Reconfigurable trusted password system and method

By designing a reconstructible trusted cryptographic system in the industrial control system, and using FPGA and modular design to achieve flexible switching between bus interfaces and national secret algorithms, the problems of limited computing resources and high module fixity in the industrial control system are solved, and efficient and flexible password processing capabilities are achieved.

CN120050027APending Publication Date: 2025-05-27百信信息技术有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411931406.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The computing resources of trusted cryptographic modules in the existing industrial control systems are limited, and complex encryption and decryption algorithms cannot be implemented. The existing TCM module cryptographic algorithms are fixed and the interface types are limited, making it difficult to adapt to the requirements of diversified application platforms.

Method used

A reconfigurable trusted cryptographic system is designed, adopting a modular design, and the conversion of the bus interface and the call of the Guose algorithm engine is realized through FPGA. Combining the reusable module and the reconfigurable bus interface, it realizes flexible switching of a variety of Guose algorithms.

Benefits of technology

It improves the flexibility and operation efficiency of the TCM module, and can realize the conversion of multiple communication buses under limited hardware resources, save FPGA hardware resources, and adapt to the diversity of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050027A_ABST
    Figure CN120050027A_ABST
Patent Text Reader

Abstract

The invention discloses a reconfigurable trusted password system and method, and relates to the field of information security, the system comprises a control module, a filling circuit, a reusable module, a reconfigurable bus interface, a random number generator and a plurality of national cryptographic algorithm engines; the control module comprises an FPGA (Field Programmable Gate Array); the filling circuit is respectively connected with the reusable module and the reconfigurable bus interface; the reusable module and the various national cryptographic algorithm engines are connected with the control module; the reusable module is connected with a plurality of national cryptographic algorithm engines; and the random number generator is connected with a plurality of national cryptographic algorithm engines. According to the method, various different cryptographic algorithms can be flexibly and quickly realized, the defect that a traditional cryptographic module can only realize a specific cryptographic algorithm is well overcome, the method can adapt to rich application platform requirements, the flexibility of the TCM module is greatly improved, and meanwhile, the method has the advantages of being small in occupied hardware resources, high in operation efficiency and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and particularly to a reconfigurable trusted password system and method. Background Art

[0002] The trusted password module is based on cryptography and is the trust source of the trusted computing platform. However, cryptographic algorithms are complex and require a high-computing-power computing platform for support. Usually, some related calculations of the cryptographic algorithms are completed in the CPU (Central Processing Unit / Processor) of the trusted computer, or a dedicated TCM module (Trusted Cryptography Module) is embedded to implement complex encryption and decryption algorithms through hardware support instructions. However, in the industrial control field, due to the limited computing resources of the industrial control system, the processing speed of its CPU is slower than that of a general computer, and the working main frequency is low. It is impossible to complete some related calculations of the cryptographic algorithms in the CPU like a trusted computer. Moreover, the existing TCM modules or chips have problems such as fixed and unchangeable cryptographic algorithms, limited interface types, only applicable to specific standards, fixed application scenarios, and lack of emphasis on function expansion, making it difficult to meet the requirements of rich application platforms, being relatively cumbersome, and having low operating efficiency. Summary of the Invention

[0003] To solve the above problems existing in the prior art, this application provides a reconfigurable trusted password system and method.

[0004] To achieve the above object, this application provides the following solutions:

[0005] In a first aspect, this application provides a reconfigurable trusted password system, including: a control module, a padding circuit, a reusable module, a reconfigurable bus interface, a random number generator, and multiple national cryptographic algorithm engines; the control module includes an FPGA.

[0006] The padding circuit is respectively connected to the reusable module and the reconfigurable bus interface; the reusable module and the multiple national cryptographic algorithm engines are both connected to the control module; the reusable module is connected to the multiple national cryptographic algorithm engines; the random number generator is connected to the multiple national cryptographic algorithm engines;

[0007] The control module is used to convert the bus interface of the industrial control system to the reconfigurable bus interface using the FPGA protocol, and is used to call the corresponding national cryptographic algorithm engine; the padding circuit pads the input data of the reconfigurable bus interface based on the national cryptographic algorithm engine called by the control module; the random number generator is used to generate security parameters; the security parameters include a secret key and a verification code; the reusable module is used to encrypt the padded input data based on the security parameters.

[0008] Optionally, the padding circuit, the reusable module, the reconfigurable bus interface, and the multiple national cryptographic algorithm engines are all implemented by programming in Verilog HDL hardware description language.

