Encryption and decryption circuit system and method based on RISC-V architecture
By designing an encryption and decryption circuit system on the RISC-V architecture, using hardware to realize encryption algorithms and perform logical resource sharing, the problems of high energy consumption and low resource utilization in the encryption and decryption process in the prior art are solved, and the effects of efficient encryption and decryption and low power consumption are achieved.
Patent Information
- Application Number
- CN202510081337.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-20
AI Technical Summary
The prior art is difficult to achieve efficient acceleration, reduce energy consumption and improve resource utilization during the encryption and decryption process, especially in embedded systems and Internet of Things devices.
The encryption and decryption circuit system based on the RISC-V architecture is adopted. The system includes a privileged register configuration module, an encryption and decryption global control module, an encryption and decryption calculation control module, etc. The encryption algorithm is implemented through hardware, and the algorithm configuration is simplified by RISC-V privileged instructions, and logical resource sharing is realized to reduce power consumption.
It realizes efficient acceleration of the encryption and decryption process, reduces energy consumption and improves resource utilization, and is suitable for embedded systems and IoT devices.
Smart Images

Figure CN119989430A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and specifically relates to an encryption and decryption circuit system and method based on RISC-V architecture. Background Art
[0002] With the rapid development of IoT technology, the demand for data storage, processing and transmission between devices is increasing. The advancement of information technology has brought more frequent digital information interactions, but also caused more serious security risks. Ensuring the security of digital information has become a topic that cannot be ignored, and data encryption is a key means to ensure information security. Although software encryption plays an important role in data protection, hardware-level security solutions are equally important and can provide more reliable and secure communication guarantees for IoT devices.
[0003] In this context, RISC-V, as an open source instruction set architecture, has gained wide attention and application worldwide with its simple design, flexible scalability and the advantages of no patent authorization. The open source nature of RISC-V enables developers to freely customize the architecture according to specific needs, reduce the threshold and cost of chip design, and provide high scalability for different application scenarios. In addition, RISC-V also provides great convenience for the expansion of cryptographic algorithms and other complex functions by defining CSR instructions and CSR registers (control status registers). This design makes it possible to expand cryptographic algorithm-specific registers and instructions on the RISC-V architecture, thereby realizing hardware-level acceleration of cryptographic algorithms and meeting the dual needs of high efficiency and low power consumption.
[0004] In modern digital system design, resource sharing and resource reuse strategies have far-reaching significance. Sharing hardware resources by multiple modules or functions can not only greatly reduce the hardware complexity and production cost of the system, but also significantly improve resource utilization, so that the same hardware resources can serve different functions at different time periods, improving the overall efficiency of the system. This method can also effectively reduce power consumption, avoid resource waste, simplify system scheduling and management, and enhance design flexibility to cope with dynamic needs in complex computing scenarios.
[0005] For data encryption, the AES algorithm is usually the best choice. However, as the core element of the encryption process, the security of the key is also crucial. The ECC algorithm can ensure the security of the key during the communication process, especially in the key exchange stage, it can effectively prevent malicious attackers from tampering with the data. On this basis, the SHA algorithm further guarantees data integrity and security. Especially in blockchain technology, SHA is widely used to ensure the immutability and transparency of transaction data. Its anti-collision and efficient computing make blockchain a core technology in many industries such as finance, supply chain, and smart contracts, and promote innovation and development in these fields.
[0006] By combining the Internet of Things, RISC-V, cryptographic algorithms, and shared resources and reuse strategies, not only can the overall performance and security of the system be improved, but it also lays a solid foundation for future technological innovation and applications. Summary of the invention
[0007] In order to solve the shortcomings of the prior art, achieve the purpose of accelerating the encryption process while reducing energy consumption in the encryption and decryption process, improving resource utilization, and enhancing the real-time and versatility of encryption and decryption operations in embedded systems, the present invention adopts the following technical solutions:
[0008] A RISC-V architecture-based encryption and decryption circuit system, comprising a privileged register configuration module, a temporary variable storage module, an encryption and decryption global control module, an encryption and decryption calculation control module, a digest algorithm control module, a symmetric algorithm calculation module, an asymmetric algorithm control module, and a computing resource data path module, characterized in that: the privileged register configuration module is connected to the encryption and decryption calculation control module via the encryption and decryption global control module, and is simultaneously connected to the computing resource data path module for encryption and decryption data interaction and status return, and the encryption and decryption calculation control module is connected to the global calculation path module after passing through the digest algorithm control module, the symmetric algorithm control module, and the asymmetric algorithm control module, respectively, to start reasoning calculations of different algorithms and working modes;
[0009] The privileged register configuration module is used to obtain privileged CSR instructions, configure encryption and decryption working modes, and input and output encryption and decryption data;
[0010] A temporary variable storage module is used to temporarily store the calculation results of round operations during the calculation process;
[0011] The encryption and decryption global control module is used to shield the software write operation during the encryption and decryption operation to ensure the normal operation of the encryption and decryption circuit;
[0012] The encryption and decryption calculation control module is used to start the inference calculation of different algorithms and different working modes according to the register status information;
[0013] A digest algorithm control module is used to control the digest hash algorithm calculation process and record work information, and call the computing resources required by the digest hash algorithm;
[0014] Symmetric algorithm control module, used to control the symmetric algorithm calculation process and record work information, and call the computing resources required by the symmetric algorithm;
[0015] Asymmetric algorithm control module, used to control the asymmetric computing process and record working information, and call the computing resources required by the asymmetric algorithm;
[0016] The global computing pathway module is used to deploy a large number of general computing resources and multiplexers to complete complex computing resource combinations based on state information.
[0017] Furthermore, the privileged register configuration module includes a parsing module, a general register read and write interface, and an extended register group. The privileged instruction obtained is a CSR (Control and Status Registers) instruction, which is used to read the data of the general register and write it into the CSR register of the interface in the form of original format / set / clear. The data in the CSR register is written into the general register of the write-back register index. Through the read and write operations on the general register, the read and write interface of the general register is extended, and read and write signals, read register index, and write register index are provided to integrate this encryption and decryption circuit into any processor; after the CSR instruction is translated by the parsing module, a read signal and a write signal and the index of the privileged register that needs to be operated in this cycle are generated to configure and read the extended register group.
[0018] Furthermore, the extended register includes a control register, a status register, an input register, an output register, a key register, an elliptic curve A parameter register, an elliptic curve B parameter register, a modulus register, a generation point register, and a random number register. The control register is used to configure the working mode of the encryption and decryption circuit, the status register is used to reflect the operating status of the encryption and decryption circuit, the input register is used to input the data to be encrypted or decrypted into the encryption and decryption circuit, the output register is used to read the encrypted data or decrypted data after completing the encryption or decryption work, the key register is used to obtain the key required for use in the encryption process, the elliptic curve A parameter register is used to implement the configuration of parameter A in the elliptic curve, the elliptic curve B parameter register is used to implement the configuration of parameter B in the elliptic curve, the modulus register is used to determine the modulus used when performing elliptic curve operations, the generation point register is used to determine the generation point of the elliptic curve, and the random number register is used to encrypt using random numbers during the encryption process.
[0019] Furthermore, the encryption and decryption circuit supports encryption and decryption of SHA256, AES128, and ECC256 by decomposing the special calculations in the calculation process of the three algorithms, integrating general computing resources for time division multiplexing, and combining the MUX unit attached to each logic resource. The state machine controls the connection of multiple computing resources to form special operations in the encryption or decryption process, so that resources can be shared in multiple security algorithms and multiple working modes, and the data flow and data path are controlled only by control signals, thereby greatly reducing the integration of logic resources.
[0020] Furthermore, the encryption and decryption circuit system based on the RISC-V architecture is characterized in that the encryption and decryption circuit can implement the encryption mode of the SHA256 algorithm, the encryption mode and decryption mode of the AES128 algorithm, and the encryption mode and decryption mode of the ECC256 algorithm.
