Authentication encryption method and device based on sequence cipher and program product

Through the authentication and encryption method based on sequence password, the existing AEAD algorithm is solved inefficient in software implementation, efficient encryption and authentication functions are realized, and the overall implementation rate of the algorithm is improved, providing strong security.

CN119966622APending Publication Date: 2025-05-09BEIJING ACAD OF INFORMATION SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510126801.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-27
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The existing integrated AEAD algorithm is inefficient in software implementation and cannot meet the high efficiency requirements of 5G/6G. At the same time, there are unpredictable hidden security problems, such as state recovery attacks when authentication security is lower than encryption security.

Method used

Using the authentication encryption method based on sequence cipher, by loading the key and initialization vector into the sequence cipher algorithm and initializing it, the sequence cipher algorithm generates a key stream to encrypt the plaintext, and the MAC authentication algorithm absorbs the plaintext associated data and the plaintext to be encrypted, feedback and update the internal state of the sequence cipher algorithm, and finally intercepts the key stream according to the preset length to generate the authentication tag.

Benefits of technology

It realizes efficient encryption and authentication functions, significantly improves the overall implementation rate of the algorithm, can provide 256-bit security to prevent key recovery attacks and 128-bit security to prevent forgery attacks, and resist a variety of mainstream attack methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966622A_ABST
    Figure CN119966622A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication encryption method, device and program product based on a sequence cipher, and the method comprises the steps: initializing the sequence cipher, carrying out the MAC state declaration of an MAC authentication algorithm through employing the internal state of a sequence cipher algorithm after initialization, generating a key stream through employing the sequence cipher algorithm, and carrying out the encryption processing of a to-be-encrypted plaintext, and obtaining a ciphertext; then, the MAC authentication algorithm is used for sequentially absorbing the plaintext associated data and the plaintext to be encrypted, the internal state of the MAC authentication algorithm after absorption is completed is fed back to the sequence cryptographic algorithm, part of the internal state of the sequence cryptographic algorithm is updated, the sequence cryptographic algorithm is initialized again, and finally, a key stream generated by the sequence cryptographic algorithm is intercepted according to a preset length. And obtaining an authentication label corresponding to the ciphertext. The encryption and authentication functions can be provided at the same time, and the overall implementation rate of the algorithm is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular to an authentication encryption method, device and program product based on a sequence cipher. Background Art

[0002] In existing information systems, people usually use encryption algorithms to ensure the confidentiality of information and authentication algorithms to ensure the integrity and verifiability of information. In encryption technology, symmetric ciphers represented by block ciphers, stream ciphers, and cryptographic hash functions have extremely high software and hardware implementation efficiency and are widely used for encryption and decryption of large-scale data. In authentication technology, MAC (message authentication code, English: Message authentication code, abbreviated as MAC) generation algorithms based on symmetric cipher design are also widely used due to their significant efficiency advantages. In addition, in order to meet the actual needs of using encryption and authentication technologies at the same time, a new type of cryptographic algorithm with both encryption and authentication functions, AEAD (Authenticated Encryption with Associated Data), that is, an authenticated encryption algorithm based on a stream cipher for associated data, came into being.

[0003] With the emergence of new mobile communication technologies such as 5G / 6G, the data transmission rate has increased significantly, thus putting forward higher efficiency requirements for various cryptographic algorithms such as encryption, MAC, AEAD, etc. The popularity of virtualization technology and software-defined networks has spawned more diverse authentication strength requirements. For example, the link layer of 4G / 5G wireless networks usually only requires 32 bits of authentication security strength, while the transport layer and application layer require 64 bits of authentication security strength, and media applications require 80 bits of security strength.

[0004] Symmetric encryption algorithms are mainly divided into two categories: block ciphers and stream ciphers. Among block ciphers, the international standard AES block cipher algorithm is undoubtedly the most widely used. Compared with block cipher algorithms, stream cipher algorithms are often more efficient when encrypting long messages. Common stream cipher algorithms include SNOW 3G, Trivium, Grain-v1, etc.

[0005] Most authentication algorithms are built on symmetric cryptographic algorithms as basic components, such as CMAC based on block ciphers, HMAC based on cryptographic hash functions, etc. In addition, there are MAC algorithms based on universal hash functions, such as UMAC, Poly1305-AES, and GMAC.

[0006] The most typical authenticated encryption (AEAD) algorithm based on a stream cipher is the AES-GCM algorithm, which is based on the block cipher AES and the MAC algorithm GMAC. The CAESAR competition (Competition for Authenticated En-cryption: Security, Applicability, and Robustness, a global cryptographic algorithm competition) jointly initiated by NIST (National Institute of Standards and Technology) and Dan Bernstein collected a large number of AEAD algorithms with better comprehensive performance than AES-GCM. After multiple rounds of evaluation, six winning AEAD algorithms such as Ascon and AEGIS were finally selected. These CAESAR winning algorithms often use an integrated encryption and authentication method to obtain higher execution efficiency. This idea is also used to design the 6G-oriented AEAD algorithm Rocca: This algorithm is considered to be an extension of AEGIS, supporting 256-bit keys and 128-bit authentication tags. It is the first symmetric cryptographic algorithm claimed to be dedicated to 6G systems.

