Data encryption method and device, computer equipment and storage medium
By filling and iteratively expanding the compressed data, selecting a certain number of word groups for iterative compression, the problem of long calculation cycles in the hash algorithm SM3 during iterative compression is solved, and the effect of shortening the data encryption time and improving the computing speed is achieved.
Patent Information
- Application Number
- CN202411865596.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-17
AI Technical Summary
The existing hash algorithm SM3 has a long calculation period during iterative compression, resulting in too long clock period, affecting the computing speed and security.
By filling and iteratively expanding the compressed data, selecting a certain number of word groups for iterative compression, and stopping iterative expansion when the preset total number of groups is reached, multiple compressions are performed in one iterative compression cycle.
It shortens the time required for data encryption, improves computing speed and security, and meets the needs of compression rounds.
Smart Images

Figure CN119945661A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cryptographic algorithms, and in particular to data encryption methods, devices, computer equipment and storage media. Background Art
[0002] Modern cryptographic technology plays an important role in social life, national security and other aspects, and is the foundation of the entire information network security. Hash algorithm is a type of cryptographic algorithm that can compress messages of any length into a fixed-length value. It is widely used in security scenarios such as data integrity verification, digital signatures and signature verification, and random number generation. Currently, the commonly used secure hash functions in the world are SHA-2 (Secure Hash Algorithm 2) and SHA-3 (Secure Hash Algorithm 3) series. In order to prevent unknown attack risks and backdoors of international hash algorithms, the State Cryptography Administration released the domestically produced hash algorithm SM3 (Commercial Secret 3 Algorithm) in 2010. It can be used for data less than 2 64 The data of bits is finally generated into a 256-bit hash value through the steps of message filling, message expansion, and iterative compression. Compared with the software implementation of cryptographic algorithms on general-purpose processors, the hardware implementation has faster computing speed and higher security, and is usually used as a hardware security engine in various security chips. Based on the widespread use of the domestic hash cryptographic algorithm SM3, it is necessary to improve its computing speed at the hardware design level. The bottleneck of the hash algorithm SM3 calculation lies mainly in the iterative compression process, which requires 64 rounds of iterative compression. Too many rounds of calculation will result in too long clock cycles. At the same time, multiple addition operations will be performed in each round of iterative compression, and too high addition carry chain delay will limit the clock frequency.
[0003] With regard to the problem of long data encryption cycle in related technologies, no effective solution has been proposed so far. Summary of the invention
[0004] Based on this, it is necessary to provide a data encryption method, device, computer equipment and storage medium that can solve the problem of long data encryption cycle in response to the above technical problems.
[0005] In a first aspect, a data encryption method is provided in this embodiment, the method comprising:
[0006] Filling the data to be compressed until the data length of the filled data to be compressed reaches a preset length, thereby obtaining first data;
[0007] Iteratively expand the first data, and select a first number of word groups from the first data after each round of iterative expansion is completed;
[0008] After compressing the target word groups selected from the first number of word groups, repeatedly performing the following steps until the first number of word groups are compressed: obtaining a compression result and selecting a new target word group from the word groups of the first data, and compressing the compression result and the new target word group;
[0009] When it is determined that the total number of word groups selected after iterative expansion reaches a second number, iterative expansion of the first data is stopped.
[0010] In some embodiments, after iteratively expanding the first data and selecting a first number of word groups from the first data after each round of iterative expansion, the method further includes:
[0011] When it is determined that the number of iterative expansions reaches a preset number, new data to be compressed is received from upstream input;
[0012] Filling the new data to be compressed until the length of the filled data reaches the preset length, thereby obtaining second data;
[0013] caching the second data;
[0014] When the iterative expansion of the first data is stopped, the second data is acquired and the second data is iteratively expanded.
[0015] In some embodiments, the step of padding the data to be compressed until the length of the padded data reaches a preset length to obtain the first data includes:
[0016] In response to a first signal of a first level, receiving data to be compressed inputted from an upstream;
[0017] Filling the data to be compressed until the length of the filled data reaches a preset length, thereby obtaining first data;
[0018] The first signal is adjusted to a second level to stop receiving data inputted from the upstream.
[0019] In some embodiments, the data to be compressed is constructed by at least one data block; and the step of filling the data to be compressed until the data length of the filled data to be compressed reaches a preset length to obtain the first data includes:
[0020] sequentially acquiring the data blocks in the data to be compressed;
[0021] When receiving the last data block in the data to be compressed, determining whether the data in the last data block is valid;
[0022] If all the data in the last data block are valid, a first bit value and a bit value corresponding to the data amount of the data to be compressed are filled at the end of the data to be compressed until the data length of the data to be compressed after filling reaches a preset length, thereby obtaining first data;
[0023] If invalid data exists in the last data block, then when the amount of data to be compressed is equal to the specified amount, a bit value corresponding to the amount of data to be compressed is filled at the end of the data to be compressed; if the amount of data to be compressed is not equal to the specified amount, a second bit value is filled at the end of the data to be compressed.
[0024] In some of the embodiments, after sequentially acquiring the data blocks in the data to be compressed, the method further includes:
[0025] Determining whether data in at least one of the received data blocks is valid;
[0026] If the data in the data block is valid, then executing the step of determining whether the data in the last data block is valid when the last data block in the data to be compressed is received.
