A stream cipher encryption and decryption method based on integer operation cryptographic permutation

Through the stream cipher encryption and decryption method based on integer operation, the problem that traditional technology is difficult to meet the needs of high-speed and real-time data encryption and decryption is solved, and efficient, fast and secure data encryption and decryption effect is achieved.

CN116112170BActive Publication Date: 2025-06-24郑建良
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310077754.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-08
Publication Date
2025-06-24
Estimated Expiration
2043-02-08

AI Technical Summary

Technical Problem

The prior art is difficult to meet the needs of high-speed and real-time data encryption and decryption, especially in the era of big data and emerging applications such as 4K video and real-time video conferencing. Traditional packet passwords such as AES are difficult to meet the encryption speed and delay requirements.

Method used

A stream cryptographic encryption and decryption method based on integer operation cryptography permutation is proposed. The key stream is generated through the overall operation and the XOR operation is used for encryption and decryption, so as to achieve fast and efficient data encryption and decryption.

Benefits of technology

Achieving ultra-high encryption speeds, the ability to encrypt one byte in half a clock cycle on Intel Core i7 processors, supports fast forwarding and real-time random access, ensuring high quality and security of key streams.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116112170B_ABST
    Figure CN116112170B_ABST
Patent Text Reader

Abstract

The present invention relates to an encryption and decryption method for a stream cipher based on integer arithmetic cryptographic permutation, comprising: initializing an internal state; using an original key to update the initialized internal state; using an initialization vector to continue updating the internal state; generating a key stream through a key stream generation function, and refreshing the internal state again after generating a set number of key streams until the generated key stream reaches the required length. The beneficial effects of the present invention are: fast encryption speed; providing a fast forward function, which can instantly jump to any position of a large file or a long data stream for encryption or decryption; supporting setting an upper limit on the data random access time, enabling fast or real-time random access; capable of working in multiple modes, and having different security strengths and encryption speeds; when performing a permutation operation, a group of bytes or bits are selected from an integer in a pseudo-random manner, and the selected bytes or bits are moved as a whole using integer arithmetic to improve efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data encryption and decryption, and particularly relates to a stream cipher encryption and decryption method (abbreviated as SSC) based on integer operation cryptographic permutation. Background Art

[0002] Block ciphers have always dominated the development of data encryption standards. However, the stream cipher RC4 designed by Ron Rivest in 1987 was the most popular cipher for a long time. It was a trade secret of RSA Security until it was leaked in 1994. After its cipher initialization algorithm was found to be defective, RC4 was gradually phased out and is now deprecated. Although new stream ciphers have been continuously developed, including the algorithms finally selected by the eStream project, their progress in applications has been slow, and none of them can approach the status that RC4 once had. In fact, the space left by RC4 has basically been filled by the new data encryption standard AES. In the era of big data, and with the advent of many high-speed communication and storage technologies (such as 5G communication and solid-state drives, etc.), the demand for high-speed and real-time data encryption has risen rapidly. AES represents the latest level of block ciphers. Its algorithm is simple and efficient, and its speed ranks among the top in block ciphers. However, it is still slower than stream ciphers and is difficult to meet the requirements of emerging applications with large amounts of data and strict latency requirements such as 4K videos and real-time video conferences. It is not the most suitable high-speed and real-time data encryption and decryption solution.

[0003] Therefore, it is particularly important to propose an encryption method with faster encryption speed and high security. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a stream cipher encryption and decryption method based on integer operation cryptographic permutation.

[0005] This stream cipher encryption and decryption method based on integer operation cryptographic permutation includes the following steps:

[0006] Abbreviate the stream cipher based on integer operation cryptographic permutation as SSC;

[0007] During encryption: Receive the plaintext sequence; Given the original key key, initialization vector IV, the number of loops rom for the mixing operation, the number of loops rog for the key stream generation operation, and the state refresh threshold srt, generate the key stream after the overall operation of SSC; Perform an exclusive OR operation on the plaintext sequence and the generated key stream to obtain the ciphertext sequence;

[0008] During decryption: Receive the ciphertext sequence; Given the original key key, initialization vector IV, number of loops rom for the mixing operation, number of loops rog for the key stream generation operation, and state refresh threshold srt, generate the key stream after the overall SSC operation; Perform an exclusive OR operation on the ciphertext sequence and the generated key stream to obtain the plaintext sequence.

[0009] The specific method for the overall SSC operation to generate the key stream is as follows:

[0010] Initialize the internal state through the internal state reset function;

[0011] Use the original key key and update the initialized internal state through the internal state update function;

[0012] Use the initialization vector IV and continue to update the internal state updated by the original key key through the internal state update function;

[0013] Generate the key stream through the key stream generation function with the given original key key, initialization vector IV, number of loops rom for the mixing operation, number of loops rog for the key stream generation operation, and state refresh threshold srt; After generating the key stream srt times, refresh the internal state through the internal state refresh function until the generated key stream reaches the required length, and the overall SSC operation ends.

[0014] Preferably, the reset function used to initialize the internal state at the start of the overall SSC operation is resetInternalState(St), where St represents the internal state, and the internal state St consists of:

[0015] Two 32-word arrays A and B,

[0016] One 32-byte array M,

[0017] Three words w, c1, and c2;

[0018] This function is specifically:

[0019] Let the word x = 0x0706050403020100;

[0020] Traverse i from 0 to 31:

[0021] St.A[i] = x,

[0022] x = x + 0x0808080808080808;

[0023] St.A and St.B respectively represent arrays A and B of the internal state St, St.A[0:3] represents the first four elements of array A, St.M represents array M of the internal state St, and St.w, St.c1, and St.c2 represent words w, c1, and c2 of the internal state St. The symbol represents a memory copy operation. Let:

[0024] St.B = St.A,

[0025]

[0026] St.w = 0,

[0027] St.c1 = 0,

[0028] St.c2 = 0;

[0029] The reset of the internal state St is completed, and the reset internal state St is returned.

