, the initial key, and the updated original key arrangement algorithm, obtain the penultimate round key;

[0146] Step S225: Determine the second key based on the penultimate round key;

[0147] Step S226: Encrypt the data to be encrypted using the second key;

[0148] Step S227: Determine the last round key in the second key; wherein the last round key is generated based on the round key of the penultimate round;

[0149] Here, the round key for the final round can be generated using the round key from the penultimate round.

[0150] Step S228: Store the penultimate round key and the final round key in the cloud, so that the decryptor can obtain the penultimate round key and the final round key from the cloud after successful identity authentication.

[0151] In this embodiment, the round keys for the last two rounds can be stored in a list on the cloud. End users need to be authenticated to access this list and obtain the round keys for the last two rounds without needing to regenerate them. Furthermore, the cloud deletes the corresponding list or bytes after sending the list or corresponding bytes containing the round keys for the last two rounds. Therefore, when decrypting, the end user only needs to generate the round keys for the first few rounds; the round keys for the last two rounds can be obtained from the list stored in the cloud. This increases key security and thus enhances encryption security.

[0152] Currently, differential analysis is a commonly used technique in cryptography to analyze cryptographic algorithms based on mathematical principles, and it is also an important indicator for measuring the security of cryptographic algorithms. However, AES is basically immune to differential analysis. IDA (Impossible Differential Analysis) is a variant of differential analysis, which is more effective for low-round AES and can be used to filter out erroneous keys. However, the huge sample size required for impossible differential analysis limits the physical conditions required to carry out this attack.

[0153] Differential Fault Analysis (DFA) is one of the earliest techniques for launching block cipher attacks by inducing computational errors. The attacker's goal is usually to recover the key information of the last round or the last two rounds. By guessing part of the key information of the last round, the attacker calculates the difference between the correct and incorrect ciphertext information. The key discriminator generated by the fault model distinguishes whether the guessed key information is correct. Based on this, the attacker uses exhaustive key search to recover the master key of the AES algorithm. However, under certain assumptions, this method can only recover the last round key. If it is assumed that the details of the key arrangement algorithm are not visible, the master key cannot be obtained.

[0154] Based on this, this application proposes an AES impossible differential fault analysis and optimization method. The analysis method integrates IDA and DFA techniques, using DFA to compensate for the large sample size problem of IDA. Using IDA allows the implementation details of the key arrangement algorithm to be ignored during DFA analysis. Finally, based on the analysis results, a method for enhancing the protection of the final round key of the AES algorithm is designed. By adding a simple XOR operation, the security of the AES algorithm is enhanced without affecting its execution efficiency, thus proposing an encryption and decryption method based on round key enhancement.

[0155] The analysis method, optimization method, encryption method, and decryption method described above will be explained in detail below:

[0156] (1) Impossible differential fault analysis method of AES;

[0157] The basic assumptions are:

[0158] ① An attacker can inject a single-byte random fault before the penultimate round of column obfuscation input each time, but the attacker does not know the specific location of the fault or the specific fault value. It is further assumed that the fault occurs at the deterministic layer of the encryption process.

[0159] ② For the same plaintext M, an attacker can obtain both the correct ciphertext C and the faulty ciphertext C under the same key K. * .

[0160] ③ The attacker has all the details of the AES encryption algorithm implementation.

[0161] The detailed steps are as follows:

[0162] Let the plaintext structure be M, the ciphertext structure be C, the single-byte random fault be δ, and the ciphertext pair difference be ΔC = (ΔC0, ΔC1, ..., ΔC2). 15 ), where △C i Represents the difference value, △C i(i = 0, 1, 2, ..., 14, 15) represents the difference value where the corresponding byte is not zero. It is impossible to have a difference value in 6 rounds. So:

[0163] Step 1, Select 2 49 Each plaintext group is traversed by the 8 bytes at positions (1,3,4,6,9,11,12,14). The remaining bytes are fixed constants, with each plaintext group having 2 bytes. 64 There are 2 in total. 127 Plaintext pair, pair 2 49 After 6 rounds of encryption, the plaintext structure can be obtained as 2 127+49 Given a set of plaintext pairs, encrypt all plaintext pairs to obtain the corresponding ciphertext pairs. Select ciphertext pairs that satisfy the difference ΔC in ΔC3, ΔC6, ΔC9, and ΔC... 12 Ciphertext pairs with a non-zero difference value but zero difference values ​​at other byte positions have a filtering probability of 2. -96 Leave behind the corresponding plaintext and ciphertext pairs, totaling approximately 2 80 right.

