An Adaptive Micro-Energy Driven Passive Sensing Node Security Encryption System

Through the adaptive microenergy-driven secure encryption system, the problem of difficult to balance data security and low power consumption caused by the energy instability of passive sensing nodes is solved, and the data security enhancement and energy utilization of passive sensing nodes are achieved, which improves its application potential in the Internet of Things.

CN119364348BActive Publication Date: 2025-07-22SOUTHWEST PETROLEUM UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411631489.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-15
Publication Date
2025-07-22
Estimated Expiration
2044-11-15

AI Technical Summary

Technical Problem

The energy source of passive sensing nodes is unstable and traditional encryption methods cannot be adaptively adjusted, which makes it difficult to balance data security guarantees and low power consumption requirements, affecting its widespread application in the Internet of Things.

Method used

A security encryption system driven by adaptive microenergy is designed, and the detection circuit and N linear window comparators are divided by multi-stage thresholds, combined with near-zero power consumption digital conversion cyclic shift encryption, adaptive microenergy drive multi-stage hash stream cipher encryption encryption, GPRESENT encryption and GHIGHT encryption, dynamically select the encryption intensity according to the energy state of the sensor node to achieve a balance between low power consumption and data security.

Benefits of technology

In the case of unstable energy in the passive sensing node, data security enhancement and energy utilization are maximized, maintenance costs are reduced, and the safety and life of passive sensing nodes are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119364348B_ABST
    Figure CN119364348B_ABST
Patent Text Reader

Abstract

The present invention discloses an adaptive micro-energy-driven passive sensing node security encryption architecture, belonging to the field of communications. The present invention includes: a micro-power energy detection module that monitors the energy state of the sensing node in real time for energy grading, and then adaptively triggers an encryption mechanism matching the current energy level to enhance the security of the node sensing data; for lightweight encryption algorithms, the present invention reduces power consumption through adaptive energy interval matching and optimization strategies; for stream cipher encryption algorithms, random salt values are added to enhance the anti-collision property of the hash function hash value, realizing micro-power-driven adaptive data dynamic encryption and solving the data security protection problem caused by energy consumption constraints for a large number of distributed deployed passive sensing nodes. The present invention can, while ensuring the security of distributed passive sensors, extend the lifespan of passive sensor devices, thereby reducing their maintenance costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communications, and particularly relates to an adaptive micro-energy-driven passive sensing node security encryption system. Background Art

[0002] With the development of various key Internet of Things technologies, the wide application scenarios of the Internet of Things require terminal sensor devices to be deployed in every corner. By deploying sensing nodes in a large-scale distributed manner, various production and operation environments can be widely monitored, and a large amount of data can be obtained therefrom. However, due to the complex diversity of the deployment environment, extreme environments such as high mountains, high-temperature environments, uninhabited areas, and areas far from power sources pose high requirements on the lifespan and power supply of sensors. In order to overcome the limitations brought by these extreme environments, it is necessary to use the energy obtained from the environment (solar energy, wind energy, vibration energy, temperature difference energy) for autonomous power supply, so that the device can operate stably for a long time without manual intervention.

[0003] The energy source of passive sensing nodes has the characteristics of limitations and instability. The traditional method needs to use a microprocessor to control ADC (analog-to-digital converter) sampling, with high power consumption, which is obviously not applicable to passive sensing nodes with unstable energy sources; for the data security encryption process, since these devices cannot have a stable and sufficient energy supply like traditional devices, they need to use most of their energy for sensing tasks, simplify or even cancel security protection measures to save energy. The fixed encryption method will also burden the insufficient passive energy of passive sensing nodes. That is, the traditional encryption method is difficult to adapt to the dynamic nature of energy acquisition of passive sensing nodes. During the implementation of the technical solution of the present invention, the inventor found that: adaptively selecting different lightweight encryption algorithms according to the energy state of passive sensing nodes can ensure the secure transmission of data of passive sensing nodes under the condition of unstable energy supply of sensing nodes, so as to achieve the best security and energy utilization rate of passive sensing nodes. Summary of the Invention

[0004] The present invention provides an adaptive micro-energy-driven passive sensing security encryption system. By accurately dividing different energy thresholds and transmitting terminal data to algorithms with different encryption intensities, low power consumption overhead and dynamic data encryption of the node are achieved, and the maintenance cost of the sensing node is reduced.

[0005] The technical solution adopted by the present invention is as follows:

[0006] An adaptive security encryption system for the Internet of Things driven by micro energy, the process includes:

[0007] For the energy detection process, to achieve energy detection with micro-power consumption drive, this patent designs a micro-power consumption drive multi-threshold division detection circuit based on the principle of linear integral circuit, and configures N micro-power consumption voltage comparators at the same time.

