A national encryption algorithm system and a national encryption algorithm packaging system
By using direct memory access and data frame mode communication in the hardware architecture, the problem of high processor load is solved, and the computing efficiency and information security of the national cryptographic algorithm system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2026-03-17
AI Technical Summary
In existing technologies, when a processor performs data decryption or encryption operations, it needs to communicate with the software via software control, resulting in a high processor load and affecting overall efficiency.
The hardware architecture employs a direct memory access module, a data flow control module, and an algorithm module. Data interaction and communication are performed through a data frame mode, reducing software involvement and improving hardware scheduling and transmission efficiency.
By directly accessing memory data through hardware, processor load is reduced, the overall efficiency of encryption or decryption operations is improved, and information security and system performance are enhanced.
Smart Images

Figure CN119865367B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security, specifically to a national cryptographic algorithm system and a national cryptographic algorithm encapsulation system. Background Technology
[0002] With the rapid development of information technology, information security is becoming increasingly important in critical sectors such as finance, healthcare, and government. National cryptographic algorithms, as domestically developed cryptographic standards, are one of the key technologies for achieving information security. However, in existing architectures, during data decryption or encryption operations, contextual communication during business operations requires data transmission through processor control software, resulting in high processor load and impacting the overall efficiency of encryption or decryption operations. Summary of the Invention
[0003] In view of this, the present invention provides a national cryptographic algorithm system and a national cryptographic algorithm encapsulation system to solve the problem that the processor load is high due to the communication and transmission of context data by the processor control software, which affects the overall efficiency of encryption or decryption operations.
[0004] In a first aspect, this invention provides a national cryptographic algorithm system, including a direct memory access module, a data flow control module, a register module, and an algorithm module. The direct memory access module is used to retrieve memory data. The data flow control module is communicatively connected to the direct memory access module. The register module is communicatively connected to the data flow control module and is used to store key information and parameter information. The algorithm module is communicatively connected to the data flow control module and is used to perform encryption or decryption operations on first preset data within the data flow control module. The data flow control module and the direct memory access module communicate and exchange data via data frames.
[0005] Beneficial Effects: In the national cryptographic algorithm system provided by this invention, the direct memory access module can directly access the memory module to retrieve memory data, which is then used to communicate with the data flow control module. Within the data flow control module, the module can configure key and parameter information through the register module and retrieve the corresponding algorithm through the algorithm module to perform encryption or decryption operations on the first preset data. This allows the national cryptographic algorithm to encrypt or decrypt the first preset data, ensuring information security.
[0006] Building upon this foundation, during data exchange and communication between the Direct Memory Access (DMI) module and the Data Flow Control (DLC) module, data transmission occurs via data frames. This means that during the computation of the national cryptographic algorithm, parameter configuration and context communication for business operations can be exchanged between the DMI and DLC modules using data frames. In other words, the large-scale data exchange is scheduled and transmitted via hardware, eliminating the need for software intervention. This approach reduces host computer involvement, relieves the pressure on processors such as the main control module, and improves the overall efficiency of the national cryptographic system during computation.
[0007] Furthermore, due to the inherent hardware characteristics of the Direct Memory Access (DMI) module, peripherals can retrieve data from the memory module without the intervention of the main control module or other processors. This enables high-speed data transfer between the memory module and the DMI module, further relieving the workload on the main control module and other processors, and improving the overall efficiency of the national cryptographic system during computation.
[0008] In some implementations, the direct memory access module includes a data input buffer, a data output buffer, a first state controller, a downlink framing unit, and an uplink deframing unit. The data input buffer buffers downlink data information sent to the data flow control module. The data output buffer buffers uplink data information received by the data flow control module. The first state controller is communicatively connected to the data input buffer and the data output buffer to control the transmission of downlink data information and the retrieval of uplink data information. The downlink framing unit reassembles downlink data information into downlink data frames. The uplink deframing unit parses the uplink data frames and buffers the parsed uplink data information into the data output buffer.
[0009] Beneficial effects: The first state controller can control the operating state of the direct memory access module, such as controlling the transmission of downlink data and the retrieval of uplink data. For example, when the first state controller detects that the data input buffer is not empty, it controls the downlink framing unit to reassemble the downlink data information in the data input buffer into downlink data frames for rapid transmission to the data flow control module. When the first state controller detects that the uplink transmission unit is not empty, it controls the uplink deframing unit to receive and parse the uplink data frames, thereby obtaining the uplink data information and caching it in the data output buffer. The uplink data information may be data obtained by encrypting or decrypting first preset data.
[0010] In some implementations, the data flow control module includes a downlink frame buffer, a computation data buffer, a second state controller, a frame header parsing unit, a downlink verification unit, an uplink framing unit, and an uplink transmission unit. The downlink frame buffer receives and buffers downlink data frames. The computation data buffer receives and buffers second preset data processed by the algorithm module. The second state controller is communicatively connected to the downlink frame buffer and the computation data buffer. The frame header parsing unit parses the downlink data frames and feeds back the parsing information to the second state controller. The downlink verification unit verifies the frame header of the downlink data frames. The uplink framing unit reassembles the second preset data into uplink data frames. The uplink transmission unit transmits the uplink data frames to the uplink deframing unit.
[0011] Beneficial effect: The second state controller can directly control the operating state of the data flow control module. The frame header parsing unit parses the downlink data frame to obtain information such as the service type, algorithm type, and data length / parameter length of the downlink data frame, and feeds this information back to the second state controller. After the algorithm module performs encryption or decryption operations on the first preset data, the encrypted or decrypted second preset data is cached in the operation data cache, so that the uplink framing unit can reassemble the second preset data into an uplink data frame, enabling the uplink transmission unit to quickly transmit the uplink data frame to the uplink deframing unit of the direct memory access module for deframing.
