A White-Box SM4 Encryption Method and System Based on Multidimensional Linear Masking
By using multi-dimensional linear mask protection keys in the white box SM4 encryption method, the problem that the prior art is difficult to resist differential calculation and differential fault attacks is solved, and higher security and faster encryption speed are achieved.
Patent Information
- Application Number
- CN202211673922.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-26
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-12-26
AI Technical Summary
The existing white box SM4 algorithm based on lookup tables is difficult to resist differential computing attacks and differential fault attacks. Although the implementation based on Boolean mask can resist DCA-like attacks, it has a high time and space overhead.
The multi-dimensional linear mask is used to protect the key, and through the encryption of several wheel functions, the XOR operation, S-box operation and linear layer technologies are used to achieve effective protection of the key.
This method can effectively resist DCA, DFA and other attacks, has stronger security, and achieves lower cost and faster encryption speed under the same security level.
Smart Images

Figure CN116132019B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of encryption, and particularly relates to a white-box SM4 encryption method and system based on multi-dimensional linear masks. Background Technique
[0002] The statements in this part only provide background technical information related to the present invention, and do not necessarily constitute prior art.
[0003] The SM4 algorithm is a commercial cryptography standard algorithm. Nowadays, most white-box SM4 algorithms are implemented based on lookup tables. In 2009, Xiao Yayin et al. proposed the first white-box implementation scheme of the SM4 algorithm, also known as the Xiao-Lai white-box SM4. Subsequently, in 2020, the white-box SM4 scheme with internal state expansion proposed by Yao Si et al. significantly increased the complexity of key extraction. In 2021, Lin Tingting et al. analyzed some existing white-box SM4 algorithms, and used BGE attack, affine equivalence attack, and DCA attack to attack the Xiao-Lai white-box, Bai-Wu white-box, Shi-Yang white-box, and the white-box scheme proposed by Yao Si et al., respectively, and proposed a SM4 white-box design scheme resistant to first-order DCA attack.
[0004] In 2018, Biryukov proposed a white-box AES implementation based on Boolean masks, which can effectively resist conventional attacks and DCA-like attacks, but has large time and space overheads.
[0005] Most of the existing white-box SM4 algorithms based on lookup tables do not resist differential computation attacks and differential fault attacks; while the implementation based on Boolean masks has large overheads. The reason is that: the structure of the white-box SM4 scheme based on lookup tables is obviously exposed, it is easy to locate the memory address, and then launch a DCA attack targeted; although the scheme using Boolean masks can resist most existing DCA-like attacks, adding non-linear masks and linear masks in each round will bring large overheads. Summary of the Invention
[0006] In order to solve the technical problems existing in the above background technique, the present invention provides a white-box SM4 encryption method and system based on multi-dimensional linear masks, which use multi-dimensional linear masks to protect the key from being extracted, can resist existing white-box attack methods, and resist attacks such as DCA and DFA, and have stronger security.
[0007] In order to achieve the above object, the present invention adopts the following technical solutions:
[0008] The first aspect of the present invention provides a white-box SM4 encryption method based on multi-dimensional linear masks, which includes:
[0009] Obtain a secret key and a plaintext, and split the plaintext bit by bit into first data, second data, third data, and fourth data;
[0010] Based on a secret key, first data, second data, third data, and fourth data, ciphertext is obtained through encryption by a number of rounds of round functions;
[0011] Among them, in each round of round function, the second data, third data, and fourth data are subjected to an exclusive OR operation to obtain a first exclusive OR operation result. After the first exclusive OR operation result, the secret key, and the first data are respectively split into a number of shares by different encoding functions, the shares corresponding to the first exclusive OR operation result and the shares corresponding to the secret key are subjected to an exclusive OR operation, an S-box operation, and a linear layer, and then an exclusive OR operation is performed with the shares corresponding to the first data to obtain a second exclusive OR operation result. Based on the second exclusive OR operation result, the input of the next round of round function is obtained.
[0012] Furthermore, the S-box operation adopts non-linear mask protection.
[0013] Furthermore, the share represents a basis vector of a multi-dimensional linear space.
[0014] Furthermore, the second exclusive OR operation result is input into a decoding function to obtain the input of the next round of round function.
