Parallel processing system and method for coexistence of encryption and decryption of WAPI, CCMP and GCMP in wireless local area network
By designing a parallel processing system that coexists WAPI, CCMP and GCMP encryption and decryption in wireless LANs, the problems of hardware complexity and high space occupancy in the prior art are solved, and hardware miniaturization and resource optimization are achieved.
Patent Information
- Application Number
- CN202411458919.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-18
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-10-18
AI Technical Summary
The existing wireless LAN encryption scheme has complicated hardware structure and high space occupancy rate due to independent processing, which is not conducive to miniaturization.
A parallel processing system that coexists with WAPI, CCMP and GCMP encryption and decryption of wireless LANs is designed. Through the selection of encryption and decryption type, the corresponding WAPI, CCMP or GCMP encryption and decryption algorithm is activated to realize the completion of three types of encryption and decryption under one set of process control.
The contract was significantly terminated, and the space occupancy rate was significantly reduced, achieving a miniaturized hardware design.
Smart Images

Figure CN119342459B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communications, and in particular to a parallel processing system and method for coexisting encryption and decryption of a wireless local area network WAPI, CCMP and GCMP. Background Art
[0002] In wireless LAN, data communication security is a very important topic. In the process of continuous development, the IEEE 802.11 protocol family provides CCMP encryption and decryption algorithms and GCMP encryption and decryption algorithms for wireless LAN secure communication. At the same time, in order to meet the needs of communication security, my country has proposed the wireless LAN security protocol WAPI with independent intellectual property rights, which can also solve the problem of wireless LAN security communication.
[0003] However, existing encryption schemes are all executed independently, which makes the hardware structure complex, the space occupancy rate is high, and it is not conducive to miniaturization. Summary of the invention
[0004] In order to solve the above problems existing in the prior art, the present invention provides a parallel processing system and method for coexisting encryption and decryption of WAPI, CCMP and GCMP in a wireless local area network. The technical problem to be solved by the present invention is achieved by the following technical solutions:
[0005] A wireless local area network WAPI, CCMP and GCMP encryption and decryption coexisting parallel processing system, including a transmitter and a receiver;
[0006] The transmitter is used to read a plaintext data frame to be encrypted from the application layer, wherein the plaintext data frame to be encrypted includes a first MAC frame header, a first security header and a first frame body, wherein the first frame body includes a status field for indicating plaintext and plaintext data; read the plaintext data from the first frame body, so that the MAC layer performs encryption processing through an encryption module, and then sends the encrypted information to the physical layer and transmits it through an air interface;
[0007] The receiver is used to receive a ciphertext data frame to be decrypted from an air interface, wherein the ciphertext data frame to be decrypted includes a second MAC frame header, a second security header, and a second frame body, wherein the second frame body includes a status field for indicating a ciphertext, ciphertext data, and an integrity check MIC ciphertext value; read the ciphertext data and the integrity check MIC ciphertext value from the second frame body, so that the MAC layer performs decryption processing through a decryption module and then sends the decrypted information to the application layer;
[0008] Correspondingly, the encryption module is used to search for the corresponding encryption key according to the encryption type to encrypt the plaintext data; the decryption module is used to search for the corresponding decryption key according to the decryption type to decrypt the ciphertext data.
[0009] In a specific embodiment, the encryption module is specifically used to: judge each execution state of the state machine in turn, and select a corresponding state from the execution state according to each encryption method to complete the encryption of plaintext data. The decryption module is specifically used to: judge each execution state of the state machine in turn, and select a corresponding state from the execution state according to each decryption method to complete the decryption of ciphertext data, wherein the execution states include: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the encryption method or decryption method includes at least two of WAPI, CCMP and GCMP.
[0010] In a specific implementation, when the encryption mode or decryption mode is WAPI, the corresponding execution states include: INIT, AAD1, AAD2, LENW, MSSG, MICT;
[0011] When the encryption mode or decryption mode is CCMP, the corresponding execution states include: INIT, AAD1, AAD2, MSSG, MICT;
[0012] When the encryption mode or the decryption mode is GCMP, the corresponding execution states include: INIT, AAD1, AAD2, MSSG, LENG, and MICT.