[0012] Based on this, in this embodiment of the invention, by configuring an interactive communication structure of data frames between the direct memory access module and the data flow control module, the process of large-scale data interaction between the memory access module and the data flow control module via data frames only requires hardware structure scheduling and configuration, without the need for software intervention. This reduces host involvement, relieves the pressure on processors such as the main control module, and helps improve the overall efficiency of the national cryptographic system during the operation process.
[0013] In some implementations, the downlink data frame includes a management frame and a service frame. The management frame includes a management frame header and management information, the latter used to configure key and parameter information. The service frame includes a service frame header and first preset data.
[0014] Beneficial effects: By setting management frames, it is convenient to initialize or update configuration keys within the data flow control module. By setting service frames, during encryption or decryption operations, the service frame header can be used to indicate which service is being performed, such as encryption / decryption, hashing, signing, and signature verification, which is beneficial for the fast and stable transmission of the initial preset data.
[0015] In some implementations, the direct memory access module further includes a management register, a descriptor cache, and a descriptor processing unit. The management register is communicatively connected to the first state controller. The descriptor cache is also communicatively connected to the first state controller, and the management register controls the reading of the descriptor list and its caching in the descriptor cache. The descriptor processing unit is communicatively connected to both the descriptor cache and the first state controller. The first state controller is configured to:
[0016] When the descriptor cache is not empty, the first state controller starts the descriptor processing unit to read the descriptor linked list from the descriptor cache, so as to obtain at least the memory start address information and the service type information.
[0017] Beneficial effects: Since the data, parameters and other information cached in the memory module are not necessarily in a contiguous area at the physical level, by setting the descriptor cache and the descriptor processing unit, the direct memory access module is made into a chain structure, so that the direct memory access module can read and transfer data in non-contiguous areas within the memory module through the descriptor linked list.
[0018] This structure allows the first preset data to be distributed across multiple non-contiguous memory modules and organized using a descriptor linked list. This reduces the number of interrupts during data transfer, thus improving efficiency. In contrast, ordinary DMA typically requires an interrupt after transferring a physically contiguous block of data, before the host can transfer the next block, introducing additional overhead.
[0019] Because the number of interrupts is reduced during data transfer from the memory module, the host (or processor) can focus more on performing other tasks without frequent intervention in the data transfer process. This helps to reduce the burden on the host (or processor) and improve the overall performance of the national cryptographic computing encapsulation system.
[0020] In some implementations, the register module includes a register interface unit, a first identifier storage unit, a key storage unit, a second identifier storage unit, and a parameter storage unit. The register module and the data flow control module are communicatively connected via the register interface unit. The first identifier storage unit stores the key sequence number of the key information and the storage address of the key information corresponding to the key sequence number. The key storage unit stores multiple types of key information, with each type of key information corresponding to at least one key sequence number. The second identifier storage unit stores the parameter sequence number of the parameter information and the storage address of the parameter information corresponding to the parameter sequence number. The parameter storage unit stores multiple types of parameter information, with each type of parameter information corresponding to at least one parameter sequence number.
[0021] Beneficial effects: By configuring a first identifier storage unit and a second identifier storage unit in the register module, specific keys and parameters can be easily indexed and identified. This facilitates quick access and management of key and parameter information while preventing direct leakage of information in the key and parameter storage units, thus providing initial protection for the keys and parameters required by the algorithm. This contributes to increasing the security, reliability, and confidentiality of the entire system's cryptographic operations.
[0022] In some implementations, the register interface unit is configured such that the control key storage unit and the parameter storage unit communicate with each other only through hardware transmission.
[0023] Beneficial effects: By configuring the register interface unit, the key and parameter data in the key storage unit and parameter storage unit can only be read and written through hardware, and cannot be read through software. Combined with the above scheme, this prevents the leakage of information in the key and parameter storage units through software channels, providing secondary protection for the keys and parameters required by the algorithm. This further enhances the security, reliability, and confidentiality of the entire system's cryptographic operations.
[0024] In some implementations, the algorithm module includes an algorithm interface unit and multiple data processing units. The algorithm interface unit is communicatively connected to the data flow control module, enabling the data flow control module to invoke the data processing units to perform encryption or decryption operations on first preset data. The multiple data processing units include at least SM2, SM3, and SM4 algorithms, and the data processing unit used to execute the SM4 algorithm is configured with a multi-threaded structure.
[0025] Beneficial Effects: The algorithm module, as an internal module of this invention, primarily interacts with the data flow control module. The algorithm interface unit is used to adapt to the communication handshake protocol of the data flow control module. The algorithm module integrates multiple data processing units, which include at least national cryptographic algorithms such as SM2 / SM3 / SM4. For example, a data processing unit uses the SM2 algorithm (SM2 cryptographic algorithm, i.e., SM2 public-key cryptography algorithm) to implement key exchange, data encryption, decryption, digital signature, and signature verification functions. A data processing unit uses the SM3 algorithm (Security Message Digest Algorithm) to process a first preset data of arbitrary length, generating a fixed-length hash value, which is typically used to verify the integrity and authenticity of the data. A data processing unit internally implements a multi-level (e.g., 32-level) pipeline using the SM4 algorithm (SM4 Block Cipher Algorithm), supporting ECB, CBC, CFB, OFB, and CTR algorithm modes to achieve data encryption and decryption services for different scenarios and needs, with high security and high efficiency.
[0026] Secondly, this invention provides a Chinese cryptographic algorithm encapsulation system, including an I / O module, a main control module, a memory module, and the Chinese cryptographic algorithm system mentioned in the first aspect. The I / O module, the main control module, the memory module, and the Chinese cryptographic algorithm system are interconnected via a system bus.
[0027] Beneficial effects: Since the national cryptographic algorithm encapsulation system includes the national cryptographic algorithm system in the first aspect, the national cryptographic algorithm encapsulation system has all the beneficial effects of the aforementioned national cryptographic algorithm system, which will not be elaborated here.