[0007] In addition, the stream cipher can also be combined with the MAC algorithm to form an AEAD algorithm with both authentication and encryption functions. The latest 5G-oriented stream cipher algorithm SNOW-V draws on the design ideas of AES-GCM and provides the SNOW-V-GCM authentication encryption algorithm based on the stream cipher formed by combining SNOW-V and GMAC.

[0008] At present, most AEAD algorithms cannot meet the application requirements of 5G / 6G due to issues such as software efficiency and security. The software implementation efficiency required by 5G is "more than 20Gbps", and security must support 256-bit keys. 6G has raised the software efficiency requirements to 100Gbps-1TGbps. Among the 6 CAESAR winning algorithms, only AEGIS meets the 5G software efficiency requirements, but does not meet the security requirements, and there is a large gap between it and the 6G software efficiency requirements. AES-GCM is subject to the software efficiency limitations of AES itself and cannot meet the software efficiency requirements of 6G. Although Rocca has met the 5G / 6G requirements in terms of software efficiency, its security has weaknesses and there is an internal state recovery attack based on the collision of authentication tags.

[0009] Compared with block ciphers, stream ciphers have a higher efficiency ceiling, but when stream ciphers are combined with general hash functions such as GMAC to form AEAD algorithms, they often lead to serious efficiency degradation. For example, SNOW-V and its improved version SNOW-Vi both have high encryption efficiency, but the AEAD algorithm SNOW-V-GCM formed by combining with GMAC can only meet 5G requirements, which is far from the 6G standard.

[0010] In general, the integrated AEAD algorithm uses instant information absorption and compression to give attackers more optional attack methods, making it more difficult to defend and evaluate, and faces many security challenges; most polynomial-based MAC generation schemes are not suitable for generating short tags and do not meet the 5G / 6G requirements for changing tag lengths at different application layers; the combination of sequence ciphers and universal hash functions means using two algorithms in hardware and software implementations, which can be considered a solution with "excessive resource overhead."

[0011] Therefore, in order to solve the unpredictable hidden security problems brought about by the instant message absorption and squeezing of the existing integrated AEAD algorithm, such as the general state recovery attack when the authentication security is lower than the encryption security (such situations are very common in actual industrial applications), it is urgent to invent an authenticated encryption method based on a sequence cipher, which provides encryption and authentication functions at the same time and greatly improves the overall implementation rate of the algorithm. Summary of the invention

[0012] In view of this, the embodiments of the present invention provide an authentication encryption method, device and program product based on a sequence cipher, which at least partially solve the problems existing in the prior art.

[0013] Other features and advantages of the present invention will become apparent from the following detailed description, or may be learned in part by practice of the present invention.

[0014] In order to achieve the above purpose, the embodiment of the present invention provides the following technical solutions:

[0015] According to a first aspect of an embodiment of the present invention, there is provided an authenticated encryption method based on a stream cipher, the method comprising:

[0016] Loading the key and the initialization vector into the stream cipher algorithm, and initializing the stream cipher algorithm to obtain the first state of the stream cipher algorithm;

[0017] Using the first state of the sequence cipher algorithm, a state declaration is made on the MAC authentication algorithm to obtain the first state of the MAC authentication algorithm;

[0018] Generate a key stream using the first state of the stream cipher algorithm, encrypt the plaintext to be encrypted, and obtain the ciphertext and the second state of the stream cipher algorithm that completes the encryption;

[0019] Utilizing the first state of the MAC authentication algorithm to sequentially absorb the plaintext associated data and the plaintext to be encrypted, to obtain a second state of the MAC authentication algorithm in which the absorption is completed;

[0020] Feedback the second state of the MAC authentication algorithm to the second state of the stream cipher algorithm, update part of the internal state of the second state of the stream cipher algorithm, and obtain an updated third state of the stream cipher algorithm;

[0021] Initializing the third state of the stream cipher algorithm to obtain a fourth state of the stream cipher algorithm;

[0022] The fourth state of the stream cipher algorithm is used to generate a key stream, and the key stream is intercepted according to a preset length to obtain an authentication tag corresponding to the ciphertext.

[0023] Furthermore, the sequence cipher algorithm is a large memory sequence cipher algorithm LOL2.0-MINI, supporting a 256-bit key K and a 128-bit initialization vector IV, and the sequence cipher algorithm includes two 128-bit LFSR registers (H, L), one NFSR register N and three FSM registers ;

[0024] The internal state of the stream cipher algorithm is ;

[0025] The MAC authentication algorithm includes four 128-bit registers. The internal state of the MAC authentication algorithm is .

