Authentication label generation method, message authentication method, system, equipment and product
By filling and grouping iterative encryption of transmission messages, and using the Davies-Meyer compression function to generate authentication tags, the problem of insufficient binding relationship between key and authentication tags in the prior art is solved, and the reliability of authentication tags and key commitment security is significantly improved.
Patent Information
- Application Number
- CN202510493495.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing authentication tag generation method does not consider the binding relationship between the key and the authentication tag, and there is a risk of forgery attacks.
By filling the transmission message to be sent, packet iterative encryption is performed using the packet cipher algorithm to generate the first final intermediate variable, and the authentication tag is generated through the Davies-Meyer compression function and it is combined to improve the one-to-one binding relationship between the key and the authentication tag.
It effectively improves the reliability of authentication tags, enhances the security of key commitments, and reduces the risk of forgery attacks.
Smart Images

Figure CN120034317A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to an authentication tag generation method, a message authentication method, system, device and product. Background Art
[0002] In the field of information security and communication, Message Authentication Code (MAC), as part of symmetric encryption technology, is an important tool to ensure the integrity of encrypted data. MAC generates an authentication tag through a tuple of a key and a message, which has the basic property of being unforgeable. Existing authentication tag generation methods do not adequately consider the binding relationship between the key and the authentication tag. For example, an attacker can construct different keys to calculate the same authentication tag, which poses a risk of forgery attacks. Therefore, a message authentication scheme that can ensure the security of the authentication tag is needed. Summary of the invention
[0003] The present disclosure provides an authentication tag generation method, a message authentication method, a system, a device and a product.
[0004] According to the first aspect of the present disclosure, a method for generating an authentication tag is provided. The method specifically comprises: performing padding processing on a transmission message to be sent to obtain a first padding message PS; performing group iterative encryption processing on the first padding message PS using a block cipher algorithm to obtain a first final intermediate variable Z L-1 ; Use the block cipher algorithm to encrypt the first final intermediate variable Z L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; the first authentication tag T is used to authenticate the transmission message to be sent.
[0005] Based on the above content, it can be known that a padding operation is performed on the transmission message to be sent to generate a first padding message; the first padding message is encrypted by applying a block cipher algorithm to perform block iterative encryption to obtain a first final intermediate variable; after the first final intermediate variable is encrypted by a block cipher algorithm, it is combined with the first final intermediate variable and input into a specified compression function to generate a first authentication tag; in this way, the transmission message to be sent is authenticated using the first authentication tag. The Davies-Meyer compression function structure is introduced to enable the generated authentication tag to have key commitment security, thereby effectively improving the one-to-one binding relationship between the shared key and the authentication tag, and can effectively improve the reliability of the authentication tag.
[0006] According to at least one embodiment of the present disclosure, the first final intermediate variable Z is encrypted using a block cipher algorithm. L-1After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, the specified compression function is input to generate the first authentication tag T, including: using the shared key and the predefined key mask to generate the intermediate key K' (K'=K⊕KM) through an XOR operation; using the intermediate key K' (K'=K⊕KM) as the encryption key of the block cipher, and L-1 Perform encryption processing to obtain the first input block; convert the first final intermediate variable Z L-1 As the second input block, it is input into the Davies-Meyer compression function together with the first input block for encryption calculation to obtain the first authentication tag T.
[0007] According to at least one embodiment of the present disclosure, a transmission message to be sent is padded to obtain a first padded message PS, including: adding a 1-bit flag at the end of the transmission message to be sent; padding 0 after the 1-bit flag so that the length of the obtained first padded message PS is an integer multiple of n bits; wherein n is the block length agreed upon by the block cipher algorithm.
[0008] According to at least one embodiment of the present disclosure, the first padding message PS is encrypted iteratively in groups using a block cipher algorithm to obtain a first final intermediate variable Z L-1 , including: performing group processing on a first padding message PS to obtain a plurality of message groups; wherein the plurality of message groups include: a first message group and a second message group; performing iterative encryption processing on the first message group using a block cipher algorithm PRP to obtain a first initial variable Y; using the first initial variable Y to calculate a first intermediate variable Z; using the block cipher algorithm PRP, the first initial variable Y and the first intermediate variable Z to calculate the plurality of message groups in sequence to obtain a first final intermediate variable Z L-1 .
[0009] According to at least one embodiment of the present disclosure, multiple message groups are calculated in sequence using a block cipher algorithm PRP, a first initial variable Y and a first intermediate variable Z, including: when the second message group is the last message group among multiple message groups, encrypting the first initial variable and the second message group using a block cipher algorithm to obtain a second initial variable; calculating the second intermediate variable using the second initial variable and the first intermediate variable, so as to calculate multiple message groups using the block cipher algorithm, the second initial variable and the second intermediate variable.
[0010] According to at least one embodiment of the present disclosure, the length of the first padding message PS, the length of the shared key and the length of the key mask are the same; the length of the message packet is the same as the length of the first authentication tag.
[0011] According to the second aspect of the present disclosure, a message authentication method is provided. The method specifically includes: receiving a transmission message and a first authentication tag T provided by a transmitting end; padding the transmission message to obtain a second padding message; performing group iterative encryption processing on the second padding message using a block cipher algorithm to obtain a second final intermediate variable; encrypting the second final intermediate variable using a block cipher algorithm, and then combining it with the second final intermediate variable and inputting a specified compression function to generate a second authentication tag T'; comparing the first authentication tag T and the second authentication tag T' to determine that they are the same, then the message authentication is passed.