[0015] The second aspect of the present invention provides a white-box SM4 encryption system based on multi-dimensional linear masking, which includes:
[0016] A data acquisition module, which is configured to: acquire a secret key and plaintext, and split the plaintext bit by bit into first data, second data, third data, and fourth data;
[0017] An encryption module, which is configured to: based on the secret key, first data, second data, third data, and fourth data, obtain ciphertext through encryption by a number of rounds of round functions;
[0018] Among them, in each round of round function, the second data, third data, and fourth data are subjected to an exclusive OR operation to obtain a first exclusive OR operation result. After the first exclusive OR operation result, the secret key, and the first data are respectively split into a number of shares by different encoding functions, the shares corresponding to the first exclusive OR operation result and the shares corresponding to the secret key are subjected to an exclusive OR operation, an S-box operation, and a linear layer, and then an exclusive OR operation is performed with the shares corresponding to the first data to obtain a second exclusive OR operation result. Based on the second exclusive OR operation result, the input of the next round of round function is obtained.
[0019] The third aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps in a white-box SM4 encryption method based on multi-dimensional linear masking as described above are implemented.
[0020] The fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps in a white-box SM4 encryption method based on multi-dimensional linear masking as described above are implemented.
[0021] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0022] The present invention provides a white-box SM4 encryption method based on multi-dimensional linear masking, which uses multi-dimensional linear masking to protect the key from being extracted, can resist existing white-box attack methods, and resist attacks such as DCA and DFA, and has stronger security.
[0023] The present invention provides a white-box SM4 encryption method based on multi-dimensional linear masking, which has a smaller implementation cost and a faster encryption speed under the same security level.
[0024] The present invention provides a white-box SM4 encryption method based on multi-dimensional linear masking, which can run on a machine completely controlled by an adversary and ensure that the key information cannot be extracted. Therefore, it has a wide range of application prospects in aspects such as digital rights management, cloud-based remote encryption systems, and efficient public key systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The specification drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0026] Figure 1 is a flowchart of a white-box SM4 encryption method based on multi-dimensional linear masking according to Embodiment 1 of the present invention;
[0027] Figure 2 is a memory read / write trajectory diagram implemented based on a lookup table according to Embodiment 1 of the present invention;
[0028] Figure 3 is a schematic diagram of a memory read / write trajectory implemented by a white-box SM4 encryption method based on multi-dimensional linear masking according to Embodiment 1 of the present invention;
[0029] Figure 4 is a CPA attack result diagram of Biryukov's scheme according to Embodiment 1 of the present invention;
[0030] Figure 5 is a CPA attack result diagram of a white-box SM4 encryption method based on multi-dimensional linear masking according to Embodiment 1 of the present invention;
[0031] Figure 6 is a DCA attack result diagram of Biryukov's scheme according to Embodiment 1 of the present invention;
[0032] Figure 7 It is the DCA attack result graph of the white-box SM4 encryption method based on multi-dimensional linear masking in the first embodiment of the present invention. Specific implementation manners
[0033] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0034] It should be noted that the following detailed description is illustrative and is intended to provide further description of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0035] Term explanation:
[0036] SM4 algorithm: Adopts a generalized Feistel structure, with both the block length and the key length being 128 bits. Both the encryption algorithm and the key expansion algorithm adopt a 32-round non-linear iterative structure. Let the input encryption key be represents the 128-bit master key, and K i represents the 32-bit round key in the i-th round. Among them, the round key is generated from the master key through the key expansion algorithm. Let the 128-bit plaintext of SM4 be X0, X1, X2, X3 are 4 32-bit data obtained by splitting the input 128-bit plaintext bit by bit. The round function F generates a 32-bit intermediate state each time, and F can be expressed as:
[0037]
[0038] where, X i+4 represents the output of the i-th round function, and X i , X i+1 , X i+2 , X i+3 are the corresponding data of X0, X1, X2, X3 in the i-th round respectively, and T is composed of the non-linear transformation τ and the linear transformation L. Expanding it, we have:
[0039]
[0040] τ(x0, x1, x2, x3) = Sbox(x0), Sbox(x1), Sbox(x2), Sbox(x3))
[0041]
[0042] where, X is the 32-bit intermediate state, and X is split into 4 8-bit data, that is, x i is an 8-bit byte, and Sbox represents the 8-in-8-out S box used by SM4. The ciphertext finally output by the SM4 algorithm is (X35 , X 34 , X 33 , X 32 ).