[0028] In some implementations, the main control module is configured as follows:
[0029] Preset data is cached in a memory module, and the starting addresses of several regions containing the cached preset data in the memory module are recorded as several first memory starting addresses. The preset data includes first preset data, second preset data, key information, and parameter information.
[0030] The feature information of the preset data is recorded in several descriptor linked lists. These descriptor linked lists are cached in the memory module, and the starting address of the region in the memory module where the descriptor linked lists are cached is recorded as the second memory starting address. The feature information includes at least the first memory starting address of the preset data, the data type, the data byte length, and the frame type.
[0031] The main control module configures the direct memory access module through the second memory starting address, so that the memory access module can read and cache the descriptor linked list from the memory module, and parse and obtain the preset data in the memory module according to the descriptor linked list.
[0032] Beneficial effects: During the data caching process within the memory module, the main control module, through the configuration of the descriptor linked list, enables the direct memory access module to continuously read discontinuous data from the memory module. Because the number of interruptions during data transfer is reduced, the main control module can focus more on performing other tasks without frequently intervening in the data transfer process. This helps to alleviate the burden on the main control module and improve the overall system performance. Attached Figure Description
[0033] To more clearly illustrate the technical solutions in the specific embodiments or related technologies of the present invention, the drawings used in the description of the specific embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0034] Figure 1 This is a schematic diagram of the overall structure of a national cryptographic algorithm system provided in an embodiment of the present invention;
[0035] Figure 2 for Figure 1 A schematic diagram of a direct memory access module shown in the figure;
[0036] Figure 3 for Figure 1 A schematic diagram of a data flow control module shown in the figure;
[0037] Figure 4 This is a schematic diagram of the structure of a management frame and a service frame provided in an embodiment of the present invention;
[0038] Figure 5 for Figure 1 A schematic diagram of the structure of the register module and algorithm module described herein;
[0039] Figure 6 This is a schematic diagram of a national cryptographic algorithm encapsulation system provided in an embodiment of the present invention;
[0040] Figure 7 A management-related business process diagram provided in an embodiment of the present invention;
[0041] Figure 8 A data-related business process diagram provided in an embodiment of the present invention;
[0042] Figure 9This is a data flow control flowchart provided in an embodiment of the present invention.
[0043] Figure label:
[0044] 100. National Cryptographic Algorithm System;
[0045] 10. Direct Memory Access Module; 11. First State Controller; 12. Data Input Buffer; 13. Downlink Framing Unit; 14. Uplink Deframing Unit; 15. Data Output Buffer; 16. Management Register; 17. Descriptor Buffer; 18. Descriptor Processing Unit; 19. Interrupt Control Unit;
[0046] 20. Data Flow Control Module; 21. Second State Controller; 22. Downlink Frame Buffer; 23. Frame Header Parsing Unit; 24. Downlink Verification Unit; 25. Calculation Data Buffer; 26. Uplink Framing Unit; 27. Uplink Transmission Unit; 281. Configuration Parameter Unit; 282. Algorithm Scheduling Unit; 283. Service Calculation Unit;
[0047] 30. Register module; 31. Register interface unit; 32. First identifier storage unit; 33. Key storage unit; 34. Second identifier storage unit; 35. Parameter storage unit;
[0048] 40. Algorithm module; 41. Algorithm interface unit; 42. Data processing unit;
[0049] 200. I / O module;
[0050] 300. Main control module;
[0051] 400. Memory module. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0053] The following is combined with Figures 1 to 9 This application describes the national cryptographic algorithm system and its encapsulation system, which aim to solve the problem that high processor load due to context data communication transmission by processor control software affects the overall efficiency of encryption or decryption operations.
[0054] Firstly, this invention provides a national cryptographic algorithm system, such as... Figure 1 and Figure 2As shown, the national cryptographic algorithm system 100 includes a direct memory access module 10, a data flow control module 20, a register module 30, and an algorithm module 40. The direct memory access module 10 is used to retrieve memory data. The data flow control module 20 is communicatively connected to the direct memory access module 10. The register module 30 is communicatively connected to the data flow control module 20 and is used to store key information and parameter information. The algorithm module 40 is communicatively connected to the data flow control module 20 and is used to perform encryption or decryption operations on the first preset data within the data flow control module 20. The data flow control module 20 and the direct memory access module 10 communicate via data frames.
[0055] In the national cryptographic algorithm system 100 provided in this embodiment of the invention, the direct memory access module 10 can directly access the memory module to retrieve memory data, and then communicate with the data flow control module 20 using the retrieved memory data. Within the data flow control module 20, the module can configure key and parameter information through the register module 30, and retrieve the corresponding algorithm through the algorithm module 40 to perform encryption or decryption operations on the first preset data. This allows the national cryptographic algorithm to be used to encrypt or decrypt the first preset data, thereby ensuring information security.
[0056] Based on this, during the data interaction and communication between the direct memory access module 10 and the data flow control module 20, data transmission between them is achieved via data frames. That is, during the computation of the national cryptographic algorithm, the parameter configuration required by the algorithm and the context communication for business operations can all be exchanged and communicated between the direct memory access module 10 and the data flow control module 20 via data frames. In other words, the large-scale data interaction is scheduled and transmitted through hardware, without the need for software intervention. This method reduces host involvement, relieves the pressure on processors such as the main control module, and helps improve the overall efficiency of the national cryptographic system during computation.
[0057] Furthermore, due to the inherent hardware characteristics of the Direct Memory Access Module 10, peripherals can retrieve data from the memory module without the intervention of the main control module or other processors. This enables high-speed data transfer between the memory module and the Direct Memory Access Module 10, further relieving the workload of the main control module and other processors, and improving the overall efficiency of the national cryptographic system during computation.