[0030] Preferably, the internal state update function used to update the initialized internal state with the original key key is applyKeyOrIV(key, szKey, St, rom). The original key key is a byte array containing szKey bytes, where szKey ≤ 64. The specific function is as follows:

[0031] Let Kiv be a byte array containing sz bytes, where sz ≤ 64;

[0032] Let i, j, k, l, p, q, r, and u all be bytes, a, b, c, d, m, n, and pw be words, and pkiv be an array of words;

[0033] (pkiv, pw) = processKeyOrIV(Kiv, sz);

[0034] The symbol facilitates the equivalent use of a more compact alias in the expression;

[0035] Perform 8 mixing operations on arrays A, B, and M:

[0036] Traverse p from 0 to 7:

[0037] First, perform a mixing operation on array M:

[0038]

[0039] (m, n, u) = computeByteMask(w), and the function computeByteMask(w) is used to calculate the byte mask.

[0040] (a, b, c, d) = mixWords(a, b, c, d, m, n, u),

[0041]

[0042] Perform a mixing operation on array A and array B:

[0043] Traverse q from 0 to 7:

[0044] pw = pw + pkiv[q],

[0045] u = q << 2,

[0046] (i, j, k, l) = M[u : u + 3],

[0047] Traverse r from 0 to rom - 1:

[0048] pw = (pw <<< 9) ⊕ (((A[i] + A[j]) ⊕ A[k]) + A[l]),

[0049] (m, n, u) = computeByteMask(pw),

[0050] (A[i], A[j], A[k], A[l]) = mixWords(A[i], A[j], A[k], A[l], m, n, u),

[0051] (i, j, k, l) = (M[i], M[j], M[k], M[l]),

[0052] pw = pw + (((B[i] ⊕ B[j]) + B[k]) ⊕ B[l]),

[0053] (m, n, u) = computeBitMask(pw), The function computeBitMask(pw) is used to calculate the bit mask,

[0054] (B[i], B[j], B[k], B[l]) = mixWords(B[i], B[j], B[k], B[l], m, n, u),

[0055] (i, j, k, l) = (i, j, k, l) ⊕ M[r & 0x1f],

[0056] Repeat the above steps until r is traversed from 0 to rom - 1, q is traversed from 0 to 7, and p is traversed from 0 to 7;

[0057] Update other state variables:

[0058] w = w + pw,

[0059]

[0060] (c1, c2) = (c1 + B[i] + B[j], c2 + B[k] + B[l])

[0061] (c1, c2) = (c1 | 0x05, c2 | 0xa0)

[0062] Return the updated internal state St;

[0063] The function mixWords(w1, w2, w3, w4, m, n, u) mixes multiple words by permuting bytes or bits.

[0064] Preferably, the function processKeyOrIV(Kiv, sz) is specifically as follows:

[0065] Pad the byte array Kiv to 64 bytes by concatenation:

[0066] i = sz

[0067] When i ≤ 32:

[0068] Kiv = Kiv || Kiv, where the symbol || represents the concatenation operation of concatenating two strings at the byte level

[0069] i = i << 1;

[0070] When i < 64:

[0071] i = 63 – i

[0072] Kiv ← Kiv || Kiv[0:i];

[0073] Calculate pw by concatenation of sz:

[0074] pw = sz || sz || sz || sz || sz || sz || sz || sz

[0075] sz represents the number of bytes included in the byte array Kiv;

[0076] Calculate the word array pkiv:

[0077]

[0078] Set the constant tm = 0x95ac9329ac4bc9b5

[0079] x = tm;

[0080] Traverse i from 0 to 7:

[0081] x = x + pw,

[0082] x = x ⊕ pkiv[i], where the symbol ⊕ represents the bitwise exclusive OR operation;

[0083] Traverse j from 0 to 7:

[0084] x = lfsr(x),

[0085] pkiv[j] = pkiv[j] + x,

[0086] Repeat the above operations until j is completely traversed;

[0087] Repeat the above operations until i is traversed from 0 to 7, and return pkiv and pw.

[0088] Preferably, the register state transition function lfsr(x) called in the function processKeyOrIV(Kiv, sz) is specifically:

[0089] i = x & 1, where the symbol & represents the bitwise AND operation,

[0090] x = x >> 1, where the symbol >> represents the logical right shift bitwise operation,

[0091] If i ≠ 0:

[0092]

[0093] Return the value of x.

[0094] Preferably:

[0095] The calculation function computeByteMask(w) of the byte mask is specifically:

[0096] m = w & 0x0101010101010101,

[0097] n = (m << 8) + 1,

[0098] m = m – n,

[0099]

[0100] u = w >> 61,

[0101] u = u << 3,

[0102] Return the values of m, n, and u;

[0103] The calculation function computeBitMask(w) of the bit mask is specifically:

[0104] m = w,

[0105]

[0106] u = w >>> 58,

[0107] Return the values of m, n, and u;

[0108] The function mixWords(w1, w2, w3, w4, m, n, u) is specifically as follows:

[0109] w1 = w1 >>> u,

[0110] w3 = w3 <<< u,

[0111] wt = (w1 & m) | (w2 & n),

[0112] w2 = (w2 & m) | (w3 & n),

[0113] w3 = (w3 & m) | (w4 & n),

[0114] w4 = (w4 & m) | (w1 & n),

[0115] w1 = wt,

[0116] m = m ^ (m >>> 32),

[0117]

[0118] w2 = w2 <<< u,

[0119] w4 = w4 >>> u,

[0120] t1 = (w2 & m) | (w4 & n),

[0121] t2 = (w3 & m) | (w1 & n),

[0122] t3 = (w4 & m) | (w2 & n),

[0123] t4 = (w1 & m) | (w3 & n),

[0124] Return the values of t1, t2, t3, and t4.

[0125] Preferably, when the initialized internal state is continuously updated by the initialization vector IV, the internal state update function used is the same as applyKeyOrIV(key, szKey, St, rom), which is St = applyKeyOrIV(IV, szIV, St, rom); where IV is a byte array containing szIV bytes, and szIV ≤ 64.