[0027] In some embodiments, compressing the target word group selected from the word group of the first data includes:
[0028] Obtain the first function and the second function according to the round of iterative expansion;
[0029] Get predefined working variables, state variables and constants;
[0030] Obtaining a first value calculated according to the first function and the first working variable, and a second value calculated according to the second function for the first state variable;
[0031] Calculate the first value, the second working variable, and the first word in the target word group according to a first carry addition retainer;
[0032] Calculate the second value, the second state variable, and the second word in the target word group according to a second carry addition retainer;
[0033] Calculating the constant quantity, the third working variable and the third state variable according to the third carry adder retainer;
[0034] A compression result is obtained according to the output values of the first carry addition retainer, the second carry addition retainer and the third carry addition retainer.
[0035] In a second aspect, a data encryption device is provided in this embodiment, the device comprising: a message filling module, a message expansion module and an iterative compression module; wherein,
[0036] The message filling module is used to fill the to-be-compressed data until the data length of the filled to-be-compressed data reaches a preset length, thereby obtaining the first data;
[0037] The message expansion module is used to iteratively expand the first data and select a first number of word groups from the first data after each round of iterative expansion; when it is determined that the total number of word groups selected after iterative expansion reaches a second number, stop iterative expansion of the first data;
[0038] The iterative compression module is used to obtain the first amount of data; after compressing the target word group selected from the word group of the first data, repeatedly perform the following steps until the first number of word groups are compressed: obtain the compression result, and compress the new target word group obtained by selecting the compression result and the word group of the first data.
[0039] In some of the embodiments, the iterative compression module includes the first number of compressors, and each of the compressors is connected in series.
[0040] In a third aspect, a computer device is provided in this embodiment, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the data encryption method described in the first aspect when executing the computer program.
[0041] In a fourth aspect, a computer-readable storage medium is provided in this embodiment, on which a computer program is stored. When the computer program is executed by a processor, the data encryption method described in the first aspect is implemented.
[0042] The above-mentioned data encryption method, device, computer equipment and storage medium, after filling the data to be compressed, selects a first number of word groups and iteratively compresses the word groups, and performs multiple compressions in one iterative expansion cycle; stops iterative expansion when the total number of selected word groups reaches a second number, ensuring that the compression rounds meet the requirements; and achieves the technical effect of shortening the time required for data encryption. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 A hardware structure block diagram of a terminal of a data encryption method in one embodiment;
[0044] Figure 2 A schematic diagram of a data encryption method in one embodiment;
[0045] Figure 3 is a structural block diagram of a data encryption device in one embodiment;
[0046] Figure 4 is a structural block diagram of a device for implementing the SM3 algorithm in one embodiment;
[0047] Figure 5 is a timing diagram of the execution of each module in a device for implementing the SM3 algorithm in one embodiment;
[0048] Figure 6 A schematic diagram of a finite state machine designed for a message filling module in one embodiment;
[0049] Figure 7 A schematic diagram of the expansion of a message expansion module in one embodiment;
[0050] Figure 8 A schematic diagram of a finite state machine designed for a message expansion module in one embodiment;
[0051] Fig. 9 is a schematic diagram of an iterative compression module in one embodiment;
[0052] Fig.10 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0054] The method embodiment provided in this embodiment can be executed in a terminal, a computer or a similar computing device. For example, running on a terminal, Figure 1 FIG. 1 is a hardware structure diagram of a terminal of a data encryption method according to an embodiment of the present application. Figure 1 As shown, the terminal may include one or more ( Figure 1 Only one is shown in the figure) processor 102 and memory 104 for storing data, wherein processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA. The above terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations shown.
[0055] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the data encryption method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, to implement the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0056] The transmission device 106 is used to receive or send data via a network. The above network includes a wireless network provided by the communication provider of the terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, referred to as RF) module, which is used to communicate with the Internet wirelessly.
[0057] In one embodiment, Figure 2 As shown, a data encryption method is provided, which is applied to Figure 1 The terminal in is used as an example to illustrate, including the following steps:
[0058] Step S202, padding the data to be compressed until the data length of the padded data to be compressed reaches a preset length, thereby obtaining first data.
[0059] Among them, the preset length is a multiple of 512. Optionally, the original message input from the upstream is converted into a bit string representation to obtain the data to be compressed. The data to be compressed is filled with a preset bit value; the preset bit value includes a "1" and multiple "0s", including: adding a "1" at the end of the data to be compressed as the start of filling, and then appending a "0" bit to the data to be compressed. Further, after the data to be compressed is filled with the preset bit value, a length field is added to the end of the data to be compressed, indicating the length of the original message input from the upstream.
[0060] Step S204, iteratively expand the first data, and select a first number of word groups from the first data after each round of iterative expansion is completed.
[0061] Among them, iterative expansion can also be called message expansion, which refers to multiple transformations of the first data through operations such as bit operations and circular shifts, thereby increasing the amount of data while improving the security of the data encryption method.
[0062] Optionally, performing an iterative expansion on the first data within a time period includes: dividing the first data into a plurality of message blocks, each message block being composed of a plurality of bits. The value of the message block before the iteration is recorded as W t , through bit operations, circular shifts and other operations, additional message blocks are generated based on each message block, and their values are recorded as W t '. Combined with W t and W t 'Select the first number of word groups. For example, when the first number is 2, and each word group contains two values, two word groups can be selected, namely, word groups W0 and W0'; W1 and W1'. It can be understood that the first number and the number of values contained in each word group can be modified according to actual needs.
[0063] Step S206, after compressing the target word group selected from the first number of word groups, repeat the following steps until the first number of word groups are compressed: obtain the compression result and select a new target word group from the word group of the first data, and compress the compression result and the new target word group.