[0058] In some embodiments, such as Figure 2As shown, the direct memory access module 10 includes a first state controller 11, a data input buffer 12, a downlink framing unit 13, an uplink deframing unit 14, and a data output buffer 15. The data input buffer 12 buffers downlink data information sent to the data flow control module 20. The data output buffer 15 buffers uplink data information received by the data flow control module 20. The first state controller 11 is communicatively connected to the data input buffer 12 and the data output buffer 15 to control the transmission of downlink data information and the retrieval of uplink data information. The downlink framing unit 13 reassembles downlink data information into downlink data frames. The uplink deframing unit 14 parses the uplink data frames and buffers the parsed uplink data information into the data output buffer 15.
[0059] Thus, the first state controller 11 can control the operating state of the direct memory access module 10, such as controlling the transmission of downlink data information and the retrieval of uplink data information. For example, when the first state controller 11 detects that the data input buffer 12 is not empty, it controls the downlink framing unit 13 to reassemble the downlink data information in the data input buffer 12 into downlink data frames for rapid transmission to the data flow control module 20. When the first state controller 11 detects that the uplink transmission unit is not empty, it controls the uplink deframing unit 14 to receive and parse the uplink data frames, thereby obtaining the uplink data information and caching it in the data output buffer 15. The uplink data information may be data information obtained by encrypting or decrypting the first preset data (i.e., the second preset data).
[0060] In some embodiments, such as Figure 3 As shown, the data flow control module 20 includes a second state controller 21, a downlink frame buffer 22, a frame header parsing unit 23, a downlink verification unit 24, a computation data buffer 25, an uplink framing unit 26, and an uplink transmission unit 27.
[0061] The downlink frame buffer 22 is used to receive and buffer downlink data frames. The computation data buffer 25 is used to receive and buffer the second preset data processed by the algorithm module 40. The second state controller 21 is communicatively connected to the downlink frame buffer 22 and the computation data buffer 25. The frame header parsing unit 23 is used to parse the downlink data frame and feed back the parsing information to the second state controller 21. The downlink verification unit 24 is used to verify the frame header of the downlink data frame. The uplink framing unit 26 is used to reassemble the second preset data into an uplink data frame. The uplink transmission unit 27 is used to transmit the uplink data frame to the uplink deframing unit 14.
[0062] The second state controller 21 can directly control the operating state of the data flow control module 20. The frame header parsing unit 23 parses the downlink data frame to obtain information such as the service type, algorithm type, and data length / parameter length of the downlink data frame, and feeds the above information back to the second state controller 21. After the algorithm module 40 performs encryption or decryption operations on the first preset data, it caches the encrypted or decrypted second preset data in the operation data cache 25, so that the uplink framing unit 26 can reassemble the second preset data into an uplink data frame, so that the uplink transmission unit 27 can quickly transmit the uplink data frame to the uplink deframing unit 14 of the direct memory access module 10 for deframing.
[0063] Based on this, in this embodiment of the invention, by configuring an interactive communication structure of data frames between the direct memory access module 10 and the data flow control module 20, the process of large-scale data interaction between the direct memory access module 10 and the data flow control module 20 via data frames only requires hardware structure scheduling and configuration, without the need for software intervention. This reduces host involvement, relieves the pressure on processors such as the main control module, and helps improve the overall efficiency of the national cryptographic system during the operation process.
[0064] It should be noted that when the first preset data is the data to be encrypted, the second preset data is the data after the encryption operation is completed. When the first preset data is the data to be decrypted, the second preset data is the data after the decryption operation is completed.
[0065] The uplink transmission unit 27 can be a buffer structure. In this case, the uplink transmission unit 27 is used to buffer uplink data frames. When the first state controller 11 detects that the uplink transmission unit 27 is not empty, the first state controller 11 controls the uplink deframe unit 14 to receive and read the uplink frame data for parsing.
[0066] At this time, the uplink transmission unit 27 can be located on one side of the data flow control module 20 or on the other side of the direct memory access control module 10, and there is no limitation on this.
[0067] In some embodiments, such as Figure 4 As shown, the downlink data frame includes management frames and service frames. The management frame includes a management frame header and management information. The management information is used to configure key and parameter information. The management frame header includes information such as service type, parameter description, and parameter sequence number. The management information includes the key, elliptic curve parameters a / b, and the coordinates (Gx, Gy) of the base point G. The service frame includes a service frame header and first preset data. The service frame header includes information such as service type, algorithm type, and data length. The first pre-approved data is cached data to be processed (encrypted or decrypted).
[0068] By setting management frames, the data flow control module 20 can easily initialize or update the configuration key. By setting service frames, the service frame header can be used to indicate which service is being performed during encryption or decryption operations, such as encryption / decryption, hashing, signing, and signature verification, which is beneficial for the fast and stable transmission of the first preset data.
[0069] In some embodiments, continue to refer to Figure 2 The direct memory access module 10 also includes a management register 16, a descriptor cache 17, and a descriptor processing unit 18. The management register 16 is communicatively connected to the first state controller 11. The descriptor cache 17 is also communicatively connected to the first state controller 11, and the management register 16 controls the reading of the descriptor list and its caching in the descriptor cache 17. The descriptor processing unit 18 is communicatively connected to both the descriptor cache 17 and the first state controller 11. The first state controller 11 is configured as follows:
[0070] When the descriptor cache 17 is not empty, the first state controller 11 starts the descriptor processing unit 18 to read the descriptor linked list from the descriptor cache 17, so as to obtain at least the memory start address information and the service type information.
[0071] Since the data, parameters, and other information cached within the memory module are not necessarily in a contiguous area at the physical level, the direct memory access module 10 is configured as a chain structure through the descriptor cache 17 and the descriptor processing unit 18, so that the direct memory access module 10 can read and transfer data in non-contiguous areas within the memory module through the symbol linked list.