[0012] According to a third aspect of the present disclosure, a message transmission system is provided, the system comprising: a sending end and a receiving end, wherein: the sending end is used to perform padding processing on the transmission message to be sent to obtain a first padding message PS; and to perform group iterative encryption processing on the first padding message PS using a block cipher algorithm to obtain a first final intermediate variable Z L-1 ; Use the block cipher algorithm to encrypt the first final intermediate variable Z L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; the transmission message and the first authentication tag T are combined and sent to the receiving end; the receiving end is used to parse the first authentication tag T and the transmission message sent by the sending end; the transmission message is padded to obtain a second padded message; the second padded message is encrypted in groups iteratively using a block cipher algorithm to obtain a second final intermediate variable; the first final intermediate variable is encrypted using a block cipher algorithm, and then combined with the second final intermediate variable and input into the specified compression function to generate a second authentication tag T'; after comparing the first authentication tag T and the second authentication tag T' and determining that they are the same, the message authentication is passed.
[0013] According to a fourth aspect of the present disclosure, an electronic device is provided, comprising: a memory storing execution instructions; and a processor executing the execution instructions stored in the memory, so that the processor executes the method described in the first aspect of any embodiment of the present disclosure.
[0014] According to a fifth aspect of the present disclosure, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the method described in the first aspect of any embodiment of the present disclosure is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The accompanying drawings illustrate exemplary embodiments of the present disclosure and together with the description serve to explain the principles of the present disclosure. These drawings are included to provide a further understanding of the present disclosure and are incorporated in and constitute a part of this specification.
[0016] Figure 1 A flowchart of a method for generating an authentication tag provided in the present invention.
[0017] Figure 2 A flowchart of a message authentication method provided in an embodiment of the present disclosure.
[0018] Figure 3 A schematic diagram of the structure of a message transmission system provided in an embodiment of the present disclosure.
[0019] Figure 4 A schematic diagram of an authentication tag generation process provided by the present disclosure.
[0020] Figure 5 The present invention is a block diagram showing the structure of an authentication tag generating device according to an embodiment of the present invention.
[0021] Figure 6 The present invention is a block diagram showing the structure of a message authentication device according to an embodiment of the present invention.
[0022] Figure 7 The present invention is a block diagram showing the structure of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0023] The present disclosure is further described in detail below in conjunction with the accompanying drawings and examples. It is understood that the specific examples described herein are only used to explain the relevant content, rather than to limit the present disclosure. It should also be noted that, for ease of description, only the parts related to the present disclosure are shown in the accompanying drawings.
[0024] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in the present disclosure can be combined with each other. The technical solution of the present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0025] In the field of information security and communication, message authentication code (MAC), as a key component of symmetric encryption technology, is an important means to ensure the integrity of encrypted data. Message authentication code MAC generates authentication tag T by processing a tuple containing a shared key K and a transmission message M, and has the basic property of being unforgeable. However, research results in recent years have shown that key-committing security has become one of the key attributes of the next generation of message authentication codes. At present, for example, in the 3GPP series of mobile communication standards, the integrity algorithm (UIA1) is one of the most widely used authentication tag generation methods. UIA1 is based on the KASUMI block cipher algorithm, uses a symmetric key to process the transmission message M, and then calculates a fixed-length authentication tag T. This method performs well in terms of efficiency and universality, and has been widely used in actual communication scenarios.
[0026] Although UIA1 and similar methods have outstanding performance and practicality, they still have the following problems and shortcomings: (1) Lack of key commitment security: UIA1 and other methods fail to provide additional security guarantees for the binding relationship between key values and authentication tags. This makes it possible for attackers to calculate the same authentication tag by constructing tuples with different key values, thus posing a potential risk of forgery attacks; (2) Weakness of message integrity verification: Due to the lack of key commitment security, the receiver cannot fully ensure the unique correspondence between the authentication tag and the shared key, which in turn weakens the reliability of message integrity verification.
[0027] The key to the above problem is that the existing authentication tag generation method fails to fully consider the binding relationship between the key and the tag, and does not introduce key commitment security in the algorithm design. At the same time, in order to balance performance and ease of use, designing a method that has both high security and reasonable computational efficiency has always been a technical difficulty. Therefore, a message authentication solution that can ensure the security of authentication tags is urgently needed.
[0028] For the convenience of description and to make the technical solutions of the specific embodiments of the present disclosure easier to understand, before describing the technical solutions of the present disclosure, the technical terms involved in the specific embodiments of the present disclosure are explained as follows.
[0029] Message Authentication Code (MAC): is a cryptographic tool used to verify the integrity of a message and ensure the authenticity of the source of the message. It is a small piece of information generated by a specific algorithm and is used to check the integrity of a message. It takes a message (such as a file, data packet, etc.) and a secret key as input to generate a short, fixed-length value, namely the MAC value or MAC tag.
[0030] Figure 1 The following is a flow chart of a method for generating an authentication tag provided by the present disclosure. Figure 1 The method shown includes steps 101 to 103. The method can be executed by an electronic device such as a server (local server or cloud server).
[0031] Specifically, Figure 1 The method shown includes steps 101 to 103 .