[0008] Furthermore, an energy determination circuit with near-zero power consumption drive is designed based on an RC circuit, which is characterized by including a multi-threshold terminal node energy window division circuit and a near-zero power consumption micro-energy adaptive triggering circuit. According to the change of the battery energy of the sensor node, this determination circuit enables different energy states to be represented as voltages with different values, so that the micro-power consumption drive multi-threshold comparator group can classify the energy of the passive sensor node according to the voltage.

[0009] For the data security encryption process, N-level encryption modules are adaptively selected according to the energy state of the passive sensor node, which are: near-zero power consumption digital conversion cyclic shift encryption (the first-level encryption method), adaptive micro-energy drive multi-level hash stream cipher encryption (the 2nd to N-2th levels of encryption), lightweight security enhancement algorithm encryption (the N-1th to Nth levels of encryption).

[0010] Furthermore, the energy state of the passive sensor node is divided into three different energy levels: low, medium, and high. The N encryption modules are specifically: near-zero power consumption digital conversion cyclic shift encryption, adaptive micro-energy drive multi-level hash stream cipher encryption, GPRESENT encryption, and GHIGHT encryption. The N encryption modules perform data encryption according to different energy levels.

[0011] Furthermore, the near-zero power consumption digital conversion cyclic shift encryption algorithm is based on the message exclusive OR algorithm. The data to be encrypted is exclusive OR converted and then cyclically shifted two bits to the right to achieve data security encryption with zero power consumption; the adaptive micro-energy drive multi-level hash stream cipher encryption enhances data security by adding a periodic trigger key, a real-time environment-driven micro-energy signal, and an energy threshold; the GPRESENT encryption introduces a Feistel structure, which reduces the complexity of the original PRESENT encryption algorithm implementation through an iterative mode of "split-transform-combine" and improves the security of the encryption algorithm; the GHIGHT encryption enhances the algorithm security by re-dividing the plaintext and ciphertext blocks and splitting the original key into 8 16-bit blocks to reduce the algorithm energy consumption.

[0012] Furthermore, the periodic trigger key is a periodic trusted key used to generate hash values for adaptive micro-energy drive multi-level hash stream cipher encryption, which is generated based on a clock signal; the real-time environment-driven micro-energy signal is a time trusted quantity obtained according to the clock signal and is a salt variable used for generating hash values by a hash function; the energy threshold is the lowest value of the energy range of each passive sensor node and is also a salt variable used for generating hash values by a hash function.

[0013] Furthermore, the implementation of the adaptive micro - energy - driven multi - level hash stream cipher encryption algorithm includes the following steps:

[0014] ① Receive the periodic trusted key;

[0015] ② Receive the timestamp signal;

[0016] ③ Receive the energy threshold signal;

[0017] ④ Select the micro - energy - driven hash encryption algorithms with different energy consumption levels according to the energy threshold signal.

[0018] Furthermore, the hash stream cipher calculation formula is:

[0019]

[0020] Among them, H() represents the hash algorithm selected according to the energy threshold of the sensing node, r represents the periodic trusted key, T represents the real - time environment - driven micro - energy signal, N represents the energy threshold signal, and M represents the data transmitted by the sensing node.

[0021] The technical solution provided by the present invention at least brings the following beneficial effects:

[0022] During the energy detection process of passive sensing nodes, the energies of different passive sensing nodes can be divided into different energy levels. After passing through the multi - threshold processing circuit, data at different energy levels can be encrypted with different intensities, so as to achieve the effect of maximizing the use of the energy of sensing nodes for security enhancement. During the data security enhancement process, by optimizing the PRESENT and HIGHT encryption algorithms, the security of the algorithm can be improved while reducing the power consumption of the algorithm, which brings a great improvement to the security enhancement of passive sensing nodes; in the stream cipher encryption mode based on the hash algorithm, not only a periodic trusted key variable is added, but also two salt variables, namely the timestamp and the energy threshold of the passive sensing node, are added. The salted hash algorithm can effectively resist rainbow table attacks and prevent dictionary attacks, etc. In this way, the balance between the data security guarantee and the low - power requirement of passive sensing nodes is achieved, and the maximum utilization of terminal energy and the security enhancement of data are realized. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0024] Figure 1It is a basic schematic diagram of an adaptive micro-energy-driven passive sensing node security encryption system provided by an embodiment of the present invention;

[0025] Figure 2 It is a circuit flow schematic diagram of an adaptive micro-energy-driven passive sensing node security encryption system provided by an embodiment of the present invention;

[0026] Figure 3 It is a running logic schematic diagram of the GPRESENT encryption algorithm in an embodiment of the present invention;

[0027] Figure 4 It is a schematic diagram of the S-box data transformation of the GPRESENT encryption algorithm in an embodiment of the present invention;

[0028] Figure 5 It is a schematic diagram of the algorithm structure of the GHIGHT encryption algorithm in an embodiment of the present invention. Detailed implementation manners

[0029] To make the objectives, technical solutions and advantages of the present invention clearer, the following will further describe the embodiments of the present invention in detail with reference to the accompanying drawings.