[0072] This structure allows the first preset data to be distributed across multiple non-contiguous memory modules and organized using a descriptor linked list. This reduces the number of interrupts during data transfer, thus improving efficiency. In contrast, ordinary DMA typically requires an interrupt after transferring a physically contiguous block of data, before the host can transfer the next block, introducing additional overhead.
[0073] Because the number of interrupts is reduced during data transfer from the memory module, the host (or processor) can focus more on performing other tasks without frequent intervention in the data transfer process. This helps to reduce the burden on the host (or processor) and improve the overall performance of the national cryptographic computing encapsulation system.
[0074] In this embodiment of the invention, multiple descriptor linked lists can also be configured to be written into the memory module. Thus, by configuring the descriptor starting address and descriptor length, and initiating a read operation of the direct memory access module 10, a series of data transfer tasks can be automatically completed, further improving work efficiency.
[0075] For example, such as Figure 2 As shown, the direct memory access module 10 may also include an interrupt control unit 19, and the first state controller 11 is communicatively connected to the interrupt control unit 19 in order to issue an interrupt command.
[0076] If the frame header verification information is found to be non-compliant (i.e., verification fails) when the downlink verification unit 24 verifies the frame header of the downlink data frame, the first state controller 11 issues a command to interrupt the operation through the interrupt control unit 19 to notify the main control module. Alternatively, after the national cryptographic algorithm system 100 has completed the encryption or decryption operation of the first preset data and output it, the operation can also be interrupted by issuing a command through the interrupt control unit 19.
[0077] In some embodiments, such as Figure 5 As shown, the register module 30 includes a register interface unit 31, a first identifier storage unit 32, a key storage unit 33, a second identifier storage unit 34, and a parameter storage unit 35. The register module 30 and the data flow control module 20 are communicatively connected through the register interface unit 31.
[0078] The first identifier storage unit 32 stores the key serial number of the key information and the storage address of the key information corresponding to the key serial number. The key storage unit 33 stores multiple types of key information, with each type of key information corresponding to at least one key serial number. The second identifier storage unit 34 stores the parameter serial number of the parameter information and the storage address of the parameter information corresponding to the parameter serial number. The parameter storage unit 35 stores multiple types of parameter information, with each type of parameter information corresponding to at least one parameter serial number.
[0079] For example, in Chinese cryptographic algorithms, the key is a secret piece of information used in encryption and decryption algorithms; it must be kept confidential to ensure data security. In symmetric encryption algorithms (such as SM4), encryption and decryption both use the same key. In asymmetric encryption algorithms (such as SM2), a pair of keys is used: a public key and a private key. The public key can be made public, but the private key must be kept strictly confidential.
[0080] Parameters are configuration information required for the algorithm to run and usually do not contain sensitive information. In Chinese cryptographic algorithms, parameters may include the algorithm version, the specific mathematical curve used (for elliptic curve algorithms such as SM2), the output size of hash algorithms (such as SM3), etc. They define how the algorithm operates, but are not directly used in the encryption or decryption process.
[0081] In the above scheme, configuring the first identifier storage unit 32 and the second identifier storage unit 34 in the register module 30 facilitates the indexing and identification of specific keys and parameters. This allows for quick access and management of key and parameter information while preventing direct leakage of information in the key storage unit 33 and parameter storage unit 35, thus providing initial protection for the keys and parameters required by the algorithm. This enhances the security, reliability, and confidentiality of the entire system's cryptographic operations.
[0082] In some embodiments, the register interface unit 31 is configured such that the control key storage unit 33 and the parameter storage unit 35 communicate with each other only through hardware transmission.
[0083] By configuring the register interface unit 31, the key and parameter data in the key storage unit 33 and parameter storage unit 35 can only be read and written through hardware, and cannot be read through software. Combined with the above scheme, leakage of information in the key storage unit 33 and parameter storage unit 35 through software channels can be avoided, providing secondary protection for the keys and parameters required by the algorithm. This further enhances the security, reliability, and confidentiality of the entire system's cryptographic operations.
[0084] In some embodiments, continue to refer to Figure 5 The algorithm module 40 includes an algorithm interface unit 41 and multiple data processing units 42. The algorithm interface unit 41 is communicatively connected to the data flow control module 20, enabling the data flow control module 20 to invoke the data processing units 42 to perform encryption or decryption operations on the first preset data. The multiple data processing units 42 include at least SM2, SM3, and SM4 algorithms, and the data processing unit 42 used to execute the SM4 algorithm is configured as a multi-threaded structure.
[0085] For example, the algorithm module 40, as an internal module of this invention, mainly interacts with the data flow control module 20. The algorithm interface unit 41 is used to adapt to the communication handshake protocol of the data flow control module 20. The algorithm module 40 integrates multiple data processing units 42, which include at least national cryptographic algorithms such as SM2 / SM3 / SM4. For example, one data processing unit 42 uses the SM2 algorithm (SM2 cryptographic algorithm, i.e., SM2 public key cryptography algorithm) to implement key exchange, data encryption, decryption, digital signature and signature verification functions. One data processing unit 42 uses the SM3 algorithm (Security Message Digest Algorithm) to process first preset data of arbitrary length and generate a fixed-length hash value, which is usually used to verify the integrity and authenticity of the data. A data processing unit 42 internally implements a multi-level (e.g., 32-level) pipeline using the SM4 algorithm (SM4 Block Cipher Algorithm), supporting ECB, CBC, CFB, OFB, and CTR algorithm modes to achieve data encryption and decryption services for different scenarios and needs, with high security and high efficiency.
[0086] It should be noted that the algorithm interface unit 41 and the register interface unit 31 can be static random access memory.
[0087] Based on this, such as Figure 3 As shown, the data flow control module 20 also includes a configuration parameter unit 281, an algorithm scheduling unit 282, and a business operation unit 283.