[0043] Example 1
[0044] This embodiment provides a white-box SM4 encryption method based on multi-dimensional linear masking, including the following steps:
[0045] Obtain the secret key K i and the plaintext, and split the plaintext bit by bit into the first data X i , the second data X i+1 , the third data X i+2 and the fourth data X i+3 ;
[0046] Based on the secret key, the first data, the second data, the third data and the fourth data, through the encryption of several rounds of round functions, obtain the ciphertext;
[0047] Among them, in each round of round function, the second data, the third data and the fourth data are XORed to obtain the first XOR operation result And after the shares corresponding to the first XOR operation result, the secret key and the first data are respectively split into several shares by different encoding functions, the shares corresponding to the first XOR operation result are XORed, S-box operated and linearly layered with the shares corresponding to the secret key, and then XORed with the shares corresponding to the first data, that is obtain the second XOR operation result X i+4 , and input the second XOR operation result into the decoding function to obtain the input of the next round of round function.
[0048] This embodiment provides a white-box SM4 encryption method based on multi-dimensional linear masking, as Figure 1 shown, for the protected i-th round of round function, the round key K i is generated through pre-computation. The input of the round function is: the 128-bit intermediate state X i || i+1 || i+2 ||X i+3 , the 32-bit round key K i . First, K i , X i are respectively split into multiple shares through the Encode1, Encode2, and Encode3 functions. During the process of round function encryption, in order to ensure correctness, the shares are XORed together in a special corresponding relationship. Finally, the final generated shares are combined through the decoding Decode function to obtain the correct round output.
[0049] Different from the white-box protection scheme based on masking proposed by Biryukov et al., this embodiment draws on the multi-dimensional linear analysis of block cipher algorithms and the relationship between multi-dimensional zero-correlation analysis and integral analysis, and divides the round key of one Byte is represented by a set of basis vectors (v0, v1, …, v n ) in a multi-dimensional vector space. Generally speaking, this set of basis vectors corresponds to a set of incorrect keys Here, these incorrect keys are called the shares of the correct key and satisfy:
[0050]
[0051] Among them, represents the k-th group of incorrect keys corresponding to the j-th Byte of the i-th round key.
[0052] After passing through the round function of SM4, these specially processed internal states will be output in the round function, and the correct round output is obtained through a Decode function. Thus, the correct round key is protected. This embodiment does not conflict with the masking protection scheme of Biryukov et al. This means that these two design schemes can be used simultaneously. Compared with the design scheme based solely on masking protection, this embodiment can further increase the difficulty for attackers to extract the round key.
[0053] Biryukov et al. defined two major classifications of the protection strategies of white-box ciphers: hiding of values and hiding of structures. For resisting white-box attacks, if the number of shares is very large, it becomes very difficult to locate their positions, and there is even no need to hide the positions of their shares. However, designing a multi-share scheme with low implementation cost is a very challenging task. Based on this, a white-box SM4 encryption method based on multi-dimensional linear masking is proposed. Specifically, it is carried out in two steps: First, implement redundant encoding in terms of structure. The Encode1, Encode2, and Encode3 functions respectively split the internal states K i , X i entering the round function F into shares. The following defines the symbolic representation. For the round function F of SM4, its input is 32 bits. Let the internal state The 32 bits are split into 8-bit variable representations Let be the 32-bit internal state after the S-box, be the internal state after the linear layer L, where is the sub-matrix R of L jThe 32-bit intermediate variable after that. Expanding, dividing the linear layer L into 4 8-input 32-output transformations gives:
[0054]
[0055] Next, use shares to represent a basis vector of a multi-dimensional linear space, and define the symbolic representation of the shares of each variable.
[0056] Let represent a share of the j-th Byte of the internal state in the i-th round. N is the number of shares (since each variable is 8 bits, the shares are all 256 values, and most of the intermediate values are redundant error values used to hide the correct encryption result, as long as the XOR result is the correct encryption). Similarly, there is representing a share of the j-th Byte of the i-th round sub-key. It should be noted that use to represent the 8-bit intermediate variable after the share passes through the S-box operation, representing one of the shares of the 32-bit intermediate variable after passing through the sub-matrix R of the linear layer L j after that. Therefore, each share The share of the intermediate variable obtained by the 8-input 32-output transformation satisfies:
[0057]
[0058] Of course, a confusion strategy is adopted during share merging to increase the distance between the shares of a real value. That is to say, it makes it extremely difficult to extract all the shares of a real value from the Boolean circuit.