[0164] Step 2: In the fifth round of a certain encryption process, after column obfuscation input, a single-byte random fault δ is injected into a certain byte. After column obfuscation, this fault is spread to 4 bytes and participates in the final round of encryption together with the round key of that round. At this time, the attacker obtains two sets of faulty ciphertext C. * The ciphertext pair (C,C) consisting of the correct ciphertext C and the correct ciphertext C * ).

[0165] Step 3: The attacker calculates a list θ of all possible differential values ​​for a column output when only one byte of the column obfuscation input is injected with a random single-byte fault. This list contains a total of 1020 four-byte elements.

[0166] Step 4: For each column of the ciphertext pair, the four distinct positions (0,7,10,13), (1,4,11,14), (2,5,8,15), and (3,6,9,12) are designated as i,j,k,l. The attacker then guesses the values ​​of the bytes at positions i,j,k,l of the round key k6 in round 6. And calculate △ i :

[0167]

[0168] And calculate (2△) i ,△ i ,△ i ,3△ i ,), (3△ i ,3△ i ,△ i ,△ i,), (△ i ,3△ i ,2△ i ,△ i ,), (△ i ,△ i ,3△ i ,2△ i The value of ,) matches the list θ, and the key that fails to match. Save to list In this process, two fault injections can be used to obtain... List of all candidate values ​​for error keys

[0169] Step 5: Apply a list to the ciphertext pairs generated in Step 1. Each key For the ciphertext pair (C,C) in round 6 * Perform a round of decryption and calculate and If the difference value ΔC of the decrypted ciphertext is zero at any of the following byte positions: (0,7,10,13), (1,4,11,14), (2,5,8,15), (3,6,9,12), and non-zero at all other byte positions, then for each... After decryption, the difference values ​​all have: ΔC≠β; keep only such plaintext-ciphertext pairs and discard the rest. The filtering probability here is 2. -32 ×2 -32 =2 -64 Such pairs are approximately 2 16 right.

[0170] Step 6: For the plaintext pair in Step 5, guess the value of k0 based on the impossible differential path in 6 rounds. The 8-byte value is used to encrypt the plaintext pair once using a guessed value. Finally, without performing an ARK, the difference ΔC is calculated, and the pairs that satisfy ΔC are selected from ΔC1, ΔC3, ΔC5, ΔC7, ΔC9, and ΔC1. 11 ,△C 13 ,△C 15 Ciphertext pairs where the difference value is non-zero and the difference of the remaining bytes is zero; the filtering probability here is approximately 1, leaving approximately 2 such ciphertext pairs. 16 right.

[0171] As can be seen from the key arrangement algorithm, based on guessing k0... 4 bytes can be used to obtain k1 2 bytes, then guess k0 Two bytes can be used to obtain k1. A 2-byte value, for k1 Take the two-byte values ​​from two different columns (one byte per column), use the guessed values ​​to encrypt the above ciphertext pair once, and calculate the difference ΔC of the resulting ciphertext pair. If the difference ΔC is in ΔC1, ΔC5, ΔC7, ΔC... 11 ,△C 13 ,△C 15 If the difference value of one byte is non-zero while the difference value of the other bytes is zero, then the two bytes of the guessed k1 are incorrect. The filtering probability here is approximately (2). 16 -1) / 2 16 =0.9999847412≈99.99985%, meaning the filtering probability is approximately 1, then there are approximately 2 pairs that satisfy this condition. 16 Yes, it covers the entire two-byte space; inject 6 more faults, and using the same method, k1 can be obtained through 8 faults. 8 bytes and k0 With 6 bytes, by changing the impossible differential path in the opposite direction, injecting 8 faults can obtain the value of another 8 bytes of k1 and the corresponding 6 bytes of k0. With all the known byte information of k1, the value of the remaining bytes of the master key can be deduced, and thus the entire master key can be recovered; at this time, with 2 faults, all 4 bytes of k6 and 2 bytes of k1 can be obtained; with 8 fault injections, all bytes of k6, 8 bytes of k1, and 6 bytes of k0 can be obtained; with 16 fault injections, the entire value of k0 can be obtained.