[0030] Under the background of the current development of the Internet of Things, the Internet of Things perceives and acquires data from the world by deploying a large number of distributed sensing nodes, providing the necessary data sources for various digital applications. According to the IOT Analytics report, it is expected that by 2025, the number of global Internet of Things devices will reach 20 billion. With the continuous expansion of the scale of Internet of Things devices, in order to better achieve the interconnection of all things, sensors need to be able to adapt to complex and diverse deployment environments, such as remote areas, areas far from power sources, high-temperature and humid environments, etc., which all pose high requirements on the lifespan and power supply of sensors to withstand extreme working environments. Therefore, researchers have proposed to install self-powered devices such as solar panels and radio frequency energy receivers on sensor nodes. In this way, sensor nodes can continuously obtain energy from the environment, and the network thus formed is called a passive wireless sensor network. The passive wireless network can achieve self-sufficiency in energy, greatly reducing the later maintenance cost and effectively expanding the application scenarios of the passive sensing network.

[0031] However, environmental factors such as light intensity, temperature changes, and the availability of RF sources will directly affect the efficiency and stability of energy harvesting. For example, when the device is in an area with weak signals, the collection of RF energy may be significantly reduced, thus affecting the normal operation of the device. This energy instability makes it difficult for sensor nodes to allocate their precious energy for data security protection. Existing traditional encryption methods, such as AES, DES, RSA and other encryption algorithms, usually require high computing resources and energy consumption. For passive sensor nodes with unstable energy sources, in order to reduce power consumption, relatively simple security measures are often chosen, and even some necessary security encryption links may be omitted. There is an obvious limitation in the current hardware method, that is, it cannot be adaptively adjusted according to energy changes. This means that the hardware encryption module cannot flexibly adjust its operations to adapt to different energy constraints or power consumption requirements, thus unable to fully meet the flexibility requirements of intermittent computing systems. As a result, it is difficult to achieve a relative balance between the data security guarantee and low power consumption requirements of passive sensor nodes, and the problems of its energy instability and low security seriously restrict the wide application of passive sensor nodes in the Internet of Things.

[0032] In view of the above problems, an embodiment of the present invention provides an adaptive security encryption system for energy-driven passive sensor nodes. The system includes two modules: terminal energy detection and data security encryption. The specific system implementation flowchart is as Figure 1 shown.

[0033] For different energy levels of passive sensor nodes, namely the first energy level, the second energy level (including n - 3 sub-energy levels), and the third energy level (including two sub-energy levels), an embodiment of the present invention designs a micro-power-driven multi-level threshold division detection circuit based on an RC circuit, and configures N linear window comparators, enabling different sensor nodes to maximize the use of their energy for data security enhancement. Specifically, the system has N different encryption mechanisms, each encryption mechanism corresponding to a different lightweight encryption algorithm. At the same time, passive sensor nodes can select the encryption algorithm corresponding to their own energy level state for encryption, so as to achieve the effect of adaptive security encryption of passive sensor nodes.

[0034] As Figure 2 shown, an embodiment of the present invention provides a micro-power-driven multi-level threshold division detection circuit based on an RC circuit, which together with N linear window comparators constitutes an adaptive security encryption system. The multi-level adaptive security encryption method includes two parts: a multi-level threshold division detection circuit and N linear window comparators. The specific implementation processes of each part are as follows:

[0035] Multi-level threshold division detection circuit: The battery power status of the passive sensing node is used as the circuit input signal. When the circuit power is connected, the current flows through the resistor to charge the capacitor. During the charging process, the voltage across the capacitor gradually increases. According to the formula (where V c is the voltage across the capacitor, V is the power supply voltage, t is the time, and RC is the integration time constant), after setting the resistance value, the battery power status of the passive sensing node is divided into different voltage levels and then enters N linear window comparators.

[0036] Linear window comparator: A total of N linear voltage comparators are set in the linear window comparator. There is a highest threshold and a lowest threshold for the terminal energy processed by the RC circuit. When the terminal energy signal is input into the linear window voltage comparator, at this time, the threshold interval can contain multiple voltage thresholds, and the energy is judged to fall in the first energy level interval, the second energy level interval, or the third energy level interval according to the voltage threshold.