[0013] In a specific implementation, when the encryption mode or decryption mode is WAPI, the encryption algorithm or decryption algorithm includes an SMS4 algorithm;
[0014] When the encryption mode or decryption mode is CCMP, the encryption algorithm or decryption algorithm includes an AES algorithm;
[0015] When the encryption mode or decryption mode is GCMP, the encryption algorithm or decryption algorithm includes a GHASH algorithm.
[0016] In a specific implementation, encrypting plaintext data includes:
[0017] Execute the INIT state to initialize the state parameters;
[0018] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the plaintext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0019] In response to the integrity verification being completed, executing the AAD2 state to determine whether the plaintext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0020] In response to the plaintext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the CCMP mode field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the GCMP field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation;
[0021] In response to the completion of the encryption operation, when it is determined through the state parameter that the encryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0022] In a specific implementation, decrypting the ciphertext data includes:
[0023] Execute the INIT state to initialize the state parameters;
[0024] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the ciphertext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0025] In response to the integrity verification being completed, executing the AAD2 state to determine whether the ciphertext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0026] In response to the ciphertext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the CCMP mode field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the GCMP field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation;
[0027] In response to the decryption operation being completed, when it is determined through the state parameter that the decryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0028] The present invention also provides a parallel processing method for coexistence of encryption and decryption of WAPI, CCMP and GCMP in a wireless local area network, which is applied to a transmitter. When performing encryption, the transmitter includes:
[0029] Reading a plaintext data frame to be encrypted from the application layer, the plaintext data frame to be encrypted includes a first MAC frame header, a first security header and a first frame body, wherein the first frame body includes a status field for indicating plaintext and plaintext data;
[0030] Plaintext data is read from the first frame body so that the MAC layer performs encryption processing through the encryption module, and then the encrypted information is sent to the physical layer and transmitted through the air interface; accordingly, the encryption module is used to search for the corresponding encryption key according to the encryption type to encrypt the plaintext data.
[0031] In a specific implementation, searching for a corresponding encryption key according to the encryption type to encrypt the plaintext data includes:
[0032] Determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each encryption method to complete encryption of plaintext data, the execution states include: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the encryption methods include at least two of WAPI, CCMP and GCMP;
[0033] Among them, encrypting plaintext data includes:
[0034] Execute the INIT state to initialize the state parameters;
[0035] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the plaintext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0036] In response to the integrity verification being completed, executing the AAD2 state to determine whether the plaintext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0037] In response to the plaintext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the CCMP mode field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the GCMP field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation;
[0038] In response to the completion of the encryption operation, when it is determined through the state parameter that the encryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0039] The present invention also provides a parallel processing method for coexistence of encryption and decryption of wireless local area network WAPI, CCMP and GCMP, which is applied to a receiver. When performing decryption, the receiver includes:
[0040] Receive a ciphertext data frame to be decrypted from an air interface, wherein the ciphertext data frame to be decrypted includes a second MAC frame header, a second security header, and a second frame body, wherein the second frame body includes a status field for indicating a ciphertext, ciphertext data, and an integrity check MIC ciphertext value;
[0041] The ciphertext data and the integrity check MIC ciphertext value are read from the second frame body so that the MAC layer performs decryption processing through the decryption module and then sends the decrypted information to the application layer; accordingly, the decryption module is used to search for the corresponding decryption key according to the decryption type to decrypt the ciphertext data.