[0059] For Encode1 and Encode3, there are:
[0060]
[0061] Among them, the shares of the internal state satisfy:
[0062]
[0063] Among them, r k is a 32-bit pseudo-random number.
[0064] For the round key of the i-th round of Encode2, it is encoded as:
[0065]
[0066] Its shares satisfy:
[0067]
[0068] After Decode, the output of the round function in the i-th round satisfies:
[0069]
[0070] By the characteristics of the Decode function, the multi-dimensional linear mask in this embodiment can ensure correct round output and protect the round key so that this scheme can resist DCA and DFA attacks. That is, X i+4 After passing through the Decode function, it serves as the first data in the input of the next round's round function.
[0071] Based on the implementation framework of the masked white-box scheme proposed by Biryukov et al., the Boolean implementation of the S-box of the SM4 algorithm was optimized. Based on four Boolean operations (AND, OR, NOT, XOR), a Boolean circuit implementation of the S-box of AES with 113 gates was generated, and the S-box of SM4 was obtained by applying the affine transformation Ax + B, where A, B:
[0072] B T =[0,1,1,0,1,0,0,1]
[0073] To enhance the security of this white-box scheme, value hiding was added on the basis of the above multi-dimensional linear mask scheme, that is, for each real value and a basis vector of its multi-dimensional linear mask value masking protection was carried out. Here, non-linear masks were used. Let V represent any intermediate variable, where V can be any real value or its share Define to represent the non-linear mask, where v1, v2 are random numbers, so the equation always holds. Here, two security strengths are given corresponding to n ∈ {0, 1}, where n = 0 represents only multi-dimensional linear mask protection; n = 1 represents the simultaneous use of multi-dimensional linear mask and non-linear mask protection.
[0074] As Figure 2 and Figure 3 shown, by collecting the memory read and write traces during the operation of the program, it was found that the white-box SM4 algorithm in this embodiment did not show obvious round characteristics, while the white-box SM4 scheme based on the lookup table showed obvious round structures.
[0075] Based on Daredevil CPAtool, the white-box SM4 scheme was tested. The state after the S-box in the first round of the SM4 algorithm was set as the predicted value, and the correlation of the trace was calculated after respectively guessing the first-round key of four bytes. If the correlation of the correct sub-key was significantly distinguishable from that of the wrong key, it was said that the first-round key of the white-box SM4 was recovered.
[0076] As Figure 4 and Figure 5 shown, the correlation of the correct key implemented by the white-box SM4 proposed in this embodiment cannot be distinguished from the correlation calculated from the wrong key, and the white-box scheme of this embodiment can resist CPA attacks.
[0077] As Figure 6 and Figure 7 shown, for each S-box, the combined DCA attack recommends all 256 keys, and the occurrence frequency of each key has no obvious difference. The occurrence frequency of the correct key is not higher than that of the wrong key. It is the same as the expected security of this embodiment. Expand the window size to 5000 and 10000, and repeat the above attacks. The combined DCA attack cannot effectively extract the correct round key. Based on the above experimental results, it is considered that this embodiment can effectively resist the combined DCA attack.
[0078] Set the round key of the first round to 0x4f907c79, set the window size to 1000, and the window sliding speed to 250 times. Randomly generate 1280 plaintexts for encryption, and collect 1280 corresponding traces. Based on the above parameters, an algebraic DCA attack experiment was carried out. For each S-box, the algebraic DCA attack recommends all 256 keys, and the occurrence frequency of each key has no obvious difference. The occurrence frequency of the correct key is not higher than that of the wrong key. It is the same as the expected security. Based on the above experimental results, it is considered that this white-box design scheme can effectively resist the algebraic DCA attack.
[0079] A white-box SM4 encryption method based on multi-dimensional linear masking provided in this embodiment realizes a Boolean-level white-box SM4 scheme based on multi-dimensional linear masking, does not expose the algorithm structure, and can resist differential computation attack (DCA) attacks. Against DCA attacks and DFA attacks, protection is only carried out in the first round and the last round, greatly reducing the time and space overhead. At the same time, the number of shares is increased, improving the security.