[0021] Furthermore, the single-round encryption module of the SHA256 algorithm includes: Ch function, ∑0 function, Maj function, ∑1 function, σ0 function, σ1 function, 32-bit addition operation, circular right shift operation, and logical right shift operation, and the single-round operation is executed in only one clock cycle.
[0022] The Ch function consists of 32-bit negation, AND operation, and XOR operation of three variables. The encryption and decryption circuit calls the 32-bit negation operation unit, 32-bit AND operation unit, and 32-bit XOR operation unit logic unit. The input of the 32-bit XOR operation resource is controlled by the state machine as the output of two 32-bit AND operation units. The input of one 32-bit AND operation unit is the first and second independent variables of the Ch function, and the input of the other 32-bit AND operation unit is the result of the negation of the first independent variable and the third independent variable. Its logic function is:
[0023]
[0024] The Maj function designs 32-bit AND and XOR operations of three variables. This function is implemented by calling 32-bit AND operation units and 32-bit XOR operation units. The state machine controls the input of the first 32-bit AND operation unit to be the first independent variable and the second independent variable, the input of the second 32-bit AND operation unit to be the first independent variable and the third independent variable, and the input of the third 32-bit AND operation unit to be the second independent variable and the third independent variable. Its logic function is:
[0025]
[0026] The ∑0 function involves three different times of circular right shift operations on a variable and the sequential XOR of the results. This function is implemented by calling three circular right shift operation units and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as circular right shift 1 bit, circular right shift 13 bits, and circular right shift 22 bits according to the state machine configuration. Its logic function is:
[0027]
[0028] The ∑1 function involves three different times of circular right shift operations on one variable and the sequential XOR of the results. This function is implemented by calling three circular right shift operation units and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as 6-bit circular right shift, 11-bit circular right shift, and 25-bit circular right shift according to the state machine configuration. Its logic function is:
[0029]
[0030] The σ0 function involves two different times of circular right shift operations and one logical right shift operation of one variable and the XOR of the results. This function is implemented by calling two circular right shift units, one logical right shift and two 32-bit XOR units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as 7-bit circular right shift, 18-bit circular right shift and 3-bit logical right shift according to the state machine. Its logic function is:
[0031]
[0032] The σ1 function involves two different times of circular right shift operations and one logical right shift operation of one variable and the sequential XOR of the results. This function is implemented by calling two circular right shift operation units, one logical right shift and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as circular right shift 17 bits, circular right shift 19 bits and logical right shift 10 bits according to the state machine configuration. Its logic function is:
[0033]
[0034] The encryption process divides 256-bit data into 32-bit blocks, and the operation process undergoes multiple encryption operations, and the encryption process is realized by calling multiple adders; the circular right shift operation is that the result after a single round of encryption is circularly right shifted and then stored in a temporary variable register stack, and the encryption and decryption calculation control module of the encryption and decryption circuit directly and intermittently registers the data returned by the data path module, so as to replace the circular right shift operation;
[0035] The message expansion process will perform message expansion according to the round information recorded in the summary algorithm module. The initial message is stored in the register stack of the privileged register. After calculating the extended message, the extended message is stored in the temporary variable register. The calculation process is to add two original messages, the result of one message after the σ0 function operation, and the result of one message after the σ1 function operation in sequence. It is necessary to call three 32-bit addition units. The message expansion function is:
[0036] W j =σ1(W j-2 )+W j-7 +σ0(W j-15 )+W j-16 ,forj=16→63
[0037] Furthermore, the single-round encryption module of the AES128 algorithm includes a byte substitution module, a row shift module, a column confusion module and a round key addition module, the last round of the AES128 single-round encryption module includes a byte substitution module, a row shift module and a round key addition module, and the encryption and decryption calculation control module calculates the encryption rounds and generates different data paths in the last round so as not to perform column mixing;
[0038] The single-round decryption module of the AES128 algorithm includes: an inverse byte substitution module, a reverse displacement module, an inverse column confusion module and a round key addition module, and the last round of the single-round decryption module includes an inverse byte substitution module, a reverse displacement module and a round key addition module. The encryption and decryption calculation control module calculates the encryption rounds and generates different data paths in the last round so as not to perform reverse column mixing;
[0039] The key expansion module of the AES128 algorithm first inputs the initial key into a 4×4 state matrix. The 4 bytes of each column of the 4×4 matrix form a word. The 4 words of the 4 columns of the matrix are named W[0], W[1], W[2] and W[3] in sequence, which form an array W in word units. The key expansion module expands the W array by 40 new columns to form an extended key array. If i is not a multiple of 4, the i-th column is determined by the following equation:
[0040]
[0041] If i is a multiple of 4, then the i-th column is determined by the following equation:
[0042]
[0043] The T function transformation is a process of word loop, byte substitution, and round constant XOR, wherein the word loop is a byte left shift, the byte substitution is the same as the byte substitution in the round operation process, and the round constant is a process of XORing according to different round numbers and different constants;
[0044] The byte substitution and reverse byte substitution modules use GF(2 8 ) is a subfield algorithm on GF(2 8 ) is based on the inversion operation of irreducible polynomials and the linear operation of matrices. In the encryption and decryption circuit, GF(2 8 ) is transformed into the inverse algorithm on the extended field of GF(2 4 ) in the extended domain, in GF(2 4 ) is directly implemented by logical functions in the extended domain, and the conversion process involves the operation process of single-bit AND operation and single-bit XOR operation. The essence of the calculation process of these transformations in the extended domain is the AND or XOR operation between specific bits. Each bit of the 32-bit XOR calculation unit deployed in the data calculation path is an independent calculation process, which converts the complex operation in the byte substitution into a universal operation for each bit, thereby realizing the complex operation; the difference between the inverse byte substitution process and the byte substitution is that the specific bits of the linear transformation are different. The data calculation path receives the control signal of the symmetric encryption control module, constructs different data paths, thereby realizing different linear transformations, and then realizing the inverse byte substitution;
[0045] The row shift and reverse row shift module, considering that the data input to the data path module is executed in columns, while the row shift and reverse row shift are executed in rows, will first perform column conversion before row shifting, and then reuse the circular shift logic resources of the data calculation path to realize row shifting, and then go through the reverse row-column conversion process after row shifting to obtain the result of row shifting;
[0046] The column mixing module, the essence of which is to perform multiple XOR operations on bytes, considering that a 32-bit XOR device resource is four 8-bit XOR devices, and there are repeated processes of column mixing and reverse column mixing, the XOR resources integrated in the calculation path module realize column mixing through data flow control, and save logic resources by multiplexing the results of forward column mixing;
[0047] The round key adding module has an operation principle of XOR operation, and the encryption and decryption circuit directly reuses XOR resources to implement round key addition;
[0048] In the key expansion module, all XOR operations are realized by reusing the 32-bit XOR calculation unit in the calculation path, the row shift process in the T function reuses the circular shift module of the calculation path, the byte substitution module reuses the byte substitution module of the round calculation process, the essence of the round constant is the algorithm of multiplying X in each round on the expansion domain, the encryption and decryption circuit directly realizes the transformation process of each bit after each round of multiplication by X, and what is shown is the XOR operation process of different bits, and the XOR calculation unit of the calculation path is directly reused;
[0049] Furthermore, the encryption process of the ECC256 algorithm uses a random number as a coefficient, performs a point multiplication operation on the point represented by the public key on the elliptic curve, and performs a point addition operation on the obtained point and the point represented by the plain text to obtain ciphertext 1, and here, this random number is used to perform a point multiplication operation on the generator point to obtain ciphertext 2;
[0050] The decryption process of the ECC256 algorithm uses the private key to perform a point multiplication operation on the key 2, and then uses the ciphertext 1 to perform a point addition operation on the result 1 to obtain the plaintext;
[0051] The modules of the ECC256 algorithm include: elliptic curve point addition operation module, elliptic curve point doubling operation, elliptic curve point multiplication operation, and 256-bit modular addition, modular subtraction, modular multiplication, and modular inverse operation;
[0052] The modular addition operation module is a 256-bit addition operation, and performs a modular operation on a prime number P. The encryption and decryption circuit implements the function of 256 addition by adding carry output, carry input and addition and subtraction mode selection to the 32-bit adder, and multiplexing the 32-bit adder through the state machine. The modular operation is a cyclic subtraction operation of the result after addition and the modulus, which is performed from the high 32 bits to the low 32 bits. When a carry output is found, it is determined whether the number is greater than the modulus. If it is greater than the modulus, a subtraction operation is initiated and the cycle is repeated. If there is no carry output, it means that the number is less than the modulus, and then the modular operation is completed.