[0126] Preferably, the key stream generation function generate(St, rom, rog) is specifically as follows:

[0127]

[0128] w = reSeed(w);

[0129] Update the 128-bit counter (c1, c2) and the word w:

[0130] c1 = lfsr(c1),

[0131] If c1 = 1, then:

[0132] c2 = lfsr(c2),

[0133] w = w + (c1 ⊕ c2);

[0134] Mix the array M of the internal state St:

[0135]

[0136] (m, n, u) = computeByteMask(w),

[0137] (a, b, c, d) = mixWords(a, b, c, d, m, n, u),

[0138]

[0139] Update the word w, mix the arrays A and B, and generate the key stream:

[0140] Traverse q from 0 to 7:

[0141] u = q << 2,

[0142] (i, j, k, l) = M[u:u + 3];

[0143] Traverse r from 0 to rom - 1:

[0144] (a, b, c, d) = (A[i], A[j], A[k], A[l]),

[0145] w = (w <<< 9) ⊕ (((a + b) ⊕ c) + d),

[0146] (m, n, u) = computeByteMask(w),

[0147] (A[i], A[j], A[k], A[l]) = mixWords(a, b, c, d, m, n, u),

[0148] (i, j, k, l) = (M[i], M[j], M[k], M[l]),

[0149] (e, f, g, h) = (B[i], B[j], B[k], B[l]),

[0150] w = w + (((e ⊕ f) + g) ⊕ h),

[0151] (m, n, u) = computeBitMask(w),

[0152] (B[i], B[j], B[k], B[l]) = mixWords(e, f, g, h, m, n, u),

[0153] (i, j, k, l) = (i, j, k, l) ⊕ M[r & 0x1f],

[0154] Repeat the above steps until r is traversed from 0 to rom - 1;

[0155] Traverse r from 0 to rog - 1:

[0156] Traverse u from 0 to 7:

[0157] v = u << 2,

[0158] (a, b, c, d) = (a, b, c, d) ⊕ C[i + v : i + v + 3],

[0159] (e, f, g, h) = (e, f, g, h) + C[j + v : j + v + 3],

[0160] Output the result of (((a, b, c, d) + A[v : v + 3]) ⊕ (e, f, g, h)) + B[v : v +

[0161] 3],

[0162] Repeat the above steps until u is traversed from 0 to 7;

[0163] (i, j) = (i, j) ⊕ M[r & 0x1f],

[0164] Repeat the above steps until r is traversed from 0 to rog - 1, and return the internal state St;

[0165] The function reSeed() called above is specifically:

[0166] r = readCCC(), and the function readCCC() is used to read the current CPU clock cycle count into the word r, and then mix - process r,

[0167] r = r + (r <<< 31),

[0168] r = r + (r <<< 15),

[0169] r = r + (r <<< 7),

[0170] If the system-on-chip integrates a hardware random number generator, then:

[0171] r = r + readRAND(), where the function readRAND() is used to read a random word from the generation result of the hardware random number generator and add the read result to the word r,

[0172] Modify the input word w with r and use the modified w as the return value:

[0173] w = w ⊕ r.

[0174] Preferably, after generating the srt-th key stream each time, the refresh function refreshInternalState(St0, rom, src) for refreshing the internal state is specifically:

[0175] ctr = src,

[0176] Traverse i from 1 to 64:

[0177] ctr = lfsr(ctr),

[0178] Repeat the above formula until i is traversed from 1 to 64;

[0179] Then calculate the byte array IV from ctr through the following operations,

[0180] IV = ctr,

[0181] Traverse i from 1 to 7:

[0182] ctr = lfsr(ctr),

[0183] IV = IV || ctr,

[0184] Repeat the above formula until i is traversed;

[0185] St = St0, where St0 represents the internal state after initialization;

[0186] St = applyKeyOrIV(IV, 64, St, rom);

[0187] Return St.

[0188] Preferably:

[0189] If the state refresh threshold srt > 0, then:

[0190] St0 = St,

[0191] gctr = 0, where gctr is a word;

[0192] When the key stream generated by the key stream generation function has not reached the set length:

[0193] If srt > 0, gctr > 0 and gctr % srt = 0, then:

[0194] src = gctr ÷ srt,

[0195] St = refreshInternalState(St0; rom; src);

[0196] Regardless of whether gctr > 0 and gctr % srt = 0 are satisfied, the following formula is executed:

[0197] gctr = gctr + 1.

[0198] The beneficial effects of the present invention are:

[0199] The present invention has an extremely high encryption speed: when tested on an Intel Core i7 processor, the present invention can encrypt one byte in approximately half a clock cycle; when single-instruction multiple-data internal instructions are available, the present invention can encrypt one byte in a quarter of a clock cycle, and the encryption speed is approximately 19.8 to 56.9 times that of AES and 6.1 to 16.7 times that of the Intel AES new instruction (AES-NI, a hardware-optimized implementation of AES);

[0200] The present invention provides a fast-forward function, which can almost instantly jump to any position in a large file or long data stream, and then encrypt or decrypt the data at that position;

[0201] The present invention supports setting an upper limit on the data random access time to avoid the increase of the access time as the file length or data stream length increases infinitely, so as to achieve fast or real-time random access to files or data streams of any size;

[0202] The present invention adopts a cipher initialization algorithm that satisfies the strict avalanche criterion and a key stream generation algorithm that passes the most rigorous statistical test tools to ensure the generation of high-quality key streams;

[0203] The minimum period of the secret key stream of the present invention reaches 128 bits (i.e., 2 128 ≈ 3.40×10 38 ), and the average period reaches 2979 bits (2 2979 ≈ 5.87×10 896 ), effectively eliminating short periods and possible security problems caused by them;

[0204] By setting different ROM and ROG values, the stream cipher of the present invention can operate in different modes, and each mode has different security strengths and encryption speeds: The preliminary cryptographic security analysis results show that the encryption method of SSC can resist various known attacks; the designed security strength of SSC is 512 bits, roughly equivalent to the quantum security strength of 256 bits, and it is quantum secure; in addition, SSC is superior to most well-known pseudorandom number generators serving non-security applications in terms of statistical characteristics, speed, and cycle length. Therefore, SSC is also very suitable for use in non-security applications;

[0205] The present invention can be used both as a stream cipher and as a pseudorandom number generator. When used as a pseudorandom number generator, it can generate pseudorandom numbers in either a deterministic mode or a non-deterministic mode; when generating pseudorandom numbers in a non-deterministic mode, SSC is similar to a true random number generator and can generate high-quality and non-repeating pseudorandom numbers, which can be used as keys, initialization vectors, seeds, salts, challenges, etc. for various cryptographic systems;