[0037] The encryption model of the present invention mainly includes four encryption modules, namely near-zero power digital conversion cyclic shift encryption, adaptive micro-energy-driven multi-level hash stream cipher encryption, GPRESENT algorithm encryption, and GHIGHT algorithm encryption.

[0038] Embodiment 1:

[0039] Referring to Figure 1 , the embodiment of the present invention provides a near-zero power digital conversion cyclic shift encryption corresponding to encryption energy level 1. Taking the data length n as an example, it includes:

[0040] Store the plaintext data to be processed in the shift register, and at the same time, the feedback shift register (LFSR) generates a pseudo-random sequence of length n; according to the different lengths of the plaintext data, the D flip-flops of the shift register and the feedback shift register will also change accordingly.

[0041] Further, for the plaintext data string M = a0a1a2…a n of length n and the pseudo-random sequence S = b0b1b2…b n of length n, this patent sets a total of n exclusive-OR logic gates based on exclusive-OR gates, and connects the data bits of M and the data bits of S to both ends of the exclusive-OR gate correspondingly; specifically, a0 and b0 are connected to the two input terminals of the first exclusive-OR gate, a1 and b1 are connected to the two input terminals of the second exclusive-OR gate, and so on. The output terminals of the exclusive-OR gates form the result data string C = c0c1c2…c n .

[0042] Among them, M is the plaintext data string; a i is a single data character in the plaintext data string; S is the pseudo-random sequence data string; bi A single digit character in a pseudo-random sequence data string; C is the result data string after exclusive OR; c i is a single data character in the result data string.

[0043] Embodiment 2:

[0044] Reference Figure 1 , the embodiment of the present invention provides an adaptive micro-energy-driven multi-level hash stream cipher encryption. Taking encryption level 2 as an example, it includes:

[0045] Store the plaintext data to be processed in a shift register, generate a string of pseudo-random sequences as a periodic trusted key by a feedback shift register (LFSR), and use the clock signal and the highest threshold as the salt variables for generating the hash value.

[0046] Furthermore, use three registers to store the periodic trusted key, the clock signal, and the highest threshold respectively; use a data input and hash stream synchronization circuit to receive the hash value and the plaintext data; use an exclusive OR gate circuit to perform bitwise exclusive OR on the plaintext data and the hash value; use a ciphertext output circuit to output the encrypted ciphertext data.

[0047] Embodiment 3:

[0048] As Figure 3 shown, the embodiment of the present invention provides a GPRESENT encryption algorithm with an algorithm strength of the (N - 1)th level. This scheme introduces a Feistel structure and modifies part of the P permutation algorithm structure. The various theoretical and hardware implementation steps of this algorithm are as follows:

[0049] A new S-box input and output: As Figure 4 shown, the input of one S-box of this algorithm comes from four different S-boxes, and the output of one S-box enters four different S-boxes. 32-bit data enters eight S-boxes, and after passing through the S-boxes, it enters the P-box permutation for data reordering. For the output data of the S-boxes, different lines represent that the data enters different S-boxes in the next round. Similarly, it can be known that the input of one S-box comes from 4 different S-boxes. The input and output expression of the S-box is as follows:

[0050]

[0051] X = X3||X2||X1||X0 → Y = Y3||Y2||Y1||Y0

[0052] Y i = S(X i ), 0 ≤ i ≤ 3

[0053] Among them, the S-box is a commonly used non-linear substitution operation in cryptography; the P-box is a substitution operation in cryptography used to reorder data; represents the input-output relationship of the S-box; X = X3||X2||X1||X0 → Y = Y3||Y2||Y1||Y0 means that each data bit X3, X2, X1, X0 of X is calculated through the S-box to obtain the output of each data bit (Y3, Y2, Y1, Y0) of Y; || represents the concatenation operation.

[0054] A new P-permutation: This P-permutation maps the 32-bit plaintext state, and each bit is swapped to the corresponding position. The function corresponding to the P layer is as shown in the formula:

[0055] For 0 ≤ i ≤ 7

[0056] b i ←b 4*i , b i+8 ←b 4*i+1

[0057] b i+16 ←b 4*i+2 , b i+24 ←b 4*i+3

[0058]

[0059] Among them, b i represents the i-th bit in the plaintext state, P(i) is the P function that performs the substitution operation, and mod is a modulo operation that returns the remainder after dividing two numbers.

