Stream Cipher Implementation Method Based on FSR and Fourth-Order CA
By combining the cascaded structure of 128-bit LFSR and 128-bit NFSR with the 4th-order CA rule, a stream cipher algorithm was designed. This algorithm addresses the shortcomings of existing stream cipher algorithms in terms of security and resistance to attacks, achieving higher security and flexibility, and is suitable for various platforms.
Patent Information
- Application Number
- CN202411324930.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2044-09-23
AI Technical Summary
Existing stream cipher algorithms are insufficient in terms of security and resistance to attacks, especially in terms of defense against cube attacks and fault attacks. They are also highly complex in design and difficult to apply flexibly on various platforms.
A cascaded 128-bit LFSR and 128-bit NFSR are used, combined with a 4th-order CA rule, to design an output function and initialization process to enhance the nonlinearity and randomness of the key stream. Key expansion and iterative updates are performed during the initialization phase to improve the confusion of the internal state.
It improves the security of stream ciphers, enhances the ability to resist cube attacks and fault attacks, simplifies the implementation process, is applicable to both software and hardware platforms, and makes the key stream generation process more random and secure.
Smart Images

Figure CN119172055B_ABST
Abstract
Description
Technical Field
[0001] This invention pertains to encryption and decryption algorithms in the field of information security, specifically a stream cipher implementation method based on FSR and fourth-order CA. Background Technology
[0002] Stream cipher algorithms are an important class of symmetric cryptographic algorithms, characterized by high encryption and decryption efficiency, simple implementation, and high flexibility. They are well-suited for both hardware and software environments and are easy to implement. Therefore, researching new stream cipher design methods is of practical significance.
[0003] The execution of stream ciphers typically involves two phases: an initialization phase and a keystream generation phase. In the initialization phase, the key (KEY) and initialization vector (IV) are first loaded into the internal state of the cryptographic algorithm. During the initialization cycle, the update function is iteratively called multiple times to update the internal state, ensuring that the KEY and IV are fully integrated into the algorithm's internal state. In the keystream generation phase, a pseudo-random keystream of bits is generated from the highly diffused internal state by calling an output function, while the update function further updates the internal state.
[0004] Common stream cipher design structures include stream ciphers based on linear feedback shift registers (LFSRs), stream ciphers based on nonlinear feedback shift registers (NFSRs), stream ciphers based on fourth-order cellular automata (CAs), and stream ciphers based on block cipher operating modes and structures. LFSR-based stream ciphers use an LFSR combined with a finite state machine (FSM) to generate the keystream sequence. The most widely used example of this type of stream cipher is the SNOW 3G algorithm used in mobile communications in the 3GPP standard. NFSR-based stream ciphers use an NFSR and a keystream generation function to generate the keystream sequence. NFSRs provide good nonlinearity for the generated sequence. Typical NFSR stream cipher algorithms include Grain v1 and Trivium. CA-based stream ciphers generate the keystream sequence using appropriate rules. CA rules can often be used as pseudo-random number generators and true random number generators, and have good parallel characteristics. Examples of such ciphers include CAR30 and CASTREAM. Among the above methods, the design of stream ciphers based on LFSR and NFSR is the most mature, and its related security analysis methods are also very complete. Among various analysis methods, cubic attacks pose a great threat to the above-mentioned stream ciphers. CA rules can increase the difficulty for attackers to find legislative variables. Combining CA with LFSR and NFSR as building blocks of stream ciphers can provide good security, and the design is simple and easy to implement. Summary of the Invention
[0005] The purpose of this invention is to leverage the favorable characteristics of a cipher suite (CA) combined with a leedback shift register (FSR) to provide a stream cipher algorithm that is highly secure, simple in design, flexible in application to various platforms, and easy to implement. This algorithm uses an LFSR and an NFSR, which are updated using a CA with specific rules. During the initialization phase, the output function's output is fed back to the LFSR and NFSR, with the LFSR influencing the NFSR's updates. During the keystream generation phase, the LFSR and NFSR are continuously updated, thus ensuring the favorable characteristics of the output function's input.
[0006] The technical solution to achieve the objective of this invention is:
[0007] The stream cipher implementation method based on FSR and fourth-order CA includes the following steps:
[0008] (1) Design the structure of the stream cipher algorithm and determine the components of the algorithm;
[0009] First, two cascaded FSRs are used as the internal state-driven part of the algorithm, that is, a cascaded structure of LFSR and NFSR is adopted.