[0042] In a specific implementation, searching for a corresponding decryption key according to the decryption type to decrypt the ciphertext data includes:
[0043] Determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each decryption mode to complete the decryption of the ciphertext data, wherein the execution state includes: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the decryption mode includes at least two of WAPI, CCMP and GCMP;
[0044] Among them, decrypting the ciphertext data includes:
[0045] Execute the INIT state to initialize the state parameters;
[0046] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the ciphertext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0047] In response to the integrity verification being completed, executing the AAD2 state to determine whether the ciphertext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0048] In response to the ciphertext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the CCMP mode field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the GCMP field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation;
[0049] In response to the decryption operation being completed, when it is determined through the state parameter that the decryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0050] The parallel processing method for coexistence of WAPI, CCMP and GCMP encryption and decryption in a wireless local area network of the present invention starts the corresponding WAPI or CCMP or GCMP encryption and decryption algorithm by selecting the encryption and decryption type, thereby completing the three types of encryption and decryption under a set of process control, thereby significantly reducing the scale of hardware circuits and significantly reducing space occupancy.
[0051] Beneficial effects of the present invention:
[0052] The parallel processing system of the wireless local area network WAPI, CCMP and GCMP encryption and decryption coexisting in the present invention starts the corresponding WAPI or CCMP or GCMP encryption and decryption algorithm by selecting the encryption and decryption type, thereby completing the three types of encryption and decryption under a set of process control, thereby significantly reducing the scale of hardware circuits and significantly reducing space occupancy.
[0053] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 It is a block diagram of a parallel processing system module for coexisting encryption and decryption of a wireless local area network WAPI, CCMP and GCMP provided by an embodiment of the present invention;
[0055] Figure 2 It is a schematic diagram of state jump of a parallel processing system in which WAPI, CCMP and GCMP encryption and decryption coexist in a wireless local area network provided by an embodiment of the present invention;
[0056] Figure 3 It is a schematic diagram of a logical unit of a parallel processing system in which WAPI, CCMP and GCMP encryption and decryption coexist in a wireless local area network provided by an embodiment of the present invention;
[0057] Figure 4It is a flow chart of a parallel processing method for coexistence of encryption and decryption of a wireless local area network WAPI, CCMP and GCMP at a transmitter end provided by an embodiment of the present invention;
[0058] Figure 5 The present invention is a flowchart of a method for parallel processing of wireless local area network WAPI, CCMP and GCMP encryption and decryption coexisting at a receiver end provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0059] The present invention is further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.
[0060] Embodiment 1
[0061] See also Figure 1 , Figure 1 It is a block diagram of a parallel processing system module for coexisting encryption and decryption of a wireless local area network WAPI, CCMP and GCMP provided by an embodiment of the present invention, including a transmitter and a receiver;
[0062] The transmitter is used to read a plaintext data frame to be encrypted from the application layer, wherein the plaintext data frame to be encrypted includes a first MAC frame header, a first security header and a first frame body, wherein the first frame body includes a status field for indicating plaintext and plaintext data; read the plaintext data from the first frame body, so that the MAC layer performs encryption processing through an encryption module, and then sends the encrypted information to the physical layer and transmits it through an air interface;
[0063] The receiver is used to receive a ciphertext data frame to be decrypted from an air interface, wherein the ciphertext data frame to be decrypted includes a second MAC frame header, a second security header, and a second frame body, wherein the second frame body includes a status field for indicating a ciphertext, ciphertext data, and an integrity check MIC ciphertext value; read the ciphertext data and the integrity check MIC ciphertext value from the second frame body, so that the MAC layer performs decryption processing through a decryption module and then sends the decrypted information to the application layer;
[0064] Correspondingly, the encryption module is used to search for the corresponding encryption key according to the encryption type to encrypt the plaintext data; the decryption module is used to search for the corresponding decryption key according to the decryption type to decrypt the ciphertext data.
[0065] In a specific embodiment, the encryption module is specifically used to: determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each encryption method to complete the encryption of plaintext data. The decryption module is specifically used to: determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each decryption method to complete the decryption of ciphertext data, wherein the execution state includes: INIT (Initialization), AAD1 (Additional Authentication Data 1), AAD2 (Additional Authentication Data 2), LENW (Length of WAPI payload), MSSG (Message or payload), LENG (Length of GCMP for AAD and payload), MICT (Message Integrity Code or Tag); the encryption method or decryption method includes at least two of WAPI, CCMP and GCMP.