[0053] The modular subtraction operation module needs to first determine the size relationship between the two numbers to be subtracted, and first perform the subtraction operation in sequence. If it is found that the subtraction process is output by a carry, it means that the minuend is smaller than the subtrahend, then the order of the two numbers is exchanged and the subtraction operation is performed again, and then the modular operation is performed; if there is no carry output during the subtraction operation, the modular operation is directly performed;
[0054] The modular multiplication operation module adopts the Montgomery modular reduction algorithm to calculate the modular multiplication operation. First, the actual calculation process of the 256-bit multiplier is analyzed based on the 32-bit multiplier, and the operation process of each 32 bits of the actual result is calculated, so as to realize the 256-bit multiplication operation. In the process of modular multiplication operation, it is necessary to first realize the 32-bit modular reduction algorithm, and then each 32-bit word of the 256-bit is sequentially spliced to obtain the 256-bit modular multiplication result.
[0055] The modular inverse calculation module uses an extended Euclidean algorithm to calculate the modular inverse, which makes better use of hardware implementation from the perspective of hardware implementation;
[0056] The essence of the point addition operation module is to obtain the horizontal coordinate and the vertical coordinate of the coordinate point of the intersection of the two-point line and the elliptic curve symmetrical about the x-axis, realize the modular addition, modular subtraction, modular multiplication and modular inverse operation of the selectively called data path module, and realize the algorithm of point addition in combination with ECC, wherein (x1, y1), (x2, y2) represent the two base points P1 and P2 of the point addition operation, and (x3, y3) represent the result coordinates;
[0057] x3=λ 2 -x1-x2
[0058] y3=λ(x1-x3)-y1
[0059]
[0060] The essence of the doubling point operation module is to obtain the horizontal coordinate and the vertical coordinate of the coordinate point of the intersection of a tangent line and an elliptic curve symmetrical about the x-axis, realize the modular addition, modular subtraction, modular multiplication and modular inverse operations of the selectively called data path module, and realize the doubling point algorithm in combination with ECC, wherein (x1, y1) represents the base points P1 and P2 of the doubling point operation, and (x3, y3) represents the result coordinates;
[0061] x3=λ 2 -2x1
[0062] y3=λ(x1-x3)-y1
[0063]
[0064] The essence of the point multiplication operation module is that after obtaining the doubled point, the coordinates of the intersection of the starting point and the doubled point with the elliptic curve about x are connected as a new point, and the coordinates of the starting point and the new point and the intersection with the elliptic curve about the x-axis are connected as a new point, and so on to achieve point multiplication, and use a binary coding algorithm to reduce the complexity of the operation, convert the coefficients of the point multiplication into binary form, and start from the highest bit to determine whether each bit is "1". If it is "1", a point addition operation is performed, and a doubling operation is performed after each judgment, and then it is used as the base point for the next point addition.
[0065] Furthermore, the encryption and decryption circuit system based on the RISC-V architecture performs encryption and decryption, including the following steps:
[0066] Step 1: configure the privileged register, continuously send privileged instructions to the encryption and decryption circuit to implement the configuration of the state, the privileged instructions are executed in a pipeline during the execution process, and the configuration work includes inputting a key, inputting a plain text or a cipher text, configuring an encryption or decryption mode, configuring the encryption or decryption algorithm used, configuring a generator register, configuring a random number register, and finally enabling the encryption and decryption circuit to start calculation;
[0067] Step 2: After the encryption or decryption is completed, the encryption and decryption circuit will perform encryption and decryption operations, and obtain calculation completion information by checking the interrupt signal or the flag bit on the status register according to different algorithms and working modes;
[0068] Step 3: After detecting that the interrupt signal is set or the calculation completion flag in the status register is set, read the data in the output register; when the data reading operation is completed, the calculation enable signal is automatically cleared.
[0069] The advantages and beneficial effects of the present invention are:
[0070] The hardware implementation of the encryption algorithm adopted by the present invention has significant advantages over software implementation. First, in terms of performance, the hardware accelerator can execute multiple computing tasks in parallel, greatly improving the speed of encryption and decryption, especially when processing big data. Secondly, the hardware implementation reduces the intermediate steps of the calculation and the delay of data transmission through dedicated circuits, significantly reducing the energy consumption of the system. Therefore, it is more efficient than the existing encryption and decryption calculations based on software implementation.
[0071] The present invention adopts RISC-V privileged instructions to simplify the configuration process of the algorithm, reduce the operations that need to be executed multiple times through general instructions, and reduce the number of memory accesses, thereby significantly reducing energy consumption, so that the system can maintain low power consumption characteristics while efficiently processing data, and is particularly suitable for embedded systems and Internet of Things devices; the logic resource sharing technology adopted by the present invention avoids the dedicated design of hardware for a specific task; therefore, compared with the existing hardware deployment based on a single encryption and decryption algorithm, the present invention has lower power consumption and higher resource utilization. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 4 is a diagram of the system hardware architecture of an embodiment of the present invention.
[0073] Figure 2 The figure is a flow chart of a method according to an embodiment of the present invention.
[0074] Figure 3 Schematic diagram of register function coding and indexing in an embodiment of the present invention.
[0075] Figure 4 Schematic diagram of the state machine jump of the summary algorithm in an embodiment of the present invention.
[0076] Figure 5 Schematic diagram of summary algorithm control and data interaction in an embodiment of the present invention.
[0077] Figure 6 Schematic diagram of the state machine jump of the symmetric encryption algorithm in an embodiment of the present invention.
[0078] Figure 7 Schematic diagram of symmetric algorithm control and data interaction in an embodiment of the present invention.
[0079] Figure 8 Schematic diagram of the state machine jump of the asymmetric encryption algorithm in an embodiment of the present invention.
[0080] Fig. 9 Schematic diagram of asymmetric algorithm control and data interaction in an embodiment of the present invention. DETAILED DESCRIPTION
[0081] The specific implementation of the present invention is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described here is only used to illustrate and explain the present invention, and is not used to limit the present invention.
[0082] like Figure 1 As shown, an encryption and decryption circuit system based on RISC-V architecture includes a privileged register configuration module, a temporary variable storage module, an encryption and decryption global control module, an encryption and decryption calculation control module, a digest algorithm control module, a symmetric encryption algorithm calculation module, an asymmetric algorithm control module, and a global calculation path module;
[0083] The privileged register configuration module is used by the user to input privileged CSR instructions, configure encryption and decryption working modes, and input and output encryption and decryption data;
[0084] A temporary variable storage module is used to temporarily store the calculation results of round operations during the calculation process;
[0085] The encryption and decryption global control module is used to shield the software write operation during the encryption and decryption operation process to ensure the normal operation of the encryption and decryption circuit.
[0086] The encryption and decryption calculation control module is used to start the inference calculation of different algorithms and different working modes according to the register status information;
[0087] The digest algorithm control module is used to control the hash algorithm calculation process and record work information, and call the computing resources required by the hash algorithm;
[0088] Symmetric algorithm control module, used to control the symmetric algorithm calculation process and record work information, and call the computing resources required by the symmetric algorithm;
[0089] Asymmetric algorithm control module, used to control the asymmetric computing process and record working information, and call the computing resources required by the asymmetric algorithm;
[0090] The global computing pathway module is used to deploy a large number of general computing resources and multiplexers to complete complex computing resource combinations based on state information.