[0010] Linear feedback shift registers provide good statistical properties. This invention uses a 128-bit LFSR as the linear part of the cryptography and uses a 4th-order linear CA rule to update the units of the linear block. The state of the LFSR is from high bit to low bit from left to right.
[0011] Nonlinear feedback shift registers provide good nonlinear characteristics, which can effectively make up for the lack of nonlinearity in LFSR-type cryptographic algorithms. This invention uses a 128-bit NFSR as the nonlinear part of the cryptography and uses a 4th-order nonlinear CA rule vector to update the units of the linear block. The state of the LFSR is from high bit to low bit from left to right.
[0012] Secondly, the update rules for LFSR and NFSR are designed. Unlike other types of registers that have corresponding update functions and feedback functions, the registers included in this implementation method have their own CA rules. LFSR uses linear CA rules to update its internal state, while NFSR uses non-linear CA rules to update its internal state.
[0013] Finally, an output function with good statistical properties is designed. The algorithm's output function accepts elements from two registers to output bits. During the initialization phase, the output bits participate in the update of LFSR and NFSR. The selection of LFSR at different stages affects the internal state update of NFSR.
[0014] (2) Design the initialization process of the stream cipher algorithm based on CA rules;
[0015] After the components of the stream cipher algorithm are determined, an initialization process is required. During the initialization phase, the output bits of the output function continuously participate in the state updates of the two FSRs. The algorithm initialization process consists of four steps:
[0016] The first step is to load the initial key and vector into two FSRs, and then fill the remaining part of the LFSR with the initial key expansion.
[0017] The second step is to ensure that each bit of LFSR and NFSR satisfies the corresponding CA rule by setting the extension bits of LFSR and NFSR.
[0018] The third step is to XOR the key bits generated during the initialization phase into the LFSR and NFSR;
[0019] The fourth step involves the algorithm performing 32 initial iterations.
[0020] During the initialization phase, the initial key and initial vector are loaded into the registers. After loading, the key is expanded to the LFSR. This step is considered to accelerate the confusion of the key and IV in the internal state on the one hand, and to prevent differential analysis and fault attacks on the other hand. During this phase, the key is XORed into two registers. No key stream is generated in the first 32 clock cycles of the algorithm.
[0021] (3) Keystream generation function
[0022] After the algorithm initialization process, the algorithm enters the key stream generation stage. At this time, the output of the output function is the key bits, and the output bits no longer participate in the update of the LFSR and NFSR states. Each iteration generates a 1-bit key, and the output bits from multiple iterations form the key stream. Due to algorithm security constraints, the maximum length of the key stream generated corresponding to a single initial key value is 2. 64 ;
[0023] Keystream generation function It is a fourth-order balanced nonlinear function that accepts 16-bit inputs from LFSR and NFSR, mixing the states of the two registers to further enhance the nonlinearity, good correlation, and statistical properties of the key stream.
[0024] (4) Algorithm encryption and decryption process;
[0025] When encrypting data, a key stream is generated based on the size of the plaintext, and the ciphertext is generated by XORing the plaintext bits bit by bit; when decrypting, the plaintext is recovered by XORing the key stream bit by bit with the ciphertext.
[0026] The beneficial effects of this invention are:
[0027] (1) The method of the present invention uses a feedback shift register combined with CA rules to improve the linearity and nonlinearity of the internal states corresponding to LFSR and NFSR. The key stream initialization stage adopts 32 rounds of iteration. LFSR and NFSR use 4th order CA bit-by-bit feedback update so that key and iv can be fully confused in the internal state.
[0028] (2) The method of the present invention uses key expansion to fill the remaining bits of the LFSR during the internal state loading stage. Compared with other CA-based stream ciphers that use the Grain cryptography algorithm to load the internal state during the loading stage (loading 31 bits of 1 and 1 bit of 0 in the last 32 bits of the LFSR), this method ensures that there will not be a large number of consecutive 1s in the internal state, thereby ensuring that the algorithm can resist fault attacks and thus improve the randomness of the output sequence.
[0029] (3) Output function It is nonlinear and balanced. After 32 iterations, the output function contains 16 and 64 different input variables in the first and second iterations, respectively, with algebraic degrees of 4 and 8. As the output sequence is continuously output, the algebraic degree and nonlinearity increase accordingly, which can effectively resist algebraic attacks.
[0030] (4) Under MS attacks targeting CA-type stream ciphers, the required state space size is larger than that required by the attack model. (where k is the size of the internal state), therefore it is impossible to combine MS attacks and brute-force attacks to recover the internal state S of the cryptographic algorithm at any given time; the required complexity is greater than that of k. Therefore, the method of the present invention can effectively counter MS attacks.