[0064] The word groups may be iteratively compressed by a preset compression function, and the data encryption result may be obtained by iterative compression of multiple cycles. Optionally, after receiving the first number of word groups, the scheme of step S206 is performed within one clock cycle so that the first number of word groups are all compressed.
[0065] Optionally, iterative compression is performed by multiple serially connected compressor pairs, the number of compressors is the same as the first number; and the compression functions included in each compressor are the same. The following steps are repeatedly performed until the first number of word groups are compressed: a target word group is selected from the word groups of the first data and input into a first compressor for compression, and the compression result output by the compressor and the new target word group are used as inputs of the next compressor to obtain a new compression result.
[0066] Step S208, when it is determined that the total number of word groups selected after iterative expansion reaches a second number, stop iteratively expanding the first data.
[0067] Wherein, the second number is the same as the number of compression rounds to be performed, and when the total number of word groups reaches the second number, it can be determined that the compression of the data to be compressed is completed. Optionally, taking 64 rounds of compression as an example, when the first number is 3 and the total number of word groups selected reaches 64, the iterative compression of the data can be completed within 22 clock cycles. Wherein, in the last clock cycle, the number of word groups selected can be set to 1 so that the total number of word groups is equal to the second number. Compared with the traditional technology, it takes 64 cycles to perform 64 compressions, which greatly shortens the time required for compression.
[0068] In the above data encryption method, by selecting a first number of word groups and iteratively compressing the word groups, the effect of performing multiple compressions within one iterative compression cycle is achieved, and through multiple iterative expansions, the total number of selected word groups reaches the second number, ensuring that the compression rounds meet the requirements, thereby achieving the technical effect of shortening the time required for data encryption.
[0069] In one embodiment, after iteratively expanding the first data and selecting a first number of word groups from the first data after each round of iterative expansion, the method also includes: receiving new data to be compressed input from upstream when it is determined that the number of iterative expansions reaches a preset number; padding the new data to be compressed until the length of the padded data reaches a preset length to obtain second data; caching the second data; and obtaining the second data and iteratively expanding the second data when the iterative expansion of the first data is stopped.
[0070] Among them, the preset number of times can be set according to the time period required for iterative expansion of the first data and the time period required to fill the compressed data. For ease of understanding, taking the second number as 22, that is, the iterative expansion requires 22 time periods, and the message filling requires 8 time periods for example, the preset number of times can be set to a number less than or equal to 13, so that after the iterative expansion of the first data is completed, a new round of iterative expansion and compression calculation can be performed on the cached second data immediately. If the preset number of times is set to a number greater than 13, the time period required for iterative expansion and compression of the second data will increase accordingly. Optionally, a register can be set to cache the second data by placing the second data in a register.
[0071] In this embodiment, by acquiring new data to be compressed before the iterative expansion is completed and caching the padded data to be compressed, that is, the second data, the time required for data encryption when the data to be compressed is continuously received is reduced.
[0072] In one embodiment, the data to be compressed is padded until the length of the data after padded reaches a preset length to obtain first data; including: receiving the data to be compressed input from upstream in response to a first signal of a first level; padding the data to be compressed until the length of the data after padded reaches a preset length to obtain first data; adjusting the first signal to a second level to stop receiving the data input from upstream.
[0073] Optionally, the first level is set to a high level, and the second level is set to a low level. Taking the first signal as a pad_ready signal as an example, by outputting the pad_ready signal to the upstream, when the pad_ready signal is a high-level signal, it indicates that the data to be compressed can be received; when the first data obtained after padding reaches 512 bits, the pad_ready signal is pulled low to indicate that the upstream data to be compressed is not accepted. It can be understood that, according to application requirements, the first level can also be set to a low level and the second level can be set to a high level.
[0074] Furthermore, after adjusting the first signal to the second level, if the number of iterative expansions reaches a preset number of times, the level of the first signal can be converted back to the first level to receive new data to be compressed again; until the new data to be compressed is filled, the level of the first signal is converted back to the second level.
[0075] In this embodiment, the input of the upstream message is controlled by the first signal to avoid the upstream information affecting the message expansion, thereby preventing the problem of inaccurate data during compression.
[0076] In one embodiment, a second signal can also be set to realize the transmission of the padded data to be compressed. The message filling module is used to fill the data to be compressed until the length of the padded data reaches a preset length to obtain the first data; the message expansion module is used to iteratively expand the first data, and a first number of word groups are selected from the first data after each round of iterative expansion is completed; when it is determined that the total number of word groups selected after iterative expansion reaches a second number, the iterative expansion step of the first data is stopped, and the message expansion module responds to the second signal of the first level to receive the first data generated by the message filling module; when the first data is fully transmitted to the message expansion module, the second signal is adjusted to the second level to stop receiving the data output by the message filling module. When the number of iterative expansions reaches the preset number, the second signal is adjusted to the second level to receive the data output by the message expansion module again. The input and expansion of the upstream message is controlled by the second signal to avoid the problem of inaccurate data during compression caused by the influence of the upstream input during the message expansion process.