[0009] Optionally, the reusable module includes: a generation circuit, an arithmetic circuit, a shift register, and a constant register;

[0010] The generation circuit is respectively connected to the arithmetic circuit, the control module, and the padding circuit; the arithmetic circuit is respectively connected to the generation circuit and the shift register; the shift register is connected to the constant register;

[0011] The generation circuit is used to convert the padded input data into bit words based on the security parameters; the arithmetic circuit is used to perform operations on the bit words to obtain operation results; the shift register is used to shift and store each operation result; the constant register is used to store the constant values shared during the operation process of the arithmetic circuit.

[0012] Optionally, the operations performed on the bit words include modular addition, modular subtraction, and point multiplication.

[0013] Optionally, the reconfigurable bus interface includes: an SPI communication interface, an I 2 C communication interface, and an Ethernet communication interface.

[0014] Optionally, the multiple national cryptographic algorithm engines include: an SM2 national cryptographic algorithm engine, an SM3 national cryptographic algorithm engine, an SM4 national cryptographic algorithm engine, and an SM9 national cryptographic algorithm engine.

[0015] Optionally, the reconfigurable trusted cryptographic system further includes: an HMAC engine;

[0016] The HMAC engine is used to verify the integrity of the input data and authenticate the identity of the sender of the authentication message based on the verification code.

[0017] Optionally, the reconfigurable trusted cryptographic system further includes a volatile memory and a non-volatile memory;

[0018] The volatile memory is used to store data during the operation of the FPGA; the non-volatile memory is used to store critical data; the critical data includes keys, configuration setting parameters, calibration parameters, and device identifiers.

[0019] In a second aspect, the present application provides a reconfigurable trusted password method, including:

[0020] Converting the bus interface of the industrial control system to a reconfigurable bus interface using the FPGA protocol;

[0021] Invoking the corresponding national cryptographic algorithm engine based on the converted reconfigurable bus interface, and filling the input data of the reconfigurable bus interface based on the invoked national cryptographic algorithm engine;

[0022] Generating security parameters; the security parameters include keys and verification codes;

[0023] Encrypting the filled input data based on the security parameters.

[0024] Optionally, encrypting the filled input data based on the security parameters includes:

[0025] Converting the filled input data into bit words based on the security parameters;

[0026] Performing operations on the bit words to obtain an operation result, and using the operation result as the encrypted input data.

[0027] According to the specific embodiments provided by the present application, the present application has the following technical effects:

[0028] The present application provides a reconfigurable trusted password system and method. Adopting the modular design concept, through functional decoupling, designing reusable modules for reconfigurable design of various national cryptographic algorithms, and constructing circuit structures with different functions, so as to be able to flexibly and quickly implement a variety of different cryptographic algorithms, thereby well overcoming the drawback that traditional cryptographic modules can only implement specific cryptographic algorithms, and greatly improving the flexibility of the TCM module. Using FPGA to implement communication protocol conversion, multiple communication buses can be converted under limited I / O hardware resources. In addition, since the reconfigurable design is based on the repeated application of some hardware resources, the hardware resources consumed are much less than the sum of the hardware resources occupied by dedicated modules that only implement a certain national cryptographic algorithm, having the advantages of less hardware resource occupation and high operating efficiency. The present application can not only flexibly implement a variety of national cryptographic algorithms, but also effectively save FPGA hardware resources. Description of the Drawings

[0029] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0030] Figure 1 FIG. 4 is a schematic structural diagram of a reconfigurable trusted password system provided by an embodiment of the present application;

[0031] Figure 2 FIG. 8 is a schematic flowchart of a reconfigurable trusted password method provided by an embodiment of the present application. Detailed implementation manners

[0032] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0033] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific implementation manners.

[0034] In an exemplary embodiment, the reconfigurable trusted password system, as the core component for building a trusted computing platform, can be widely applied in fields such as secure communication and industrial Internet encryption devices. Based on this, the present application provides a reconfigurable trusted password system, as shown in Figure 1 FIG. 21, the system includes: a control module, a padding circuit, a reusable module, a reconfigurable bus interface, an HMAC engine, a volatile / non-volatile memory, a random number generator, and various national cryptographic algorithm engines. The control module uses a general FPGA (Field-Programmable Gate Array) as the core processor. Among them, the various national cryptographic algorithm engines at least include: SM2 national cryptographic algorithm engine, SM3 national cryptographic algorithm engine, SM4 national cryptographic algorithm engine, and SM9 national cryptographic algorithm engine. The reconfigurable bus interface at least includes: an SPI communication interface, an I 2 2C communication interface, and an Ethernet communication interface.