[0066] In a specific implementation, when the encryption mode or decryption mode is WAPI, the corresponding execution states include: INIT, AAD1, AAD2, LENW, MSSG, MICT;
[0067] When the encryption mode or decryption mode is CCMP, the corresponding execution states include: INIT, AAD1, AAD2, MSSG, MICT;
[0068] When the encryption mode or the decryption mode is GCMP, the corresponding execution states include: INIT, AAD1, AAD2, MSSG, LENG, and MICT.
[0069] In a specific implementation, when the encryption mode or decryption mode is WAPI, the encryption algorithm or decryption algorithm includes an SMS4 algorithm;
[0070] When the encryption mode or decryption mode is CCMP, the encryption algorithm or decryption algorithm includes an AES algorithm;
[0071] When the encryption mode or decryption mode is GCMP, the encryption algorithm or decryption algorithm includes a GHASH algorithm.
[0072] In a specific implementation, encrypting plaintext data includes:
[0073] Execute the INIT state to initialize the state parameters;
[0074] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the plaintext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0075] In response to the integrity verification being completed, executing the AAD2 state to determine whether the plaintext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0076] In response to the plaintext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the CCMP mode field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the GCMP field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation;
[0077] In response to the completion of the encryption operation, when it is determined through the state parameter that the encryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0078] In a specific implementation, decrypting the ciphertext data includes:
[0079] Execute the INIT state to initialize the state parameters;
[0080] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the ciphertext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0081] In response to the integrity verification being completed, executing the AAD2 state to determine whether the ciphertext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0082] In response to the ciphertext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the CCMP mode field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the GCMP field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation;
[0083] In response to the decryption operation being completed, when it is determined through the state parameter that the decryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0084] It should be noted that when performing encryption or decryption, since different encryption or decryption types have different encryption or decryption methods, the execution states will be different, and the specific encryption or decryption units will also be different.
[0085] SMS4 corresponds to the u_sm4i integrity protection unit and u_sm4c encryption and decryption unit, AES corresponds to the u_aesi integrity protection unit and u_aesc encryption and decryption unit, and GHASH corresponds to the u_aesi and u_gcm_ghash integrity protection units and u_aesc encryption and decryption units.
[0086] See also Figure 2 , Figure 2 This is a schematic diagram of the state jump of a parallel processing system in which WAPI, CCMP and GCMP encryption and decryption coexist in a wireless local area network provided by an embodiment of the present invention. Taking WAPI encryption as an example, multiple state machines jump to control u_sm4i for integrity protection, and u_sm4c is used to perform encryption. Specifically, in the six states of INIT, AAD1, AAD2, LENW, MSSG, and MICT, pn, wapi_add1, wapi_add2, lent and multiple MPDU signals are successively XORed, and u_sm4i is iterated for processing to obtain mic_plan; and u_sm4c is used to iterate and XOR multiple MPDUs, and finally XOR mic_plan to complete the encryption of the reorganized data. Correspondingly, in the WAPI decryption process, multiple state machines jump to control u_sm4i for integrity protection, and u_sm4c is used for decryption.
[0087] Taking CCMP encryption as an example, through multiple state machine jumps, u_aesi is controlled to perform integrity protection, and u_aesc is used for encryption; specifically, in the five states of INIT, AAD1, AAD2, MSSG, and MICT, ccmp_iv, ccmp_add1, ccmp_add2 and multiple MPDU signals are XORed in turn, and u_aesi is iterated for processing to obtain mic_plan; and u_aesc is used to encrypt each MPDU. Correspondingly, in the CCMP decryption process, multiple state machine jumps are used to control u_aesi for integrity protection, and u_aesc is used for decryption.