[0080] Embodiment 2
[0081] This embodiment provides a white-box SM4 encryption system based on multi-dimensional linear masking, which specifically includes:
[0082] A data acquisition module, which is configured to: acquire a secret key and a plaintext, and split the plaintext bit by bit into first data, second data, third data, and fourth data;
[0083] An encryption module, which is configured to: obtain a ciphertext through encryption of a number of rounds of round functions based on a secret key, first data, second data, third data, and fourth data;
[0084] Wherein, in each round of round function, the second data, the third data, and the fourth data are subjected to an exclusive OR operation to obtain a first exclusive OR operation result, and after the first exclusive OR operation result, the secret key, and the first data are respectively split into a number of shares by different encoding functions, the shares corresponding to the first exclusive OR operation result and the shares corresponding to the secret key are subjected to an exclusive OR operation, an S-box operation, and a linear layer, and then an exclusive OR operation is performed with the shares corresponding to the first data to obtain a second exclusive OR operation result, and the input of the next round of round function is obtained based on the second exclusive OR operation result.
[0085] It should be noted here that each module in this embodiment corresponds one by one to each step in Embodiment 1, and the specific implementation process is the same, so it will not be repeated here.
[0086] Embodiment 3
[0087] This embodiment provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the steps in a white-box SM4 encryption method based on multi-dimensional linear masking as described in Embodiment 1 above.
[0088] Embodiment 4
[0089] This embodiment provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps in a white-box SM4 encryption method based on multi-dimensional linear masking as described in Embodiment 1 above.
[0090] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a hardware embodiment, a software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.
[0091] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device produce means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0092] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0093] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0094] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0095] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A white-box SM4 encryption method based on multi-dimensional linear masking, characterized in that, Including: Obtain a secret key and a plaintext, and split the plaintext bit by bit into a first data, a second data, a third data, and a fourth data; Based on the secret key, the first data, the second data, the third data, and the fourth data, through encryption by a number of rounds of round functions, obtain a ciphertext; Wherein, each round of round function performs an exclusive OR operation on the second data, the third data, and the fourth data to obtain a first exclusive OR operation result, and after splitting the first exclusive OR operation result, the secret key, and the first data into a number of shares respectively using different encoding functions, the shares corresponding to the first exclusive OR operation result and the shares corresponding to the secret key are subjected to an exclusive OR operation, an S-box operation, and a linear layer, and then an exclusive OR operation is performed with the shares corresponding to the first data to obtain a second exclusive OR operation result, and based on the second exclusive OR operation result, the input of the next round of round function is obtained, and the share represents a basis vector of a multi-dimensional linear space.
2. The white-box SM4 encryption method based on multi-dimensional linear masking according to claim 1, wherein The S-box operation adopts non-linear mask protection.
3. The white-box SM4 encryption method based on multi-dimensional linear masking as claimed in claim 1, wherein The second exclusive OR operation result is input into a decoding function to obtain the input of the next round of round function.
4. A white-box SM4 encryption system based on multi-dimensional linear masking, characterized in that, Including: A data acquisition module, which is configured to: obtain a secret key and a plaintext, and split the plaintext bit by bit into a first data, a second data, a third data, and a fourth data; An encryption module, which is configured to: based on the secret key, the first data, the second data, the third data, and the fourth data, through encryption by a number of rounds of round functions, obtain a ciphertext; Wherein, each round of round function performs an exclusive OR operation on the second data, the third data, and the fourth data to obtain a first exclusive OR operation result, and after splitting the first exclusive OR operation result, the secret key, and the first data into a number of shares respectively using different encoding functions, the shares corresponding to the first exclusive OR operation result and the shares corresponding to the secret key are subjected to an exclusive OR operation, an S-box operation, and a linear layer, and then an exclusive OR operation is performed with the shares corresponding to the first data to obtain a second exclusive OR operation result, and based on the second exclusive OR operation result, the input of the next round of round function is obtained, and the share represents a basis vector of a multi-dimensional linear space.
5. The white-box SM4 encryption system based on multi-dimensional linear masking as described in claim 4, wherein The S-box operation adopts non-linear mask protection.
6. The white-box SM4 encryption system based on multi-dimensional linear masking as claimed in claim 4, wherein, The second exclusive OR operation result is input into a decoding function to obtain the input of the next round of round function.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps in a white-box SM4 encryption method based on multi-dimensional linear mask as described in any one of claims 1-3.
8. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps in a white-box SM4 encryption method based on multi-dimensional linear mask as described in any one of claims 1-3.
Citation Information
Patent Citations
16-wheel SM4-128 / 128 white box password implementation method
CN110278072A