[0077] In one embodiment, filling the data to be compressed based on a preset bit value includes: sequentially obtaining data blocks in the data to be compressed; when receiving the last data block in the data to be compressed, determining whether the data in the last data block is valid; if all the data in the last data block is valid, filling the end of the data to be compressed with a first bit value and a bit value corresponding to the data amount of the data to be compressed, until the data length of the data to be compressed after filling reaches a preset length, thereby obtaining the first data. If there is invalid data in the last data block, when the data amount of the data to be compressed is equal to a specified number, filling the end of the data to be compressed with a bit value corresponding to the data amount of the data to be compressed; when the data amount of the data to be compressed is not equal to the specified number, filling the end of the data to be compressed with a second bit value.
[0078] After the data to be compressed is obtained, the data to be compressed can be converted into multiple data blocks, the converted data blocks are sequentially obtained in units of time periods, and data filling is performed after all the data to be compressed is obtained.
[0079] The first bit value is obtained according to the filling requirement when the compression algorithm is executed. When the SM3 algorithm is executed, the first bit value includes 1 "1" and k "0"s; so that filling 1 "1" and k "0"s can satisfy the condition of the smallest non-negative integer of l+1+k≡448mod 512, where l is the data length of the bit value corresponding to the data amount of the data to be compressed.
[0080] Optionally, when the preset length is 512 bits and the data to be compressed is divided into multiple data blocks in units of 64 bits: when adding the first bit value, first add part of the first bit value, including 1 "1" and several "0". Then judge whether the following three conditions are all met: the preset extension condition is met, the filled part of the first bit value is valid, and the data to be compressed after the filled part of the first bit value needs to be filled with data of the length of 2 data blocks. If all three conditions are met, a 64-bit bit string is filled at the end of the data to be compressed, and the bit string is used to represent the amount of data to be compressed before filling. If the preset extension condition is met, the condition that the filled part of the first bit value is valid, but the length of the data to be compressed after the filled part of the first bit value is not equal to 2 data blocks, then a number of groups of "0" strings are filled at the end of the data to be compressed, and each group of "0" strings represents 64 "0". After filling several groups of "0" strings, if the data length of the data to be compressed after the first bit value of the filling part is equal to 2 data blocks, a 64-bit bit string is filled at the end of the data to be compressed, and the bit string is used to represent the amount of data to be compressed before filling.
[0081] Among them, the preset extension condition is used to indicate that the first data can be iteratively extended at present. Optionally, the above-mentioned message extension module and message filling module perform handshake, and if the handshake is successful, it is judged that the preset extension condition is met; otherwise, it is judged that the preset extension condition is not met. Optionally, when the iterative extension of the first data has not started, or when the number of iterative extensions reaches a preset number, it is judged that the preset extension condition is met; if the iterative extension of the first data has started and the number of iterative extensions has not reached the preset number, it is judged that the preset extension condition is not met.
[0082] The second bit value is obtained according to the filling requirements when the compression algorithm is executed. When the SM3 algorithm is executed, the second bit value includes multiple "0", and the number of "0" is determined according to the difference between the amount of data to be compressed and the preset length. The specified number can be determined according to the state machine used to fill the compressed data. Optionally, the preset length is 512 bits, and the data to be compressed is divided into multiple data blocks in units of 64 bits; the specified number is set to 12 words. Counting starts after receiving the data block. When counting to 12 words, if there is invalid data in the last data block, a 64-bit bit string is filled at the end of the data to be compressed, and the bit string is used to represent the amount of data to be compressed before filling. If 12 words are not counted, if there is invalid data in the last data block, several groups of second bit values are filled at the end of the data to be compressed until the final 2 data blocks need to be filled.
[0083] In this embodiment, the padding bits are determined according to the data volume of the data to be compressed, so that the first data obtained after padding meets the padding requirement of the data encryption algorithm.
[0084] Furthermore, in one embodiment, after sequentially acquiring data blocks in the data to be compressed, the method further includes: determining whether data in at least one received data block is valid; if the data in the data block is valid, executing the step of determining whether the data in the last data block is valid when the last data block in the data to be compressed is received.
[0085] Optionally, when it is determined that invalid data exists in the received data block, the step of executing: when the last data block in the data to be compressed is received, determining whether the data in the last data block is valid is not output. When it is determined that all data in the received data block is valid, the next data block is received until the last data block is received, and the step of executing: determining whether the data in the last data block is valid is performed. In this embodiment, the input data is checked during the process of receiving the data block to ensure that valid data is obtained, thereby improving the stability of the data encryption method.
[0086] In one embodiment, compressing a target word group selected from a word group of first data includes: obtaining a first function and a second function according to rounds of iterative expansion; obtaining predefined working variables, state variables, and a constant quantity; obtaining a first value calculated according to the first function and the first working variable, and a second value calculated according to the second function for the first state variable; calculating the first value, the second working variable, and the first word in the target word group according to a first carry addition retainer; calculating the second value, the second state variable, and the second word in the target word group according to a second carry addition retainer; calculating the constant quantity, the third working variable, and the third state variable according to a third carry addition retainer; and obtaining a compression result according to output values of the first carry addition retainer, the second carry addition retainer, and the third carry addition retainer.
[0087] The first function and the second function are preset functions. Optionally, the first function and the second function are called based on the function signature during the compression process. The first function and the second function in different iteration expansion rounds may be the same or different. Optionally, the first working variable is used as the input of the first function to obtain the first value of the output. The first state variable is used as the input of the second function to obtain the second value of the output.