[0026] Furthermore, the sequence cipher algorithm is a large memory sequence cipher algorithm LOL2.0-DOUBLE, supporting a 256-bit key K and a 256-bit initialization vector IV, and the sequence cipher algorithm includes a 512-bit linear feedback shift register, two nonlinear feedback shift registers and and two finite state machines FSM, wherein the 512-bit linear feedback shift register includes four 128-bit registers, namely and ; The two finite state machines FSM include four 128-bit registers, respectively and ;

[0027] The internal state of the stream cipher algorithm is ;

[0028] The MAC authentication algorithm includes six 128-bit registers. The internal state of the MAC authentication algorithm is .

[0029] Further, the key and the initialization vector are loaded into the stream cipher algorithm, and the stream cipher algorithm is initialized to obtain the first state of the stream cipher algorithm, including:

[0030] Loading the key K and the initialization vector IV into the stream cipher algorithm includes: ,in, The internal state after the key and initialization vector are loaded and fully obfuscated for the stream cipher algorithm;

[0031] Perform standard initialization processing on the loaded stream cipher algorithm to obtain the first state of the stream cipher algorithm, including: ,in, It is the first state of the stream cipher algorithm, and ScInit is the initialization process.

[0032] Further, using the first state of the sequence cipher algorithm, a state declaration is performed on the MAC authentication algorithm to obtain the first state of the MAC authentication algorithm, including:

[0033] copying a portion of the first state of the stream cipher algorithm into the internal state of the first MAC authentication algorithm, ,in, The first state of the MAC authentication algorithm after the state declaration. The first state of the stream cipher algorithm;

[0034] If the sequence cipher algorithm is the LOL2.0-MINI algorithm, then , ;

[0035] If the stream cipher algorithm is the LOL2.0-DOUBLE algorithm, then , .

[0036] Further, the first state of the stream cipher algorithm is used to generate a key stream, and the plaintext to be encrypted is encrypted to obtain the ciphertext and the second state of the stream cipher algorithm that completes the encryption, including:

[0037] , ,in, is the first state of the stream cipher algorithm, The second state of the stream cipher algorithm, Z is the key stream, M is the plaintext to be encrypted, C is the encrypted ciphertext, and ScEnc is the stream cipher algorithm update function Iterative calls, is the sum of the register bits of the serial cipher algorithm, is the number of bits of the key stream data block.

[0038] Further, the plaintext associated data and the plaintext to be encrypted are absorbed in sequence by using the first state of the MAC authentication algorithm to obtain the absorbed second state of the MAC authentication algorithm, the second state of the MAC authentication algorithm is fed back to the second state of the stream cipher algorithm, and part of the internal state of the second state of the stream cipher algorithm is updated to obtain the updated third state of the stream cipher algorithm, including:

[0039] Utilize the first state of the MAC authentication algorithm to absorb plain text associated data, ,in, is the first state of the MAC authentication algorithm, AD is the associated data corresponding to the plaintext to be encrypted (the associated data can include identity information, communication parameters, etc. according to user needs, or it can be left blank), Absorb is the first state of the MAC authentication algorithm after absorbing the associated data. Absorb is the MAC authentication algorithm update function. Iterative calls, is the sum of the register bits of the MAC authentication algorithm, The number of bits of the data block to be absorbed;

[0040] The first state of the MAC authentication algorithm after absorbing the associated data absorbs the plaintext to be encrypted. , where M is the plaintext to be encrypted, The second state of the MAC authentication algorithm after absorbing the plain text;

[0041] ,in, The second state of the MAC authentication algorithm after absorbing the plaintext. is the second state of the stream cipher algorithm, It is the third state of the stream cipher algorithm;

[0042] If the sequence cipher algorithm is the LOL2.0-MINI algorithm, then , ;

[0043] If the stream cipher algorithm is the LOL2.0-DOUBLE algorithm, then , .

[0044] Further, the third state of the stream cipher algorithm is initialized to obtain the fourth state of the stream cipher algorithm; a key stream is generated using the fourth state of the stream cipher algorithm, and the key stream is intercepted according to a preset length to obtain an authentication tag corresponding to the ciphertext, including:

[0045] ,in, is the third state of the stream cipher algorithm, The fourth state of the stream cipher algorithm;

[0046] ,in, is the fifth state of the stream cipher algorithm, and T is the label of the corresponding length.

[0047] According to a second aspect of an embodiment of the present invention, there is provided an authentication encryption device based on a sequence cipher, the device comprising: a processor and a memory;

[0048] The memory is used to store one or more program instructions;

[0049] The processor is used to run one or more program instructions to execute the steps of the authentication encryption method based on a sequence cipher as described in any one of the above items.

[0050] According to a third aspect of an embodiment of the present invention, a computer program product is provided, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, which, when executed by a computer, enable the computer to implement the steps of a sequence cipher-based authentication encryption method as described in any one of the above items.

