Integrated Circuit for Encryption, Encryption Device, and Encryption Method
By using pseudo-data group and pseudo-state vector to simulate internal state vector updates when the encryption module does not receive the data group, interfering with power consumption analysis, the problem of security reduction in SHA-3 encryption algorithm under different data group lengths is solved, and hardware resource consumption is reduced through shared cache, improving the security of the encryption algorithm and the efficiency of the integrated circuit.
Patent Information
- Application Number
- CN202510552063.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-04-29
AI Technical Summary
The existing SHA-3 encryption algorithm is easy to analyze when the data group length is different, resulting in a decrease in the security of the encryption algorithm and an increase in the consumption of integrated circuit hardware resources.
When the encryption module does not receive the target data group, it uses the pseudo-data group and the pseudo-state vector to simulate the update of the internal state vector, interferes with power consumption analysis, improves the power consumption randomness of the encryption module, and uses shared cache to reduce hardware resource consumption.
It reduces the exposure risk of encryption algorithms, improves security, reduces the hardware resource consumption of integrated circuits, and reduces the area.
Smart Images

Figure CN120068171B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of encryption technologies, and in particular, to integrated circuits for encryption, encryption devices, and encryption methods. Background Art
[0002] The SHA-3 (Secure Hash Algorithm 3) algorithm has wide applications in aspects such as global hashing, random hashing, stream encryption, and generating message authentication. Although the SHA3 algorithm is a relatively secure encryption algorithm, there are still many methods and means to obtain the key information of encryption, resulting in a decline in the security of the algorithm. For example, the SHA-3 algorithm includes multiple sub-encryption algorithms, and each sub-encryption algorithm has its corresponding data group length. When the data group lengths of the sub-encryption algorithms are different, there will be differences in the operation bandwidth and power consumption of each sub-encryption algorithm during the encryption process. Based on the DPA (Differential Power Analysis) method, the power consumption during the operation of the encryption algorithm can be analyzed, and then the sub-encryption algorithm used can be inferred and key information such as the key can be obtained. Summary of the Invention
[0003] The present application provides an integrated circuit for encryption to at least solve the problem of the decline in the security of the encryption algorithm in the related art.
[0004] The present application provides an integrated circuit for encryption, and the integrated circuit includes:
[0005] A data processing module, configured to obtain data to be encrypted, and divide the data to be encrypted into at least one target data group according to the target data group length corresponding to the target encryption algorithm;
[0006] A data generator, configured to generate a pseudo data group and a pseudo state vector;
[0007] An encryption module, configured to sequentially receive the target data groups sent by the data processing module, and when receiving a target data group, update the internal state vector of the target encryption algorithm according to the received target data group, and when not receiving a target data group, update the pseudo state vector according to the pseudo data group, wherein the operation of updating the pseudo state vector according to the pseudo data group is used to simulate the operation of updating the internal state vector according to the target data group.
[0008] The present application provides an encryption method, and the method includes:
[0009] Receiving a target data group sent by a data processing module, where the target data group is obtained by the data processing module dividing data to be encrypted according to the target data group length corresponding to the target encryption algorithm;
[0010] If the target data group is received, update the internal state vector of the target encryption algorithm according to the received target data group;
[0011] If the target data group is not received, obtain the pseudo data group and the pseudo state vector generated by the data generator, and update the pseudo state vector according to the pseudo data group, wherein the operation of updating the pseudo state vector according to the pseudo data group is used to simulate the operation of updating the internal state vector according to the target data group.
[0012] The present application provides an encryption device, and the encryption device integrates the integrated circuit for encryption as described above.