[0172] Figure 3A This is a schematic diagram of an impossible differential path in six rounds according to an embodiment of this application, as shown below. Figure 3A As shown in the diagram, white squares represent two plaintexts or features whose differences are the same, while black squares represent two plaintexts or features whose differences are different. If possessing... If the plaintext pair of features obtained after passing through the impossible differential path for 6 rounds satisfies the feature β, then the guessed key is incorrect and needs to be eliminated. Wherein, MC -1 SB represents the inverse operation of MC. -1 SR represents the inverse operation of SB. -1 RK represents the inverse operation of SR. -1 This represents the inverse operation of RK.

[0173] (2) Optimization methods;

[0174] Based on the above analysis, the AES algorithm is enhanced with security features to obtain the enhanced AES-128 key arrangement algorithm:

[0175] The initial key is represented as W0 = (w[0], w[1], w[2], w[3]), and the key expansion function expands W0 into 10 arrays (W1, ..., W...). 10), which contains 40 new words (w[4], w[5], ..., w

[43] ), and the newly generated 10 arrays are used as the round keys for each round for round key addition operations.

[0176] Let the random number generated by the AES algorithm be R = (r[0], r[1], r[2], r[3]), where the parentheses contain four characters. The key generation method for the penultimate round is as follows:

[0177]

[0178] For example,

[0179]

[0180] The round key for the i-th round (excluding the penultimate round) is generated as follows:

[0181]

[0182] For example,

[0183]

[0184]

[0185] When i equals 36 (the penultimate round key), a random number is generated. After the random number is integerized, it forms four words: r[0], r[1], r[2], r[3]. This random number is part of the AES algorithm. The frequency of random number generation can be customized according to the environment and security requirements in the encryption cycle of the algorithm. Let the random number be R. Then, each time the penultimate round key is generated, each key word will be XORed with r[0], r[1], r[2], r[3] in addition to the original operation. Then, a new penultimate round key is obtained, and then the final round key is generated. When the AES-192 key is extended to 12 rounds or the AES-256 key is extended to 14 rounds, the value of i is 44 and 52 respectively when the penultimate round key is generated. The generation method of the other round keys is the same as the original algorithm.

[0186] (3) Encryption and decryption methods;

[0187] Figure 3B This is a schematic diagram of the system architecture corresponding to the encryption and decryption methods in the embodiments of this application, as shown below. Figure 3BAs shown, the system architecture includes at least an edge node 31, a cloud 32, and an end user 33. The edge node 31 obtains an encryption key using the aforementioned optimization method, and places the penultimate round key and the final round key into a round key list. This round key list is then uploaded to the cloud 32. Finally, the edge node 31 uses the encryption key to encrypt the data to be encrypted and sends the encrypted data to the end user 33. The end user 33 calculates the round keys for all rounds except the penultimate and final rounds based on a pre-agreed initial key and key arrangement algorithm. The end user 33 then sends an authentication request to the cloud 32 to obtain the round key list (i.e., the penultimate and final round keys), thereby obtaining the complete encryption key to decrypt the encrypted data.

[0188] In other words, in edge computing scenarios, the key arrangement algorithm in the original AES-128 algorithm is replaced with the optimized key arrangement algorithm in this scheme, while the AES-128 encryption and decryption process remains unchanged. The encryption and decryption process for data owners communicating with the cloud, edge nodes, and end users is as follows (assuming the random number generation frequency is once per block): the data is divided into several 128-bit blocks, and each block is encrypted or decrypted, where:

[0189] ① Encryption process:

[0190] 1) Obtain the initial key, and the random number generator generates a random number, which is then integerized to form 4 words;

[0191] 2) The optimized key arrangement algorithm in this scheme is XORed with the four words composed of the above random numbers to obtain 10 wheel keys, from which two new final wheel keys will be generated;

[0192] 3) Store the two final round sub-keys and add them to the final round key storage list θ; the storage list θ is stored in the cloud;

[0193] 4) Use the initial key to perform round key addition on the blocks to obtain the corresponding intermediate ciphertext;

[0194] 5) The intermediate ciphertext is encrypted using the 10 sub-keys mentioned above for ten rounds to obtain the final ciphertext.