[0051] The embodiment of the present invention provides an authentication encryption method, device and program product based on a sequence cipher, the method comprising: initializing the sequence cipher, using the internal state of the sequence cipher algorithm after initialization, making a MAC state declaration for the MAC authentication algorithm, and using the sequence cipher algorithm to generate a key stream to encrypt the plaintext to be encrypted to obtain the ciphertext; then using the MAC authentication algorithm to absorb the plaintext associated data and the plaintext to be encrypted in turn, feeding back the internal state of the MAC authentication algorithm after absorption to the sequence cipher algorithm, updating part of the internal state of the sequence cipher algorithm, initializing the sequence cipher algorithm again, and finally intercepting the key stream generated by the sequence cipher algorithm according to a preset length to obtain the authentication tag corresponding to the ciphertext. The present invention can provide encryption and authentication functions at the same time, and greatly improve the overall implementation rate of the algorithm. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the implementation methods of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the implementation methods or the description of the prior art. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other implementation drawings can be derived from the provided drawings without creative work.

[0053] Figure 1 A schematic diagram of a flow chart of an authentication encryption method based on a sequence cipher provided in an embodiment of the present invention;

[0054] Figure 2 A schematic diagram of the encryption and decryption principles of an authentication encryption method based on a sequence cipher provided in an embodiment of the present invention;

[0055] Figure 3 A schematic diagram of the updating process of the MAC authentication algorithm provided by an embodiment of the present invention;

[0056] Figure 4 A schematic diagram of the initialization phase of the LOL2.0-MINI algorithm provided by an embodiment of the present invention;

[0057] Figure 5 A schematic diagram of the key stream generation phase of the LOL2.0-MINI algorithm provided in an embodiment of the present invention;

[0058] Figure 6 A schematic diagram of the initialization phase of the LOL2.0-DOUBLE algorithm provided in an embodiment of the present invention;

[0059] Figure 7 A schematic diagram of the key stream generation phase of the LOL2.0-DOUBLE algorithm provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0060] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0061] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0062] Figure 1The figure shows a flow chart of an authenticated encryption method based on a sequence cipher according to an embodiment of the present invention.

[0063] like Figure 1 As shown, the authenticated encryption method based on a stream cipher according to an embodiment of the present invention may include step S100, step S200, step S300, step S400, step S500, step S600 and step S700.

[0064] The sequence cipher algorithm in the embodiment of the present invention can be a large memory sequence cipher algorithm LOL2.0-MINI, supporting a 256-bit key K and a 128-bit initialization vector IV. The sequence cipher algorithm includes two 128-bit LFSR registers (H, L), one NFSR register N and three FSM registers. , then the internal state of the stream cipher algorithm is .

[0065] The LFSR of LOL2.0-MINI consists of 16 16-bit units stored in two 128-bit registers (H, L).

[0066] The MAC authentication algorithm corresponding to the LOL2.0-MINI algorithm includes four 128-bit registers. The internal state of the MAC authentication algorithm is .

[0067] There are two optional methods for updating LFSR: LFSR-1 and LFSR-2. The feedback function f of both methods can be expressed as of the form, and the substitution Both are defined as , the only difference is Definition:

[0068] LFSR-1: For LFSR-1, , where x is 128 bits long and is split into eight 16-bit words , is a constant, where the component , , ..., Polynomial The root of the polynomial is 16, and the operation is defined for ,in, Representation in finite fields Multiplication operation is performed on the polynomial formula as follows:

[0069] LFSR-2: The following basic operations are defined:

[0070] ( ): Move left (right) Bit, low (high) Fill the bits with 0; ( ): Change the status Split into bit words, and then for each word ( ) operation. For example: ,in , for bit word, then .

[0071] : Both Bit word, For a single 0-1 bit, choose the function Defined as: .

[0072] :two Bit Status First decompose into m-bit words: , ,in , yes Bit words are recorded from high to low as .Thus we get is defined as: .

[0073] According to the above definition, define LFSR-2 Function .

[0074] The R function is a combination of three basic operations of AES: byte substitution (SB), row shift (SR), and column mix (MC), namely .

[0075] Each 128-bit register state X can be divided into eight 16-bit bytes , Is the least significant byte; or divided into 16 8-bit bytes , is the least significant byte, that is, .

[0076] 128-bit register status The mapping between the 4×4 byte state array of the AES round function is as follows: .

[0077] The key loading method and status update method of LOL2.0-MINI algorithm are as follows: Divide 256-bit key , load sequence password status: .

[0078] Sequence Cipher Update UpdS: Calculate Intermediate Variables , calculate the feedback of LFSR , calculate the key stream data block , sequential update nonlinear drive , sequentially update the FSM, .

[0079] The sequence cipher is initialized SCInit, with 12 iterations: UpdS(S), , ; The last step , .

[0080] The combination of LOL2.0-MINI algorithm and MAC authentication algorithm instance is LOL2.0-MINI&SCMAC.

[0081] Figure 4 A schematic diagram of the initialization phase of the LOL2.0-MINI algorithm provided by an embodiment of the present invention; Figure 5 A schematic diagram of the key stream generation phase of the LOL2.0-MINI algorithm provided in an embodiment of the present invention.