[0088] The configuration parameter unit 281 mainly writes / reads algorithm parameters into / out of the register module 30 through a mapping relationship using frame header parameter numbers. The algorithm scheduling unit 282 selects a suitable data processing unit 42 to perform algorithm calculations according to the instructions of the second state controller 21. The service processing unit 283 enables the scheduled data processing unit 42 to perform encryption or decryption operations on the first preset data.
[0089] Secondly, the present invention also provides a national cryptographic algorithm encapsulation system, such as... Figure 6 As shown, the national cryptographic algorithm encapsulation system includes an I / O module 200, a main control module 300, a memory module 400, and a national cryptographic algorithm system 100 as described in any embodiment of the first aspect. The I / O module 200, the main control module 300, the memory module 400, and the national cryptographic algorithm system 100 are interconnected via a system bus.
[0090] Since the national cryptographic algorithm encapsulation system includes the national cryptographic algorithm system 100 in the first aspect, the national cryptographic algorithm encapsulation system possesses all the beneficial effects of the aforementioned national cryptographic algorithm system 100, which will not be elaborated here.
[0091] In some embodiments, the main control module 300 is configured as follows:
[0092] Preset data is cached in a memory module, and the starting addresses of several regions containing the cached preset data in the memory module are recorded as several first memory starting addresses. The preset data includes first preset data, second preset data, key information, and parameter information.
[0093] The feature information of the preset data is recorded in several descriptor linked lists. These descriptor linked lists are cached in the memory module, and the starting address of the region in the memory module where the descriptor linked lists are cached is recorded as the second memory starting address. The feature information includes at least the first memory starting address of the preset data, the data type, the data byte length, and the frame type.
[0094] The main control module configures the direct memory access module through the second memory starting address, so that the memory access module can read and cache the descriptor linked list from the memory module, and parse and obtain the preset data in the memory module according to the descriptor linked list.
[0095] In other words, during the data caching process within the memory module 400, the main control module 300, through the configuration of the descriptor linked list, enables the direct memory access module 10 to continuously read discontinuous data from the memory module 400. Because the number of interruptions during data transfer is reduced, the main control module 300 can focus more on performing other tasks without frequently intervening in the data transfer process. This helps to alleviate the burden on the main control module 300 and improve the overall system performance.
[0096] For example, such as Figure 7 As shown, the workflow of the national cryptographic algorithm system 100 when executing management-related business is as follows:
[0097] 1. The software caches multiple parameters required by the algorithm in memory module 400. For example, it records the memory starting address as A1 (i.e., the first memory starting address), and writes the first memory starting address, parameter type, parameter byte length, and frame type (management frame) into one or more descriptor linked lists. Then, it writes the descriptor linked list into memory module 400 and records the memory starting address as B1 (i.e., the second memory starting address).
[0098] 2. Configure the direct memory access module 10 to control the management register 16, configure the second memory starting address of the descriptor linked list, configure the descriptor byte length register, and configure the management register 16 to start the first state controller 11.
[0099] 3. The direct memory access module 10 reads a descriptor list of a specified length from the memory module 400 and caches it in the descriptor cache 17.
[0100] 4. The first state controller 11 detects that the descriptor cache 17 is not empty, initiates a read operation on the descriptor cache 17 to read out the descriptor linked list, parses it, and obtains the first memory address of the data to be processed, the length of the data to be tested in bytes, the service type and other information.
[0101] 5. The first state controller 11 drives the direct memory access module 10 to read the data to be processed from the memory module 400 and cache it in the data input buffer 12. When the first state controller 11 detects that the data input buffer 12 is not empty, it reassembles the management frame header of the downlink data frame according to the previously obtained information.
[0102] 6. After the management frame header of the downlink data frame is assembled, the operation of reading data input buffer 12 is initiated, and the frame header + data is transmitted to the data flow control module 20 at the same time.
[0103] 7. When the first state controller 11 detects that the uplink frame buffer is not empty, it initiates a read operation to read the frame header and parse it. It finds that the service type is management frame. It can be seen that the returned uplink frame does not carry data but only the uplink frame header. Therefore, the FSM controller initiates an interrupt to inform the CPU that this service has been completed.
[0104] In some embodiments, such as Figure 8 As shown, the workflow of the national cryptographic algorithm system 100 when executing data-related business is as follows:
[0105] 1. The software caches the data to be processed in memory module 400, records the starting address of memory module 400 as A (first memory starting address), and writes the first memory starting address, the length of the byte to be tested, and the frame type (business frame) into one or more descriptor linked lists. Then, the descriptor linked list is written into the memory module, and the starting address is recorded as B (second memory starting address).
[0106] 2. Configure the direct memory access module 10 control management register 16, configure the second memory starting address of the descriptor linked list, the descriptor byte length register, and configure management register 16 to start the direct memory access module 10.
[0107] 3. The direct memory access module 10 reads a descriptor list of a specified length from the memory module 400 and caches it in the descriptor cache 17.
[0108] 4. The first state controller 11 detects that the descriptor cache 17 is not empty, initiates a read cache operation to read the descriptor linked list, parses it, and obtains the first memory address of the data to be processed, the length of the data to be tested in bytes, the service type and other information.
[0109] 5. The first state controller 11 drives the read logic to read the data to be processed from the memory module 400 and cache it in the data input buffer 12. When the first state controller 11 detects that the data input buffer 12 is not empty, it reassembles the service frame header of the downlink data frame according to the previously learned information.
[0110] 6. After the service frame header of the downlink data frame is assembled, the operation of reading data input buffer is initiated, and the service frame header + data is transmitted to the data flow control module 20 at the same time.
[0111] 7. When the first state controller 11 detects that the data output buffer 15 is not empty, it initiates a read operation to read and parse the frame header, obtaining information such as service type, algorithm type, data length, and write-back address. If it is necessary to write back the data result, the first state controller 11 drives the direct memory access module 10 to perform a write operation, writing the calculation result data back to the designated memory module. If it is not necessary to write back, it initiates an interrupt to inform the CPU that the service has been completed.