[0088] Exemplarily, an initial value is obtained and assigned to eight 32-bit data A i ~H i . i ~H i Calculate A i+1 ~H i+1 For example, the calculation formula is as follows:
[0089] 1. B i+1 =A i
[0090] 2. C i+1 =B i <<<9
[0091] 3. D i+1 =C i
[0092] 4. F i+1 =E i
[0093] 5. G i+1 =F i <<<19
[0094] 6. H i+1 =G i
[0095] 7. [s0, c0] = CSA0 (FF (A i ,Bi ,C i ),D i ,W i ')
[0096] 8. t0=s0+(c0<<1)
[0097] 9. [s1,c1]=CSA1(A i <<<12,E i ,T i )
[0098] 10. t1=(s1+(c1<<1))<<<7
[0099] 11. [s2,c2]=CSA2(GG(E i ,F i ,G i ),H i ,W i )
[0100] 12. t2=s2+(c2<<1)
[0101] 13. t3 = A i <<<12⊕t1
[0102] 14. A i+1 =t0+t3
[0103] 15. E i+1 =P0(t1+t2)
[0104] Among them, A i , B i , C i , D i is a predefined working variable; E i 、F i , G i , H i is a predefined state variable; T i is a predefined constant; i is a positive integer, indicating the number of rounds of iterative compression. The first working variable is A i ,B i ,C i ; The first state variable is E i ,F i ,G i ; The first function is FF; The first value is FF(A i ,B i ,C i ); the second function is GG; the second value GG(E i ,F i ,G i ); predefined constant quantity Ti ; The second working variable is D i ; The first character is W i '; The second state variable is H i ; The second character is W i .
[0105] In this embodiment, when a carry adder retainer is used to replace addition, three operands can be processed at one time, thereby reducing the number of additions, and by reducing the delay of the critical path, the circuit delay caused by the addition operation is shortened.
[0106] Based on the same inventive concept, the embodiment of the present application also provides a data encryption device for implementing the data encryption method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more data encryption device embodiments provided below can refer to the limitations on the data encryption method above, and will not be repeated here.
[0107] In one embodiment, Figure 3 As shown, a data encryption device is provided, including: a message filling module, a message expansion module and an iterative compression module; wherein,
[0108] A message filling module, used for filling the data to be compressed until the data length of the filled data to be compressed reaches a preset length, thereby obtaining first data;
[0109] A message expansion module, configured to iteratively expand the first data, and select a first number of word groups from the first data after each round of iterative expansion is completed; and stop iterative expansion of the first data when it is determined that the total number of word groups selected after iterative expansion reaches a second number;
[0110] The iterative compression module is used to obtain a first amount of data; after compressing a target word group selected from the word group of the first data, repeatedly perform the following steps until the first amount of word groups are compressed: obtain a compression result, and compress a new target word group obtained by selecting the compression result and the word group of the first data.
[0111] In some embodiments, the iterative compression module includes a first number of compressors, each compressor is connected in series, and the compressors of the iterative compression module can perform the same number of compressions as the first number in a time period.
[0112] In some of the embodiments, after iteratively expanding the first data and selecting a first number of word groups from the first data after each round of iterative expansion, the message filling module is also used to: when it is determined that the number of iterative expansions reaches a preset number, receive new data to be compressed input from the upstream; fill the new data to be compressed until the length of the filled data reaches a preset length to obtain second data; cache the second data; and when stopping the iterative expansion of the first data, obtain the second data and iteratively expand the second data.
[0113] In some of the embodiments, the data to be compressed is constructed by at least one data block; the message filling module fills the data to be compressed until the data length of the data to be compressed after filling reaches a preset length to obtain the first data, including: obtaining the data blocks in the data to be compressed in sequence; when the last data block in the data to be compressed is received, judging whether the data in the last data block is valid; if all the data in the last data block is valid, filling the end of the data to be compressed with a first bit value and a bit value corresponding to the data amount of the data to be compressed until the data length of the data to be compressed after filling reaches a preset length to obtain the first data; if there is invalid data in the last data block, then when the data amount of the data to be compressed is equal to a specified number, filling the end of the data to be compressed with a bit value corresponding to the data amount of the data to be compressed; when the data amount of the data to be compressed is not equal to the specified number, filling the end of the data to be compressed with a second bit value.
[0114] Optionally, after sequentially acquiring the data blocks in the data to be compressed, the message filling module is also used to: determine whether the data in at least one received data block is valid; if the data in the data block is valid, then executing the step of determining whether the data in the last data block is valid when the last data block in the data to be compressed is received.
[0115] In some of the embodiments, the message expansion module fills the data to be compressed until the length of the data after filling reaches a preset length to obtain first data; including: receiving the data to be compressed input from the upstream in response to the first signal of the first level; filling the data to be compressed until the length of the data after filling reaches a preset length to obtain the first data; adjusting the first signal to the second level to stop receiving the data input from the upstream.
[0116] In some of the embodiments, the iterative compression module compresses a target word group selected from a word group of the first data, including: obtaining a first function and a second function according to rounds of iterative expansion; obtaining predefined working variables, state variables, and a constant quantity; obtaining a first value calculated according to the first function and the first working variable, and a second value calculated according to the second function for the first state variable; calculating the first value, the second working variable, and the first word in the target word group according to a first carry addition retainer; calculating the second value, the second state variable, and the second word in the target word group according to a second carry addition retainer; calculating the constant quantity, the third working variable, and the third state variable according to a third carry addition retainer; and obtaining a compression result according to output values of the first carry addition retainer, the second carry addition retainer, and the third carry addition retainer.
[0117] Each module in the above data encryption device can be implemented in whole or in part by software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module.