[0082] The sequence cipher algorithm in the embodiment of the present invention can also be a large memory sequence cipher algorithm LOL2.0-DOUBLE, which supports a 256-bit key K and a 256-bit initialization vector IV. The sequence cipher algorithm includes a 512-bit linear feedback shift register, two nonlinear feedback shift registers, and And two finite state machines FSM, where the 512-bit linear feedback shift register includes four 128-bit registers, namely and ; The two finite state machines FSM include four 128-bit registers, namely and , the internal state of the stream cipher algorithm is , the corresponding MAC authentication algorithm includes six 128-bit registers, and the internal state of the MAC authentication algorithm is .

[0083] The LFSR of LOL2.0-DOUBLE consists of 32 16-bit units, which are used It is represented and stored in H and L as follows: , .

[0084] There are two optional methods for updating LFSR: LFSR-1 and LFSR-2. The feedback function f of both methods can be expressed as of the form, and the substitution Defined as , the only difference is Definition:

[0085] LFSR-1: For LFSR-1, , where x is 256 bits long and is split into 16 16-bit words ,definition ,in , , ..., Polynomial The root of , and define the operation for ,in, Representation in finite fields The polynomial formula is as follows:

[0086]

[0087] LFSR-2: According to the above definition, LFSR-2 The function is defined as .

[0088] The LOL2.0-DOUBLE algorithm is loaded and updated as follows: Divide the 256-bit key and IV: , , load sequence password status: , .

[0089] Sequence Cipher Update UpdS: Calculate Intermediate Variables , , calculate the feedback of LFSR , , calculate the key stream data block , sequential update nonlinear drive , sequentially update the FSM .

[0090] The sequence cipher is initialized SCInit, with 12 iterations: UpdS(S), , ; The last step .

[0091] The combination of the LOL2.0-DOUBLE algorithm and the MAC authentication algorithm instance is LOL2.0-DOUBLE&SCMAC.

[0092] Figure 6 A schematic diagram of the initialization phase of the LOL2.0-DOUBLE algorithm provided in an embodiment of the present invention; Figure 7 A schematic diagram of the key stream generation phase of the LOL2.0-DOUBLE algorithm provided in an embodiment of the present invention.

[0093] The internal state of the MAC authentication algorithm, MacState, consists of µ 128-bit registers with a total of Bit, ,MacState’s update function updE uses the AES round function R as the basic building block.

[0094] refer to Figure 2 In step S100, the key and the initialization vector are loaded into the stream cipher algorithm, and the stream cipher algorithm is initialized to obtain the first state of the stream cipher algorithm.

[0095] Specifically, the above steps include:

[0096] Load the key K and initialization vector IV into the stream cipher algorithm, ,in, The internal state after the key and initialization vector are loaded and fully obfuscated for the stream cipher algorithm.

[0097] Perform standard initialization processing on the loaded stream cipher algorithm to obtain the first state of the stream cipher algorithm, including: ,in, It is the first state (ScState) of the stream cipher algorithm, and ScInit is the initialization process.

[0098] In step S200, the first state of the stream cipher algorithm is used to declare the state of the MAC authentication algorithm to obtain the first state of the MAC authentication algorithm.

[0099] Specifically, the above steps include:

[0100] Copy a portion of the first state of the stream cipher algorithm into the internal state of the MAC authentication algorithm, ,in, The first state of the MAC authentication algorithm after the state declaration. It is the first state of the stream cipher algorithm.

[0101] If the stream cipher algorithm used is the LOL2.0-MINI algorithm, then , .

[0102] If the stream cipher algorithm used is the LOL2.0-DOUBLE algorithm, then , .

[0103] In step S300, a key stream is generated using the first state of the stream cipher algorithm, and the plaintext to be encrypted is encrypted to obtain the ciphertext and the second state of the stream cipher algorithm that completes the encryption.

[0104] Specifically, the above steps include:

[0105] , ,in, is the first state of the stream cipher algorithm, The second state of the stream cipher algorithm, Z is the key stream, M is the plaintext to be encrypted, C is the encrypted ciphertext, and ScEnc is the stream cipher algorithm update function Iterative calls, is the sum of the register bits of the serial cipher algorithm, is the number of bits of the key stream data block.

[0106] Next, in step S400, the plaintext associated data and the plaintext to be encrypted are sequentially absorbed using the first state of the MAC authentication algorithm to obtain a second state of the MAC authentication algorithm in which the absorption is completed.

[0107] Specifically, the above steps include:

[0108] First, use the first state of the MAC authentication algorithm to absorb the plaintext associated data. ,in, is the first state of the MAC authentication algorithm, AD is the associated data corresponding to the plaintext to be encrypted, that is, the length message of the plaintext to be encrypted and 10*, Absorb is the first state of the MAC authentication algorithm after absorbing the associated data. Absorb is the MAC authentication algorithm update function. Iterative calls, is the sum of the register bits of the MAC authentication algorithm, The number of bits of the data block to be absorbed.