[0206] When the present invention performs a permutation operation, instead of moving bytes or bits one by one like traditional methods, it randomly selects a group of bytes or bits from an integer in a pseudorandom manner and uses integer operations to move the selected bytes or bits as a whole to improve efficiency;

[0207] The cryptographic permutation operation based on integer operations in the present invention can be used to replace the traditional cryptographic permutation operations used in other security systems, thereby improving the operating efficiency of these security systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0208] Figure 1 It is a diagram of the overall encryption process of the present invention;

[0209] Figure 2 It is a diagram of the overall decryption process of the present invention;

[0210] Figure 3 It is a detailed diagram of the encryption process of the present invention;

[0211] Figure 4 It is a detailed diagram of the decryption process of the present invention;

[0212] Figure 5 It is a schematic diagram of continuously updating the internal state during the key stream generation process;

[0213] Figure 6 It is a schematic diagram of generating the key stream for ROG times;

[0214] Figure 7 It is a schematic diagram of extracting bytes according to a byte mask;

[0215] Figure 8 Schematic diagram for extracting bits according to a bit mask;

[0216] Figure 9 Schematic diagram for updating the word w of the internal state in non-deterministic mode. Detailed implementation manners

[0217] The present invention will be further described below in conjunction with embodiments. The descriptions of the following embodiments are only for helping to understand the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.

[0218] As an embodiment, the stream cipher encryption and decryption method based on integer operation cryptography permutation is specifically as follows:

[0219] Assume that the plaintext sequence is x i = x0, x1, x2... x n , and the ciphertext sequence is y i = y0, y1, y2... y n , and the original key key and the initialization vector IV generate a key stream z after the overall SSC operation i = z0, z1, z2... z n ;

[0220] As Figures 1 to 4 shown, during encryption, the plaintext sequence and the key stream are subjected to an exclusive OR operation; during decryption, the ciphertext sequence and the same key stream are subjected to an exclusive OR operation. The exclusive OR operation in the figure is represented by the symbol ⊕, f is the state update function, St is the internal state, and gen is the key stream generation function;

[0221] The encryption process is: y i = x i ⊕ z i ;

[0222] The decryption process is: x i = y i ⊕ z i ;

[0223] The process of generating the key stream by the overall SSC operation is roughly divided into two parts: (1). Initialization of the internal state in the early stage: First, reset the internal state, then update the internal state with the key, and then further update the internal state with the IV; (2). Calculate and output the key stream, and the internal state is continuously updated during the process of outputting the key stream;

[0224] (1) Initialization of the internal state in the early stage

[0225] The reset function for initializing the internal state is resetInternalState(St), where St represents the internal state, and the internal state St consists of:

[0226] Two 32-word arrays A and B,

[0227] A 32-byte array M,

[0228] Three words w, c1, and c2; c1 and c2 together form a 128-bit counter

[0229] Specifically, the function is as follows:

[0230] Let the word x = 0x0706050403020100;

[0231] Traverse i from 0 to 31:

[0232] St.A[i] = x,

[0233] x = x + 0x0808080808080808;

[0234] St.A and St.B respectively represent arrays A and B of the internal state St, St.A[0:3] represents the first four elements of array A, St.M represents array M of the internal state St, St.w, St.c1, and St.c2 represent words w, c1, and c2 of the internal state St, and the symbol represents the memory copy operation, and let:

[0235] St.B = St.A,

[0236]

[0237] St.w = 0,

[0238] St.c1 = 0,

[0239] St.c2 = 0;

[0240] The reset of the internal state St is completed, and the reset internal state St is returned;

[0241] The above operation process resets the internal state St. Specifically, it takes two 32-word arrays St.A and St.B as two 256-byte tables, initializes them respectively as identity permutations of size 256 (the value of each element in the identity permutation is equal to its index in the permutation), initializes the 32-byte array M as an identity permutation of size 32, and sets all other variables in St to 0. For example: if St.A[0] = 0x0706050403020100, then St.A[1] = St.A[0] + 0x0808080808080808, St.A[2] = St.A[1] + 0x0808080808080808... and so on, St.A

[31] = St.A

[30] + 0x0808080808080808. The value of St.B is the same as that of St.A. The value of St.M is the value of the first 4 words of St.A.

[0242] The methods of first updating the internal state with the key and then continuing to update the internal state with the IV are as follows:

[0243] Let the constant tm = 0x95ac9329ac4bc9b5, Kiv be a byte array containing sz bytes, where sz ≤ 64;

[0244] Let i, j, k, l, p, q, r, and u all be bytes, a, b, c, d, m, n, and pw be words, and pkiv be a word array;

[0245] (pkiv, pw) = processKeyOrIV(Kiv, sz);

[0246]

[0247] Perform 8 mixing operations on arrays A, B, and M:

[0248] Traverse p from 0 to 7:

[0249] First perform a mixing operation on array M:

[0250]

[0251] (m, n, u) = computeByteMask(w), and the function computeByteMask(w) is used to calculate the byte mask,

[0252] (a, b, c, d) = mixWords(a, b, c, d, m, n, u),

[0253]

[0254] Perform mixing operations on arrays A and B:

[0255] Traverse q from 0 to 7:

[0256] pw = pw + pkiv[q],

[0257] u = q << 2,

[0258] (i, j, k, l) = M[u:u + 3],

[0259] Traverse r from 0 to rom - 1:

[0260] pw = (pw <<< 9) ⊕ (((A[i] + A[j]) ⊕ A[k]) + A[l]),

[0261] (m, n, u) = computeByteMask(pw),

[0262] (A[i], A[j], A[k], A[l]) = mixWords(A[i], A[j], A[k], A[l], m, n, u),

[0263] (i, j, k, l) = (M[i], M[j], M[k], M[l]),

[0264] pw = pw + (((B[i] ⊕ B[j]) + B[k]) ⊕ B[l]),

[0265] (m, n, u) = computeBitMask(pw), The function computeBitMask(pw) is used to calculate the bit mask,

[0266] (B[i], B[j], B[k], B[l]) = mixWords(B[i], B[j], B[k], B[l], m, n, u),

[0267] (i, j, k, l) = (i, j, k, l) ⊕ M[r & 0x1f],

[0268] Repeat the above steps until r is traversed from 0 to rom - 1, q is traversed from 0 to 7, and p is traversed from 0 to 7;