[0032] In step 101, the transmission message to be sent is padded to obtain a first padded message PS. The transmission message to be sent here can be understood as a message that the sender needs to send to the receiver. In order to ensure that the transmission message can be smoothly sent to the receiver, the transmission message can be padded. It should be noted that the length of the first padded message PS obtained after padding must be an integer multiple of n bits to facilitate subsequent encryption calculations. The specific implementation of the padding method will be described in detail in the subsequent embodiments, and will not be repeated here.
[0033] In step 102, the first padding message PS is encrypted iteratively using a block cipher algorithm to obtain a first final intermediate variable Z L-1 . The block cipher algorithm (Pseudo Random Permutation, PRP) mentioned here can be called a pseudo-random permutation algorithm. In addition, other block cipher algorithms can also be used, such as the Advanced Encryption Standard (AES) or SM4 block cipher. In the subsequent embodiments, a block cipher algorithm is taken as an example of the PRP algorithm for expansion. PRP: Pseudo-random permutation is a concept commonly used in cryptography to describe an ideal encryption property, that is, the encryption process looks like a random permutation operation, making it difficult for attackers to infer the plaintext information by analyzing the ciphertext.
[0034] In practical applications, after the first filled message is obtained by filling in the manner described above, the first filled message can be further processed by grouping. When grouping, the number of bits n occupied by each group is determined. The number of bits n occupied by a general group is determined according to the block cipher algorithm. When the selected block cipher algorithm is different, the number of bits n of each group obtained by grouping may also be different.
[0035] For example, assuming that the AES-128 block cipher is used as an example, and that the length of the first padding message PS is 256 bits (n=128), after grouping, L=2 message blocks are obtained: PS=PS 0 ||PS 1 , where each packet PS i (i=0,1) is 128 bits long. These two message groups can be called the first message group and the second message group, respectively. When performing subsequent iterative encryption processing, iterative encryption is performed in the order of the message groups, that is, the first message group is encrypted first, and then the second message group is encrypted in combination with the encryption result of the first message group, and so on, to complete the encryption processing of all message groups. In order to ensure encryption continuity, skipping iterative encryption processing is not allowed.
[0036] The first final intermediate variable Z L-1 It can be understood that it is obtained by encrypting all message groups in the first padding message using the group iterative encryption processing method described above. That is, after completing the encryption processing of the last message group (that is, the fourth message group mentioned above), the intermediate variable obtained is the first final intermediate variable. By iteratively encrypting the message groups obtained after grouping, that is, each group will be XORed with the encryption result of the previous group, and then encrypted, the integrity of the data can be effectively ensured.
[0037] In step 103, the first final intermediate variable Z is encrypted using a block cipher algorithm. L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; the first authentication tag T is used to authenticate the transmission message to be sent.
[0038] The specified compression function mentioned here may be a Davies-Meyer compression function. The Davies-Meyer compression function structure is a method for constructing a compression function in cryptography, which plays a key role in generating the first authentication tag T.
[0039] The Davies-Meyer compression function includes two input blocks and one output block. The first input block: as the key of the block cipher, that is, the result of encrypting the first final intermediate variable using the block cipher algorithm is used as the first input block. The second input block: as the input of the block cipher, that is, the first final intermediate variable Z is encrypted. L-1 As the second input block. Output block: is the result of the XOR operation between the second input block and the first input block, as the first authentication tag T.
[0040] Through the scheme described above, a padding operation is performed on the transmission message to be sent to generate a first padding message PS; the first padding message PS is encrypted by applying a block cipher algorithm to perform block iterative encryption, thereby obtaining a first final intermediate variable Z L-1 After the first final intermediate variable is encrypted using a block cipher algorithm, it is combined with the first final intermediate variable Z L-1 The combination is input into the specified compression function to generate a first authentication tag T; in this way, the transmission message to be sent is authenticated using the first authentication tag T. The Davies-Meyer compression function structure is introduced to make the generated authentication tag have key commitment security, thereby effectively improving the one-to-one binding relationship between the shared key and the authentication tag.
[0041] In one or more embodiments of the present disclosure, the first final intermediate variable Z is encrypted using a block cipher algorithm PRP. L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, the specified compression function is input to generate the first authentication tag T, including: using the shared key and the predefined key mask to generate the intermediate key K' (K'=K⊕KM, indicating that the shared key K and the key mask KM are subjected to an exclusive OR operation, where ⊕ indicates an exclusive OR operation) by an exclusive OR operation; using the intermediate key K' (K'=K⊕KM) as the encryption key of the block cipher, and performing an exclusive OR operation on the first final intermediate variable Z L-1 Perform encryption processing to obtain the first input block; convert the first final intermediate variable Z L-1 As the second input block, it is input into the Davies-Meyer compression function together with the first input block for encryption calculation to obtain the first authentication tag T.
[0042] Specifically, the first final intermediate variable Z is encrypted by using the block cipher algorithm PRP with the key mask KM. L-1 Encryption is performed to obtain the encrypted result as the first input block. Under the Davies-Meyer compression function structure, encryption calculation is performed. This calculation process utilizes the pseudo-random permutation characteristics of the block cipher algorithm PRP to convert the first final intermediate variable Z L-1 Combined with the key mask KM through complex encryption transformation (for example, through XOR processing and combination), an encryption result of fixed length is output as the first input block. Then the first final intermediate variable Z L-1 as the second input block.