[0109] The MAC authentication algorithm absorbs a block consisting of ν 128-bit sub-blocks at a time. Bit Block .

[0110] Figure 3 The figure shows the state update process of the MAC authentication algorithm. follow Figure 3 The structure shown. The definition of the update function updE is determined by three parameters: R mask , feedback mask and message sequence The R mask determines whether to apply Figure 3 The R function in slash: Only in Use when, otherwise the direct drop will Input to Feedback mask Control is represented by the dashed line of the feedforward operation: If ,but The calculation can be expressed as ⋆. The message sequence should satisfy the following criteria: all integers 1 to ν are included in the sequence MSG[i] = 0 if ,but ,otherwise .

[0111] The detailed algorithm of updE is as follows:

[0112] Algorithm input: MacState , data block .

[0113] Algorithm output: Updated MacState .

[0114] definition , ;

[0115] calculate ;

[0116] definition .

[0117] For a non-negative integer e, define The operation for e consecutive R is as follows: , .

[0118] The first state of the MAC authentication algorithm after absorbing the associated data absorbs the plaintext to be encrypted. , where M is the plaintext to be encrypted, It is the second state of the MAC authentication algorithm after absorbing the plain text.

[0119] In step S500, the second state of the MAC authentication algorithm is fed back to the second state of the stream cipher algorithm, and part of the internal state of the second state of the stream cipher algorithm is updated to obtain an updated third state of the stream cipher algorithm.

[0120] Specifically, the above steps include:

[0121] ,in, The second state of the MAC authentication algorithm after absorbing the plaintext. is the second state of the stream cipher algorithm, It is the third state of the stream cipher algorithm.

[0122] If the stream cipher algorithm used is the LOL2.0-MINI algorithm, then The input-output relationship can be expressed as , , the update function related parameters are defined as , that is, MacState can be expressed as , the data block is , update function It can be expressed as: .

[0123] If the stream cipher algorithm used is the LOL2.0-DOUBLE algorithm, then The input-output relationship can be expressed as , , the update function related parameters are defined as , that is: MacState can be expressed as , the data block is , update function It can be expressed as: .

[0124] In step S600, the third state of the stream cipher algorithm is initialized to obtain the fourth state of the stream cipher algorithm.

[0125] Specifically, the above steps include:

[0126] , is the third state of the stream cipher algorithm, It is the fourth state of the stream cipher algorithm.

[0127] Finally, in step S700, a key stream is generated using the fourth state of the stream cipher algorithm, and the key stream is intercepted according to a preset length to obtain an authentication tag corresponding to the ciphertext.

[0128] Specifically, the above steps include:

[0129] The key stream generation phase is performed using the fourth state of the stream cipher algorithm. , where T is the key stream, It is the fifth state of the stream cipher algorithm after the key stream is generated, and ScEnc is the key stream generation process.

[0130] According to the predefined label length, a key stream of preset length is intercepted from the key stream T as the label corresponding to the ciphertext. .

[0131] The output of the authenticated encryption method based on a stream cipher provided by the present invention is a ciphertext and a corresponding label.

[0132] The embodiment of the present invention can provide 256-bit security to prevent key recovery attacks; it can provide 128-bit security to prevent forgery attacks. Both LOL2.0-MINI&SCMAC and LOL2.0-DOUBLE&SCMAC algorithms provide 256-bit security, and can resist mainstream attack methods such as linear source periodic analysis, selected IV attack under related keys, cubic attack, sliding attack, correlation analysis, guess determination analysis, time-storage compromise attack, algebraic attack, etc. to prevent key recovery attacks; at the same time, it provides 128-bit security to prevent forgery attacks.

[0133] Based on the embodiment of the present invention, the software performance of LOL2.0-MINI & SCMAC and LOL2.0-DOUBLE & SCMAC algorithms was implemented using C++ (Visual Studio 2022) on a laptop equipped with an Inteli7-11800H CPU (@2.30GHz, Turbo Boost up to @4.6GHz). All experiments were performed in a single process / threaded manner. Software performance is measured in Gbps in the form of a sequence cipher. Stream ciphers are more sensitive to data length than block ciphers because the speed increases with the increase in data processing length. Therefore, the software performance evaluation was performed using message lengths ranging from 32 bytes to 16384 bytes. The same experiments were performed on SNOW-V and Rocca using the original C++ code on the same platform for a fair comparison. LOL2.0-MINI and LOL2.0-DOUBLE were also used in combination with standard GCM. The results are shown in the following table (Performance (Gbps) of SNOW-V, Rocca, LOL2.0-MINI and LOL2.0-DOUBLE software in AEAD mode). It can be seen that LOL2.0-MINI and LOL2.0-DOUBLE have higher efficiency with SCMAC mode than with GCM mode.

[0134]

[0135] In addition, an embodiment of the present invention also provides a device, which includes: a processor and a memory; the memory is used to store one or more program instructions; the processor is used to run one or more program instructions to execute the steps of a sequence password-based authentication encryption method as described above.