[0060] Table 1 GPESENT P-box substitution table

[0061] i 0 1 2 3 4 5 6 7 <![CDATA[P i > 0 8 16 24 1 9 17 25 i 8 9 10 11 12 13 14 15 <![CDATA[P i > 2 10 18 26 3 11 19 27 i 16 17 18 19 20 21 22 23 <![CDATA[P i > 4 12 20 28 5 13 21 29 i 24 25 26 27 28 29 30 31 <![CDATA[P i > 6 14 22 30 7 15 23 31

[0062] Furthermore, for the GPRESENT lightweight encryption algorithm, a register composed of 64 D flip-flops is used to store the plaintext data, and 64 multiplexers (MUX) are used to divide the stored data into two 32-bit branches, left and right.

[0063] Furthermore, in each round of the encryption process, the key generation unit generates the corresponding round key according to the current round number and the initial key, and a 2-bit XOR gate array performs a bitwise XOR operation on the 32-bit R i-1 (or other intermediate data) and the round key K i-1 synchronously under the control of the clock signal, and then performs the S-box substitution operation.

[0064] Furthermore, for the S-box substitution operation, 4-bit input data is sent to a read-only memory (ROM), and the ROM outputs the corresponding mapping value according to the input address; for the P-box permutation, it realizes the data permutation through a group of multiplexers (MUX). The selection signals of the MUX are set according to the permutation rules of the P-box, and the bits of the input data are rearranged and then output to complete one round of the round function operation.

[0065] Furthermore, the XOR circuit module in the left and right branch update circuit of the Feistel structure performs a 32-bit XOR operation between the round function output and L i-1 . The inputs of the 32-bit XOR gate array are respectively connected to the register storing L i-1 and the round function output signal line. Triggered by the clock signal, the value of R i is calculated. The register composed of D flip-flops stores the calculated L i and R i values at the rising edge of the clock signal. The inputs of these registers are connected to the XOR circuit module and the R i-1 of the previous round (for updating L i ), and the outputs are connected to the input ports required for the next round of encryption operation to prepare for the next round of encryption operation.

[0066] Furthermore, the counter in the 32-round iteration control circuit starts counting from 1, and each counting rising edge triggers one round of encryption operation. The clock signal of the counter is synchronized with the main clock signal of the entire circuit, and its counting range is set from 0 to 32. When the counter value is 0, the circuit performs the initial data processing and initial key loading operations. When the counter value is between 1 and 32, each clock cycle coordinates each sub-circuit (round key generation, round function, left and right branch update, etc.) to complete one round of encryption operation. During each round of encryption process, control signals are transmitted between each sub-circuit to ensure that they work in the correct order and timing. For example, the control signal can enable or disable the operations of certain circuit modules, or adjust the internal working mode of the module to ensure the orderly progress of the entire encryption process. When the counter reaches 32, the encryption process is completed. At this time, the data in the registers storing L 32 and R 32 is used as the final ciphertext, finally realizing the security enhancement of the data.

[0067] In the embodiment of the present invention, after modifying the algorithm, a detailed analysis of the security of GPRESENT is carried out, mainly divided into linear cryptanalysis and differential cryptanalysis. The specific analysis process is as follows:

[0068] Linear cryptanalysis: The 5-round iteration structure of the PRESENT algorithm has at least 10 differential active S-boxes. The maximum linear approximation probability of the 4-round iteration structure of the PRESENT algorithm is about 2 -7. The maximum linear approximation probability of the S-box of the PRESENT cipher is 2 -2 , and the algorithm contains at least 4 active S-boxes in each round. By applying the Piling-Up Lemma, the linear bias of the active S-boxes of the 10-round GPRESENT cipher can be calculated as shown in the formula:

[0069] ε = 2 10*4-1 × (2 -2 ) 10*4 = 2 -41

[0070]

[0071] where ε represents the linear bias. The higher the linear bias, the higher the success rate of the linear attack; N L represents the square of the reciprocal of the linear bias, which is used to measure the data complexity required for the linear attack.

[0072] For the improved PRESENT lightweight encryption algorithm, for the 32-round algorithm, according to the formula, the estimated data complexity of the linear attack is 2 82 , exceeding the security threshold of 2 64 . Therefore, the SFP cipher can completely resist linear cryptanalysis.

[0073] Differential cryptanalysis: For differential and linear cryptanalysis, the number of the minimum active S-boxes determines the security of the cipher. For this GPRESENT algorithm, the S-boxes in the entire round function satisfy:

[0074] 1. The input of one S-box comes from four different S-boxes, and the output of one S-box enters four different S-boxes.

[0075] 2. The input with a one-bit difference will always result in a two-bit or higher output difference.

[0076] 3. The active S-box patterns of 1-1-1 and 1-2-1 will not appear.

[0077] 4. The 1-2-2-1 pattern will have the minimum number of active S-boxes because any other pattern with a smaller number of active S-boxes will violate 1, 2, and 3.