[0013] In the integrated circuit of some embodiments of the present application, when the encryption module does not receive the target data group, updating the pseudo state vector according to the pseudo data group can make the encryption module still have power consumption when it is in the waiting state, and this power consumption is not the power consumption of the encryption algorithm, which is equivalent to interfering with the power consumption of the encryption module, so that it is no longer possible to infer the encryption algorithm operated by the encryption module based on methods such as DPA. In this way, the exposure risk of the encryption algorithm is reduced, the security of the encryption algorithm is improved, and the problem of the security decline of the encryption algorithm in some technologies is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0015] Figure 1 It is a schematic diagram of a module of an integrated circuit encrypted using the SHA3 algorithm in some technologies;
[0016] Figure 2 It is a schematic diagram of a module of an integrated circuit provided by some embodiments of the present application;
[0017] Figure 3 It is a schematic diagram of a module of a shared cache provided by some embodiments of the present application;
[0018] Figure 4 It is a schematic diagram of the overall data movement provided by some embodiments of the present application;
[0019] Figure 5 It is a schematic flowchart of an encryption method provided by some embodiments of the present application;
[0020] Figure 6 It is a schematic diagram of a module of an encryption device provided by some embodiments of the present application. Detailed implementation manners
[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0022] It should be noted that the orientation or positional relationship indicated by the terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise", "axial", "radial", "circumferential", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present application. The terms "installation", "connection", and "coupling" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. The terms "parallel", "perpendicular", and "equal" include the described situations and situations similar to the described situations, and the range of the similar situations is within the acceptable deviation range, where the acceptable deviation range is determined by those of ordinary skill in the art considering the measurement being discussed and the errors associated with the measurement of a specific quantity (i.e., the limitations of the measurement system). For example, "parallel" includes absolute parallelism and approximate parallelism, where the acceptable deviation range of approximate parallelism can be, for example, within 5° deviation; "perpendicular" includes absolute perpendicularity and approximate perpendicularity, where the acceptable deviation range of approximate perpendicularity can also be, for example, within 5° deviation. "Equal" includes absolute equality and approximate equality, where the acceptable deviation range of approximate equality can be, for example, that the difference between the two equal ones is less than or equal to 5% of either of them. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific situations.
[0023] The SHA3 encryption algorithm consists of a total of six sub - encryption algorithms, namely SHA3 - 224, SHA3 - 256, SHA3 - 384, SHA3 - 512, SHAKE - 128, and SHAKE - 256. Among them, SHA3 - 224, SHA3 - 256, SHA3 - 384, and SHA3 - 512 are hash functions with fixed output lengths, while SHAKE - 128 and SHAKE - 256 are hash functions with expandable output lengths. In the above six sub - encryption algorithms, each sub - encryption algorithm has its corresponding data - group length. The data - group length represents the length of the smallest data unit during the operation of the encryption algorithm. For example, the data - group length corresponding to SHA3 - 224 is 1152 bit, the data - group lengths corresponding to SHA3 - 256 and SHAKE - 256 are 1088 bit, and the data - group length corresponding to SHA3 - 384 is 832 bit. Taking SHA3 - 224 as an example for illustration. When running SHA3 - 224 for data encryption, if the length of the data to be encrypted exceeds 1152 bit, the data to be encrypted needs to be split into multiple groups according to the length of 1152 bit, and the length of each group is 1152 bit. If the length of the data to be encrypted is less than 1152 bit, or the length of the data to be encrypted is not an integer multiple of 1152 bit, padding data (such as 0s and 1s) needs to be added to the data to be encrypted to make the length of the data to be encrypted an integer multiple of 1152 bit.
[0024] Refer to in combination Figure 1 , which is a schematic diagram of the module of the integrated circuit 100 encrypted using the SHA3 algorithm in some technologies. Figure 1 In, the integrated circuit 100 includes a data - processing module 11 and an encryption module 12. The data - processing module 11 is used to split the data to be encrypted according to the data - group length corresponding to the encryption algorithm, and add padding data to the data to be encrypted when the length of the data to be encrypted is not an integer multiple of the data - group length. After completing data splitting and data padding, the data - processing module 11 can sequentially send each data group obtained by splitting to the encryption module 12. The encryption module 12 maintains an initial internal state vector of the encryption algorithm, and the encryption process can include an absorption stage and an extrusion stage. Among them, the absorption stage includes the following steps:
[0025] 1) After the data - processing module 11 sends the first data group to the encryption module 12, the encryption module 12 can perform an exclusive - OR operation on the first data group and the initial internal state vector, and use the result of the exclusive - OR operation as the input of the f function. The output of the f function can be used as the updated internal state vector S1 of the encryption algorithm.
[0026] 2) After the data processing module 11 sends the second data group to the encryption module 12, the encryption module 12 can perform an exclusive OR operation on the second data group and the internal state vector S1, and use the result of the exclusive OR operation as the input of the f function. The output of the f function can be used as the updated internal state vector S2 of the encryption algorithm.