[0269] Update other state variables:

[0270] w = w + pw,

[0271]

[0272] (c1, c2) = (c1 + B[i] + B[j], c2 + B[k] + B[l]),

[0273] (c1, c2) = (c1 | 0x05, c2 | 0xa0),

[0274] Return the updated internal state St;

[0275] As Figure 5 shown, during the process of generating the key stream, the internal state continues to be updated by the function mixWords(w1, w2, w3, w4, m, n, u) which mixes multiple words by permuting bytes or bits. The function mixWords(w1, w2, w3, w4, m, n, u) is specifically as follows:

[0276] w1 = w1 >>> u,

[0277] w3 = w3 <<< u,

[0278] w t = (w1 & m) | (w2 & n),

[0279] w2 = (w2 & m) | (w3 & n),

[0280] w3 = (w3 & m) | (w4 & n),

[0281] w4 = (w4 & m) | (w1 & n),

[0282] w1 = wt,

[0283] m = m ⊕ (m >>> 32),

[0284]

[0285] w2 = w2 <<< u,

[0286] w4 = w4 >>> u,

[0287] t1 = (w2 & m) | (w4 & n),

[0288] t2 = (w3 & m) | (w1 & n),

[0289] t3 = (w4 & m) | (w2 & n),

[0290] t4 = (w1 & m) | (w3 & n),

[0291] Return the values of t1, t2, t3, and t4.

[0292] The above internal state initialization process uses a key or initialization vector (IV) to update the internal state St. This key or initialization vector is denoted as kiv, which is a byte array containing sz bytes (sz ≤ 64). Word rom (abbreviation for rounds of mixing) refers to the number of rounds of mixing operations to be performed, which is a global cryptographic parameter.

[0293] The function processKeyOrIV(Kiv,sz) called by the above internal state initialization process is specifically as follows:

[0294] Pad the byte array Kiv to 64 bytes by concatenation:

[0295] i = sz,

[0296] When i ≤ 32:

[0297] Kiv = Kiv||Kiv,

[0298] i = i<<1;

[0299] When i < 64:

[0300] i = 63–i,

[0301] Kiv←Kiv||Kiv[0:i];

[0302] Calculate pw by concatenating sz:

[0303] pw = sz||sz||sz||sz||sz||sz||sz||sz,

[0304] sz represents the number of bytes included in the byte array Kiv;

[0305] Calculate the word array pkiv:

[0306]

[0307] Set the constant tm = 0x95ac9329ac4bc9b5,

[0308] x = tm;

[0309] Traverse i from 0 to 7:

[0310] x = x+pw,

[0311] x = x⊕pkiv[i],

[0312] Traverse j from 0 to 7:

[0313] x = lfsr(x),

[0314] pkiv[j] = pkiv[j] + x,

[0315] Repeat the above operation until j is traversed completely;

[0316] Repeat the above operation until i is traversed from 0 to 7, and return pkiv and pw.

[0317] (2) Calculate and output the key stream, and continuously update the internal state during the output of the key stream;

[0318] The design goal of the SSC stream cipher is to output a high-quality key stream securely and efficiently. SSC will continue to update the internal state during the generation of the key stream, that is, first perform rom times of mixing on the current St. In each mixing, byte mixing is performed on the first table St.A, and then bit mixing is performed on the second table St.B. After updating the internal state, SSC then executes rog times of loops to output the key stream. The key stream generation function generate(St, rom, rog) is specifically as follows:

[0319]

[0320] w = reSeed (w);

[0321] Update the 128-bit counter (c1, c2) and the word w:

[0322] c1 = lfsr(c1),

[0323] If c1 = 1, then:

[0324] c2 = lfsr(c2),

[0325] w = w + (c1 ⊕ c2);

[0326] Mix the array M of the internal state St:

[0327]

[0328] (m, n, u) = computeByteMask(w),

[0329] (a, b, c, d) = mixWords(a, b, c, d, m, n, u),

[0330]

[0331] Update the word w, mix the array A and the array B, and generate the key stream:

[0332] Traverse q from 0 to 7:

[0333] u = q << 2,

[0334] (i, j, k, l) = M[u : u + 3];

[0335] Traverse r from 0 to rom - 1:

[0336] (a, b, c, d) = (A[i], A[j], A[k], A[l]),

[0337] w = (w <<< 9) ⊕ (((a + b) ⊕ c) + d),

[0338] (m, n, u) = computeByteMask(w),

[0339] (A[i], A[j], A[k], A[l]) = mixWords(a, b, c, d, m, n, u),

[0340] The process of extracting bytes during the mixing process is as Figure 7 shown: Assume the input word X = 0xA51A3B6D51235AB1, and after the operation, m = 0x0000FFFFFF00FFFF;

[0341] (i, j, k, l) = (M[i], M[j], M[k], M[l]),

[0342] (e, f, g, h) = (B[i], B[j], B[k], B[l]),

[0343] w = w + (((e ⊕ f) + g) ⊕ h),

[0344] (m, n, u) = computeBitMask(w),

[0345] (B[i], B[j], B[k], B[l]) = mixWords(e, f, g, h, m, n, u), The process of extracting bits during the mixing process is as Figure 8 shown: Assume the input word X = 0xA51A3B6D51235AB1, and after the operation, m = 0xB4E7D638CA831E5A;

[0346] (i, j, k, l) = (i, j, k, l) ⊕ M[r & 0x1f],

[0347] Repeat the above steps until r is traversed from 0 to rom - 1;

[0348] Traverse r from 0 to rog - 1:

[0349] Traverse u from 0 to 7:

[0350] v = u << 2,

[0351] (a, b, c, d) = (a, b, c, d) ⊕ C[i + v : i + v + 3],

[0352] (e, f, g, h) = (e, f, g, h) + C[j + v : j + v + 3],

[0353] Output the result of (((a, b, c, d) + A[v : v + 3]) ⊕ (e, f, g, h)) + B[v : v +

[0354] 3],

[0355] Repeat the above steps until u is traversed from 0 to 7;

[0356] (i, j) = (i, j) ⊕ M[r & 0x1f],

[0357] As Figure 6 shown, repeat the above steps until r is traversed from 0 to rog - 1, and return the internal state St;