[0078] 5. If any other case has three or four differential active S-boxes in the round function body of any round, there will be at least six or more active S-boxes in total.

[0079] Therefore, the entire algorithm contains at least 6 active S-boxes in each round. Thus, there will be at least 6 × 10 = 60 active S-boxes in the first 10 rounds of the algorithm. For the GPRESENT algorithm, the maximum differential probability of its S-box is 2 -2, the differential probability of the first ten rounds is 2 -60 , at least 2 120 of data complexity is required for a successful attack. Exceeding 2 64 of the security threshold, so this algorithm can resist differential analysis.

[0080] The GPRESENT algorithm and the PRESENT algorithm have the characteristics of being superior to the original PRESENT encryption algorithm in terms of security. Specifically, for the GPRESENT cipher, its maximum differential probability for 12 rounds is 2 -144 , the differential analysis complexity for 12 rounds is 2 144 , the GPRESENT cipher only needs 12 rounds to achieve the same ability to resist differential analysis as the PRESENT cipher. For the GPRESENT cipher, its maximum linear bias for 11 rounds is 2 -45 , that is, the GPRESENT cipher only needs 11 rounds to achieve 2 90 of linear attack complexity. That is, for the GPRESENT cipher, only 11 rounds are needed to achieve the same ability to resist linear analysis as 28 rounds of the PRESENT cipher.

[0081] As Figure 5 shown, the embodiment of the present invention provides a GHIGHT encryption algorithm. The algorithm strength is at the Nth level. Consider dividing the plaintext P and the ciphertext C into 4 16-bit blocks P3,..., P0 and C3,..., C0, and the original key K into 8 16-bit blocks K7,..., K0. The initial transformation uses two whitening key bytes RK0, RK1 to transform a plaintext P into the input of the first-round function, X0 = X 0,3 ||...||X 0,0 . In the final transformation, the data is shifted to the right, and four whitening keys WK2, WK3 are used to transform X 32 = X 32,3 ||...||X 32,0 into the ciphertext C. Both of these conversions perform exclusive OR and modular addition. The 4 16-bit whitening keys WK3,..., WK0 for the initial and final transformations.

[0082] For l ≥ 0, WK l ← K 6+l , WK l+2 ← K l

[0083] The rouNd function remains unchanged. The key RK i for the i-th round is composed of SK 2*i and SK 2*i+1 , and the values are respectively:

[0084] SK 2*i = SK 4*i+1|SK 4*i+2

[0085] SK 2*i+1 =SK 4*i |SK 4*i+3

[0086] where SK 4*i , SK 4*i+1 , SK 4*i+2 , SK 4*i+3 is generated in the same way as the HIGHT encryption algorithm.

[0087] The initial transformation module uses two whitening key bytes RK0 and RK1 to transform the plaintext P into the input X0 of the first-round function. To implement the XOR and modular addition operations, for each 16-bit block, a dedicated 16-bit XOR gate array and a modular adder are designed. The design of the modular adder is based on an adder and a comparator. To perform modular 2 16 addition, for example, the adder first performs an addition operation on the input data, and its output result is connected to the comparator. The comparator compares the addition result with 2 16 , and if it is greater, subtracts 2 16 through the subtractor to obtain the final modular addition result.

[0088] Furthermore, the whitening keys RN0 and RK1 are stored in specific registers respectively. These registers are composed of D flip-flops and stably store the key values under the control of the clock signal. The outputs of the registers storing RK0 and RK1 are respectively connected to the corresponding input ports of the XOR gate array and the modular adder with the corresponding plaintext block inputs. Specifically, for P0, it passes through the XOR gate array and the modular adder in sequence with RK0 to obtain X 0,0 , and the same operations are performed on P1, P2, and P3 respectively. Finally, X0 = X 0,3 ||...||X 0,0 . The round function module remains unchanged, and a 16-bit XOR gate array is designed in the round key addition transformation part. The input data and the round key are respectively connected to two groups of input pins of the XOR gate array. Under the control of the clock signal, the bitwise XOR operation of the input data and the round key is realized.

[0089] Furthermore, the S-box circuit is implemented by using a look-up table (LUT) method. For a specific S-box, such as an S-box with 4-bit input and output, a ROM (read-only memory) with 16 storage units is used. The address line of the ROM is connected to the corresponding bits of the input data, and the corresponding mapped value is output according to the input address. For the processing of 16-bit data, multiple S-boxes may need to be cascaded. The data transmission of the input and output of each S-box should be synchronized by the clock signal to ensure the correctness of data processing.

[0090] Further, the P-box circuit implements data permutation through a multiplexer (MUX). According to the permutation rule of the P-box, the input and output pins of the MUX are connected accordingly. The input data is connected to the input port of the MUX. Triggered by the clock signal, the data bits are rearranged according to the selection signal to achieve the permutation effect.