[0027] 3) And so on. After the data processing module 11 sends the nth data group to the encryption module 12, the encryption module 12 can perform an exclusive OR operation on the nth data group and the internal state vector Sn-1, and use the result of the exclusive OR operation as the input of the f function. The output of the f function can be used as the updated internal state vector Sn of the encryption algorithm.
[0028] In the extrusion stage, the encryption module 12 reads a data string of specified bit positions from the internal state vector Sn, and outputs the data string as the encryption result of the data to be encrypted. Specifically, for an encryption algorithm with a fixed output length (such as SHA3-224, SHA3-256), the length of the read data string is equal to the output length of the encryption algorithm; for an encryption algorithm with an extensible output length (such as SHAKE-128, SHAKE-256), the length of the read data string can be specified by the user.
[0029] Although the SHA3 algorithm is a relatively secure encryption algorithm, there are still many methods and means to obtain the key information of encryption, resulting in a decrease in the security of the algorithm. For example, when the data group lengths of the encryption algorithms are different, there are differences in the operation bandwidth and power consumption of each encryption algorithm during the encryption process. Based on the DPA (Differential Power Analysis) method, the power consumption during the operation of the encryption algorithm can be analyzed, and then the encryption algorithm used can be inferred and key information such as the key can be obtained. In addition, because the data group lengths of each encryption algorithm are different, in some integrated circuits, each encryption algorithm can have its corresponding cache area. The data groups of each encryption algorithm are stored in the corresponding cache area, which undoubtedly increases the area of the integrated circuit and increases the consumption of hardware resources.
[0030] In view of this, the present application first provides an integrated circuit for encryption, which can improve the security of the encryption algorithm, reduce the consumption of hardware resources of the integrated circuit, and reduce the area of the integrated circuit. Referring to Figure 2 , it is a schematic diagram of the modules of the integrated circuit 200 provided by some embodiments of the present application. Figure 2 In it, the integrated circuit 200 includes a data processing module 21, a data generator 23, and an encryption module 22.
[0031] The data processing module 21 is used to obtain the data to be encrypted and divide the data to be encrypted into at least one target data group according to the length of the target data group corresponding to the target encryption algorithm. Regarding the division of data groups, reference can be made to Figure 1 the description, which will not be elaborated here.
[0032] The data generator 23 is used to generate a pseudo data group and a pseudo state vector. Among them, the pseudo data group represents the simulated target data group, and the pseudo state vector represents the simulated internal state vector.
[0033] The encryption module 22 is used to sequentially receive the target data groups sent by the data processing module 21. Specifically, the data processing module 21 and the encryption module 22 can be connected through a bus (not shown). Based on the multiplex arbitration usage characteristics of the bus, only when the data processing module 21 is selected by the arbiter, the data processing module 21 is allowed to use the bus and sequentially send the divided target data groups to the encryption module 22. When the data processing module 21 is not selected by the arbiter, the data processing module 21 is not allowed to use the bus and cannot send the target data groups to the encryption module 22. In this case, the encryption module 22 needs to wait. Based on the above principle, the process of the data processing module 21 sending the target data groups to the encryption module 22 may be intermittent. For example, assume that the data processing module 21 divides into 10 target data groups. In the time period from 1 to 5 milliseconds, the data processing module 21 obtains the right to use the bus and sends the first 6 target data groups to the encryption module 22. In the time period from 6 to 7 milliseconds, the data processing module 21 does not obtain the right to use the bus and pauses the sending of the target data groups. In the time period from 8 to 11 milliseconds, the data processing module 21 obtains the right to use the bus and sends the remaining target data groups to the encryption module 22.
[0034] In this embodiment, when the encryption module 22 receives the target data group, it can update the internal state vector of the target encryption algorithm according to the received target data group, and when it does not receive the target data group, it can update the pseudo state vector according to the pseudo data group. Among them, the operation of updating the pseudo state vector according to the pseudo data group is used to simulate the operation of updating the internal state vector according to the target data group. Specifically, for the process of updating the internal state vector of the target encryption algorithm according to the received target data group, reference can be made to Figure 1 the description, which will not be elaborated here. The following focuses on the update principle of the pseudo state vector.
[0035] When updating the pseudo-state vector based on the pseudo-data group, the pseudo-data group can be used to simulate the target data group that the encryption module 22 will receive in the future, and the pseudo-state vector can be used to simulate the current internal state vector of the encryption algorithm. The pseudo-data group and the pseudo-state vector are subjected to an exclusive OR operation, and the operation result is input into the f function to obtain a new pseudo-state vector, which is equivalent to simulating the operation of updating the internal state vector based on the target data group.