[0136] In addition, an embodiment of the present invention further provides a computer program product, which includes computer program instructions. When the computer program instructions are executed by a processor, the steps of the authentication encryption method based on a sequence cipher as described above are implemented.

[0137] The embodiment of the present invention provides a universal MAC design framework that matches the large memory sequence cipher. The authentication part shares part of the internal state with the initialized sequence cipher, and absorbs the associated data or message using the MAC state update function (usually similar to the nonlinear component of the sequence cipher); then the internal state of the MAC algorithm is reloaded into the extracted state position of the sequence cipher, and after the same sequence cipher initialization phase, the truncated output key stream block is used as a label. It not only avoids the unpredictable hidden security issues brought about by the instant plaintext absorption and compression of the integrated AEAD algorithm, such as the general state recovery attack when the identity authentication security is lower than the encryption security (such situations are very common in actual industrial applications), but also overcomes the efficiency and resource consumption brought about by the algorithm that calculates two completely different core operations, greatly improving the overall implementation rate of the algorithm, while providing encryption and authentication functions.

[0138] The LOL2.0-MINI&SCMAC and LOL2.0-DOUBLE&SCMAC provided by the embodiments of the present invention both support tags up to 128 bits, provide 256 bits of security to prevent key recovery attacks and 128 bits of security to prevent forgery attacks without considering IV reuse. It limits the key stream length to a maximum of 128 bits in a single key IV pair. , and each key can be associated with at most different IVs. For a fixed key, the number of different messages generated is at most , and the associated data length of a fixed key can reach .

[0139] In addition, LOL2.0-MINI&SCMAC and LOL2.0-DOUBLE&SCMAC are software-oriented AVX implementation solutions, and LOL2.0-DOUBLE&SCMAC can reach the 100Gbps rate requirement proposed by 6G.

[0140] In the embodiment of the present invention, the processor may be an integrated circuit chip having the ability to process signals. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, or discrete hardware components. The methods, steps, and logic block diagrams disclosed in the embodiments of the present invention may be implemented or executed. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present invention may be directly embodied as being executed by a hardware decoding processor, or may be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The processor reads the information in the storage medium and completes the steps of the above method in combination with its hardware. The storage medium may be a memory, for example, a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM) and direct RAM bus random access memory (DRRAM).The storage medium described in the embodiment of the present invention is intended to include but is not limited to these and any other suitable types of memory. Those skilled in the art should be aware that in one or more of the above examples, the functions described in the present invention can be implemented by a combination of hardware and software. When the software is applied, the corresponding function can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein the communication medium includes any medium that is convenient for transmitting a computer program from one place to another. The storage medium can be any available medium that a general or special-purpose computer can access. Although the present invention has been described in detail above with general descriptions and specific embodiments, it is obvious to those skilled in the art that some modifications or improvements can be made to it on the basis of the present invention. Therefore, these modifications or improvements made on the basis of not departing from the spirit of the present invention all belong to the scope of protection claimed in the present invention.

[0141] The above description is only a preferred embodiment of the present invention and does not limit the present invention in any form. Those skilled in the art may make some simple modifications, equivalent changes or modifications using the technical contents disclosed above, which all fall within the protection scope of the present invention.

Claims

1. An authenticated encryption method based on a sequence cipher, characterized in that: The method comprises: Loading the key and the initialization vector into the stream cipher algorithm, and initializing the stream cipher algorithm to obtain the first state of the stream cipher algorithm; Using the first state of the sequence cipher algorithm, a state declaration is made on the MAC authentication algorithm to obtain the first state of the MAC authentication algorithm; Generate a key stream using the first state of the stream cipher algorithm, encrypt the plaintext to be encrypted, and obtain the ciphertext and the second state of the stream cipher algorithm that completes the encryption; Utilizing the first state of the MAC authentication algorithm to sequentially absorb the plaintext associated data and the plaintext to be encrypted, to obtain a second state of the MAC authentication algorithm in which the absorption is completed; Feedback the second state of the MAC authentication algorithm to the second state of the stream cipher algorithm, update part of the internal state of the second state of the stream cipher algorithm, and obtain an updated third state of the stream cipher algorithm; Initializing the third state of the stream cipher algorithm to obtain a fourth state of the stream cipher algorithm; The fourth state of the stream cipher algorithm is used to generate a key stream, and the key stream is intercepted according to a preset length to obtain an authentication tag corresponding to the ciphertext.

2. The authentication encryption method based on a stream cipher according to claim 1, characterized in that: The sequence cipher algorithm is a large memory sequence cipher algorithm LOL2.0-MINI, which supports a 256-bit key K and a 128-bit initialization vector IV. The sequence cipher algorithm includes two 128-bit LFSR registers (H, L), one NFSR register N and three FSM registers. ; The internal state of the stream cipher algorithm is ; The MAC authentication algorithm includes four 128-bit registers. The internal state of the MAC authentication algorithm is .