[0091] like Figure 2 As shown, the software transmits the encryption and decryption circuit working mode configuration information, including encryption and decryption algorithm configuration, encryption and decryption working mode configuration, encryption and decryption circuit interrupt enable configuration, and error interrupt enable configuration, by sending CSR instructions to the privileged register module of this encryption and decryption circuit; transmits encryption and decryption data information, including encryption and decryption data, encryption and decryption keys, and elliptic curve A parameters, elliptic curve B parameters, modulus, generator point, and random number required in the asymmetric algorithm;
[0092] The configurations that need to be completed rely on the privileged CSR instruction characteristics of the RISC-V architecture. The specific behavior of the CSR instruction is to read the data in the general register, write the data in the general register to the CSR register in the original format / set / clear, and then write the data in the CSR register to the general register indexed by the write-back register;
[0093] For general register read and write operations, this module expands the general register read and write interface and provides read and write signals, read register index, and write register index so as to integrate this encryption and decryption circuit into any processor;
[0094] For the configuration of extended registers, this module sets up an internal extended register group. After translating the CSR instruction, this module will generate read and write signals and the index of the privileged register that needs to be operated in this cycle, so as to configure and read the extended register group.
[0095] After completing the configuration of the parameter information, the software needs to configure the software startup. After startup, the privileged register configuration module will instruct the encryption and decryption global control module to enter the start-up calculation state. When the encryption and decryption global control module enters the start-up calculation state, it will send a shielding signal to the privileged register configuration module, indicating that all write register behaviors in the privileged register configuration module are shielded. This is done to avoid the software rewriting data when the hardware is calculating, which may cause errors in the final encryption and decryption calculation results.
[0096] After the encryption and decryption global control module enters the start-up calculation state, the module will also instruct the encryption and decryption calculation control module to start a specific calculation mode, including digest algorithm encryption mode, symmetric algorithm encryption mode, symmetric algorithm decryption mode, asymmetric algorithm encryption mode, and asymmetric algorithm decryption mode; when entering the digest algorithm calculation mode, the encryption and decryption calculation control module will send an enable signal to the digest algorithm control module, and the digest algorithm control module will obtain the control right of the calculation data path, and then rebuild the calculation data path during the calculation process to complete the privileged calculation in the calculation process; when entering the symmetric algorithm calculation mode, the encryption and decryption calculation control module will send an enable signal to the symmetric algorithm control module, and the symmetric algorithm control module will obtain the control right of the calculation data path, and then rebuild the calculation data path during the calculation process to complete the special calculation in the calculation process; when entering the asymmetric algorithm calculation mode, the encryption and decryption calculation control module will send an enable signal to the asymmetric algorithm control module, and the asymmetric algorithm control module will start multiple internal state machines and complete the asymmetric algorithm calculation through some algorithm combinations. In this process, the asymmetric algorithm control module will also call the calculation resources in some calculation data paths;
[0097] After configuring the encryption and decryption circuit to start calculation, the software can obtain the calculated data in two ways. The first is to continuously read the calculation completion status bit in the status register. When the calculation completion status bit is found to be "1", the software can start to read the value in the output register. Depending on the configured algorithm, the value of the output register to be read is different. The other way is to obtain the interrupt response of the encryption and decryption circuit. When the software receives the interrupt response notification of the encryption and decryption circuit, the software can start to read the value in the output register to obtain the result data.
[0098] like Figure 3As shown, the extended register configuration module expands 10 privileged registers in machine mode, namely, control register, status register, input register, output register, key register, elliptic curve A parameter register, elliptic curve B parameter register, modulus register, generation point register, and random number register. Its function is that the control register is used to configure the working mode of this encryption and decryption circuit, the status register is used to reflect the running state of the encryption and decryption circuit, the input register is used to input the data to be encrypted or decrypted into this encryption and decryption circuit, the output register is used to read out the encrypted data or decrypted data after completing the encryption or decryption work, the key register is used to obtain the key required for use in the encryption process, the elliptic curve A parameter register is used to configure the parameter A in the elliptic curve, the elliptic curve B parameter register is used to configure the parameter B in the elliptic curve, the modulus register is used to determine the modulus used when performing elliptic curve operations, the generation point register is used to determine the generation point of the elliptic curve, and the random number register is used to encrypt using random numbers during the encryption process; at the same time, the index of the privileged register is customized, and the user uses the CSR instruction and combines the index of each register to locate the privileged register.
[0099] like Figure 4 As shown in the figure, when the user configures the working mode to the SHA256 encryption working state, the encryption and decryption calculation control module will control the digest algorithm control module to enter the calculation state. The state machine of the digest algorithm calculation control module starts in the IDLE state, and then jumps to SHA256_ENCRYPT to start the SHA256 algorithm encryption operation. The SHA256 algorithm requires 64 rounds of encryption operations.
[0100] After completing 64 rounds of SHA256 encryption calculation, the state of the digest algorithm control module will jump to SHA256_UPDATE, perform the superposition operation of the calculation result and the initial key, update the ciphertext output register group, and set the calculation completion flag. Then it will jump to the FINISH state and wait for the software to read the encrypted data. After the reading is completed, the software clears the enable end, the digest algorithm control module jumps back to the IDLE state, and the encryption and decryption global control module and the encryption and decryption calculation control module are restored to the default.
[0101] like Figure 5 As shown, the global calculation control module will control the summary algorithm state machine that starts the summary algorithm calculation control module. After the startup is completed, the summary algorithm calculation state machine will send a path construction signal and a round signal to the calculation data path. The calculation data path will construct different data paths according to the different signals.
[0102] During the encryption process, a key is required in each round. The key starts with the natural number '0' and increases by 32 digits after the decimal point of the binary representation of the cube root of each prime number, totaling 64 prime numbers. After the compression of the first block message is completed, it needs to be superimposed with an initial message. The initial message starts with the natural number '0' and increases by 32 digits after the decimal point of the binary representation of the square root of each prime number, totaling 8 prime numbers. Considering that the implementation of cube roots and square roots in hardware is not as good as directly storing data and selecting through rounds, the performance and area are better, so these data are directly stored in the calculation data path in circuit implementation.
[0103] At the beginning of the first round of encryption, the digest algorithm control module will control the encrypted data and messages of the calculation data path to come from the register group of the privileged register configuration module, while in the subsequent rounds, the encrypted data and messages come from the temporary variable storage module. After a round of encryption operation, the encrypted data will be temporarily stored in the temporary variable storage module.
[0104] For message extension, in the first round to the 16th round of calculation, no message extension is performed. The digest algorithm control module will control the message output signal of the calculation path to be directly the message input signal, and then store it in the temporary variable register. When the message is extended, the digest algorithm calculation control module sends a control signal to the calculation path so that the output key signal comes from the result of the message extension.
[0105] The same general computing resources are used for the SHA256 encryption operation process and the SHA256 message expansion process, and the encryption operation needs to be performed after the message expansion is completed. This encryption and decryption circuit reduces the deployment of logic resources through state machine multiplexing and increases the utilization of logic resources. Considering that the area priority in the embedded field is greater than the speed, this security is more reasonable. After each round of operation is completed, the results of the round operation are interleaved to reduce the use of logical right shift resources.
[0106] In the embodiment of the present invention, the single-round encryption module of the SHA256 algorithm includes: Ch function, ∑0 function, M aj Function, ∑1 function, σ0 function, σ1 function, 32-bit addition operation, circular right shift operation, logical right shift operation, all computing resources come from the computing data path; the single round of operation only executes one clock cycle.