[0035] The padding circuit is respectively connected to the reusable module and the reconfigurable bus interface. The reusable module and multiple national cryptography algorithm engines are both connected to the control module. The reusable module is connected to multiple national cryptography algorithm engines. The random number generator is connected to multiple national cryptography algorithm engines. The FPGA, as a processor, is connected to the HMAC engine, volatile / non-volatile memory, and random number generator through its internal bus.

[0036] The control module is used to convert the bus interface of the industrial control system to the reconfigurable bus interface using the FPGA protocol and is used to call the corresponding national cryptography algorithm engine. The padding circuit pads the input data of the reconfigurable bus interface based on the national cryptography algorithm engine called by the control module. The random number generator is used to generate security parameters. The security parameters include keys and verification codes. The reusable module is used to encrypt the padded input data based on the security parameters. The control module completes data integrity verification and user identity recognition through the HASH value generated by the HMAC engine. The HMAC engine, volatile / non-volatile memory, and random number generator are all called by the control module through its internal bus to complete data interaction, and finally realize the encryption function of the input data.

[0037] Among them, the national cryptography algorithms include three mainstream national cryptography algorithms, namely SM2, SM3, and SM4, and also include the latest SM9 national cryptography algorithm, etc.

[0038] In another exemplary embodiment of the present application, in order to further improve flexibility and operating efficiency, the padding circuit, reusable module, reconfigurable bus interface, and multiple national cryptography algorithm engines provided above in the present application are all implemented by programming in Verilog HDL hardware description language, and the modules are connected through internal logic circuits.

[0039] Based on the above settings, the control module can effectively reduce the consumption of hardware resources by calling different national cryptography algorithm engines and using the reusable module. The reconfigurability achieved through the reconfiguration of the bus interface and the hardware implementation of national cryptography algorithms can greatly improve the flexibility of the trusted password module.

[0040] In another exemplary embodiment of the present application, in order to be able to flexibly and quickly implement multiple different cryptographic algorithms, through functional decoupling, internal logic circuits such as shift registers and constant registers involved in multiple national cryptography algorithms such as SM2, SM3, SM4, and SM9 are used as reusable components, and a reconfigurable design is carried out for various national cryptography algorithms to form circuit structures with different functions. Based on this, the reusable module adopted in the present application includes: a generation circuit, an arithmetic circuit, a shift register, and a constant register.

[0041] The generation circuit is respectively connected to the arithmetic circuit, the control module, and the padding circuit. The arithmetic circuit is respectively connected to the generation circuit and the shift register. The shift register is connected to the constant register.

[0042] The generation circuit is used to convert the filled input data into bit words based on security parameters. The arithmetic circuit is used to perform relevant calculations such as modulo addition, modulo subtraction, and dot multiplication on the bit words (e.g., 32-bit words) to obtain arithmetic results. The shift register is used to shift and store each arithmetic result. Among them, the shift register is mainly responsible for shifting and storing the data of each step of operation. The constant register is used to store the constant values shared in the operation process of the arithmetic circuit.

[0043] In summary, as a processor, the FPGA is connected to the HMAC engine, volatile / non-volatile memory, and random number generator through its internal bus to achieve data interaction, and through logical control, it calls various national cryptographic algorithms. By using the reconfigurable technology, it simplifies the implementation on the hardware circuit of the national cryptographic algorithm through reusable modules, and realizes the multiplexing of I / O on the bus interface, thereby improving the flexibility of the national cryptographic algorithm, expanding the interface types, and fully adapting to the diversity of industrial control systems and the usage scope of trusted cryptographic modules.

[0044] In an exemplary embodiment, as Figure 2 shown, a reconfigurable trusted password method is provided, including:

[0045] Step 200: Convert the bus interface of the industrial control system to a reconfigurable bus interface using the FPGA protocol.

[0046] Step 201: Invoke the corresponding national cryptographic algorithm engine based on the converted reconfigurable bus interface, and fill the input data of the reconfigurable bus interface based on the invoked national cryptographic algorithm engine.

[0047] Step 202: Generate security parameters. The security parameters include keys and verification codes.

[0048] Step 203: Encrypt the filled input data based on the security parameters.

[0049] As an alternative implementation, the implementation process of step 203 includes:

[0050] Step 2031: Convert the filled input data into bit words based on the security parameters.

[0051] Subsidy 2032: Perform operations on the bit words to obtain arithmetic results, and use the arithmetic results as the encrypted input data.