3. The authentication encryption method based on a stream cipher according to claim 1, characterized in that: The sequence cipher algorithm is a large memory sequence cipher algorithm LOL2.0-DOUBLE, which supports a 256-bit key K and a 256-bit initialization vector IV. The sequence cipher algorithm includes a 512-bit linear feedback shift register, two nonlinear feedback shift registers and and two finite state machines FSM, wherein the 512-bit linear feedback shift register includes four 128-bit registers, namely and ; The two finite state machines FSM include four 128-bit registers, respectively and ; The internal state of the stream cipher algorithm is ; The MAC authentication algorithm includes six 128-bit registers. The internal state of the MAC authentication algorithm is .

4. The authentication encryption method based on a sequence cipher according to claim 2 or 3, characterized in that: The key and the initialization vector are loaded into the stream cipher algorithm, and the stream cipher algorithm is initialized to obtain the first state of the stream cipher algorithm, including: Loading the key K and the initialization vector IV into the stream cipher algorithm includes: ,in, It is the internal state after the stream cipher algorithm is loaded; Perform standard initialization processing on the loaded stream cipher algorithm to obtain the first state of the stream cipher algorithm, including: ,in, It is the first state of the stream cipher algorithm, and ScInit is the initialization process.

5. The authentication encryption method based on a sequence cipher according to claim 2 or 3, characterized in that: Using the first state of the sequence cipher algorithm, a state declaration is made on the MAC authentication algorithm to obtain the first state of the MAC authentication algorithm, including: copying a portion of the first state of the stream cipher algorithm into the internal state of the MAC authentication algorithm, ,in, It is the first state of the MAC authentication algorithm. The first state of the stream cipher algorithm; If the sequence cipher algorithm is the LOL2.0-MINI algorithm, then , ; If the stream cipher algorithm is the LOL2.0-DOUBLE algorithm, then , .

6. The authentication encryption method based on a sequence cipher according to claim 2 or 3, characterized in that: The key stream is generated by using the first state of the stream cipher algorithm, and the plaintext to be encrypted is encrypted to obtain the ciphertext and the second state of the stream cipher algorithm that completes the encryption, including: , ,in, is the first state of the stream cipher algorithm, The second state of the stream cipher algorithm, Z is the key stream, M is the plaintext to be encrypted, C is the encrypted ciphertext, and ScEnc is the stream cipher algorithm update function Iterative calls, is the sum of the register bits of the serial cipher algorithm, is the number of bits of the key stream data block.

7. The authentication encryption method based on a sequence cipher according to claim 2 or 3, characterized in that: Utilizing the first state of the MAC authentication algorithm to sequentially absorb the plaintext associated data and the plaintext to be encrypted, to obtain a second state of the MAC authentication algorithm in which the absorption is completed; Feeding back the second state of the MAC authentication algorithm to the second state of the stream cipher algorithm, updating part of the internal state of the second state of the stream cipher algorithm, and obtaining an updated third state of the stream cipher algorithm, including: Utilize the first state of the MAC authentication algorithm to absorb plain text associated data, ,in, is the first state of the MAC authentication algorithm, AD is the associated data corresponding to the plaintext to be encrypted, Absorb is the first state of the MAC authentication algorithm after absorbing the associated data. Absorb is the MAC authentication algorithm update function. Iterative calls, is the sum of the register bits of the MAC authentication algorithm, The number of bits of the data block to be absorbed; The first state of the MAC authentication algorithm after absorbing the associated data absorbs the plaintext to be encrypted. , where M is the plaintext to be encrypted, The second state of the MAC authentication algorithm after absorbing the plain text; ,in, The second state of the MAC authentication algorithm after absorbing the plaintext. is the second state of the stream cipher algorithm, It is the third state of the stream cipher algorithm; If the sequence cipher algorithm is the LOL2.0-MINI algorithm, then , ; If the stream cipher algorithm is the LOL2.0-DOUBLE algorithm, then , .

8. The authentication encryption method based on a sequence cipher according to claim 7, characterized in that: Initializing the third state of the stream cipher algorithm to obtain a fourth state of the stream cipher algorithm; Generate a key stream using the fourth state of the stream cipher algorithm, intercept the key stream according to a preset length, and obtain an authentication tag corresponding to the ciphertext, including: ,in, is the third state of the stream cipher algorithm, The fourth state of the stream cipher algorithm; ,in, is the fifth state of the stream cipher algorithm, and T is the label of the corresponding length.

9. An authentication encryption device based on a sequence cipher, characterized in that: The device comprises: a processor and a memory; The memory is used to store one or more program instructions; The processor is used to run one or more program instructions to execute the steps of the authentication encryption method based on a stream cipher as described in any one of claims 1 to 8.

10. A computer program product, characterized in that The computer program product comprises computer program instructions, which, when executed by a processor, implement the steps of the authentication encryption method based on stream cipher as claimed in any one of claims 1 to 8.