[0118] In one embodiment, in combination Figure 3 The device and peripheral input modules shown can implement the SM3 algorithm. Figure 4 A structural block diagram of a device for implementing the SM3 algorithm is provided, such as Figure 4 As shown, the device for implementing the SM3 algorithm includes a message filling module, a message expansion module and an iterative compression module, and the device is also connected to a peripheral input module. Among them, the peripheral input module, as the upstream of the message filling module, inputs the original message, i.e., the data to be compressed in the above embodiment, to the message filling module through a FIFO (First Input First Output) queue. After the original message is processed by the message filling module, the message expansion module and the iterative compression module, the data hash_res processed by the SM3 algorithm is output.
[0119] Among them, when the first signal input to the upstream by the message filling module, that is, the pad_ready signal is a high-level signal, it means that the FIFO can input data to the message filling module. The FIFO inputs 64 bits, that is, 8-byte wide data, to the message filling module in each cycle. At the same time, the peripheral input module indicates the validity of each byte through msg_keep, 1 for valid and 0 for invalid; msg_valid indicates whether the input data is valid; msg_last indicates whether the input data is the last group; and msg_data indicates the input 64 bits (8 bytes) of data. Optionally, the number of bits of data input to the message filling module in each clock cycle can be changed by adjusting the data interface between the peripheral input module and the message filling module. Since the SM3 algorithm processes a maximum of 512 bits, that is, 64 bytes, at a time, taking the example of FIFO inputting 64 bits to the message filling module in each cycle, 8 clock cycles are required to complete the message filling process.
[0120] After the message filling module fills the original message, the message expansion module will output a second signal to the message filling module, that is, when the expand_ready signal is a high-level signal, the filled data will be transmitted to the message expansion module, and the message expansion module will expand the message based on the received data, which lasts for 22 clock cycles. Among them, when the message expansion module outputs the second signal to the message filling module, the message filling module indicates that the input filling block is valid by outputting pad_valid; indicates the data input to the message expansion module by outputting pad_data; and indicates the last data input to the message expansion module by outputting pad_last.
[0121] After the message expansion module expands the padded data for one clock cycle, a specified number of words are selected from the expanded data to form a group, and at least two word groups obtained by the combination are input into the iterative compression module. Among them, iterative compression will also be performed for 22 clock cycles, but will lag behind the message expansion by 1 clock cycle. Among them, the message expansion module indicates the validity of the data output to the iterative compression module by outputting the expand_valid signal; expand_data indicates the data input by the message expansion module to the iterative compression module; expand_last indicates the last data input by the message expansion module to the iterative compression module.
[0122] Furthermore, when the number of 512-bit message blocks to be processed is large, the message filling module can be notified to send a new round of data when the iterative compression of the current bit block has not been completed, and the incoming data can be cached in the message expansion module. In this way, the clock cycle required for a new round of 512-bit block message filling can be hidden, which is conducive to the iterative compression module to immediately start a new round of iterative compression calculation of bit blocks after completing the iterative compression calculation of the current bit block. Figure 5 is a timing diagram of the execution of each module in a device for implementing the SM3 algorithm in this embodiment, such as Figure 5 As shown, taking the example of FIFO inputting 64 bits to the message filling module in each cycle, except for the first time receiving the bit block corresponding to the original message input by the peripheral input module, 31 clock cycles (clk) are required for data compression, each subsequent bit block corresponding to a new original message received only requires 22 clock cycles (clk) for compression.
[0123] The following describes the methods executed in the message filling module, the message expansion module, and the iterative compression module in turn.
[0124] Among them, for the message filling module, the received original message will be filled. Optionally, assuming that the length of the original message m is l (in bits), the steps of message filling include: first, adding the bit "1" to the end of the message, then adding k "0s", k is the smallest non-negative integer that satisfies l+1+k≡448mod 512, and finally, adding a 64-bit bit string, which is the binary representation of the length l. In this embodiment, the input and output data of the message filling module are set to 64 bits, so that the data with a width of 64 bits can be aligned during filling.
[0125] Whenever the data length of the first data obtained after filling by the message filling module reaches 512 bits, the pad_ready signal will be pulled low to inform the upstream input module FIFO that the message filling module is not ready to receive new data; conversely, the pad_ready signal will be pulled high to inform the upstream input module FIFO that the message filling module is ready to receive new data.
[0126] The message filling module combines with the finite state machine to realize data filling. Figure 6 The schematic diagram of the finite state machine designed for the message filling module is as follows: Figure 6As shown in Figure 1, the finite state machine designed for the message padding module contains a total of 6 states: IDLE indicates idle state, DATA_OUT indicates directly outputting the 64-bit data transmitted from the upstream, DATA_LAST indicates outputting the last block of the original message, PAD_00 indicates outputting 64 "0s", PAD_10 indicates outputting 1 "1" and 63 "0s", and PAD_LEN indicates outputting the length of the original message. The jump relationship between these states is shown in Table 1.