[0358] When the function mixWords uses a byte mask, the byte is extracted (when a certain byte of the mask m is FF, the corresponding byte of x is extracted, and when a certain byte of the mask m is 00, the corresponding byte of x is masked); when using a bit mask, the bit is extracted (when a certain bit of the mask m is 1, the corresponding bit of x is extracted, and when a certain bit of the mask m is 0, the corresponding bit of x is masked);

[0359] The function reSeed() called above is specifically:

[0360] r = readCCC(), and the function readCCC() is used to read the current CPU clock cycle count into the word r, and then mix r,

[0361] r = r + (r <<< 31),

[0362] r = r + (r <<< 15),

[0363] r = r + (r <<< 7),

[0364] If the system - on - chip integrates a hardware random number generator, then:

[0365] r = r + readRAND(), and the function readRAND() is used to read a random word from the generation result of the hardware random number generator and add the read result to the word r,

[0366] Modify the input word w with r and use the modified w as the return value:

[0367] w = w ⊕ r。

[0368] The key stream generation function generate(St, rom, rog) can be repeatedly called to generate a key stream of the required length. The word rom (abbreviation for rounds of mixing) refers to the number of cycles of the mixing operation to be performed, and the byte rog (abbreviation for rounds of generation) refers to the number of cycles of the key stream generation operation to be performed after the mixing operation. They are two global cryptographic parameters.

[0369] The designed security strength of the SSC stream cipher is 512 bits. Since rog is a byte, its maximum value can reach 255. Even when rog = 255, the key stream output by SSC still has very high quality and cannot be distinguished from a true random number sequence using existing popular statistical test tools. In actual use, SSC adopts a relatively conservative security policy, and it is recommended that the value of rog used does not exceed 8.

[0370] srt indicates that the internal state needs to be refreshed after every srt calls to the function generate. When refreshing the internal state each time, the following steps are executed: First, calculate an IV based on src (state refreshing counter, which is the current call count of the function generate), then copy the saved St0 during the initialization process to St, and finally call applyKeyOrIV with the calculated IV as a parameter to further update St. The refresh function refreshInternalState(St0, rom, src) for refreshing the internal state is specifically as follows:

[0371] ctr = src,

[0372] Traverse i from 1 to 64:

[0373] ctr = lfsr(ctr),

[0374] Repeat the above formula until i has been traversed from 1 to 64;

[0375] Then calculate the byte array IV from ctr through the following operations

[0376] IV = ctr,

[0377] Traverse i from 1 to 7:

[0378] ctr = lfsr(ctr),

[0379] IV = IV || ctr,

[0380] Repeat the above formula until i has been traversed;

[0381] St = St0, where St0 represents the internal state after initialization;

[0382] St = applyKeyOrIV(IV, 64, St, rom);

[0383] Return St.

[0384] The function refreshInternalState provides a function to directly jump to the corresponding internal state from a given src value. The time required for this state jump does not increase as the src value becomes larger. That is to say, the jump time is the same each time and is almost real-time. There are srt calls to the generate function between two adjacent calls to the refreshInternalState function. Therefore, this jump cannot reach every state but can only reach a certain state interval. The size of each state interval is determined by srt. The smaller the interval, the smaller the upper limit of the time required to access any state in the interval, that is, the smaller the guaranteed random access delay of the data.

[0385] When the SSC works in the non-deterministic mode, an update operation will be performed on St.w. For example, on a system that supports reading true random numbers, the value of St.w can be determined by the read true random number value, making it non-repeatable, or in other words, having uncertainty. Since St.w will be used as the input for the functions computeByteMask and computeBitMaks for mask calculation, the mask will also have uncertainty. Combining Figure 5 It can be seen that the core of the mixWords operation is to use St.w for mask calculation and the corresponding mixed word operation. Therefore, the internal state after the mixWords operation will also have uncertainty, and of course, the final generated output result will also have uncertainty. The update of the internal state in the non-deterministic mode is as Figure 9 shown.

[0386] From the implementation principle of the SSC in the non-deterministic mode, it can be seen that the SSC in the non-deterministic mode is similar to a true random number generator and can be used in many applications, such as providing random Keys for encryption and decryption, providing random numbers for lotteries or games, providing salts for password hashing operations, etc. Different from the true random number generator, the SSC in the non-deterministic mode has higher speed, lower cost, and is easier to implement.

[0387] As can be seen from Table 1 and Table 2 below, the SSC of the present invention is superior to the existing algorithms in both the key stream generation speed and the data encryption speed; in Table 1 and Table 2, m2 in SSC-m2g1 means rom = 2, and g1 means rog = 1, and so on; in addition, FF is the abbreviation of FastForwarding, indicating that the measured is the fast forward speed; all tests are completed on an Intel Core i7 processor.

[0388] Table 1 Comparison Table of Key Stream Generation Speed (cycles / byte)

[0389] Keystream size(KB) 1 10 100 1000 10000 RC4 5.87 3.88 3.80 3.81 3.83 HC-128 18.5 3.17 1.52 1.35 1.34 Rabbit 6.65 5.36 5.25 5.23 5.24 Salsa20 6.51 5.94 5.84 5.83 5.90 Sosemanuk 13.6 3.13 2.02 1.91 1.90 ChaCha8 7.22 2.8 2.35 2.30 2.30 ChaCha12 8.11 3.79 3.34 3.29 3.29 ChaCha20 10.09 5.77 5.31 5.27 5.28 ZUC (Zuchongzhi algorithm) 31.38 23.27 22.27 22.13 22.19 SSC-m2g1 15.17 2.25 0.93 0.81 0.79 SSC-m1g1 10.51 1.56 0.63 0.53 0.52 SSC-m1g2 10.48 1.43 0.51 0.42 0.41 SSC-m1g4 10.41 1.39 0.45 0.35 0.34 SSC-m1g8 10.42 1.38 0.42 0.31 0.30 SSC-m2g1 SSE2 15.39 2.24 0.91 0.77 0.76 SSC-m1g1 SSE2 10.62 1.56 0.62 0.52 0.51 SSC-m1g2 SSE2 10.41 1.42 0.49 0.39 0.38 SSC-m1g4 SSE2 10.33 1.38 0.43 0.33 0.32 SSC-m1g8 SSE2 10.37 1.36 0.39 0.28 0.27 SSC-m2g1 AVX2 13.4 1.90 0.68 0.55 0.54 SSC-m1g1 AVX2 9.33 1.27 0.44 0.35 0.35 SSC-m1g2 AVX2 9.27 1.16 0.33 0.24 0.23 SSC-m1g4 AVX2 9.26 1.14 0.28 0.18 0.18 SSC-m1g8 AVX2 9.30 1.05 0.23 0.14 0.14 SSC-m2g1 FF 0.69 0.52 0.51 0.51 0.51 SSC-m1g1 FF 0.35 0.27 0.26 0.26 0.26 SSC-m1gx FF 0.35 / x 0.27 / x 0.26 / x 0.26 / x 0.26 / x