[0195] ②Decryption process:

[0196] 1) The end user requests the storage list θ in the cloud, and obtains the list θ or the corresponding byte value after identity authentication; at the same time, the cloud deletes the corresponding storage list θ or the corresponding byte value.

[0197] 2) Using the initial key, call the key arrangement algorithm to generate 8 rounds of sub-keys, and combine them with list θ to obtain the corresponding last round sub-key, resulting in a total of 10 rounds of sub-keys;

[0198] 3) Use the last round key to perform round key addition on the ciphertext;

[0199] 4) Use the 10 rounds of wheel keys to perform 10 rounds of decryption operations on the received ciphertext to obtain the decrypted plaintext blocks.

[0200] In other words, addressing the existing problems and shortcomings of current solutions, this application proposes an AES impossible differential fault analysis method, an optimization method, an encryption method, and a decryption method. Among these, the following seven core points are highlighted:

[0201] First, choose an impossible differential distinguisher;

[0202] Second, construct an impossible difference path by combining this impossible difference distinguisher;

[0203] Third, select input plaintext-ciphertext pairs with specific difference values. Based on impossible difference paths, the output difference values ​​of these plaintext-ciphertext pairs satisfy specific conditions.

[0204] Fourth, at this point, a random single-byte fault is injected into the column confusion input of the impossible differential path in round r-1. The corresponding bytes of the round key of the last round on the impossible differential path are filtered out by differential fault injection, and these filtered last round keys are put into the filtering list.

[0205] Fifth, if the ciphertext satisfies that the differential value after decryption of all erroneous keys in the elimination list is not on an impossible differential path, then the erroneous key that satisfies this condition is called a completely wrong key. At the same time, the guessed key value corresponding to the input differential value of the plaintext that satisfies an impossible differential path in the first round of encryption is eliminated. By combining the two differential methods, the candidate space of the round keys required by the guessing algorithm can be greatly reduced.

[0206] Sixth, a random number generator is added to the AES algorithm component. The random number generator's integer values ​​are then used in the key expansion operation, specifically in the penultimate round key generation of the key expansion function. This enhances the security of the last two round keys of the AES algorithm. The resulting final round keys are stored in a list in the cloud. End users need to be authenticated to access this list and obtain the final round keys without needing to regenerate them. The cloud deletes the corresponding list or bytes after sending the final round key list or corresponding bytes.

[0207] Seventh, during decryption, only the first 8 round keys need to be generated; the final round key can be obtained from the list of round keys stored in the cloud.

[0208] Therefore, the solution adopted in the embodiments of this application can achieve the following technical effects:

[0209] 1) The analysis method can greatly reduce the key candidate space of round keys required by impossible differential analysis algorithms.

[0210] 2) The analysis method can directly eliminate the erroneous key candidate space of the first two rounds through the last round key until the master key is found. It does not need to derive the intermediate round keys sequentially according to the key arrangement algorithm. This means that the design of the key arrangement algorithm is that the key arrangement of the middle round is invalid.

[0211] 3) Based on the properties of impossible differential paths, the analysis method does not require guessing the key of subsequent rounds and deriving it based on the key expansion function to recover the initial key. The properties of the first round key expansion are known from the original expansion algorithm. Any improved key arrangement scheme generates the same properties for the first round key. The four words of the first round key need to be used in the operation with the four words of all the initial keys, and each word can only be XORed once. All the byte information of the first round key comes from the initial key. Therefore, this method can pose a significant threat to the key arrangement scheme of the AES algorithm. At the same time, this scheme can analyze higher rounds of the AES algorithm. Combined with the existing impossible differential analysis of 7, 8, and 9 rounds, the analysis can be achieved by satisfying that the encryption two rounds reach the impossible differential path.