[0091] Further, the round key generation module is used to generate the i-th round key RK i , which consists of SK 2*i and SK 2*i+1 . Among them, the generation of SK 4*i , SK 4*i+1 , SK 4*i+2 , SK 4*i+3 is consistent with the HIGHT encryption algorithm. Based on the SK generation logic of the HIGHT algorithm, the design of this module includes circuit components such as shift registers and logic operation units. The shift register moves data according to specific displacement rules under the drive of the clock signal. The logic operation unit (such as AND gate, OR gate, NOT gate, etc.) performs logic operations on the shifted data according to the algorithm requirements to generate the SK value; according to the formula SK 2*i = SK 4*i+1 | SK 4*i+2 and SK 2*i+1 = SK 4*i | SK 4*i+3 , the generated SKs are combined into RK i using logic gates (such as OR gates). In the hardware circuit, the generated values of SK 4*i , SK 4*i+1 , SK 4*i+2 , SK 4*i+3 are connected to the corresponding input pins of the OR gate, and the output of the OR gate is the value of RK i .

[0092] The final transformation module shifts the data X 32 to the right and transforms it into the ciphertext C using four whitening keys WK2 and WK3. The data shift circuit realizes the right shift operation of data by designing a shift register. For X 32 = X 32,3 || …… || X 32,0 , each 16-bit block is shifted to the right by a 16-bit shift register, and the shift amount is precisely set according to the algorithm requirements. The shift register moves data according to the specified shift rhythm under the control of the clock signal. Similar to the whitening key processing in the initial transformation module, this module uses XOR and modular addition circuits. WK2 and WK3 are stored in dedicated registers, and the outputs of these registers are connected to the corresponding inputs of the XOR gate array and modular adder together with the shifted data. After XOR and modular addition operations, each block C3, C2, C1, C0 of the ciphertext C is obtained.

[0093] After modifying the algorithm in the embodiments of the present invention, a detailed analysis of the security of GPRESENT is carried out, mainly including avalanche effect cryptanalysis and differential cryptanalysis resistance. The specific analysis process is as follows:

[0094] Avalanche effect cryptanalysis: The avalanche effect test steps for the GHIGHT algorithm are as follows:

[0095] 1. Randomly fix a group of keys K and randomly select a group of plaintext P.

[0096] 2. Obtain the initial ciphertext C after encryption.

[0097] 3. Flip the first bit of the plaintext, keep the rest unchanged, and then encrypt it together with the key.

[0098] 4. Obtain the ciphertext C0 after encryption.

[0099] 5. Calculate as the avalanche degree of the plaintext on the first bit.

[0100] 6. Repeat the above steps to find the avalanche degree of all bits of the plaintext P.

[0101] 7. Repeat the previous steps 1000 times. Each time, the plaintext P is random and the key is the initial fixed key. After the above experiments, a total of 1000 groups of avalanche data are obtained. Under the condition of reducing energy consumption, this avalanche data all shows good performance.

[0102] Differential cryptanalysis resistance: GHIGHT uses modular addition operation as a non - linear component in the round function. In the differential process, cyclic shift and exclusive - or operation propagate differentials with a probability of 1. Therefore, the differential cryptanalysis of GHIGHT only needs to analyze the exclusive - or differential of the modular addition operation. When the input modular addition differentials Δα, Δβ, Δr and the output modular addition differential Δσ are given, where Δα and Δβ are the input differentials of the exclusive - or operation, the modular addition differential probability in the GHIGHT encryption algorithm can be calculated by the following formula:

[0103]

[0104] where C=(10000000) T , L=(11111111), A w[i] represents the state transition matrix. w[i]=Δα[i]||Δβ[i]||Δσ[i + r], and its value has 8 states. The state transition matrices corresponding to w[i]=001, 010, 100 are the same, and the state matrices corresponding to 011, 110, 101 are the same. The specific ones are as follows:

[0105]

[0106] From the above formula, when the input differences of the round function used by GHIGHT are not all 0, the maximum differential probability obtained with a 16-bit input word length is 2 -3 , and the maximum differential probability of GHIGHT encrypted for 27 rounds is 2 -81 , and the data complexity required for at least one successful attack is 2 81 , which is much greater than the security threshold 2 64 , so GHIGHT can resist differential analysis.

[0107] When comparing the security with the original HIGHT encryption algorithm, the GHIGHT encryption algorithm is more suitable for the energy system of passive sensing nodes driven by micro-power consumption in terms of its security and encryption performance.