[0390] Table 2 Comparison Table of Data Encryption Speed (cycles / byte)

[0391]

[0392]

Claims

1. A method for encrypting and decrypting a stream cipher based on integer operation cryptographic permutation, characterized in that, It includes the following steps: Abbreviate the stream cipher based on integer operation cryptography permutation as SSC; During encryption: Receive the plaintext sequence; Given the original key key, initialization vector IV, the number of loops rom for the mixing operation, the number of loops rog for the key stream generation operation, and the state refresh threshold srt, generate the key stream after the overall SSC operation; Perform an exclusive OR operation on the plaintext sequence and the generated key stream to obtain the ciphertext sequence; During decryption: Receive the ciphertext sequence; Given the original key key, initialization vector IV, the number of loops rom for the mixing operation, the number of loops rog for the key stream generation operation, and the state refresh threshold srt, generate the key stream after the overall SSC operation; Perform an exclusive OR operation on the ciphertext sequence and the generated key stream to obtain the plaintext sequence; The specific way for the overall SSC operation to generate the key stream is as follows: Initialize the internal state through the reset function; The reset function is resetInternalState(St), where St represents the internal state, and the internal state St consists of: Two 32-word arrays A and B, A 32-byte array M, Three words w, c1, and c2; The specific function is: Let the word x = 0x0706050403020100; Traverse i from 0 to 31: St.A[i] = x, x = x + 0x0808080808080808; St.A and St.B respectively represent arrays A and B of the internal state St, St.A[0:3] represents the first four elements of array A, St.M represents array M of the internal state St, St.w, St.c1, and St.c2 represent words w, c1, and c2 of the internal state St, and the symbol ⟸ represents the memory copy operation. Let: St.B = St.A, St.M ⟸ St.A[0:3] St.w = 0, St.c1 = 0, St.c2 = 0; The reset of the internal state St is completed, and the reset internal state St is returned Use the original key key to update the initialized internal state through the internal state update function; The internal state update function is applyKeyOrIV(key, szKey, St, rom), and the original key key is a byte array containing szKey bytes, where szKey ≤ 64; The specific function is: Let Kiv be a byte array containing sz bytes, where sz ≤ 64; Let i, j, k, l, p, q, r, and u be bytes, a, b, c, d, m, n, and pw be words, and pkiv be an array of words; (pkiv, pw) = processKeyOrIV(Kiv, sz); (A, B, M, w, c1, c2) ↔ (St.A, St.B, St.M, St.w, St.c1, St.c2), and the symbol ↔ is used to set aliases for variables; Perform 8 mixing operations on arrays A, B, and M: Traverse p from 0 to 7: First perform a mixing operation on array M: (a, b, c, d) ⟸ M, (m, n, u) = computeByteMask (w), where the function computeByteMask (w) is used to calculate the byte mask, (a, b, c, d) = mixWords (a, b, c, d, m, n, u), M ⟸ (a, b, c, d), Perform a mixing operation on arrays A and B: Traverse q from 0 to 7: pw = pw + pkiv[q], u = q << 2, where the symbol << represents the bitwise operation of logical left shift, (i, j, k, l) = M[u : u + 3], Traverse r from 0 to rom - 1: pw = (pw <<< 9) ⊕ (((A[i] + A[j]) ⊕ A[k]) + A[l]), where the symbol <<< represents the bitwise operation of left rotation, (m, n, u) = computeByteMask (pw), (A[i], A[j], A[k], A[l]) = mixWords (A[i], A[j], A[k], A[l], m, n, u), (i, j, k, l) = (M[i], M[j], M[k], M[l]), pw = pw + (((B[i] ⊕ B[j]) + B[k]) ⊕ B[l]), (m, n, u) = computeBitMask (pw), where the function computeBitMask (pw) is used to calculate the bit mask, (B[i], B[j], B[k], B[l]) = mixWords (B[i], B[j], B[k], B[l], m, n, u), (i, j, k, l) = (i, j, k, l) ⊕ M[r & 0x1f], Repeat the above steps until r is traversed from 0 to rom - 1, q is traversed from 0 to 7, and p is traversed from 0 to 7; Update other state variables: w = w + pw, (i, j, k, l) ⟸ pw & 0x1f1f1f1f, (c1, c2) = (c1 + B[i] + B[j], c2 + B[k] + B[l]), (c1, c2) = (c1 | 0x05, c2 | 0xa0), Return the updated internal state St; The function mixWords (w1, w2, w3, w4, m, n, u) mixes multiple words by permuting bytes or bits; Use the initialization vector IV to continue updating the internal state updated by the original key key through the internal state update function; Generate a key stream through a key stream generation function using a given original key key, initialization vector IV, number of rounds rom of the mixing operation, number of rounds rog of the key stream generation operation, and state refresh threshold srt; after generating the key stream srt times, refresh the internal state through a refresh function until the generated key stream reaches the required length; the function processKeyOrIV (Kiv, sz) is specifically as follows: Pad the byte array Kiv to 64 bytes by concatenation: i = sz, When i ≤ 32: Kiv = Kiv || Kiv, where the symbol || represents the concatenation operation of concatenating two strings at the byte level, i = i << 1; When i < 64: i = 63 – i, Kiv ← Kiv || Kiv[0:i]; Calculate the word pw by concatenating sz: pw = sz || sz || sz || sz || sz || sz || sz || sz, sz represents the number of bytes included in the byte array Kiv; Calculate the word array pkiv: pkiv ⟸ kiv; Set the constant tm = 0x95ac9329ac4bc9b5, x = tm; Traverse