[0212] 4) The analysis method proves that the design of the AES key arrangement algorithm has flaws. The final key of the algorithm is contained in the ciphertext, which is easily obtained by attackers and is also the easiest to overlook. Based on the analysis and research of AES, this method makes reasonable improvements to the key generation method of the last two rounds of the key arrangement algorithm, thereby enhancing the security of the final key of AES, resisting differential fault analysis, and realizing the security enhancement of the AES algorithm. At the same time, this method only adds a simple XOR operation, which will not affect the performance of the algorithm. In addition, it can reduce the execution steps of decryption operation when decrypting data, sacrificing storage, but improving the execution efficiency of the decryption algorithm.

[0213] Based on the foregoing embodiments, this application provides an encryption device, which includes the included units, the modules included in each unit, and the components included in each module. It can be implemented by a processor in the encryption device; of course, it can also be implemented by specific logic circuits. In the implementation process, the processor can be a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processor), or FPGA (Field Programmable Gate Array), etc.

[0214] Figure 4 This is a schematic diagram of the composition structure of the encryption device in an embodiment of this application, as shown below. Figure 4 As shown, the device 400 includes:

[0215] The acquisition unit 401 is used to acquire the data to be encrypted and the first key; wherein the first key is obtained through the original key arrangement algorithm;

[0216] The update unit 402 is used to update the original key arrangement algorithm if the final key of the first key is obtained through a differential fault attack and the initial key of the first key is obtained through the final key and the constructed impossible differential path.

[0217] The determining unit 403 is used to determine the second key based on the initial key and the updated original key arrangement algorithm;

[0218] The encryption unit 404 is used to encrypt the data to be encrypted using the second key.

[0219] In some embodiments, the apparatus further includes:

[0220] Path building unit, used to construct impossible differential paths;

[0221] The plaintext pair determination unit is used to determine multiple plaintext pairs from a number of plaintexts based on the impossible differential path.

[0222] A plaintext encryption unit is used to encrypt the multiple plaintext pairs based on the first key to obtain multiple first ciphertext pairs;

[0223] An attack unit is used to perform a differential fault attack on the encryption process to obtain multiple erroneous final round keys.

[0224] An initial key determination unit is used to process the multiple sets of first ciphertext pairs based on the impossible differential path and the multiple erroneous final round keys to obtain the initial key of the first key.

[0225] In some embodiments, the attack unit includes:

[0226] The first guessing key determination module is used to determine the final round key for multiple guesses;

[0227] The fault injection module is used to perform single-byte fault injection on the encryption process to obtain multiple possible differential values ​​corresponding to the fault injection.

[0228] The matching module is used to match the multiple guessed final round keys with the multiple possible difference values ​​to obtain multiple incorrect final round keys.

[0229] In some embodiments, the initial key determination unit includes:

[0230] The second guessing key determination module is used to determine the initial key for multiple guesses;

[0231] The decryption module is used to decrypt the multiple sets of first ciphertext pairs using the multiple erroneous final round keys to obtain the decryption result;

[0232] A filtering module is used to filter the multiple sets of first ciphertext pairs based on the decryption result and preset conditions to obtain filtered ciphertext pairs.

[0233] The key exclusion module is used to exclude the multiple guessed initial keys based on the filtered ciphertext pairs and the impossible differential paths, so as to obtain the initial key of the first key.

[0234] In some embodiments, the decryption module includes:

[0235] The fault injection component is used to inject a single-byte fault into the penultimate round of encryption in the encryption process to obtain a state matrix of injected faults.

[0236] An encryption component is used to further encrypt the state matrix of the injected fault based on the first key to obtain multiple sets of second ciphertext pairs;

[0237] The decryption component is used to decrypt the multiple sets of first ciphertext pairs and the multiple sets of second ciphertext pairs using the multiple erroneous final round keys, to obtain the decryption results of the first ciphertext pairs and the decryption results of the second ciphertext pairs;

[0238] Correspondingly, the filtering module includes:

[0239] The difference value determination component is used to determine the difference value of the ciphertext pair based on the decryption results of the first ciphertext pair and the decryption results of the second ciphertext pair.