[0108] In summary, an adaptive micro-energy-driven passive sensing node security encryption system provided by an embodiment of the present invention can adaptively and fully utilize the energy of the sensing node under the extremely unstable energy of the passive sensing node, provide sufficient security enhancement for data transmission, and ultimately achieve a relative balance between the data security guarantee and low-power requirements of the passive sensing node.

[0109] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and creative concepts of the present invention, and these all belong to the protection scope of the present invention.

Claims

1. An adaptive micro-energy-driven passive sensing node security encryption system, characterized in that, Comprising: A micro-power-driven multi-level threshold division energy detection circuit, which is composed of an RC circuit and N linear window comparators, is used to detect the energy state of the sensing node in a near-zero power consumption manner and classify the energy; An energy adaptive encryption control unit, which is used to automatically trigger a data encryption mechanism matching the energy level according to the energy classification result. Among them, the first-level energy corresponds to the use of a near-zero power consumption cyclic shift encryption algorithm, the 2nd to N-2th level energy corresponds to the use of an adaptive micro-energy-driven multi-level hash stream cipher encryption algorithm, and the N-1th to Nth level energy corresponds to the use of a lightweight security-enhanced encryption algorithm; Among them, the RC circuit converts the node environment energy state into voltage signals with different amplitudes, so that the linear window comparator, that is, the micro-power-driven multi-threshold comparator group, can determine the energy level according to the preset threshold and trigger the corresponding energy level encryption mechanism; Among them, the adaptive micro-energy-driven multi-level hash stream cipher encryption algorithm is to store the plaintext data to be processed in a shift register, and a pseudo-random sequence is generated by a feedback shift register (LFSR) as a periodic trusted key. The clock signal and the highest threshold are used as the salt variables for generating the hash value; further, three registers are used to store the periodic trusted key, the clock signal, and the highest threshold respectively; a data input and hash stream synchronization circuit is used to receive the hash value and the plaintext data; an exclusive OR gate circuit is used to perform bitwise exclusive OR on the plaintext data and the hash value; a ciphertext output circuit is used to output the encrypted ciphertext data.

2. The secure encryption system according to claim 1, wherein the near-zero power consumption cyclic shift encryption algorithm is based on the message exclusive OR algorithm, and the plaintext data to be processed is stored in a shift register, and at the same time, a feedback shift register (LFSR) generates a pseudo-random sequence of length n; according to the different lengths of the plaintext data, the D flip-flops of the shift register and the feedback shift register will also change accordingly.

3. The security encryption system according to claim 2, characterized in that, The near-zero power consumption cyclic shift encryption algorithm is applied to the plaintext data string M = a0a1a2…a of length n n and the pseudo-random sequence S = b0b1b2…b of length n n , and a total of n exclusive-OR logic gates are set based on exclusive-OR gates. The data bits of M and the data bits of S are correspondingly connected to both ends of the exclusive-OR gates, so as to realize near-zero power consumption encryption through exclusive-OR operations.

4. The secure encryption system according to claim 1, characterized in that, The N-1 level lightweight security enhanced encryption algorithm corresponds to the GPRESENT encryption algorithm. The GPRESENT encryption algorithm introduces the Feistel structure. The exclusive OR circuit module in the left and right branch update circuits of the Feistel structure performs a 32-bit exclusive OR operation between the round function output and L i-1 ; At the same time, part of the P permutation algorithm structure of the GPRESENT encryption algorithm is modified. The P permutation in the GPRESENT encryption algorithm maps the 32-bit state plaintext, and each bit is swapped to the corresponding position in the P-box permutation table to achieve lightweight security enhancement.

5. The security encryption system according to claim 1, wherein The Nth energy level lightweight security-enhanced encryption algorithm corresponds to the GHIGHT encryption algorithm, which divides the plaintext P and the ciphertext C into 4 16-bit blocks P3, ……, P0 and C3, ……, C0, and the original key K is divided into 8 16-bit blocks K7, ……, K0; by re-dividing the plaintext and ciphertext blocks and splitting the original key into 8 16-bit blocks, the energy consumption of the algorithm is reduced and the security of the algorithm is enhanced.

6. The secure encryption system according to claim 1, characterized in that, The implementation of the adaptive micro-energy-driven multi-level hash stream cipher encryption algorithm includes the following steps: Receiving a periodic trusted key; Receiving a timestamp signal; Receiving an energy threshold signal; Selecting a micro-energy-driven hash encryption algorithm with different energy consumption levels according to the energy threshold signal.

Citation Information

Patent Citations

  • Base-station-like energy supply encryption method based on RFID passive transmission

    CN113225734A

  • Data processing method based on industrial internet-of-things intelligent chip and related equipment

    CN113689310A