[0036] It can be understood that during the process of updating the pseudo-state vector, the encryption module 22 is in an operating state, that is, there is power consumption. However, this power consumption is the power consumption for updating the pseudo-state vector, not the power consumption for updating the internal state vector of the target encryption algorithm, which is equivalent to interfering with the power consumption of the encryption module 22. If one wants to analyze the power consumption of the encryption module 22 based on methods such as DPA and infer the encryption algorithm used based on the analyzed power consumption, the result will surely be inaccurate. In this way, the exposure risk of the encryption algorithm is greatly reduced, and the security of the encryption algorithm is improved.
[0037] In summary, in the technical solutions of some embodiments of the present application, when the encryption module 22 has not received the target data group, updating the pseudo-state vector based on the pseudo-data group can make the encryption module 22 still have power consumption when it is in a waiting state, and this power consumption is not the power consumption of the encryption algorithm, which is equivalent to interfering with the power consumption of the encryption module 22, so that it is no longer possible to infer the encryption algorithm operated by the encryption module 22 based on methods such as DPA. In this way, the exposure risk of the encryption algorithm is reduced, the security of the encryption algorithm is improved, and the problem of the decreased security of the encryption algorithm in some technologies is solved.
[0038] Specifically, when generating the pseudo-data group and the pseudo-state vector, the data generator 23 can generate the pseudo-data group according to the length of the target data group corresponding to the target encryption algorithm, and generate the pseudo-state vector according to the length of the internal state vector of the target encryption algorithm. In this way, it can be ensured that the simulated internal state vector update operation is closer to the real internal state vector update operation, thereby improving the simulation accuracy.
[0039] In some embodiments, the data generator 23 is used to generate the pseudo-data group at multiple time points, and generate the pseudo-state vector at multiple time points, and at least two time points have different pseudo-data groups, and at least two time points have different pseudo-state vectors. The encryption module 22 is used to obtain the latest target pseudo-data group and target pseudo-state vector generated by the data generator 23 when it has not received the target data group, and update the target pseudo-state vector based on the target pseudo-data group.
[0040] Specifically, the data generator 23 can update the pseudo data group every first preset duration and update the pseudo state vector every second preset duration. The first preset duration and the second preset duration can be the same or different, and the present application does not limit this. Additionally, the pseudo data groups generated at different time points can be different, and the pseudo state vectors generated at different time points can be different. In this way, the pseudo data group and the pseudo state vector can be in a dynamic change process, increasing the difficulty of capturing or predicting the pseudo data group and the pseudo state vector, reducing the leakage risk of the pseudo data group and the pseudo state vector, and improving the data security of the pseudo data group and the pseudo state vector.
[0041] In some embodiments, when the target array is not received, the encryption module 22 can update the pseudo state vector every random duration or perform a random number of pseudo state vector update operations. For example, assume that the encryption module 22 waits for 5 milliseconds, and during these 5 milliseconds, 3 updates of the pseudo state vector need to be performed. Then, after the first update, the second update can be performed after an interval of 1 millisecond, and after the second update, the third update can be performed after an interval of 2.5 milliseconds. This randomness of the interval duration increases the power consumption randomness of the encryption module 22 and further improves the inference difficulty of the encryption algorithm. Another example, assume that during the transmission of the target data group, the encryption module 22 waits twice. The duration of the first wait is 4 milliseconds, and the duration of the second wait is 7 milliseconds. Then, during the first wait, the pseudo state vector can be updated three times, and during the second wait, the pseudo state vector can be updated twice. This randomness of the update times can also increase the power consumption randomness of the encryption module 22 and thus improve the inference difficulty of the encryption algorithm.
[0042] It should be noted that in the case of performing multiple updates on the pseudo state vector, the latest pseudo data group and pseudo state vector can be obtained from the data generator 23 each time an update is performed. Of course, the pseudo state vector obtained after the previous update can also be used as the latest pseudo state vector, and the pseudo state vector can be updated based on the latest pseudo data group obtained from the data generator 23. The present application does not limit this.