[0088] Taking GCMP encryption as an example, through multiple state machine jumps, u_gcm_ghash is controlled to perform integrity protection, and u_aesc is used for encryption; specifically, in INIT, gcmp_0 data is first processed with u_aesi, and then in the six states of AAD1, AAD2, MSSG, LENG, and MICT, gcmp_add1, gcmp_add2, multiple MPDU signals and lent_lena are XORed in turn, and u_gcm_ghash is iterated for processing to obtain mic_plan; and u_aesc is used to encrypt each MPDU respectively. Correspondingly, in the GCMP decryption process, u_aesi and u_gcm_ghash are controlled to perform integrity protection through multiple state machine jumps, and u_aesc is used for decryption.
[0089] Of course, during the encryption and decryption process, if the amount of data of the three types of WAPI, CCMP and GCMP is the same, the above process can be executed in parallel. And if the execution is interrupted due to power failure, failure, etc., the processing can be continued after the interruption is restored.
[0090] Preferably, an information display module may also be included. Since the three types of data are executed synchronously, the number of data to be processed, data being processed and data processed of each type of data may be displayed, and correspondingly, the processing priority and the like may also be included.
[0091] See also Figure 3 , Figure 3 It is a schematic diagram of the logical units of a parallel processing system in which WAPI, CCMP and GCMP encryption and decryption coexist in a wireless local area network provided by an embodiment of the present invention. When the encryption and decryption module is implemented in hardware, for example, input data can be controlled by a master control unit, and WAPI, CCMP and GCMP encryption and decryption processing can be implemented by corresponding sub-control units.
[0092] The present invention also provides a parallel processing method for coexistence of encryption and decryption of wireless local area network WAPI, CCMP and GCMP at the transmitter end, see Figure 4 , the transmitter, when performing encryption, comprises:
[0093] Reading a plaintext data frame to be encrypted from the application layer, the plaintext data frame to be encrypted includes a first MAC frame header, a first security header and a first frame body, wherein the first frame body includes a status field for indicating plaintext and plaintext data;
[0094] Plaintext data is read from the first frame body so that the MAC layer performs encryption processing through the encryption module, and then the encrypted information is sent to the physical layer and transmitted through the air interface; accordingly, the encryption module is used to search for the corresponding encryption key according to the encryption type to encrypt the plaintext data.
[0095] In a specific implementation, searching for a corresponding encryption key according to the encryption type to encrypt the plaintext data includes:
[0096] Determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each encryption method to complete encryption of plaintext data, the execution states include: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the encryption methods include at least two of WAPI, CCMP and GCMP;
[0097] Among them, encrypting plaintext data includes:
[0098] Execute the INIT state to initialize the state parameters;
[0099] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the plaintext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0100] In response to the integrity verification being completed, executing the AAD2 state to determine whether the plaintext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0101] In response to the plaintext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the CCMP mode field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the GCMP field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation;
[0102] In response to the completion of the encryption operation, when it is determined through the state parameter that the encryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0103] The present invention also provides a parallel processing method for coexisting encryption and decryption of wireless local area network WAPI, CCMP and GCMP at the receiver end, see Figure 5 , the receiver, when performing decryption, comprises:
[0104] Receive a ciphertext data frame to be decrypted from an air interface, wherein the ciphertext data frame to be decrypted includes a second MAC frame header, a second security header, and a second frame body, wherein the second frame body includes a status field for indicating a ciphertext, ciphertext data, and an integrity check MIC ciphertext value;
[0105] The ciphertext data and the integrity check MIC ciphertext value are read from the second frame body so that the MAC layer performs decryption processing through the decryption module and then sends the decrypted information to the application layer; accordingly, the decryption module is used to search for the corresponding decryption key according to the decryption type to decrypt the ciphertext data.
[0106] In a specific implementation, searching for a corresponding decryption key according to the decryption type to decrypt the ciphertext data includes:
[0107] Determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each decryption mode to complete the decryption of the ciphertext data, wherein the execution state includes: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the decryption mode includes at least two of WAPI, CCMP and GCMP;
[0108] Among them, decrypting the ciphertext data includes:
[0109] Execute the INIT state to initialize the state parameters;
[0110] In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the ciphertext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated;
[0111] In response to the integrity verification being completed, executing the AAD2 state to determine whether the ciphertext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter;
[0112] In response to the ciphertext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the CCMP mode field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the GCMP field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation;
[0113] In response to the decryption operation being completed, when it is determined through the state parameter that the decryption mode is GCMP, the LENG state is executed to perform message integrity marking.