[0240] A filtering component is used to filter the multiple sets of first ciphertext pairs based on the difference value of the ciphertext pairs and preset conditions to obtain filtered ciphertext pairs.

[0241] In some embodiments, the fault injection component includes:

[0242] The fault injection sub-component is used to determine the number of rounds for an impossible differential path being constructed;

[0243] The fault injection sub-component is also used to determine the number of attacks for the differential fault attack based on the number of rounds of the impossible differential path.

[0244] The fault injection component is also used to inject a single-byte fault into the penultimate round of encryption during the encryption process of the number of attacks, so as to obtain a state matrix of injected faults.

[0245] In some embodiments, the determining unit 403 includes:

[0246] The random number generation module is used to generate random numbers.

[0247] The round key calculation module is used to obtain the penultimate round key using the random number, the initial key, and the updated original key arrangement algorithm.

[0248] The key calculation module is used to determine the second key based on the round key of the penultimate round.

[0249] In some embodiments, the round key calculation module includes:

[0250] The round key calculation component is used to obtain the round key of the preset round using the initial key and the original key arrangement algorithm;

[0251] The round key calculation component is also used to perform an XOR operation on the random number and the round key of the preset round based on the updated original key arrangement algorithm to obtain the round key of the penultimate round.

[0252] In some embodiments, the apparatus further includes:

[0253] A storage unit is used to determine the last round key in the second key; wherein the last round key is generated based on the round key of the penultimate round;

[0254] The storage unit is also used to store the penultimate round key and the final round key in the cloud, so that the decryptor can obtain the penultimate round key and the final round key from the cloud after successful identity authentication.

[0255] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0256] It should be noted that, in the embodiments of this application, if the above-mentioned encryption method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device (which may be a personal computer, server, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM (Read Only Memory), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0257] Correspondingly, this application provides an encryption device, including a memory and a processor. The memory stores a computer program that can run on the processor. When the processor executes the program, it implements the steps in the encryption method provided in the above embodiments.

[0258] Correspondingly, embodiments of this application provide a readable storage medium on which a computer program is stored, which, when executed by a processor, implements the steps in the above-described encryption method.

[0259] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0260] It should be noted that, Figure 5 This is a schematic diagram of a hardware entity of an encryption device according to an embodiment of this application, such as... Figure 5 As shown, the hardware entity of the encryption device 500 includes: a processor 501, a communication interface 502, and a memory 503, wherein...

[0261] Processor 501 typically controls the overall operation of encryption device 500.

[0262] The communication interface 502 enables the encryption device 500 to communicate with other electronic devices (including decryption devices) or servers via a network.

[0263] The memory 503 is configured to store instructions and applications executable by the processor 501, and can also cache data to be processed or already processed by the various modules in the processor 501 and the encryption device 500 (e.g., image data, audio data, voice communication data and video communication data), which can be implemented by FLASH (flash memory) or RAM (Random Access Memory).

[0264] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0265] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0266] Furthermore, in the various embodiments of this application, all functional units can be integrated into one processing module, or each unit can be a separate unit, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in a combination of hardware and software functional units. Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0267] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0268] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0269] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0270] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An encryption method characterized by, The method includes: Obtain the data to be encrypted and the first key; wherein the first key is obtained through the original key arrangement algorithm; If multiple erroneous final-round keys of the first key are obtained through a differential fault attack, and the initial key of the first key is obtained through the multiple erroneous final-round keys and an impossible differential path is constructed, then the original key arrangement algorithm is updated. Based on the initial key and the updated original key arrangement algorithm, the second key is determined; The data to be encrypted is encrypted using the second key.

2. The method of claim 1, wherein, The process of obtaining multiple erroneous final-round keys of the first key through a differential fault attack, and obtaining the initial key of the first key through the multiple erroneous final-round keys and a constructed impossible differential path, includes: Constructing impossible difference paths; Based on the impossible differential path, multiple plaintext pairs are determined from several plaintexts; Based on the first key, the multiple plaintext pairs are encrypted to obtain multiple first ciphertext pairs; By performing a differential fault attack on the encryption process, multiple incorrect final round keys are obtained. Based on the impossible differential path and the multiple erroneous final round keys, the multiple sets of first ciphertext pairs are processed to obtain the initial key of the first key.