[0107] The Ch function consists of 32-bit negation, AND operation, and XOR operation of three variables. The encryption and decryption circuit calls the 32-bit negation operation unit, 32-bit AND operation unit, and 32-bit XOR operation unit logic unit. The input of the 32-bit XOR operation resource is controlled by the state machine as the output of two 32-bit AND operation units. The input of one 32-bit AND operation unit is the first variable and the second independent variable of the Ch function, and the input of the other 32-bit AND operation unit is the result of the negation of the first independent variable and the third independent variable. Its logic function is:
[0108]
[0109] M aj The function designs 32-bit AND and XOR operations of three variables. This function is implemented by calling 32-bit AND operation units and 32-bit XOR operation units. The state machine controls the input of the first 32-bit AND operation unit to be the first independent variable and the second independent variable, the input of the second 32-bit AND operation unit to be the first independent variable and the third independent variable, and the input of the third 32-bit AND operation unit to be the second independent variable and the third independent variable. Its logic function is:
[0110]
[0111] The ∑0 function involves three different times of circular right shift operations on a variable and the sequential XOR of the results. This function is implemented by calling three circular right shift operation units and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as circular right shift 1 bit, circular right shift 13 bits, and circular right shift 22 bits according to the state machine configuration. Its logic function is:
[0112]
[0113] The ∑1 function involves three different times of circular right shift operations on one variable and the sequential XOR of the results. This function is implemented by calling three circular right shift operation units and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as 6-bit circular right shift, 11-bit circular right shift, and 25-bit circular right shift according to the state machine configuration. Its logic function is:
[0114]
[0115] The σ0 function involves two different times of circular right shift operations and one logical right shift operation of one variable and the XOR of the results. This function is implemented by calling two circular right shift units, one logical right shift and two 32-bit XOR units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as 7-bit circular right shift, 18-bit circular right shift and 3-bit logical right shift according to the state machine. Its logic function is:
[0116]
[0117] The σ1 function involves two different times of circular right shift operations and one logical right shift operation of one variable and the sequential XOR of the results. This function is implemented by calling two circular right shift operation units, one logical right shift and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as circular right shift 17 bits, circular right shift 19 bits and logical right shift 10 bits according to the state machine configuration. Its logic function is:
[0118]
[0119] The encryption process divides 256-bit data into 32-bit blocks, and the operation process undergoes multiple encryption operations, and the encryption process is realized by calling multiple adders; the circular right shift operation is that the result after a single round of encryption is circularly right shifted and then stored in a temporary variable register stack, and the encryption and decryption calculation control module of the encryption and decryption circuit directly and intermittently registers the data returned by the data path module, so as to replace the circular right shift operation;
[0120] The message expansion process will perform message expansion according to the round information recorded in the digest algorithm module. The calculation process is to add two original keys, the result of one key after the σ0 function operation, and the result of one key after the σ1 function operation in sequence. It is necessary to call three 32-bit addition units. The message expansion function is:
[0121] W j =σ1(W j-2 )+W j-7 +σ0(W j-15 )+W j-16 , for j=16→63
[0122] like Figure 6As shown, when the user configures the working mode to be the AES128 symmetric encryption working state, the encryption and decryption calculation control module will control the symmetric algorithm control module to enter the encryption calculation state, and the state machine of the symmetric algorithm calculation control module will start in the IDLE state, and then jump to AES_INITIAL after the calculation is turned on. In this state, the round key addition calculation and the first row shift operation will be performed on the plaintext, and the key expansion will be performed at the same time. In this state, the byte substitution module, the shift operation resources and the XOR operation resources are reused, and then it will jump to the AES_COL3, AES_COL2, AES_COL1, and AES_COL0 states at once. In this state, the encryption and decryption calculation control module will perform a round of AES128 algorithm operations on 128 bits in units of 32 bits, including byte substitution, column mixing, row shifting, and round key addition. At the same time, in the states of AES_COL3, AES_COL2, AES_COL1, and AES_COL0, the 32-bit key expansion work will be performed at the same time to improve the calculation efficiency.
[0123] The encryption and decryption control module will record the encryption rounds. In the last round of operation, the column mixing calculation is skipped by linking the output of byte substitution and the input of row shift. After completing 10 operations, the state of the encryption and decryption calculation control module will jump to the FINISH state to notify the global control module to start reading the ciphertext. After the global control module clears the global calculation enable, the encryption and decryption calculation module jumps back to the IDLE state.
[0124] When the user configures the working mode to AES128 decryption working state, the starting state is IDLE. At this time, the key input to the encryption and decryption circuit is the original key. Before the decryption operation, the key must be expanded 10 times. The states are KEY_COL0, KEY_COL1, KEY_COL2, and KEY_COL3 respectively. 10 rounds of key expansion operations are performed in 32-bit units in the 4 states.
[0125] After completing the key expansion, it will jump to AES_INITIAL to perform round key addition calculations and the first reverse shift operation on the key, and then jump to the AES_EXPAND state to perform key reverse expansion. In this state, the byte substitution module, shift operation resources and XOR operation resources are reused, and then it will jump to AES_COL0, AES_COL1, AES_COL2, and AES_COL3 states at once. In this state, the encryption and decryption calculation control module will perform a round of operations of the AES128 algorithm on 128 bits in units of 32 bits, including reverse byte substitution, reverse column mixing, reverse shift, and round key addition. At the same time, in the states of AES_COL0, AES_COL1, AES_COL21, and AES_COL3, the 32-bit key reverse expansion work is performed at the same time to improve the calculation efficiency.
[0126] The encryption and decryption control module will record the encryption rounds. In the last round of operation, the inverse column mixing calculation is skipped by linking the output of the inverse byte substitution and the input of the reverse shift. After completing 10 operations, the state of the encryption and decryption calculation control module will jump to the FINISH state to notify the global control module to start reading the plaintext. After the global control module clears the global calculation enable, the encryption and decryption calculation module jumps back to the IDLE state.
[0127] like Figure 7 As shown, the global calculation control module will control the AES algorithm state machine that starts the symmetric algorithm calculation control module. After the startup is completed, the AES algorithm calculation state machine will send a path construction signal and a round signal to the calculation data path. The calculation data path will build different data paths according to the difference of this signal. At the same time, the AES algorithm control state machine will send a column data selection signal to the temporary register group module to control the selection of word data and word key to participate in the round operation in the calculation data path;
[0128] At the beginning of the first round of encryption, the digest algorithm control module will control the data and key sources of the calculation data path to be the register group of the privileged register configuration module, and in the subsequent rounds, the data source is the single-column encryption and decryption data temporary register, and the key source is the single-column key temporary register. After a round of encryption operation, the intermediate data and intermediate extended key will be temporarily stored in the temporary register group;
[0129] In the embodiment of the present invention, the single-round encryption module of the AES128 algorithm includes a byte substitution module, a row shift module, a column confusion module and a round key addition module, and the last round of the AES128 single-round encryption module includes a byte substitution module, a row shift module and a round key addition module. The encryption and decryption calculation control module calculates the encryption rounds and generates different data paths in the last round so as not to perform column mixing.
[0130] The single-round decryption module of the AES128 algorithm includes: an inverse byte substitution module, a reverse displacement module, an inverse column confusion module and a round key addition module. The last round of the single-round decryption module includes an inverse byte substitution module, a reverse displacement module and a round key addition module. The encryption and decryption calculation control module calculates the encryption rounds and generates different data paths in the last round so as not to perform reverse column mixing.