i from 0 to 7: x = x + pw, x = x ⊕ pkiv[i], where the symbol ⊕ represents the bitwise exclusive OR operation; Traverse j from 0 to 7: x = lfsr (x), pkiv[j] = pkiv[j] + x, Repeat the above operations until j is traversed; Repeat the above operations until i is traversed from 0 to 7, and return pkiv and pw; The register state conversion function lfsr (x) called in the function processKeyOrIV (Kiv, sz) is specifically as follows: i = x & 1, where the symbol & represents the bitwise AND operation, x = x >> 1, where the symbol >> represents the logical right shift bitwise operation, If i ≠ 0: x = x tm; Return the value of x; The function computeByteMask(w) for calculating the byte mask is specifically as follows: m = w & 0x0101010101010101, n = (m ≪ 8) + 1, m = m - n, n = m(—), where the symbol ¯ represents the inversion operation of swapping 0 and 1, u = w ≫ 61, u = u ≪ 3, Return the values of m, n, and u; The function computeBitMask (w) for calculating the bit mask is specifically as follows: m = w, n = m(—), u = w ≫ 58, Return the values of m, n, and u; The function mixWords (w1, w2, w3, w4, m, n, u) is specifically as follows: w1 = w1 >>> u, where the symbol >>> represents the right rotation bitwise operation, w3 = w3 <<< u, where the symbol <<< represents the left rotation bitwise operation, w t = (w1 & m) | (w2 & n), where the symbol | represents the bitwise operation of OR, w2 = (w2 & m) | (w3 & n), w3 = (w3 & m) | (w4 & n), w4 = (w4 & m) | (w1 & n), w1 = w t , m = m ⊕ (m >>> 32), n = m(—), w2 = w2 <<< u, w4 = w4 >>> u, t1 = (w2 & m) | (w4 & n), t2 = (w3 & m) | (w1 & n), t3 = (w4 & m) | (w2 & n), t4 = (w1 & m) | (w3 & n), Return t 1、 t 2、 The values of t3 and t4; The key stream generation function generate(St, rom, rog) is specifically as follows: (A, B, C, M, w, c1, c2) ↔ (St.A, St.B, St.C, St.M, St.w, St.c1, St.c2); w = reSeed (w); Update the 128-bit counter (c1, c2) and the word w: c1 = lfsr (c1), If c1 = 1, then: c2 = lfsr (c2), w = w + (c1 ⊕ c2); Mix the array M of the internal state St: (a, b, c, d) ⟸ M, (m, n, u) = computeByteMask (w), (a, b, c, d) = mixWords (a, b, c, d, m, n, u), M ⟸ (a, b, c, d); Update the word w, mix the arrays A and B, and generate the key stream: Traverse q from 0 to 7: u = q << 2, (i, j, k, l) = M[u : u + 3]; Traverse r from 0 to rom - 1: (a, b, c, d) = (A[i], A[j], A[k], A[l]), w = (w <<< 9) ⊕ (((a + b) ⊕ c) + d), (m, n, u) = computeByteMask (w), (A[i], A[j], A[k], A[l]) = mixWords (a, b, c, d, m, n, u), (i, j, k, l) = (M[i], M[j], M[k], M[l]), (e, f, g, h) = (B[i], B[j], B[k], B[l]), w = w + (((e ⊕ f) + g) ⊕ h), (m, n, u) = computeBitMask (w), (B[i], B[j], B[k], B[l]) = mixWords (e, f, g, h, m, n, u), (i, j, k, l) = (i, j, k, l) ⊕ M[r & 0x1f], Repeat the above steps until r is traversed from 0 to rom - 1; Traverse r from 0 to rog - 1: Traverse u from 0 to 7: v = u << 2, (a, b, c, d) = (a, b, c, d) ⊕ C[i + v : i + v + 3], (e, f, g, h) = (e, f, g, h) + C[j + v : j + v + 3], Output the result of (((a, b, c, d) + A[v : v + 3]) ⊕ (e, f, g, h)) + B[v : v + 3], Repeat the above steps until u is traversed from 0 to 7; (i, j) = (i, j) ⊕ M[r & 0x1f], Repeat the above steps until r is traversed from 0 to rog - 1, and return the internal state St; The specific function reSeed() called above is: r = readCCC (), the function readCCC() is used to read the current CPU clock cycle count into the word r, and then mix r, r = r + (r <<< 31), r = r + (r <<< 15), r = r + (r <<< 7), If the system chip integrates a hardware random number generator, then: r = r + readRAND(), the function readRAND() is used to read a random word from the generation result of the hardware random number generator and add the read result to the word r, Modify the input word w with r and use the modified w as the return value: w = w ⊕ r; The specific function refreshInternalState (St0, rom, src) for refreshing the internal state is: ctr = src, Traverse i from 1 to 64: ctr = lfsr (ctr), Repeat the above formula until i is traversed from 1 to 64; Then calculate the byte array IV from ctr through the following operations, IV = ctr, Traverse i from 1 to 7: ctr = lfsr (ctr), IV = IV || ctr, Repeat the above formula until i is traversed; St = St0, St0 represents the internal state after initialization; St = applyKeyOrIV (IV, 64, St, rom); Return St; If the state refresh threshold srt > 0, then: St0 = St, gctr = 0, gctr is a word; When the key stream generated by the key stream generation function has not reached the set length: If srt > 0, gctr > 0 and gctr % srt = 0, the symbol % represents the modulo operation, then: src = gctr ÷ srt, St = refreshInternalState(St0; rom; src); Regardless of whether gctr > 0 and gctr % srt = 0 are satisfied, the following formula is executed: gctr = gctr + 1.

2. The encryption and decryption method of the stream cipher based on integer operation cryptography permutation according to claim 1, characterized in that: When updating the initialized internal state with the initialization vector IV, the internal state update function used is the same as applyKeyOrIV(key, szKey, St, rom), which is St = applyKeyOrIV(IV, szIV, St, rom); where IV is a byte array containing szIV bytes, and szIV ≤ 64.

Citation Information

Patent Citations

  • Sequence password realization method and key stream generating method and device

    CN103701591A

  • Method and system for generating unpredictable pseudo-random numbers

    US20130129088A1