[0052] Based on the above description, this method uses an FPGA to implement communication protocol conversion, and can implement the conversion of multiple communication buses such as SPI, I2C, and Ethernet with limited I / O hardware resources. In addition, since the reconfigurable design is based on the repeated application of certain hardware resources, the hardware resources it consumes are much less than the sum of the hardware resources occupied by a dedicated module that only implements a certain national cryptographic algorithm. The reconfigurable cryptographic module can not only flexibly implement multiple national cryptographic algorithms, but also effectively save FPGA hardware resources.

[0053] In an exemplary embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.

[0054] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0055] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0056] In each of the embodiments provided in the present application, the database involved may include at least one of a relational database and a non-relational database. The non-relational database may include a distributed database based on blockchain, etc., and is not limited thereto. In each of the embodiments provided in the present application, the processor may be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., and is not limited thereto.

[0057] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0058] Specific examples are used in this article to elaborate on the principles and implementation manners of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A reconfigurable trusted cryptographic system, characterized in that: The reconfigurable trusted cryptographic system includes: a control module, a filling circuit, a reusable module, a reconfigurable bus interface, a random number generator, and a variety of national secret algorithm engines; the control module includes an FPGA; The filling circuit is connected to the reusable module and the reconfigurable bus interface respectively; the reusable module and the multiple national secret algorithm engines are connected to the control module; the reusable module is connected to the multiple national secret algorithm engines; the random number generator is connected to the multiple national secret algorithm engines; The control module is used to convert the bus interface of the industrial control system to the reconfigurable bus interface using the FPGA protocol, and to call the corresponding national secret algorithm engine; the filling circuit fills the input data of the reconfigurable bus interface based on the national secret algorithm engine called by the control module; the random number generator is used to generate security parameters; the security parameters include a key and a verification code; the reusable module is used to encrypt the filled input data based on the security parameters.

2. The reconfigurable trusted cryptographic system according to claim 1, characterized in that: The filling circuit, the reusable module, the reconfigurable bus interface and the various national secret algorithm engines are all implemented through Verilog HDL hardware description language programming.

3. The reconfigurable trusted cryptographic system according to claim 1, characterized in that: The reusable module includes: a generating circuit, an operating circuit, a shift register and a constant register; The generating circuit is connected to the operation circuit, the control module and the filling circuit respectively; the operation circuit is connected to the generating circuit and the shift register respectively; the shift register is connected to the constant register; The generating circuit is used to convert the padded input data into a bit word based on the security parameter; the operating circuit is used to operate on the bit word to obtain an operation result; the shift register is used to shift and store each of the operation results; and the constant register is used to store a constant value shared by the operating circuit during the operation process.

4. The reconfigurable trusted cryptographic system according to claim 3, characterized in that: The operations performed on the bit words include modular addition operations, modular subtraction operations, and dot multiplication operations.

5. The reconfigurable trusted cryptographic system according to claim 1, characterized in that: The reconfigurable bus interface includes: an SPI communication interface, an I 2 C communication interface and Ethernet communication interface.

6. The reconfigurable trusted cryptographic system according to claim 1, characterized in that: The multiple national secret algorithm engines include: SM2 national secret algorithm engine, SM3 national secret algorithm engine, SM4 national secret algorithm engine and SM9 national secret algorithm engine.

7. The reconfigurable trusted cryptographic system according to claim 1, characterized in that: The reconfigurable trusted cryptographic system further comprises: an HMAC engine; The HMAC engine is used to verify the integrity of input data and the identity of the sender of the authentication message based on the verification code.

8. The reconfigurable trusted cryptographic system according to claim 1, characterized in that: The reconfigurable trusted cryptographic system also includes a volatile memory and a non-volatile memory; The volatile memory is used to store data during the FPGA operation process; the non-volatile memory is used to store key data; the key data includes keys, configuration setting parameters, calibration parameters and device identification.

9. A reconstructible trusted cryptographic method, characterized in that: The reconstructable trusted password method comprises: Use FPGA protocol to convert the bus interface of industrial control system to reconfigurable bus interface; Calling a corresponding national secret algorithm engine based on the converted reconfigurable bus interface, and filling input data of the reconfigurable bus interface based on the called national secret algorithm engine; Generate security parameters; the security parameters include a key and a verification code; The padded input data is encrypted based on the security parameter.

10. The reconfigurable trusted password method according to claim 9, characterized in that: Encrypting the padded input data based on the security parameter includes: converting the padded input data into a bit word based on the security parameter; An operation is performed on the bit word to obtain an operation result, and the operation result is used as encrypted input data.