[0131] The key expansion module of the AES128 algorithm first inputs the initial key into a 4×4 state matrix. The 4 bytes in each column of this 4×4 matrix form a word. The 4 words in the 4 columns of the matrix are named W[0], W[1], W[2] and W[3] respectively. They form an array W in word units. The key expansion module expands the W array by 40 new columns to form an extended key array. If i is not a multiple of 4, the i-th column is determined by the following equation:
[0132]
[0133] If i is a multiple of 4, then the i-th column is determined by the following equation:
[0134]
[0135] The T function transformation is a process of word loop, byte substitution, and round constant XOR, wherein the word loop is a byte left shift, the byte substitution is the same as the byte substitution in the round operation process, and the round constant is a process of XORing according to different round numbers and different constants;
[0136] Byte substitution and reverse byte substitution modules, using GF(2 8 ) is a subfield algorithm on GF(2 8 ) is based on the inversion operation of irreducible polynomials and the linear operation of matrices. In the encryption and decryption circuit, GF(2 8 ) is transformed into the inverse algorithm on the extended field of GF(2 4 ) in the extended domain, in GF(2 4 ) is directly implemented by logical functions in the extended domain, and the conversion process involves the operation process of single-bit AND operation and single-bit XOR operation. The essence of the calculation process of these transformations in the extended domain is the AND or XOR operation between specific bits. Each bit of the 32-bit XOR calculation unit deployed in the data calculation path is an independent calculation process, which converts the complex operation in the byte substitution into a universal operation for each bit, thereby realizing the complex operation; the difference between the inverse byte substitution process and the byte substitution is that the specific bits of the linear transformation are different. The data calculation path receives the control signal of the symmetric encryption control module, constructs different data paths, thereby realizing different linear transformations, and then realizing the inverse byte substitution;
[0137] The row shift and reverse row shift modules, considering that the data input to the data path module is executed by column, and the row shift and reverse row shift are executed by row, therefore, before the row shift is performed, the column conversion is performed first, and then the circular shift logic resources of the data calculation path are reused to realize the row shift, and after the row shift, the reverse row-column conversion process is performed to obtain the row shift result;
[0138] Column mixing module, the essence of the column mixing module is to perform multiple XOR operations on bytes. Considering that the 32-bit XOR device resources are 4 8-bit XOR devices, and the column mixing and reverse column mixing have repeated processes, the XOR resources integrated in the calculation path module realize column mixing through data flow control, and save logic resources by multiplexing the results of forward column mixing;
[0139] The round key adding module has an operation principle of XOR operation, and the encryption and decryption circuit directly reuses XOR resources to implement round key addition;
[0140] Key expansion module, all XOR operations are realized by reusing the 32-bit XOR calculation unit in the calculation path. The row shift process in the T function reuses the circular shift module of the calculation path. The byte substitution module reuses the byte substitution module of the round calculation process. The essence of the round constant is the algorithm of multiplying X in each round on the expansion domain. The encryption and decryption circuit directly realizes the transformation process of each bit after each round of multiplication by X, which is manifested by the XOR operation process of different bits, directly reusing the XOR calculation unit of the calculation path;
[0141] like Figure 8 As shown, when the user configures the working mode to be the ECC256 encryption working state, the starting state is IDLE, and then jumps to DOT_PRODUCT0. In this state, the random number in the random number register and the public key in the key register are multiplied by a point operation. In this state, the waiting state is maintained, and an enable signal for the point multiplication operation is generated at the same time. The point multiplication operation is started, and the key register is written after the calculation is completed and the jump to DOT_PRODUCT1 is performed. In this state, the random number and the generator point in the generator point register are multiplied by a point operation, and the point multiplication operation is started again, and the calculation is written to the generator point register after completion and jumps to the POINT_ADD0 state. After the point multiplication operation of the plaintext and the key register is completed, the point addition operation of the updated key is completed, and the point addition operation is started, and the output register is written after the calculation is completed.
[0142] When the user configures the working mode to the ECC256 decryption working state, the starting state DOT_PRODUCT2 is used. In this state, the first 256-bit data in the input register and the private key in the key register are multiplied. In this state, the waiting state is maintained, the point multiplication operation is started, and the output register is written after the calculation is completed and the state is jumped to the POINT_ADD1 state. The second 256-bit data in the input register and the updated result after the point multiplication operation in the output register are added, and the output register is written again after the calculation is completed.
[0143] like Fig. 9As shown, the global calculation module global calculation control module will control the algorithm state machine of the asymmetric algorithm calculation control module to start. After the startup is completed, different state jumps are performed according to the encryption or decryption working mode configuration. The module includes a point multiplication controller, which is used to control the start of the point addition controller and the doubling controller; the point addition controller is used to start the modular addition controller, modular subtraction controller, modular multiplication controller, and modular inversion controller according to the formula of the point addition operation; the doubling controller is used to start the modular addition controller, modular subtraction controller, modular multiplication controller, and modular inversion controller according to the formula of the doubling operation; the modular addition controller, modular subtraction controller, modular multiplication controller, and modular inversion controller control the 32-bit multiplier and 32-bit carry adder in the start-up calculation data path according to the specific hardware implementation method to complete the modular operation;
[0144] In this process, the operands of the adder and multiplier come from the temporary register bank or from the privileged register bank when the data is first used, and are written to the temporary register bank after the calculation is completed or to the privileged register when the final result is completed.
[0145] The modular addition operation module is a 256-bit addition operation, and performs a modular operation on a prime number P. The encryption and decryption circuit implements the function of 256 addition by adding carry output, carry input and addition and subtraction mode selection to the 32-bit adder, and multiplexing the 32-bit adder through the state machine. The modular operation is a cyclic subtraction operation of the result after addition and the modulus, which is performed from the high 32 bits to the low 32 bits. When a carry output is found, it is determined whether the number is greater than the modulus. If it is greater than the modulus, a subtraction operation is initiated and the cycle is repeated. If there is no carry output, it means that the number is less than the modulus, and then the modular operation is completed.
[0146] The modular subtraction operation module needs to first determine the size relationship between the two numbers to be subtracted, and first perform the subtraction operation in sequence. If it is found that the subtraction process is output by a carry, it means that the minuend is smaller than the subtrahend, then the order of the two numbers is exchanged and the subtraction operation is performed again, and then the modular operation is performed; if there is no carry output during the subtraction operation, the modular operation is directly performed;
[0147] The modular multiplication operation module adopts the Montgomery modular reduction algorithm to calculate the modular multiplication operation. First, the actual calculation process of the 256-bit multiplier is analyzed based on the 32-bit multiplier, and the operation process of each 32 bits of the actual result is calculated, so as to realize the 256-bit multiplication operation. In the process of modular multiplication operation, it is necessary to first realize the 32-bit modular reduction algorithm, and then each 32-bit word of the 256-bit is sequentially spliced to obtain the 256-bit modular multiplication result.
[0148] The modular inverse calculation module uses an extended Euclidean algorithm to calculate the modular inverse, which makes better use of hardware implementation from the perspective of hardware implementation;
[0149] The essence of the point addition operation module is to obtain the horizontal coordinate and the vertical coordinate of the coordinate point of the intersection of the two-point line and the elliptic curve symmetrical about the x-axis, realize the modular addition, modular subtraction, modular multiplication and modular inverse operation of the selectively called data path module, and realize the algorithm of point addition in combination with ECC, wherein (x1, y1), (x2, y2) represent the two base points P1 and P2 of the point addition operation, and (x3, y3) represent the result coordinates;
[0150] x3=λ 2 -x1-x2
[0151] y3=λ(x1-x3)-y1
[0152]
[0153] The essence of the doubling point operation module is to obtain the horizontal coordinate and the vertical coordinate of the coordinate point of the intersection of a tangent line and an elliptic curve symmetrical about the x-axis, realize the modular addition, modular subtraction, modular multiplication and modular inverse operations of the selectively called data path module, and realize the doubling point algorithm in combination with ECC, wherein (x1, y1) represents the base points P1 and P2 of the doubling point operation, and (x3, y3) represents the result coordinates;
[0154] x3=λ 2 -2x1
[0155] y3=λ(x1-x3)-y1
[0156]
[0157] The essence of the point multiplication operation module is that after obtaining the doubled point, the coordinates of the intersection of the starting point and the doubled point with the elliptic curve about x are connected as a new point, and the coordinates of the starting point and the new point and the intersection with the elliptic curve about the x-axis are connected as a new point, and so on to achieve point multiplication, and use a binary coding algorithm to reduce the complexity of the operation, convert the coefficients of the point multiplication into binary form, and start from the highest bit to determine whether each bit is "1". If it is "1", a point addition operation is performed, and a doubling operation is performed after each judgment, and then it is used as the base point for the next point addition.