[0043] Then the first input block is combined with the first final intermediate variable Z L-1 Perform an XOR operation to generate the first authentication tag T. The key mask KM is a fixed constant, and the key mask has the same length (that is, the same number of bits) as the shared key, and is used to modify or "mask" the original key through a certain logical operation (such as XOR operation). The key mask can be used as an additional security layer to prevent the key from being directly read during storage or transmission.
[0044] Through the above scheme, the security of the Davies-Meyer structure is enhanced because it uses a block cipher as its basis. If the block cipher is secure, then the Davies-Meyer compression function constructed based on the block cipher is also secure. This helps protect the authentication tag T from various commitment attacks. This feature ensures the uniqueness of the first authentication tag T, making it difficult for an attacker to find two different messages with the same authentication tag.
[0045] In one or more embodiments of the present disclosure, a transmission message to be sent is padded to obtain a first padded message PS, including: adding a 1-bit flag at the end of the transmission message to be sent; padding 0 after the 1-bit flag, and the length of the obtained first padded message PS is an integer multiple of n bits; wherein n is the block length agreed upon by the block cipher algorithm.
[0046] In practical applications, during the process of message encryption and transmission, bit padding of the transmission message M to be sent is a crucial operation. Its purpose is to generate a first padded message PS whose length is an integer multiple of the packet length n, so as to facilitate subsequent iterative group encryption calculations on multiple message groups.
[0047] The following example illustrates the padding rule. First, a 1-bit flag is added to the end of the transmission message M. This flag can be used as an identifier to accurately identify and process the padding content in the subsequent de-padding process. After adding this flag, several 0 bits are then padded after it.
[0048] The number of 0 bits to be padded needs to be determined according to specific conditions, that is, the length of the first padded message PS after padding must be an integer multiple of n bits. Here n represents the block length of the block cipher algorithm PRP. During the encryption process, the block cipher algorithm usually divides and processes the data according to a fixed block length, so the length of the padded message must meet this requirement to ensure that the data can be correctly grouped and processed during the encryption process and subsequent operations.
[0049] Only by performing bit filling strictly in accordance with the filling rules can the generated first filling message PS meet the requirements of subsequent data encryption and transmission, and ensure the security and integrity of the data.
[0050] By using the scheme described above, the proposed padding message is obtained by padding the transmission message to be sent. The message contains the transmission message with actual meaning, and also contains various meaningless padding contents. In addition, the length of the first padding message PS after padding is an integer multiple of n, which is convenient for subsequent splitting of message groups and encryption of message groups.
[0051] In actual applications, the filling content and filling rules can be set according to the user's actual needs. However, when setting, it is necessary to ensure that the encryption process and the decryption process use the same filling rules.
[0052] In one or more embodiments of the present disclosure, the first padding message PS is encrypted iteratively using a block cipher algorithm to obtain a first final intermediate variable Z. L-1, including: grouping the first padding message PS to obtain multiple message groups. Among them, the multiple message groups include: the first message group and the second message group. Using the block cipher algorithm PRP to perform iterative encryption processing on the first message group to obtain the first initial variable Y. Calculating the first intermediate variable Z using the first initial variable Y. Using the block cipher algorithm PRP, the first initial variable Y, and the first intermediate variable Z to calculate the multiple message groups in sequence to obtain the first final intermediate variable Z L-1 .
[0053] In practical applications, when grouping the first padding message PS, it is grouped according to the length of the message group agreed in advance. Suppose the length of the first padding message PS is 2n, then it can be split into two message groups, that is, the first message group and the second message group. It should be noted that the first message group and the second message group mentioned here refer to any two adjacent groups among the multiple message groups obtained by splitting the first padding message PS. For example, it can be the first two adjacent message groups, the middle two adjacent message groups, or the last two message groups. If the length M1 of the first padding message PS is relatively long, then more than two groups of message groups can be split
[0054] If the first message group mentioned here is the first message group obtained by splitting (that is, there is no any message group before the first message group), then it can be assumed that there is a first initial variable Y, and the first message group PS is encrypted and calculated using the shared key K 0 : Y = PRP K (PS 0 ). Then, calculate the first intermediate variable Z using the first initial variable Y, that is, initialize the first intermediate variable Z to be the same as the first initial variable Y: Z = Y
[0055] If the first message group is not the first message group obtained by splitting, that is, there are other message groups before the first message group. Suppose there is a first initial variable Y calculated using other previous message groups, and the first message group PS is encrypted and calculated using the shared key K i : Y = PRP K (Y PS i ). Then, perform an exclusive OR calculation on the first initial variable Y obtained by the latest encryption calculation and the first intermediate variable Z calculated using other previous message groups: Z = Y Z
[0056] In the above manner, the multiple message groups obtained by splitting are encrypted in sequence. The group iterative encryption allows the algorithm to divide the first padding message into small blocks for processing, which helps to improve the processing speed, especially when processing a large number of padding messages, the message encryption processing efficiency will be significantly improved. In addition, dividing the first padding message PS into small message groups can simplify the complexity of the algorithm, making it easier to implement and optimize. Through multiple iterations, the difficulty of cracking the MAC can be increased, because the attacker needs to crack the key and algorithm of multiple iterations, which is usually much more difficult than a single iteration.