[0112] 8. After the last piece of data is written back, initiate an interrupt to notify the CPU that the service has been completed.
[0113] Thus, the national cryptographic algorithm system 100 of the present invention has the following advantages:
[0114] Higher transfer efficiency allows the data to be processed to be distributed across multiple non-contiguous memory regions of the memory module 400 and organized using linked lists. This reduces the number of interrupts during data transfer, thus improving efficiency. Ordinary DMA typically requires an interrupt after transferring a physically contiguous block of data, followed by the main control module 300 transferring the next block, which introduces additional overhead.
[0115] Simplifying the main control module's processing reduces the number of interruptions during data transmission, allowing it to focus on other tasks without frequent intervention. This reduces the workload on the main control module and improves overall system performance.
[0116] Supports batch processing. In this design, the software can write multiple descriptor linked lists into the corresponding memory, configure the descriptor start address and descriptor length, and initiate a read operation by the direct memory access module 10 to automatically complete a series of data transfer tasks, further improving work efficiency.
[0117] In addition, such as Figure 9 As shown, the control flow of the data flow control module 20 includes the following steps:
[0118] 1. The second state controller 21 detects that the downlink frame buffer 22 is not empty and initiates a read operation to read the frame header of the downlink data frame. This downlink data frame can be a management frame or a service frame.
[0119] 2. The frame header parsing unit 23 verifies the fields of the frame header. If they do not conform to the protocol specifications of the frame fields, such as the presence of descriptors other than SM2 / SM3 / SM4 algorithms in the frame fields, it sends feedback to the first state controller 11, which then issues an error interrupt to notify the main control module. If the verification is successful, the following operations are performed.
[0120] 3. The frame header parsing unit 23 parses the frame header and feeds back the key information to the second state controller 21.
[0121] 4. The second state controller 21 jumps to different states for processing based on the feedback information. If it is a management frame, steps 5 and 6 are executed. If it is a service frame, steps 7-10 are executed.
[0122] 5. Read the algorithm parameter information from the cache, write it into register module 30 according to the parameter description and parameter number, and wait for the signal that register module 30 has finished writing.
[0123] 6. After receiving the signal that the write is complete, the second state controller 21 jumps to the management frame header reassembly state, reassembles the header of the uplink data frame of the management frame, sends the header to the direct memory access module 10, ends the management frame processing flow, and jumps to step 1.
[0124] 7. Read the data to be processed from the buffer, and simultaneously reassemble the frame header of the uplink data frame using the frame information. Unlike management frames, the pre-assembly of the uplink data frame header is mainly to improve the transmission efficiency of the uplink data frame.
[0125] 8. The configuration parameter unit 281 retrieves the parameters required for the algorithm, such as the key and elliptic curve parameters, from the register module 30 according to the parameter sequence number. The algorithm scheduling unit 282 transmits the data to the corresponding data processing unit 42 for processing.
[0126] 9. The second state controller 21 detects that the operation data buffer 25 is not empty, indicating that there is an operation result output. It sends the frame header of the uplink data frame and reads the result data in the operation data buffer 25 and continuously sends it to the direct memory access module 10.
[0127] 10. Once the last data transfer is complete, proceed to step 1.
[0128] by Figure 6The illustrated example uses a national cryptographic algorithm encapsulation system integrating a national cryptographic algorithm system 100. The user encrypts sensitive information using the SM4 algorithm to obtain data A (i.e., the second preset data). Then, data A is hashed using SM3 to obtain a hash value B. Finally, hash value B is signed using SM2 to obtain a signature value C. To obtain tamper-proof and non-repudiable user sensitive information (i.e., the first preset data), the usage process is described as follows:
[0129] First, the user stores data A, hash value B, and signature value C into an external medium, such as a removable memory, according to regulations. Then, the relevant instructions are written into the ICCM (Instruction Closely Coupled Memory) instruction cache of the main control module 300, and the CPU executes the instructions.
[0130] The national cryptographic algorithm encapsulation system uses the serial port of I / O module 200, such as SPI (Service Provider Interface), USB (Universal Serial Bus), I2C (Inter-Integrated Circuit), or UART (Universal Asynchronous Receiver / Transmitter), to move data from the mobile storage into memory module 400. That is, the data to be processed is cached in memory such as DDR (Double Data Rate Synchronous Dynamic Random Access Memory) or AMBA (Advanced Microcontroller Bus Architecture), which can be either continuous address cache or discrete address cache.
[0131] The main control module 300 records the location, service type, and data length of the data cached in the memory module into one or more descriptor linked lists, and caches the descriptor linked lists in a contiguous address of the memory module 400. The main control module 300 configures the location and byte length of the descriptor linked lists in memory to the direct memory access module 10, and starts the direct memory access module 10 to move the data cached in the memory module 400.
[0132] The national cryptographic algorithm system 100 initiates the direct memory access module 10 to move the descriptor linked list. After parsing the descriptor linked list, the direct memory access module 10 reads the data and reassembles it into downlink data frames, which are then transmitted to the data flow control module 20. The data flow control module 20 first performs a hash operation on data A using the SM3 algorithm kernel through frame header analysis and frame splitting, and compares the result with the hash value B. If the comparison passes, it then calls the SM2 algorithm kernel to perform digital signature verification on the signature value C. If the signature verification passes, it calls the SM4 algorithm kernel to decrypt information A, ultimately obtaining the sensitive data. The data flow control module 20 then reassembles the uplink data frame and sends it to the direct memory access module 10.
[0133] After parsing the frame header and disassembling the uplink data frame, the direct memory access module 10 writes the sensitive data back to the corresponding location in the pre-defined memory module 400. After the write-back is complete, an interrupt is sent to notify the main control module 300.