[0158] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some or all of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. An encryption and decryption circuit system based on RISC-V architecture, comprising a privileged register configuration module, a temporary variable storage module, an encryption and decryption global control module, an encryption and decryption calculation control module, a digest algorithm control module, a symmetric algorithm calculation module, an asymmetric algorithm control module, and a computing resource data path module, characterized in that: The privileged register configuration module is connected to the encryption and decryption calculation control module through the encryption and decryption global control module, and is also connected to the computing resource data path module for encryption and decryption data interaction and status return. The encryption and decryption calculation control module is connected to the global calculation path module after passing through the summary algorithm control module, the symmetric algorithm control module, and the asymmetric algorithm control module respectively, so as to start the reasoning calculation of different algorithms and working modes; The privileged register configuration module is used to obtain privileged instructions, configure encryption and decryption working modes, and input and output encryption and decryption data; A temporary variable storage module is used to temporarily store the calculation results of round operations during the calculation process; The encryption and decryption global control module is used to shield the software write operation during the encryption and decryption operation; The encryption and decryption calculation control module is used to start the inference calculation of different algorithms and different working modes according to the register status information; The digest algorithm control module is used to control the digest algorithm calculation process and record work information, and call the computing resources required by the digest algorithm; Symmetric algorithm control module, used to control the symmetric algorithm calculation process and record work information, and call the computing resources required by the symmetric algorithm; Asymmetric algorithm control module, used to control the asymmetric computing process and record working information, and call the computing resources required by the asymmetric algorithm; The global computing pathway module is used to deploy computing resources and multiplexers to complete complex computing resource combinations based on status information.
2. The encryption and decryption circuit system based on the RISC-V architecture according to claim 1, characterized in that: The privileged register configuration module includes a parsing module, a general register read and write interface, and an extended register group. The privileged instruction obtained is a CSR instruction, which is used to read the data of the general register and write it into the CSR register of the interface in the form of original format / set / clear. The data in the CSR register is written into the general register of the write-back register index. After the CSR instruction is translated by the parsing module, a read signal and a write signal are generated as well as the index of the privileged register that needs to be operated in this cycle to configure and read the extended register group.
3. The encryption and decryption circuit system based on RISC-V architecture according to claim 1, characterized in that: The extended register includes a control register, a status register, an input register, an output register, a key register, an elliptic curve A parameter register, an elliptic curve B parameter register, a modulus register, a generation point register, and a random number register. The control register is used to configure the working mode of the encryption and decryption circuit, the status register is used to reflect the running state of the encryption and decryption circuit, the input register is used to input the data to be encrypted or decrypted into the encryption and decryption circuit, the output register is used to read out the encrypted data or decrypted data after completing the encryption or decryption work, the key register is used to obtain the key required for use in the encryption process, the elliptic curve A parameter register is used to implement the configuration of parameter A in the elliptic curve, the elliptic curve B parameter register is used to implement the configuration of parameter B in the elliptic curve, the modulus register is used to determine the modulus used when performing elliptic curve operations, the generation point register is used to determine the generation point of the elliptic curve, and the random number register is used to encrypt using random numbers during the encryption process.
4. The encryption and decryption circuit based on RISC-V architecture according to claim 1, characterized in that: The encryption and decryption circuit supports encryption and decryption of SHA256, AES128, and ECC256. It decomposes the special calculations in the calculation process of the three algorithms, integrates time-division multiplexing of general computing resources, and combines the MUX unit attached to each logical resource. The state machine controls the connection of multiple computing resources to form special operations in the encryption or decryption process, so that multiple security algorithms and multiple working modes can share resources, and the data flow and data path are controlled only by control signals.
5. The encryption and decryption circuit system based on RISC-V architecture according to claim 4, characterized in that: The encryption and decryption circuit can implement the encryption mode of the SHA256 algorithm, the encryption mode and decryption mode of the AES128 algorithm, and the encryption mode and decryption mode of the ECC256 algorithm.
6. The encryption and decryption circuit system based on RISC-V architecture according to claim 5, characterized in that: The single-round encryption module of the SHA256 algorithm includes: Ch function, ∑0 function, M aj Function, ∑1 function, σ0 function, σ1 function, 32-bit addition operation, circular right shift operation, logical right shift operation, a single round of operation executes only one clock cycle; The Ch function consists of 32-bit negation, AND operation, and XOR operation of three variables. The encryption and decryption circuit calls the 32-bit negation operation unit, 32-bit AND operation unit, and 32-bit XOR operation unit logic unit. The input of the 32-bit XOR operation resource is controlled by the state machine as the output of two 32-bit AND operation units. The input of one 32-bit AND operation unit is the first and second independent variables of the Ch function, and the input of the other 32-bit AND operation unit is the result of the negation of the first independent variable and the third independent variable. Its logic function is: M aj The function designs 32-bit AND and XOR operations of three variables. This function is implemented by calling 32-bit AND operation units and 32-bit XOR operation units. The state machine controls the input of the first 32-bit AND operation unit to be the first independent variable and the second independent variable, the input of the second 32-bit AND operation unit to be the first independent variable and the third independent variable, and the input of the third 32-bit AND operation unit to be the second independent variable and the third independent variable. Its logic function is: The ∑0 function involves three different times of circular right shift operations on a variable and the sequential XOR of the results. This function is implemented by calling three circular right shift operation units and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as circular right shift 1 bit, circular right shift 13 bits, and circular right shift 22 bits according to the state machine configuration. Its logic function is: The ∑1 function involves three different times of circular right shift operations on one variable and the sequential XOR of the results. This function is implemented by calling three circular right shift operation units and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as 6-bit circular right shift, 11-bit circular right shift, and 25-bit circular right shift according to the state machine configuration. Its logic function is: The σ0 function involves two different times of circular right shift operations and one logical right shift operation of one variable and the XOR of the results. This function is implemented by calling two circular right shift units, one logical right shift and two 32-bit XOR units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as 7-bit circular right shift, 18-bit circular right shift and 3-bit logical right shift according to the state machine. Its logic function is: The σ1 function involves two different times of circular right shift operations and one logical right shift operation of one variable and the sequential XOR of the results. This function is implemented by calling two circular right shift operation units, one logical right shift and two 32-bit XOR operation units. The circular right shift module in the data path can select different circular right shift units, which are respectively configured as circular right shift 17 bits, circular right shift 19 bits and logical right shift 10 bits according to the state machine configuration. Its logic function is: The encryption process divides 256-bit data into 32-bit blocks, and the operation process undergoes multiple encryption operations, and the encryption process is realized by calling multiple adders; the circular right shift operation is that the result after a single round of encryption is circularly right shifted and then stored in a temporary variable register stack, and the encryption and decryption calculation control module of the encryption and decryption circuit directly and intermittently registers the data returned by the data path module, so as to replace the circular right shift operation; The message expansion process will perform message expansion according to the round information recorded in the summary algorithm module. The initial message is stored in the register stack of the privileged register. After calculating the extended message, the extended message is stored in the temporary variable register. The calculation process is to add two original messages, the result of one message after the σ0 function operation, and the result of one message after the σ1 function operation in sequence. It is necessary to call three 32-bit addition units. The message expansion function is: IN j =σ1(W j-2 )+W j-7 +σ0(W j-15 )+W j-16 ,forj=16→63。 