[0114] The parallel processing method for coexistence of WAPI, CCMP and GCMP encryption and decryption in a wireless local area network of the present invention starts the corresponding WAPI or CCMP or GCMP encryption and decryption algorithm by selecting the encryption and decryption type, thereby completing the three types of encryption and decryption under a set of process control, thereby significantly reducing the scale of hardware circuits and significantly reducing space occupancy.
[0115] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.
[0116] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality of components or steps.
[0117] The above contents are further detailed descriptions of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the protection scope of the present invention.
Claims
1. A parallel processing system for wireless local area network WAPI, CCMP and GCMP encryption and decryption coexisting, characterized in that: Includes a transmitter and a receiver; The transmitter is used to read a plaintext data frame to be encrypted from the application layer, wherein the plaintext data frame to be encrypted includes a first MAC frame header, a first security header and a first frame body, wherein the first frame body includes a status field for indicating plaintext and plaintext data; read the plaintext data from the first frame body, so that the MAC layer performs encryption processing through an encryption module, and then sends the encrypted information to the physical layer and transmits it through an air interface; The receiver is used to receive a ciphertext data frame to be decrypted from an air interface, wherein the ciphertext data frame to be decrypted includes a second MAC frame header, a second security header, and a second frame body, wherein the second frame body includes a status field for indicating a ciphertext, ciphertext data, and an integrity check MIC ciphertext value; read the ciphertext data and the integrity check MIC ciphertext value from the second frame body, so that the MAC layer performs decryption processing through a decryption module and then sends the decrypted information to the application layer; Correspondingly, the encryption module is used to search for the corresponding encryption key according to the encryption type to encrypt the plaintext data; the decryption module is used to search for the corresponding decryption key according to the decryption type to decrypt the ciphertext data; The encryption module is specifically used to: determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each encryption method to complete the encryption of the plaintext data; encrypt the plaintext data, including: Execute the INIT state to initialize the state parameters; In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the plaintext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated; In response to the integrity verification being completed, executing the AAD2 state to determine whether the plaintext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter; In response to the plaintext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the CCMP mode field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the GCMP field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; In response to the completion of the encryption operation, when it is determined through the state parameter that the encryption mode is GCMP, the LENG state is executed to perform message integrity marking.
2. The wireless local area network encryption and decryption coexistence parallel processing system according to claim 1, characterized in that: The decryption module is specifically used to: determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each decryption method to complete the decryption of the ciphertext data, wherein the execution state includes: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the encryption method or decryption method includes at least two of WAPI, CCMP and GCMP.
3. The wireless local area network encryption and decryption coexistence parallel processing system according to claim 2, characterized in that: When the encryption mode or decryption mode is WAPI, the corresponding execution states include: INIT, AAD1, AAD2, LENW, MSSG, MICT; When the encryption mode or decryption mode is CCMP, the corresponding execution states include: INIT, AAD1, AAD2, MSSG, MICT; When the encryption mode or the decryption mode is GCMP, the corresponding execution states include: INIT, AAD1, AAD2, MSSG, LENG, and MICT.
4. The wireless local area network encryption and decryption coexistence parallel processing system according to claim 3, characterized in that: When the encryption mode or decryption mode is WAPI, the encryption algorithm or decryption algorithm includes the SMS4 algorithm; When the encryption mode or decryption mode is CCMP, the encryption algorithm or decryption algorithm includes an AES algorithm; When the encryption method or decryption method is GCMP, the encryption algorithm or decryption algorithm includes the GHASH algorithm.