[0031] (5) The algorithm is simple and secure. The use of FSR components and CA makes it easy to implement in both software and hardware. Attached Figure Description
[0032] Figure 1 This is a structural diagram of the algorithm initialization phase in the method of this invention;
[0033] Figure 2 This is a structural diagram of the algorithm key stream generation stage in the method of the present invention;
[0034] Figure 3 The logic diagram for linear CA;
[0035] Figure 4 This is a logic operation diagram for nonlinear CA. Detailed Implementation
[0036] The present invention will be further described below with reference to the accompanying drawings and embodiments, but this is not intended to limit the scope of the invention.
[0037] Example
[0038] The stream cipher implementation method based on FSR and fourth-order CA includes the following steps:
[0039] Step (1) Design the stream cipher algorithm structure and determine the components of the algorithm;
[0040] (1.1) Two cascaded FSRs are used as the internal state driving part of the algorithm, that is, the cascaded structure of LFSR and NFSR is adopted. The LFSR and NFSR components are designed. The two registers have simple structure and are easy to implement. They provide the basic source sequence with good statistical properties. Both registers are 128 bits and are used as linear and nonlinear modules respectively. The two registers are connected in series. LFSR affects the internal state update of NFSR.
[0041] Both the LFSR and NFSR are 128-bit registers. The 128-bit LFSR uses... It means that among them express The moment of LFSR A status bit, 128 bits of NFSR It means that among them express The moment of NFSR One status bit;
[0042] (1.2) The LFSR uses the linear rule CA to update its internal state, referring to... Figure 3 NFSR uses non-linear rules of CA to update its internal state, referencing Figure 4 The update rules for LFSR and NFSR are based on Rule 43350. The update CA rule for LFSR is expressed as follows: ,
[0043] The update CA rule for NFSR is expressed as follows: ,in This represents the i-th bit of LFSR and NFSR. Indicates LFSR and NFSR in Time of the first The value corresponding to each bit, of which ;
[0044] The update of NFSR is affected by LFSR, the highest digit of LFSR. The XOR operation is performed at each stage of the algorithm until the least significant bit of NFSR is reached, which is represented as follows: ,in These are extension bits in the NFSR. The extension bits exist to ensure that every update in both the LFSR and NFSR satisfies the CA rule. In both the LFSR and NFSR, such extension bits include... ;
[0045] The extension bits of LFSR and NFSR total six bits, which are loaded and updated using the corresponding status bits of the registers, as follows:
[0046]
[0047] The fourth-order linear and fourth-order nonlinear rules based on the fourth-order CA rule Rule 43350 are used as the internal state update rules for LFSR and NFSR. The updated CA rules have been tested and can provide better random sequences than the original design, and can improve the security of the algorithm.
[0048] (1.3) Design an output function with good statistical properties;
[0049] Keystream generation function It is a fourth-order balanced nonlinear function. The output function uses 16 state bits from the LFSR and NFSR as input, and outputs a single bit as the key bit after a mixture of linear and nonlinear operations. Let be the key bit output. Let be the key stream bits output by the algorithm at time t. The output function is:
[0050] , The corresponding variable is ,
[0051] in Indicates the selected LFSR state bit. This indicates the selected NFSR state bit.
[0052] Step (2) Design the stream cipher algorithm initialization process based on CA rules, referring to Figure 1 The specific process is as follows:
[0053] (2.1) Read the 128-bit initial key and 96-bit initial vector ;
[0054] Load the 128-bit initial key and 96-bit initialization vector into the NFSR and LFSR, using the following padding rules for the 128-bit LFSR: For 128-bit NFSRs, the following padding rules apply: ;
[0055] For the remaining 32 bits of the LFSR's internal state, padding is performed using the initial key, with the following specific rules: ;
[0056] (2.2) During the initialization and operation phase, all internal status bits of LFSR and NFSR, except for the least significant bit, follow the corresponding CA rules:
[0057]
[0058] (2.3) During the initialization phase, the key stream output function is used. The output bits are XORed with the LFSR and NFSR, and the specific steps are as follows:
[0059] (2.3.1) Take 16 variables from LFSR and NFSR as the output function. Input variables: Generate a key stream using the rules defined in (2.2);
[0060] (2.3.2) During the initialization phase, the output function only receives the input sequences from the LFSR and NFSR and does not produce any output. The generated key stream participates in the update of the LFSR and NFSR until the initialization phase ends: ;
[0061] (2.4) Initial Iteration Variables The initial iteration rounds are set to 32 rounds. After 32 iterations, the initial keys participating in key expansion will be fully mixed into the LFSR.