7. The encryption and decryption circuit system based on RISC-V architecture according to claim 5, characterized in that: The single-round encryption module of the AES128 algorithm includes a byte substitution module, a row shift module, a column confusion module and a round key addition module. The last round of the AES128 single-round encryption module includes a byte substitution module, a row shift module and a round key addition module. The encryption and decryption calculation control module calculates the encryption rounds and generates different data paths in the last round so as not to perform column mixing. The single-round decryption module of the AES128 algorithm includes: an inverse byte substitution module, a reverse displacement module, an inverse column confusion module and a round key addition module, and the last round of the single-round decryption module includes an inverse byte substitution module, a reverse displacement module and a round key addition module. The encryption and decryption calculation control module calculates the encryption rounds and generates different data paths in the last round so as not to perform reverse column mixing; The key expansion module of the AES128 algorithm first inputs the initial key into a 4×4 state matrix. The 4 bytes of each column of the 4×4 matrix form a word. The 4 words of the 4 columns of the matrix are named W[0], W[1], W[2] and W[3] in sequence, which form an array W in word units. The key expansion module expands the W array by 40 new columns to form an extended key array. If i is not a multiple of 4, the i-th column is determined by the following equation: If i is a multiple of 4, then the i-th column is determined by the following equation: The T function transformation is a process of word loop, byte substitution, and round constant XOR, wherein the word loop is a byte left shift, the byte substitution is the same as the byte substitution in the round operation process, and the round constant is a process of XORing according to different round numbers and different constants; The byte substitution and reverse byte substitution modules use GF(2 8 ) is a subfield algorithm on GF(2 8 ) is based on the inversion operation of irreducible polynomials and the linear operation of matrices. In the encryption and decryption circuit, GF(2 8 ) is transformed into the inverse algorithm on the extended field of GF(2 4 ) in the extended domain, in GF(2 4 ) is directly implemented by logical functions in the extended domain, and the conversion process involves the operation process of single-bit AND operation and single-bit XOR operation. The essence of the calculation process of these transformations in the extended domain is the AND or XOR operation between specific bits. Each bit of the 32-bit XOR calculation unit deployed in the data calculation path is an independent calculation process, which converts the complex operation in the byte substitution into a universal operation for each bit, thereby realizing the complex operation; the difference between the inverse byte substitution process and the byte substitution is that the specific bits of the linear transformation are different. The data calculation path receives the control signal of the symmetric encryption control module, constructs different data paths, thereby realizing different linear transformations, and then realizing the inverse byte substitution; The row shift and reverse row shift module, considering that the data input to the data path module is executed in columns, while the row shift and reverse row shift are executed in rows, will first perform column conversion before row shifting, and then reuse the circular shift logic resources of the data calculation path to realize row shifting, and then go through the reverse row-column conversion process after row shifting to obtain the result of row shifting; The column mixing module, the essence of which is to perform multiple XOR operations on bytes, considering that a 32-bit XOR device resource is four 8-bit XOR devices, and there are repeated processes of column mixing and reverse column mixing, the XOR resources integrated in the calculation path module realize column mixing through data flow control, and save logic resources by multiplexing the results of forward column mixing; The round key adding module has an operation principle of XOR operation, and the encryption and decryption circuit directly reuses XOR resources to implement round key addition; In the key expansion module, all XOR operations are realized by reusing the 32-bit XOR calculation unit in the calculation path, the row shift process in the T function reuses the circular shift module of the calculation path, the byte substitution module reuses the byte substitution module of the round calculation process, the essence of the round constant is the algorithm of performing multiplication by X in each round on the expansion domain, the encryption and decryption circuit directly realizes the transformation process of each bit after each round of multiplication by X, and what is manifested is the XOR operation process of different bits, and the XOR calculation unit of the calculation path is directly reused.
8. The encryption and decryption circuit system based on RISC-V architecture according to claim 5, characterized in that: The encryption process of the ECC256 algorithm uses a random number as a coefficient, performs a point multiplication operation on the point represented by the public key on the elliptic curve, and performs a point addition operation on the obtained point and the point represented by the plain text to obtain ciphertext 1. Here, this random number is used to perform a point multiplication operation on the generator point to obtain ciphertext 2; The decryption process of the ECC256 algorithm uses the private key to perform a point multiplication operation on the key 2, and then uses the ciphertext 1 to perform a point addition operation on the result 1 to obtain the plaintext; The modules of the ECC256 algorithm include: elliptic curve point addition operation module, elliptic curve point doubling operation, elliptic curve point multiplication operation, and 256-bit modular addition, modular subtraction, modular multiplication, and modular inverse operation; The modular addition operation module is a 256-bit addition operation, and performs a modular operation on a prime number P. The encryption and decryption circuit implements the function of 256 addition by giving the 32-bit adder an increase in carry output, carry input, and addition and subtraction mode selection, and multiplexing the 32-bit adder through the state machine. The modular operation is a cyclic subtraction operation of the result after addition and the modulus, which is performed from the high 32 bits to the low 32 bits in sequence. When a carry output is found, it is determined whether the number is greater than the modulus. If it is greater than the modulus, a subtraction operation is initiated and the cycle is repeated. If there is no carry output, it means that the number is less than the modulus, and then the modular operation is completed; the modular subtraction operation module needs to first determine the size relationship between the two numbers to be subtracted, and first perform subtraction operations in sequence. If it is found that the subtraction process is output by a carry, it means that the minuend is smaller than the subtrahend, then the order of the two numbers is exchanged and the subtraction operation is performed again, and then the modular operation is performed; if there is no carry output during the subtraction operation, the modular operation is directly performed; The modular multiplication operation module adopts the Montgomery modular reduction algorithm to calculate the modular multiplication operation. First, the actual calculation process of the 256-bit multiplier is analyzed based on the 32-bit multiplier, and the operation process of each 32 bits of the actual result is calculated, so as to realize the 256-bit multiplication operation. In the process of modular multiplication operation, it is necessary to first realize the 32-bit modular reduction algorithm, and then each 32-bit word of the 256-bit is sequentially spliced to obtain the 256-bit modular multiplication result. The modular inverse calculation module uses an extended Euclidean algorithm to calculate the modular inverse, which makes better use of hardware implementation from the perspective of hardware implementation; The essence of the point addition operation module is to obtain the horizontal coordinate and the vertical coordinate of the coordinate point of the intersection of the two-point line and the elliptic curve symmetrical about the x-axis, realize the modular addition, modular subtraction, modular multiplication and modular inverse operation of the selectively called data path module, and realize the algorithm of point addition in combination with ECC, wherein (x1, y1), (x2, y2) represent the two base points P1 and P2 of the point addition operation, and (x3, y3) represent the result coordinates; x3=λ 2 -x1-x2 y3=λ(x1-x3)-y1 The essence of the doubling point operation module is to obtain the horizontal coordinate and the vertical coordinate of the coordinate point of the intersection of a tangent line and an elliptic curve symmetrical about the x-axis, realize the modular addition, modular subtraction, modular multiplication and modular inverse operations of the selectively called data path module, and realize the doubling point algorithm in combination with ECC, wherein (x1, y1) represents the base points P1 and P2 of the doubling point operation, and (x3, y3) represents the result coordinates; x3=λ 2 -2x1 y3=λ(x1-x3)-y1 The essence of the point multiplication operation module is to obtain the doubled point, connect the coordinates of the intersection of the starting point and the doubled point with the elliptic curve about x as a new point, connect the starting point and the new point and the coordinate point symmetrical about the intersection with the elliptic curve about the x axis as a new point, and so on to achieve point multiplication, and use the binary coding algorithm to reduce the complexity of the operation, convert the coefficient of the point multiplication into binary form, and judge whether each bit is 1 in turn starting from the highest bit. If it is 1, perform a point addition operation, and perform a doubling operation after each judgment, and then use it as the base point for the next point addition.
9. An encryption and decryption circuit method based on RISC-V architecture, characterized in that: According to any one of claims 1 to 8, the encryption and decryption circuit system based on the RISC-V architecture performs encryption and decryption, comprising the following steps: Step 1: configure the privileged register, continuously send privileged instructions to the encryption and decryption circuit to implement the configuration of the state, the privileged instructions are executed in a pipeline during the execution process, and the configuration work includes inputting a key, inputting a plain text or a cipher text, configuring an encryption or decryption mode, configuring the encryption or decryption algorithm used, configuring a generator register, configuring a random number register, and finally enabling the encryption and decryption circuit to start calculation; Step 2: After the encryption or decryption is completed, the encryption and decryption circuit will perform encryption and decryption operations, and obtain calculation completion information by checking the interrupt signal or the flag bit on the status register according to different algorithms and working modes; Step 3: After detecting that the interrupt signal is set or the calculation completion flag in the status register is set, read the data in the output register; When the data reading operation is completed, the calculation enable signal is automatically cleared.
Citation Information
Patent Citations
Memory sensitive data encryption protection system based on hardware tag
CN112906015A
Encryption and decryption method and circuit based on asynchronous circuit
CN117240430A
Processor with block cipher algorithm, and a data encryption and decryption method operated by the processor
US20230067896A1
Protecting against resets by untrusted software during cryptographic operations
US20230267235A1
Method and system for a quantum-enhanced decryption process for RSA and AES encryptions
US20240340169A1