[0127] Table 1 Jump of the finite state machine of the message filling module
[0128] Current Status Jump conditions Next state IDLE msg_valid&~msg_last DATAOUT IDLE msg_valid&msg_last DATA_LAST DATA_OUT msg_valid&msg_last DATA_LAST DATA_LAST word_cnt==12&~(&msg_keep) PAD_LEN DATA_LAST word_cnt! =12&~(&msg_keep) PAD_00 DATA_LAST &msg_keep PAD_10 PAD_10 pad_valid&expand_ready&need_pad_cnt==2 PAD_LEN PAD_10 pad_valid&expand_ready&need_pad_cnt! =2 PAD_00 PAD_00 need_pad_cnt==2 PAD_LEN
[0129] Among them, msg_valid means that the input data is valid; the original message input from the upstream will be divided into multiple data blocks based on the settings of the message filling module input interface, msg_last means that the input data is the last data block of the original message, ~msg_last means that the input data is not the last data block of the original message; word_cnt means counting the input words; &msg_keep means that the 8 bytes input by the last data block are all valid, ~(&msg_keep) means that there are invalid bytes in the 8 bytes input by the last data block; pad_valid means that the padding block output by the message filling module is valid; expand_ready means that the message expansion module is ready to receive the data output by the message filling module; need_pad_cnt means the number of blocks that still need to be filled in the message filling module.
[0130] Among them, for the message expansion module, after the waiting message filling module sends 16 words to the message expansion module, the message expansion module starts to work. Optionally, the 16 words passed in are W0, W1, W2, ..., W 15 The expansion can be achieved by following the expansion function. Specifically, the following formula (1) is used to expand W 16 , W 17 , …, W 67 ; Expand according to the following formula (2) to obtain W0', W1'...W 63 '.
[0131]
[0132] The message expansion module will expand 3 words in 1 clock cycle. Figure 7 Provides a schematic diagram of message expansion module expansion, such as Figure 7As shown, in the first clock cycle, W0, W1, W2 and the expanded W0', W1', W2' can be extracted through the expansion function, and W0, W1, W2, W0', W1', W2' can be constructed to obtain a word group. Optionally, the first number is set to 3, and three groups are constructed: W0 and W0'; W1 and W1'; W2 and W2'. After the word group is constructed, the message expansion module transmits the extracted word group to the downstream iterative compression module in the next clock cycle. Optionally, 3 groups of 6 words are transmitted to the iterative compression module and used as the message words required for the compression function calculation in the iterative compression module.
[0133] Optionally, the message expansion module also includes an 8-word register, which can be used to cache data output by a new round of message filling module, so that the iterative compression module can start a new round of calculation immediately after completing the iterative compression calculation of the current 512-bit block.
[0134] The message expansion module combines with the finite state machine to realize data filling. Figure 8 The finite state machine designed for the message expansion module is shown, which contains three states: REC_DATA indicates that the message expansion module receives the data passed by the message filling module; EXPAND_OUT indicates that the message expansion module passes the compressed word to the iterative compression module while expanding the message; PRELOAD indicates that the filling message of the next round of 512-bit blocks is received in advance when the processing of the current round of 512-bit blocks is not completed. The jump relationship between these states is shown in Table 2 below.
[0135] Table 2 Jump of the finite state machine of the message expansion module
[0136] Current Status Jump conditions Next state REC_DATA pad_data_cnt == 14 EXPAND_OUT EXPAND_OUT clk_cnt==13&pad_valid PRELOAD EXPAND_OUT clk_cnt == 21 REC_DATA PRELOAD clk_cnt == 21 EXPAND_OUT
[0137] Among them, pad_data_cnt is the counter of the padding block input by the message padding module; clk_cnt is the clock counter after the message expansion module enters the expansion state; pad_valid indicates that the input padding block is valid.
[0138] Wherein, for the iterative compression module, after the message expansion module transmits the first number of word groups to the iterative compression module, the iterative compression module starts to work. Fig. 9 A schematic diagram of an iterative compression module is provided, such as Fig. 9 As shown on the left, the iterative compression module consists of three compressors, compressor 1, compressor 2, and compressor 3; Fig. 9As shown on the right, the operation logic of each compressor is the same. CSA0, CSA1, and CSA2 are three carry save adders (CSAs) in the iterative compression module. In the compression function, the combinational logic involved in calculating the new round of A and E values from the current A to H values is the most complex, and is the two critical paths in the circuit implementation. In order to reduce the delay of the critical path, that is, to shorten the circuit delay caused by the addition operation, the carry save adder is used to replace the addition while being able to process 3 operands at a time, thereby reducing the number of additions. The critical path delay of a compressor is the sum of the delays of a CSA and two adders. In the actual circuit implementation, a total of 3 CSAs and 5 adders are required.
[0139] based on Fig. 9 The iterative compression module shown can combine 3 rounds of round functions into 1 round and complete it within one clock cycle. The SM3 algorithm requires a total of 64 rounds of iterative operations of the compression function. Since 1 clock cycle executes 3 round function compressions, the entire iterative compression operation can be completed in 22 clock cycles. In particular, in the 22nd clock cycle, only one compression function calculation is required and the calculation result of the previous round is XORed to complete the calculation of the entire iterative compression. Furthermore, other numbers of serially connected compressors can also be set in the iterative compression module.
[0140] The SM3 algorithm is modified based on the SHA-256 algorithm, and both require three steps: message filling, message expansion, and iterative compression. The first two steps of both are some shifts and Boolean operations, and the iterative compression process requires multiple addition operations, which will cause a huge carry delay chain. In traditional technology, a traditional optimization method for the iterative compression step is to rewrite the compression function and insert registers on the critical path to increase the calculation frequency. Another optimization method for the iterative compression step is to merge multiple rounds of compression functions into one round by loop expansion. Different from traditional technology, the iterative compression module in this embodiment completes multiple iterative compression calculations within one clock cycle by adopting round compression, so as to achieve the effect of shortening the time required for iterative compression calculations.