[0062] Algorithm The iteration continues, during which the output function participates in two NFSR state update processes. The iteration ends and initialization is completed.
[0063] Before initialization begins, a 128-bit initial key is loaded into a 128-bit NFSR, and a 96-bit initialization vector is loaded into the high 96 bits of the LFSR. The remaining 32 bits of the LFSR are loaded through key expansion. Compared to Grain-type stream ciphers, which load the remaining 32 bits as 1s, the expanded register state is more resistant to differential analysis. For stream ciphers with a designed CA, using the Grain-type stream cipher loading method, after initializing the rounds, the remaining 32 bits are loaded as 1s, resulting in a large number of consecutive 1s in the register during the initialization phase, which can easily lead to fault attacks.
[0064] Step (3) Keystream Generation Phase: After the initialization phase, after each round of updating LFRS and NFSR, 16 variables are selected from the internal states of LFRS and NFSR as the output function. The input variables are used to generate a keystream using a defined function. , refer to Figure 2 The specific process is as follows:
[0065] (3.1) Let the plaintext length be... ;
[0066] (3.2) Update LFSR and NFSR. At this time, the output bits of the output function no longer participate in the update of LFSR and NFSR;
[0067] (3.3) Output function output ,at this time That is, the key bits;
[0068] (3.4) ,like Proceed to step (3.2);
[0069] like End the iteration, and complete this process. The key stream is obtained by sorting the key streams according to their generation time. .
[0070] Step (4) Algorithm encryption and decryption process, the specific process is as follows:
[0071] (4.1) The specific process for the encryption implementation of the algorithm is as follows;
[0072] (4.1.1) Input plaintext The plaintext length is ;
[0073] (4.1.2) Plaintext With key stream Perform a bit-by-bit XOR operation to obtain the ciphertext. That is, each bit operation in the ciphertext is , The first of the ciphertext Bit, For the plaintext of the first Bit, For the first key stream Bit;
[0074] (4.2) The specific process for decrypting the algorithm is as follows;
[0075] (4.2.1) Input ciphertext ;
[0076] (4.2.2) ciphertext With key stream Perform a bitwise XOR operation to obtain the plaintext. That is, each bit operation in the ciphertext is .
[0077] The method of this invention is based on CA, LFSR, and NFSR. LFSR and NFSR are used as generators for random sequences. The two registers are updated using CA with different rules (linear CA and nonlinear CA). During the initialization phase, the key is extended to LFSR. Compared with other CA cryptographic algorithms, it can better complete the mixed diffusion of key and IV during the initialization phase. The output function accepts values from the two registers to generate a key stream of a certain length, effectively resisting fault attacks and cube attacks, and improving the security of the algorithm.
Claims
1. A stream cipher implementation method based on FSR and fourth-order CA, characterized in that, Includes the following steps: (1) Design the structure of the stream cipher algorithm and determine the components of the algorithm; First, two cascaded FSRs are used as the internal state-driven part of the algorithm; Secondly, two update rules for FSR are designed, including linear CA and nonlinear CA; Finally, design an output function with good statistical properties; (2) Design the initialization process of the stream cipher algorithm based on CA rules; After the components of the stream cipher algorithm are determined, an initialization process is required. During the initialization phase, the output bits of the output function continuously participate in the state updates of the two FSRs. The algorithm initialization process consists of four steps: The first step is to load the initial key and vector into two FSRs, and then fill the remaining part of the LFSR with the initial key expansion. The second step is to ensure that each bit of LFSR and NFSR satisfies the corresponding CA rule by setting the extension bits of LFSR and NFSR. The third step is to XOR the key bits generated during the initialization phase into the LFSR and NFSR; The fourth step involves the algorithm performing 32 initial iterations. (3) Key stream generation stage; After the algorithm initialization process, the algorithm enters the key stream generation stage. At this time, the output of the output function is the key bit, and the key bit no longer participates in the update of the LFSR and NFSR states. Each iteration generates 1 bit of the key, and the key bits from multiple iterations form the key stream. Due to algorithm security constraints, the maximum length of the key stream generated corresponding to a single initial key value is 2. 64 ; (4) Algorithm encryption and decryption process; During encryption and decryption, the sender generates a key stream of the same length as the plaintext according to the algorithm, XORs the key stream with the plaintext bit by bit to obtain the ciphertext, and sends the ciphertext to the receiver through the communication channel. After receiving the ciphertext, the receiver generates a key stream of the same length as the ciphertext according to the algorithm with the agreed key and initial value, XORs the key stream with the ciphertext bit by bit to obtain the plaintext.