3. The method according to claim 2, characterized in that, The encryption process is subjected to a differential fault attack, resulting in multiple erroneous final-round keys, including: Determine the final round key from multiple guesses; A single-byte fault injection is performed on the encryption process to obtain multiple possible differential values ​​corresponding to the fault injection. By matching the multiple guessed final round keys with the multiple possible difference values, multiple incorrect final round keys are obtained.

4. The method according to claim 2, characterized in that, The initial key for the first key is obtained by processing the multiple sets of first ciphertext pairs based on the impossible differential path and the multiple erroneous final-round keys, including: Determine the initial key from multiple guesses; The multiple sets of first ciphertext pairs are decrypted using the multiple erroneous final round keys to obtain the decryption results; Based on the decryption results and preset conditions, the multiple sets of first ciphertext pairs are filtered to obtain filtered ciphertext pairs. Based on the filtered ciphertext pair and the impossible differential path, the multiple guessed initial keys are eliminated to obtain the initial key of the first key.

5. The method according to claim 4, characterized in that, The step of using the multiple erroneous final-round keys to decrypt the multiple sets of first ciphertext pairs to obtain decryption results includes: A single-byte fault injection is performed on the penultimate round of encryption to obtain a state matrix of injected faults; Based on the first key, the state matrix of the injected fault is further encrypted to obtain multiple sets of second ciphertext pairs; Using the multiple erroneous final-round keys, the multiple sets of first ciphertext pairs and the multiple sets of second ciphertext pairs are decrypted to obtain the decryption results of the first ciphertext pairs and the decryption results of the second ciphertext pairs; Correspondingly, the filtering of the multiple sets of first ciphertext pairs based on the decryption result and preset conditions to obtain filtered ciphertext pairs includes: Based on the decryption results of the first ciphertext pair and the second ciphertext pair, determine the ciphertext pair difference value; Based on the difference value of the ciphertext pair and the preset conditions, the multiple sets of first ciphertext pairs are filtered to obtain filtered ciphertext pairs.

6. The method according to claim 5, characterized in that, The single-byte fault injection is performed on the penultimate round of encryption to obtain a state matrix of injected faults, including: Determine the number of rounds for constructing the impossible difference path; The number of attacks for the differential fault attack is determined based on the number of rounds of the impossible differential path. During the encryption process of the number of attacks, a single-byte fault injection is performed on the penultimate round of encryption to obtain the state matrix of injected faults.

7. The method according to any one of claims 1 to 6, characterized in that, The algorithm for determining the second key based on the initial key and the updated original key includes: Get random numbers; Using the random number, the initial key, and the updated original key arrangement algorithm, the penultimate round key is obtained; The second key is determined based on the round key of the penultimate round.

8. The method according to claim 7, characterized in that, The step of arranging the random number, the initial key, and the updated original key into an algorithm to obtain the penultimate round key includes: Using the initial key and the original key arrangement algorithm, the round key for the preset round is obtained; Based on the updated original key arrangement algorithm, the random number and the preset round key are XORed to obtain the penultimate round key.

9. The method according to claim 7, characterized in that, The method further includes: Determine the last round key in the second key; wherein the last round key is generated based on the round key of the penultimate round; The penultimate round key and the final round key are stored in the cloud, so that the decryptor can obtain the penultimate round key and the final round key from the cloud after successful identity authentication.

10. An encryption device, characterized in that, The device includes: An acquisition unit is used to obtain the data to be encrypted and a first key; wherein the first key is obtained through a raw key arrangement algorithm; The update unit is configured to update the original key arrangement algorithm if multiple erroneous final round keys of the first key are obtained through a differential fault attack, and the initial key of the first key is obtained through the multiple erroneous final round keys and the constructed impossible differential path. The determining unit is used to determine the second key based on the initial key and the updated original key arrangement algorithm; An encryption unit is used to encrypt the data to be encrypted using the second key.