[0134] Finally, the main control module 300 reads the decrypted data at the corresponding address in the memory module 400, thus obtaining the user's sensitive information (such as the decrypted second preset data).
[0135] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A national encryption algorithm system, characterized in that, The application relates to a data flow control method and device. The application comprises: a direct memory access module (10) for calling preset data in memory data, wherein the preset data comprises first preset data; a data flow control module (20) in communication connection with the direct memory access module (10); a register module (30) in communication connection with the data flow control module (20), the register module (30) being used for storing secret key information and parameter information; and an algorithm module (40) in communication connection with the data flow control module (20), the algorithm module (40) being used for performing encryption or decryption operation on the first preset data in the data flow control module (20); wherein the data flow control module (20) and the direct memory access module (10) are in data interaction communication through the mode of data frames; the direct memory access module (10) comprises: a data input buffer (12) for buffering downlink data information sent to the data flow control module (20); a data output buffer (15) for buffering uplink data information received by the data flow control module (20); and a first state controller (11) in communication connection with the data input buffer (12) and the data output buffer (15) to control the downlink data information issuing and the uplink data information recycling; 2. The SM algorithm system according to claim 1, characterized in that, the direct memory access module (10) further comprises: a management register (16) in communication connection with the first state controller (11); a descriptor buffer (17) in communication connection with the first state controller (11), the management register (16) controlling reading of a descriptor chain table and buffering into the descriptor buffer (17), wherein the descriptor chain table is used for recording characteristic information of preset data buffered into a memory module, the characteristic information comprising a first memory starting address, a data type, a data byte length and a frame type of the preset data; and a descriptor processing unit (18) in communication connection with the descriptor buffer (17) and the first state controller (11); the first state controller (11) is configured to: when the descriptor buffer (17) is not empty, the first state controller (11) starts the descriptor processing unit (18) to read the descriptor chain table from the descriptor buffer (17) to obtain at least memory starting address information and service type information of the preset data. The direct memory access module (10) comprises: a downlink framing unit (13) for recombining the downlink data information into downlink data frames; 3. The national encryption algorithm system according to claim 2, characterized in that, an uplink deframing unit (14) for analyzing uplink data frames and buffering the analyzed uplink data information into the data output buffer (15). The data flow control module (20) comprises: a downlink frame buffer (22) for receiving and buffering the downlink data frames; an operation data buffer (25) for receiving and buffering second preset data after operation of the algorithm module (40); A second state controller (21) is in communication connection with the downlink frame buffer (22) and the operation data buffer (25); A frame header analysis unit (23) is configured to analyze the downlink data frame and feed back analysis information to the second state controller (21); A downlink verification unit (24) is configured to verify the frame header of the downlink data frame; An uplink framing unit (26) is configured to reframe the second preset data into the uplink data frame; An uplink transmission unit (27) is configured to transmit the uplink data frame to the uplink deframing unit (14).
4. The national encryption algorithm system according to claim 2, characterized in that, The downlink data frame comprises: A management frame comprising a management frame header and management information, wherein the management information is used to configure the key information and the parameter information; And a service frame comprising a service frame header and the first preset data.
5. The SM algorithm system according to any one of claims 1 to 4, characterized in that, The register module (30) comprises: A register interface unit (31) in communication connection between the register module (30) and the data flow control module (20); A first identifier storage unit (32) configured to store a key serial number of the key information and a storage address of the key information corresponding to the key serial number; A key storage unit (33) configured to store a plurality of the key information, wherein one of the key information is set in correspondence with at least one of the key serial numbers; A second identifier storage unit (34) configured to store a parameter serial number of the parameter information and a storage address of the parameter information corresponding to the parameter serial number; And a parameter storage unit configured to store a plurality of the parameter information, wherein one of the parameter information is set in correspondence with at least one of the parameter serial numbers.
6. The national encryption algorithm system according to claim 5, characterized in that, The register interface unit (31) is configured to: Control the key storage unit (33) and the parameter storage unit to be in communication connection only through a hardware transmission mode.
7. The SM algorithm system according to any one of claims 1 to 4, characterized in that, The algorithm module (40) comprises an algorithm interface unit (41) and a plurality of data operation units (42); The algorithm interface unit (41) is in communication connection with the data flow control module (20) so that the data flow control module (20) is configured to call the data operation units (42) to perform encryption operation or decryption operation on the first preset data; The plurality of data operation units (42) at least comprise SM2, SM3 and SM4 algorithms, and the data operation unit (42) configured to execute the SM4 algorithm is configured in a multi-thread structure.
8. A national encryption algorithm packaging system, characterized in that, The I / O module (200), the main control module (300), the memory module (400) and the national secret algorithm system in any one of claims 1 to 7; Wherein, the I / O module (200), the main control module (300), the memory module (400) and the national secret algorithm system are in communication connection through a system bus.
9. The SM algorithm packaging system according to claim 8, characterized in that, The main control module (300) is configured to: The preset data is cached in the memory module (400), and the first addresses of regions in the memory module (400) where the preset data is cached are recorded as a plurality of first memory first addresses; the preset data includes first preset data, second preset data, key information and parameter information; Characteristic information of the preset data is recorded in a plurality of descriptor chain tables, the descriptor chain tables are cached in the memory module (400), and the first address of a region in the memory module (400) where the descriptor chain table is cached is recorded as a second memory first address; the characteristic information at least includes the first memory first address of the preset data, data type, data byte length and frame type; The host module (300) configures the direct memory access module (10) through the second memory first address, so that the memory access module reads and caches the descriptor chain table from the memory module (400), and parses and obtains the preset data in the memory module (400) according to the descriptor chain table.
Citation Information
Patent Citations
SATA bridging real-time transmission encryption system and method based on a domestic cryptographic algorithm
CN109657502A
A national cryptographic algorithm acceleration processing system based on an FPGA
CN109902043A