2. The stream cipher implementation method based on FSR and fourth-order CA according to claim 1, characterized in that, Step (1) involves designing the overall structure of the stream cipher algorithm and determining its components. The specific process is as follows: (1.1) The cascaded LFSR and NFSR are used as the internal state-driven part of the algorithm; Both the LFSR and NFSR are 128-bit registers. The 128-bit LFSR uses... It means that among them express The moment of LFSR A status bit, 128 bits of NFSR. It means that among them express The moment of NFSR One status bit; (1.2) The LFSR uses a linear CA rule to update its internal state, while the NFSR uses a non-linear CA rule. The update rules for LFSR and NFSR are based on Rule 43350. The update CA rule for LFSR is expressed as follows: The symbol ^ indicates a bitwise XOR operation. The update CA rule for NFSR is expressed as follows: ,in This represents the i-th bit of LFSR and NFSR. Indicates LFSR and NFSR in Time of the first The value corresponding to each bit, where the symbol '&' represents a bitwise logical AND operation. ; For LFSRs and NFSRs updated using CA rules, it is necessary to ensure that the update of each bit satisfies the corresponding CA rule. The corresponding extension bits: (1.3) Design an output function with good statistical properties; Keystream generation function It is a fourth-order balanced nonlinear function. The output function uses 16 state bits from the LFSR and NFSR as input, and outputs a single bit as the key bit after a mixture of linear and nonlinear operations. Let be the key bit output. For the algorithm in The key stream bits output at each moment, The output function is: , The corresponding variable is , in Indicates the selected LFSR state bit. This indicates the selected NFSR state bit.
3. The stream cipher implementation method based on FSR and fourth-order CA according to claim 1, characterized in that, The initialization process of the algorithm based on FSR and CA rules in step (2) is as follows: (2.1) Load the 128-bit initial key and the 96-bit initial vector iv into the NFSR and LFSR. For the remaining 32 bits of internal state of the LFSR, use the initial key for expansion padding. The LFSR and NFSR use the following padding rules: in, , , Represents the first key bits, The first initial vector represents the first initial vector. 1 bit; (2.2) During the initialization and operation phase, all internal status bits of LFSR and NFSR, except for the least significant bit, follow the corresponding CA rules: (2.3) Keystream output function during the initialization phase The output XORed to Participate in the internal state updates of LFSR and NFSR: ; (2.4) Algorithm execution The round of iterations involves the output function participating in two NFSR state update processes.
4. The stream cipher implementation method based on FSR and fourth-order CA according to claim 1, characterized in that, In step (3), after the initialization phase of the key stream generation process, after each round of updating the LFSR and NFSR, 16 variables are selected from the internal states of the LFSR and NFSR as the output function. The input variables are used to generate a keystream using a defined function. The specific process is as follows: (3.1) Let the plaintext length be... ; (3.2) Update LFSR and NFSR. At this time, the output bits of the output function no longer participate in the update of LFSR and NFSR; (3.3) Output function output ,at this time That is, the key bits; (3.4) ,like Proceed to step (3.2); like End the iteration, and complete this process. The key stream is obtained by sorting the key streams according to their generation time. .
5. The stream cipher implementation method based on FSR and fourth-order CA according to claim 1, characterized in that, The encryption and decryption process described in step (4) is as follows: (4.1) The specific process for the encryption implementation of the algorithm is as follows; (4.1.1) Input plaintext The plaintext length is ; (4.1.2) Plaintext With key stream Perform a bit-by-bit XOR operation to obtain the ciphertext. That is, each bit operation in the ciphertext is , The first of the ciphertext Bit, For the plaintext of the first Bit, For the first key stream Bit; (4.2) The specific process for decrypting the algorithm is as follows; (4.2.1) Input ciphertext ; (4.2.2) ciphertext With key stream Perform a bitwise XOR operation to obtain the plaintext. That is, each bit operation in the ciphertext is .
Citation Information
Patent Citations
Initialization method and device of ZUC-256 stream cryptographic algorithm and communication method
CN110011798A
Stream cipher implementation method based on NFSR and clock-controlled double LFSR
CN115314206A