[0057] Next, calculate the first final intermediate variable Z L-1 The relevant plans are explained in detail.
[0058] In one or more embodiments of the present disclosure, multiple message groups are calculated in sequence using a block cipher algorithm, a first initial variable, and a first intermediate variable, including: when the second message group is the last message group among the multiple message groups, encrypting the first initial variable and the second message group using a block cipher algorithm to obtain a second initial variable; and calculating the second intermediate variable using the second initial variable and the first intermediate variable, so that multiple message groups can be calculated using the block cipher algorithm, the second initial variable, and the second intermediate variable.
[0059] Here, it is assumed that the second message packet is the last message packet PS obtained by splitting the first padding message PS. L-1 Correspondingly, the second to last message packet is called the first message packet PS L-2 When performing encryption calculation, it is assumed that there is a first initial variable Y calculated using the first message group, and the first message group PS is encrypted using the shared key K. L-2 Perform encryption calculation: Y=PRP K (Y PS L-2 ). Then, the first initial variable Y obtained by the latest encryption calculation and the first intermediate variable Z obtained by the previous first message group calculation are used. L-2 Perform XOR calculation: Z L-1 =Y Z L-2 .
[0060] It can be seen from the above scheme that when calculating the intermediate variable, each message group is used for loop iterative calculation, and the first final intermediate variable Z obtained by the last encryption calculation is used. L-1 As a parameter for the subsequent calculation of the first authentication tag T, there is a strict one-to-one correspondence between the transmission message M, the shared key K and the first authentication tag, and at the same time, it can effectively prevent the key tuple content from being illegally tampered with, thereby improving MAC reliability.
[0061] In order to facilitate subsequent grouping and encryption calculation, the length of the first padding message PS, the length of the shared key K and the length of the key mask KM are the same. In addition, the length of the message group PS is the same as the length of the first authentication tag T.
[0062] Based on the same idea, the embodiment of the present disclosure also proposes a message authentication method, which is applied to a message receiving end (the message receiving end may be a local computer device or a cloud computer device, etc.). Figure 2 A flowchart of a message authentication method provided by an embodiment of the present disclosure. Figure 2 It can be seen that the specific steps include the following. Step 201: Receive the transmission message and the first authentication tag provided by the sender. Step 202: Fill the transmission message to obtain a second filled message. Step 203: Use a block cipher algorithm to perform group iterative encryption on the second filled message to obtain a second final intermediate variable. Step 204: After encrypting the second final intermediate variable using a block cipher algorithm, combine it with the second final intermediate variable and input the specified compression function to generate a second authentication tag. Step 205: After comparing the first authentication tag and the second authentication tag and determining that they are the same, the message authentication is passed.
[0063] In passing Figure 1 After the corresponding embodiment calculates and obtains the first authentication tag T, the transmission message M can be combined with the first authentication tag T, and the combined data structure can be M||T. The combined transmission message M and the first authentication tag T are sent to the receiving end together.
[0064] After receiving the transmission message M and the first authentication tag T, the receiving end will verify whether the first authentication tag T is consistent and then determine whether the transmission message M is safe and reliable. When verifying the first authentication tag T, the receiving end uses the same calculation method as the sending end to calculate the second authentication tag T', and then determines whether the first authentication tag T and the second authentication tag T' are the same. If they are the same, it means that the authentication is passed; otherwise, if they are not the same, it is considered that the authentication has failed. This means that the transmission message M may have been tampered with or abnormal conditions such as transmission errors and data loss have occurred during the transmission process, and the group of transmission messages will be discarded.
[0065] The process of calculating the second authentication tag T' is the same as the process of calculating the first authentication tag T, that is, the message filling rule, the shared key K, the key mask KM and the selected specified compression function must be consistent. For details, please refer to the calculation process of calculating the first authentication tag T, which will not be repeated here.
[0066] Based on the same idea, the embodiment of the present disclosure also provides a message transmission system. Figure 3A schematic diagram of the structure of a message transmission system provided by an embodiment of the present disclosure. Figure 3 As can be seen in FIG, the system includes: a sending end 31 and a receiving end 32. The sending end 31 is used to perform padding processing on the transmission message to be sent to obtain a first padding message PS; perform block iterative encryption processing on the first padding message PS using a block cipher algorithm to obtain a first final intermediate variable Z L-1 ; Use the block cipher algorithm to encrypt the first final intermediate variable Z L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; the first authentication tag T is used to authenticate the transmission message to be sent.
[0067] The receiving end 32 is used to parse the first authentication tag and transmission message sent by the sending end; fill the transmission message to obtain a second filled message; use a block cipher algorithm to perform group iterative encryption on the second filled message to obtain a second final intermediate variable; use a block cipher algorithm to encrypt the first final intermediate variable, then combine it with the second final intermediate variable and input it into a specified compression function to generate a second authentication tag; compare the first authentication tag and the second authentication tag and determine that they are the same, then the message authentication is passed.
[0068] The sending end 31 is configured to execute Figure 1 The corresponding authentication tag generation method generates a first authentication tag T, and sends a data structure M||T consisting of the transmission message M and the first authentication tag T to the receiving end 32.