[0141] At the same time, the conventional technology only considers the optimization of the iterative compression process, while ignoring the impact of message filling and message expansion on subsequent iterative compression. In this embodiment, by placing a message buffer in the message expansion module, the message filling module can input data into the message expansion module in advance when each group of iterative compression is about to be completed, so as to immediately start the next group of 512-bit iterative compression calculations after completing the iterative compression of the current 512-bit group. In addition, when the hardware design of the device for implementing the SM3 algorithm in this embodiment is performed, the front-to-back dependency relationship between message filling and message expansion in the SM3 algorithm is fully considered. Therefore, when the message to be hashed is very long, the average processing time of each 512-bit group will be greatly shortened, further shortening the time required for SM3 algorithm processing.
[0142] Each module in the above-mentioned device for implementing the SM3 algorithm can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each of the above modules.
[0143] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Fig.10 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a data encryption method is implemented. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, etc. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device shell, or an external keyboard, touchpad or mouse.
[0144] Those skilled in the art will understand that Fig.10The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0145] In one embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiments when executing the computer program.
[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0147] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0148] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., but are not limited to this.
[0149] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0150] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A data encryption method, characterized in that: The method comprises: Filling the data to be compressed until the data length of the filled data to be compressed reaches a preset length, thereby obtaining first data; Iteratively expand the first data, and select a first number of word groups from the first data after each round of iterative expansion is completed; After compressing the target word groups selected from the first number of word groups, repeatedly performing the following steps until the first number of word groups are compressed: obtaining a compression result and selecting a new target word group from the word groups of the first data, and compressing the compression result and the new target word group; When it is determined that the total number of word groups selected after iterative expansion reaches a second number, iterative expansion of the first data is stopped.
2. The method according to claim 1, characterized in that: After iteratively expanding the first data and selecting a first number of word groups from the first data after each round of iterative expansion is completed, the method further includes: When it is determined that the number of iterative expansions reaches a preset number, new data to be compressed is received from upstream input; Filling the new data to be compressed until the length of the filled data reaches the preset length, thereby obtaining second data; caching the second data; When the iterative expansion of the first data is stopped, the second data is acquired and the second data is iteratively expanded.
3. The method according to claim 1, characterized in that The method of filling the data to be compressed until the length of the filled data reaches a preset length to obtain the first data comprises: In response to a first signal of a first level, receiving data to be compressed inputted from an upstream; Filling the data to be compressed until the length of the filled data reaches a preset length, thereby obtaining first data; The first signal is adjusted to a second level to stop receiving data inputted from the upstream.
4. The method according to claim 1 or 3, characterized in that: The data to be compressed is constructed from at least one data block; The step of padding the data to be compressed until the length of the data to be compressed after padding reaches a preset length, thereby obtaining the first data, comprises: sequentially acquiring the data blocks in the data to be compressed; When receiving the last data block in the data to be compressed, determining whether the data in the last data block is valid; If all the data in the last data block are valid, a first bit value and a bit value corresponding to the data amount of the data to be compressed are filled at the end of the data to be compressed until the data length of the data to be compressed after filling reaches a preset length, thereby obtaining first data; If invalid data exists in the last data block, then when the amount of data to be compressed is equal to the specified amount, a bit value corresponding to the amount of data to be compressed is filled at the end of the data to be compressed; if the amount of data to be compressed is not equal to the specified amount, a second bit value is filled at the end of the data to be compressed.
5. The method according to claim 4, characterized in that After sequentially acquiring the data blocks in the data to be compressed, the method further includes: Determining whether data in at least one of the received data blocks is valid; If the data in the data block is valid, then executing the step of determining whether the data in the last data block is valid when the last data block in the data to be compressed is received.
6. The method according to claim 1, characterized in that The compressing the target word group selected from the word group of the first data includes: Obtain the first function and the second function according to the round of iterative expansion; Get predefined working variables, state variables and constants; Obtaining a first value calculated according to the first function and the first working variable, and a second value calculated according to the second function for the first state variable; Calculate the first value, the second working variable, and the first word in the target word group according to a first carry addition retainer; Calculate the second value, the second state variable, and the second word in the target word group according to a second carry addition retainer; Calculating the constant quantity, the third working variable and the third state variable according to the third carry adder retainer; A compression result is obtained according to the output values of the first carry addition retainer, the second carry addition retainer and the third carry addition retainer.
7. A data encryption device, characterized in that: The device comprises: a message filling module, a message expansion module and an iterative compression module; wherein, The message filling module is used to fill the to-be-compressed data until the data length of the filled to-be-compressed data reaches a preset length, thereby obtaining the first data; The message expansion module is used to iteratively expand the first data and select a first number of word groups from the first data after each round of iterative expansion; when it is determined that the total number of word groups selected after iterative expansion reaches a second number, stop iterative expansion of the first data; The iterative compression module is used to obtain the first amount of data; after compressing the target word group selected from the word group of the first data, repeatedly perform the following steps until the first number of word groups are compressed: obtain the compression result, and compress the new target word group obtained by selecting the compression result and the word group of the first data.
8. The device according to claim 7, characterized in that The iterative compression module includes the first number of compressors, and each of the compressors is connected in series.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method and system for realizing reconfiguration of multiple hash algorithms
CN111464308A
SM3 algorithm acceleration method, processor, chip and electronic equipment
CN112367158A
Data compression method and device, electronic equipment and storage medium
CN113721986A
SM3 algorithm implementation circuit and method and electronic equipment
CN114676448A
Data encryption method and related product
CN116094715A