5. The wireless local area network encryption and decryption coexistence parallel processing system according to claim 1, characterized in that: Decrypt ciphertext data, including: Execute the INIT state to initialize the state parameters; In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the ciphertext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated; In response to the integrity verification being completed, executing the AAD2 state to determine whether the ciphertext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter; In response to the ciphertext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the CCMP mode field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the GCMP field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; In response to the decryption operation being completed, when it is determined through the state parameter that the decryption mode is GCMP, the LENG state is executed to perform message integrity marking.
6. A parallel processing method for coexistence of WAPI, CCMP and GCMP encryption and decryption in a wireless local area network, applied to a transmitter, characterized in that: The transmitter, when performing encryption, comprises: Reading a plaintext data frame to be encrypted from the application layer, the plaintext data frame to be encrypted includes a first MAC frame header, a first security header and a first frame body, wherein the first frame body includes a status field for indicating plaintext and plaintext data; Reading plaintext data from the first frame body, so that the MAC layer performs encryption processing through the encryption module, and then sends the encrypted information to the physical layer and transmits it through the air interface; accordingly, the encryption module is used to search for a corresponding encryption key according to the encryption type to encrypt the plaintext data; Search for the corresponding encryption key according to the encryption type to encrypt the plaintext data, including: Determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each encryption method to complete encryption of plaintext data, the execution states include: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the encryption methods include at least two of WAPI, CCMP and GCMP; Among them, encrypting plaintext data includes: Execute the INIT state to initialize the state parameters; In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the plaintext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated; In response to the integrity verification being completed, executing the AAD2 state to determine whether the plaintext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter; In response to the plaintext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the CCMP mode field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; or in response to the plaintext data including the GCMP field, the valid data length of the plaintext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the encryption operation; In response to the completion of the encryption operation, when it is determined through the state parameter that the encryption mode is GCMP, the LENG state is executed to perform message integrity marking.
7. A parallel processing method for coexistence of WAPI, CCMP and GCMP encryption and decryption in a wireless local area network, applied to a receiver, characterized in that: The receiver, when performing decryption, comprises: Receive a ciphertext data frame to be decrypted from an air interface, wherein the ciphertext data frame to be decrypted includes a second MAC frame header, a second security header, and a second frame body, wherein the second frame body includes a status field for indicating a ciphertext, ciphertext data, and an integrity check MIC ciphertext value; Read the ciphertext data and the integrity check MIC ciphertext value from the second frame body, so that the MAC layer performs decryption processing through the decryption module and then sends the decrypted information to the application layer; accordingly, the decryption module is used to search for a corresponding decryption key according to the decryption type to decrypt the ciphertext data; Search for the corresponding decryption key according to the decryption type to decrypt the ciphertext data, including: Determine each execution state of the state machine in turn, and select a corresponding state from the execution state according to each decryption mode to complete the decryption of the ciphertext data, wherein the execution state includes: INIT, AAD1, AAD2, LENW, MSSG, LENG, MICT; the decryption mode includes at least two of WAPI, CCMP and GCMP; Among them, decrypting the ciphertext data includes: Execute the INIT state to initialize the state parameters; In response to the completion of the initialization INIT, the AAD1 state is executed to determine whether the ciphertext data includes the first additional authentication data ADD1, and if so, the integrity of the first additional authentication data is verified and the state parameter is updated; In response to the integrity verification being completed, executing the AAD2 state to determine whether the ciphertext data includes the second additional authentication data ADD2, and if so, performing integrity verification on the second additional authentication data and updating the state parameter; In response to the ciphertext data including the service quality control information and the WAPI mode field, the LENW state is executed to determine the WAPI valid data length and perform integrity verification on the WAPI valid data length, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the CCMP mode field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; or in response to the ciphertext data including the GCMP field, the valid data length of the ciphertext data is determined and the validity of the valid data length is judged, and then the MSSG state is executed to complete the decryption operation; In response to the decryption operation being completed, when it is determined through the state parameter that the decryption mode is GCMP, the LENG state is executed to perform message integrity marking.
Citation Information
Patent Citations
Method for encrypting and deciphering wireless local area network WAPI and CCMP
CN101753290A
Encryption and decryption method and device for wireless local area network communication system
CN113938882A