[0069] The receiving end 32 is configured to receive the data structure M||T and based on the received transmission message M and the shared key K, Figure 2 The method shown calculates the second authentication tag T'. Then, the message integrity is verified by comparing the second authentication tag T' calculated by the receiving end 32 with the received first authentication tag T. If they are equal, it means that the transmission message M is reliable and the transmission message M is accepted. Otherwise, the transmission message M is rejected.
[0070] For ease of understanding, the implementation process of the above solution will be described below through specific embodiments.
[0071] like Figure 4 A schematic diagram of an authentication tag generation process provided by the present disclosure. It is assumed here that a KASUMI block cipher is used to calculate an instance of a first authentication tag T for a 96-bit transmission message M.
[0072] In this example, the block cipher algorithm PRP uses the classic KASUMI block cipher, which is also the block cipher recommended in the UIA1 integrity algorithm in the 3GPP series of mobile communication standards. This block cipher uses a 128-bit key input and a 64-bit message block.
[0073] Assume that the shared key K = 0x 0000 0000 0000 0000 0000 0000 0000 0000; the transmission message M = 0x 0000 0000 0000 0000 0000 0000; the key mask KM = 0x 0000 0000 0000 0000 0000 00000000 0001.
[0074] First, pad the transmission message. In order to make the message length meet the requirements of the block encryption algorithm, the transmission message M needs to be bit padded. The padding rule is: add a 1-bit flag bit at the end of the transmission message M, and then pad it with 0 until the message length reaches a multiple of n bits. The first padded message PS after padding is: PS=M||1||0 * . The length of the padded first padding message PS is an integer multiple of n bits. Assume that the first padding message PS has a total of L packets, each of which is n bits.
[0075] Next, the intermediate variables Y and Z are initialized. The first initial variable Y is encrypted by the block cipher algorithm PRP. The first message block PS is obtained by splitting the first padding message PS using the shared key K. 0 Encryption: Y=PRP K (PS 0 ). Then the first intermediate variable Z is initialized to be the same as the first initial variable Y: Z=Y.
[0076] Next, multiple message packets are iterated and calculated. For each packet PS in the first padded message PS after padding, i , perform the following iterative calculation: For each message packet PS i , use the block cipher algorithm PRP encryption operation to update the first initial variable Y and the first intermediate variable Z: Y=PRP K (Y PS i ), Z=Y Z.
[0077] Next, the first authentication tag T is calculated. The Davies-Meyer compression function can be used to calculate the authentication tag T. Specifically, after completing the iterative encryption calculation of all message packets, the Davies-Meyer compression function structure is used to generate the final first authentication tag T:L-1 and K KM is used as the transmission message and key input of the block cipher algorithm PRP, and encryption calculation is performed under the Davies-Meyer compression function structure: T=Z L-1 PRP K KM (Z L-1 ). Among them, Z L-1 It is the last first final intermediate variable in the iteration process. The key mask KM is a fixed constant. After encryption calculation, the n-bit calculation result T is used as the final first authentication tag. The corresponding 64-bit authentication tag calculation result is: 0x DD13E475 7210 D5B5.
[0078] After calculating and obtaining the first authentication tag T, the sending end may send the generated first authentication tag T to the receiving end together with the transmission message M. The data structure during sending is M||T.
[0079] After receiving M||T, the receiving end will verify the first authentication tag T. The receiving end recalculates the second authentication tag T' corresponding to the transmission message based on the shared key K it holds and the received transmission message M. The specific calculation steps are the same as the calculation process of the first authentication tag T in the previous article. If T'=T, the receiving end believes that the transmission message M has not been tampered with and can accept the transmission message M; otherwise, the receiving end believes that the transmission message M may have been tampered with or forged and rejects the transmission message M.
[0080] The disclosed scheme introduces a key commitment security mechanism, combines a block cipher authentication tag generation method with an optimized communication system ( Figure 3 The system shown can be designed for a communication system, which significantly improves the security and reliability of message authentication and also has the following advantages.
[0081] Achieving key commitment security: By introducing the Davies-Meyer compression function, a strong binding relationship between the shared key K and the first authentication tag T using Davies-Meyer is guaranteed.
[0082] Enhanced reliability of message integrity verification: The verification process of the first authentication tag T is more rigorous. It adopts an improved iterative calculation method, combined with the pseudo-random permutation characteristics of the block cipher algorithm PRP, to ensure the unique correspondence between the authentication tag and the shared key K, thereby significantly improving the accuracy of message integrity verification and effectively preventing security issues caused by key forgery or message tampering.
[0083] Providing provable security guarantees: Compared with traditional methods, the disclosed scheme starts from cryptographic theory, provides a provable mathematical basis for key commitment security through security assumptions based on the block cipher algorithm PRP and combines the theoretical framework of shared key commitment security.
[0084] In addition, the present disclosure is not only applicable to current mobile communication systems (such as 3GPP standards), but can also be extended to other communication fields that require high security. Technically, the block cipher algorithm is highly substitutable (such as AES, SM4, etc.), and the flexible design of the key mask KM enables the solution to adapt to different application scenarios.
[0085] Based on any of the above embodiments, the present disclosure also provides a device for generating an authentication label. Figure 5 FIG. 1 is a schematic block diagram of the structure of an authentication tag generating device according to an embodiment of the present disclosure. Figure 5 As shown, the authentication label generating device includes the following modules.
[0086] The first filling module 51 is used to perform filling processing on the transmission message to be sent to obtain a first filling message PS.
[0087] The first group iteration module 52 is used to perform group iteration encryption processing on the first padding message PS using a block cipher algorithm to obtain a first final intermediate variable Z L-1 .
[0088] The first label generation module 53 is used to generate the first final intermediate variable Z using a block cipher algorithm. L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; the first authentication tag T is used to authenticate the transmission message to be sent.
[0089] The first label generation module 53 is used to generate the first final intermediate variable Z using a block cipher algorithm. L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, the specified compression function is input to generate the first authentication tag T, including: using the shared key and the predefined key mask to generate the intermediate key K' (K'=K⊕KM) through an XOR operation; using the intermediate key K' (K'=K⊕KM) as the encryption key of the block cipher, and L-1 Perform encryption processing to obtain the first input block; convert the first final intermediate variable Z L-1 As the second input block, it is input into the Davies-Meyer compression function together with the first input block for encryption calculation to obtain the first authentication tag T.
[0090] The first filling module 51 is used to add a 1-bit flag at the end of the transmission message to be sent; fill 0 after the 1-bit flag so that the length of the obtained first filling message PS is an integer multiple of n bits; where n is the block length agreed upon by the block cipher algorithm.
[0091] The first group iteration module 52 is used to group the first padding message PS to obtain multiple message groups; wherein the multiple message groups include: a first message group and a second message group; iteratively encrypt the first message group using a block cipher algorithm to obtain a first initial variable Y; calculate the first intermediate variable Z using the first initial variable Y; calculate the multiple message groups in turn using the block cipher algorithm PRP, the first initial variable Y and the first intermediate variable Z to obtain a first final intermediate variable Z L-1 .
[0092] The first group iteration module 52 is used to encrypt the first initial variable and the second message group using a block cipher algorithm to obtain a second initial variable when the second message group is the last message group among multiple message groups; and to calculate the second intermediate variable using the second initial variable and the first intermediate variable, so as to calculate multiple message groups using the block cipher algorithm, the second initial variable and the second intermediate variable.
[0093] The length of the first padding message PS, the length of the shared key and the length of the key mask are the same; the length of the message packet is the same as the length of the first authentication tag.
[0094] Based on any of the above implementations, the present disclosure also provides a message authentication device. Figure 6 FIG. 1 is a schematic block diagram of a message authentication device according to an embodiment of the present disclosure. Figure 6 As shown, the authentication tag generation device includes the following modules. A receiving module 61 is used to receive a transmission message and a first authentication tag T provided by a transmitting end. A second filling module 62 is used to fill the transmission message to obtain a second filled message. A second group iteration module 63 is used to perform group iterative encryption processing on the second filled message using a block cipher algorithm to obtain a second final intermediate variable. A second tag generation module 64 is used to encrypt the second final intermediate variable using a block cipher algorithm, and then combine it with the second final intermediate variable and input it into a specified compression function to generate a second authentication tag T'. An authentication module 65 is used to compare the first authentication tag T and the second authentication tag T' and determine that they are the same, then the message authentication is passed.
[0095] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, which will not be repeated here.
[0096] The execution subject of the authentication tag generation method and the message authentication method in the specific implementation of the present disclosure may be an electronic device such as a server (including a local server or a cloud server).
[0097] Therefore, based on any one of the above embodiments, the present disclosure further provides an electronic device, which can execute the authentication tag generation method and the message authentication method of any one of the embodiments described above in the present disclosure.
[0098] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0099] Figure 7 The present invention is a block diagram showing the structure of an electronic device according to an embodiment of the present invention.
[0100] The hardware structure of the electronic device 1000 can be implemented using a bus architecture. The bus architecture can include any number of interconnected buses and bridges, depending on the specific application and overall design constraints of the hardware. The bus 1100 connects various circuits including one or more processors 1200, memory 1300 and / or hardware modules together. The bus 1100 can also connect various other circuits 1400 such as peripherals, voltage regulators, power management circuits, external antennas, etc.
[0101] The bus 1100 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Component (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the figure only uses one connecting line, but does not mean that there is only one bus or one type of bus.
[0102] The present disclosure also provides a readable storage medium, in which a computer program is stored, and the computer program is used to implement the above method when executed by a processor. "Readable storage medium" can be any device that can contain, store, communicate, propagate or transmit a program for use in an instruction execution system, device or equipment or in combination with these instruction execution systems, devices or equipment. More specific examples of readable storage media include the following: an electrical connection portion (electronic device) with one or more wirings, a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and editable read-only memory (EPROM or flash memory), an optical fiber device, and a portable read-only memory (CDROM), etc.
[0103] The present disclosure also provides a computer program product. The method of the present disclosure can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed, the process or function of the present disclosure is executed in whole or in part.
[0104] The computer program or instructions may be stored in a readable storage medium or transmitted from one readable storage medium to another readable storage medium, for example, the computer program or instructions may be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired or wireless means. The readable storage medium may be any available medium that can be accessed or a data storage device such as a server, data center, etc. that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it may also be an optical medium, such as a digital video disk; it may also be a semiconductor medium, such as a solid state drive. The computer readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.
[0105] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0106] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present disclosure. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing method device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing method device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0107] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0108] These computer program instructions may also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0109] In the description of this specification, the description with reference to the terms "one embodiment / method", "some embodiments / methods", "example", "specific example", or "some examples" etc. means that the specific features, structures, or characteristics described in conjunction with the embodiment / method or example are included in at least one embodiment / method or example of the present disclosure. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment / method or example. Moreover, the specific features, structures, or characteristics described may be combined in any one or more embodiments / methods or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments / methods or examples described in this specification and features of different embodiments / methods or examples, unless they are contradictory.
[0110] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the present disclosure, "plurality" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0111] Those skilled in the art should understand that the above embodiments are only for the purpose of clearly illustrating the present disclosure, and are not intended to limit the scope of the present disclosure. For those skilled in the art, other changes or modifications may be made based on the above disclosure, and these changes or modifications are still within the scope of the present disclosure.
Claims
1. A method for generating an authentication tag, characterized in that: include: Perform padding processing on the transmission message to be sent to obtain a first padding message PS; The first padding message PS is encrypted iteratively in groups using a block cipher algorithm to obtain a first final intermediate variable Z L-1 ; The first final intermediate variable Z is encrypted using the block cipher algorithm L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; and the first authentication tag T is used to authenticate the transmission message to be sent.
2. The method according to claim 1, characterized in that: The first final intermediate variable Z is encrypted using the block cipher algorithm L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After combination, the specified compression function is input to generate the first authentication tag T, including: Generate an intermediate key K' by using the shared key and the predefined key mask through an XOR operation; The intermediate key K' is used as the encryption key of the block cipher, and the first final intermediate variable Z L-1 Perform encryption processing to obtain a first input block; The first final intermediate variable Z L-1 As the second input block, it is input into the Davies-Meyer compression function together with the first input block for encryption calculation to obtain a first authentication tag T.
3. The method according to claim 2, characterized in that The transmission message to be sent is padded to obtain a first padded message PS, including: Add a 1-bit flag at the end of the transmission message to be sent; 0 is filled after the 1-bit flag bit, so that the length of the first padding message PS obtained is an integer multiple of n bits; wherein n is the block length agreed upon by the block cipher algorithm.
4. The method according to claim 3, characterized in that The first padding message PS is encrypted iteratively in groups using a block cipher algorithm to obtain a first final intermediate variable Z L-1 ,include: The first filling message PS is grouped to obtain a plurality of message groups; wherein the plurality of message groups include: a first message group and a second message group; Iteratively encrypt the first message group using the block cipher algorithm to obtain a first initial variable Y; Calculate a first intermediate variable Z using the first initial variable Y; The plurality of message groups are calculated in sequence using the block cipher algorithm PRP, the first initial variable Y and the first intermediate variable Z to obtain the first final intermediate variable Z. L-1 .
5. The method according to claim 4, characterized in that Calculating the plurality of message groups in sequence using the block cipher algorithm PRP, the first initial variable Y, and the first intermediate variable Z includes: When the second message group is the last message group among the multiple message groups, encrypting the first initial variable and the second message group by using the block cipher algorithm to obtain a second initial variable; The second initial variable and the first intermediate variable are used to calculate a second intermediate variable, so as to calculate the multiple message groups using the block cipher algorithm, the second initial variable and the second intermediate variable.
6. The method according to claim 4, characterized in that The length of the first padding message PS, the length of the shared key and the length of the key mask are the same; The length of the message packet is the same as the length of the first authentication tag.
7. A message authentication method, characterized in that: The method comprises: Receive a transmission message and a first authentication tag T provided by a sending end; Performing padding processing on the transmission message to obtain a second padding message; Performing block iterative encryption processing on the second padding message by using a block cipher algorithm to obtain a second final intermediate variable; After encrypting the second final intermediate variable using the block cipher algorithm, the second final intermediate variable is combined with the second final intermediate variable and then input into a specified compression function to generate a second authentication tag T'; If the first authentication tag T and the second authentication tag T' are compared and determined to be identical, the message authentication is successful.
8. A message transmission system, characterized in that: The system comprises: a transmitting end and a receiving end, wherein: The transmitting end is used to perform padding processing on the transmission message to be sent to obtain a first padding message PS; perform block iterative encryption processing on the first padding message PS using a block cipher algorithm to obtain a first final intermediate variable Z L-1 ; Using the block cipher algorithm to encrypt the first final intermediate variable Z L-1 After encryption, it is combined with the first final intermediate variable Z L-1 After the combination, a specified compression function is input to generate a first authentication tag T; the transmission message and the first authentication tag T are combined and sent to a receiving end; The receiving end is used to parse the first authentication tag and the transmission message sent by the sending end; perform padding processing on the transmission message to obtain a second padding message; perform block iterative encryption processing on the second padding message using a block cipher algorithm to obtain a second final intermediate variable; and perform block cipher encryption on the first final intermediate variable Z using the block cipher algorithm. L-1 After encryption, it is combined with the second final intermediate variable and input into a specified compression function to generate a second authentication tag T'; after comparing the first authentication tag T and the second authentication tag T' and determining that they are the same, the message authentication is passed.
9. An electronic device, characterized in that: include: A memory storing execution instructions; as well as A processor, wherein the processor executes the execution instructions stored in the memory, so that the processor executes the method according to any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
DES encryption method
CN117978365A
Message Authentication Device, Message Authentication Method, Message Authentication Program and Storage Medium therefor
US20090138710A1