[0043] In some embodiments, the data generator 23 is further configured to generate a flag bit for characterizing whether to update the pseudo state vector when generating the pseudo data group, and each pseudo data group has its corresponding flag bit. Specifically, assuming that the length of the target data group corresponding to the target encryption algorithm is r, then the length of the pseudo data group can be r + 1 bits. Among these r + 1 bits, 1 bit is the flag bit (such as the first bit), and the remaining r bits are the pseudo data group. The value of the flag bit can be 0 or 1. When the value of the flag bit is equal to 0, it indicates that the pseudo state vector is not updated. When the value of the flag bit is equal to 1, it indicates that the pseudo state vector needs to be updated. When the encryption module 22 updates the target pseudo state vector based on the target pseudo data group, it can first determine the value of the flag bit of the target pseudo data group. If the flag bit of the target pseudo data group is the first value (such as 1), then update the target pseudo state vector according to the target pseudo data group. If the flag bit of the target pseudo data group is the second value (such as 0), then stop updating the target pseudo state vector.
[0044] This operation of updating the pseudo state vector according to the flag bit is equivalent to making a second determination based on the value of the flag bit of the target pseudo data group when the target pseudo data group and the target pseudo state vector are obtained. For example, when the encryption module 22 has not received the target data group, it is assumed that the latest target pseudo data group and the target pseudo state vector generated by the data generator 23 have been obtained. However, if the value of the flag bit of the target pseudo data group is 0, then the target pseudo state vector is not updated. On the contrary, if the value of the flag bit of the target pseudo data group is 1, then the target pseudo state vector can be updated. In this way, the power consumption randomness of the encryption module 22 can be further improved.
[0045] In some embodiments, the data generator 23 is further configured to randomly generate pseudo data groups at each time point according to the length of the target data group, and randomly generate pseudo state vectors at each time point according to the length of the internal state vector. Among them, randomly generating a pseudo data group means that the data in the pseudo data group is random. Similarly, randomly generating a pseudo state vector means that the data in the pseudo state vector is random. When the data in the pseudo data group and the pseudo state vector is random, the power consumption of the encryption module 22 can also be random. In this way, the power consumption randomness of the encryption module 22 can be further improved.
[0046] In some embodiments, the data generator 23 is further configured to randomly generate the flag bit values of each pseudo data group when generating the pseudo data group. In this way, the operation of the encryption module 22 to update the pseudo state vector is random, and the power consumption randomness of the encryption module 22 can be further improved.
[0047] In some embodiments, the encryption module 22 is further configured to save the internal state vector of the target encryption algorithm before updating the target pseudo-state vector, and after updating the target pseudo-state vector, if the target data group is received, perform a specified operation on the received target data group and the saved internal state vector, and use the result of the specified operation as the updated internal state vector of the target encryption algorithm. The specified operation includes an exclusive OR operation, and using the result of the exclusive OR operation as the input of the f function and performing the f function operation.
[0048] Simply put, the target pseudo-data group and the target pseudo-state vector are only used to interfere with the power consumption of the encryption module 22, but do not participate in the update of the internal state vector of the target encryption algorithm. When updating the target pseudo-state vector based on the target pseudo-data group, it is necessary to first save the latest internal state vector of the target encryption algorithm. During the process of updating the target pseudo-state vector, the latest internal state vector of the target encryption algorithm remains unchanged. After the encryption module 22 receives the target data group sent by the data processing module 21 again, the internal state vector of the target encryption algorithm can be updated based on the target data group and the saved latest internal state vector.
[0049] For example, assume that after the encryption module 22 receives the target data group D1, it does not receive any other target data groups after D1. Then the encryption module 22 can perform the following operations in sequence:
[0050] 1) Update the internal state vector of the target encryption algorithm based on the target data group D1 to obtain the updated latest internal state vector T1.
[0051] 2) Save the latest internal state vector T1, and obtain the latest target pseudo-data group D2 and target pseudo-state vector T2 generated by the data generator 23.
[0052] 3) Perform an exclusive OR operation on the target pseudo-data group D2 and the target pseudo-state vector T2, and input the result of the exclusive OR operation into the f function to obtain the latest pseudo-state vector T3.
[0053] 4) In the case where the target data group has not been received yet, continue to obtain the latest target pseudo-data group D3 and target pseudo-state vector T4 generated by the data generator 23.
[0054] 5) Perform an exclusive OR operation on the target pseudo-data group D3 and the target pseudo-state vector T4, and input the result of the exclusive OR operation into the f function to obtain the latest pseudo-state vector T5.
[0055] 6) In the case where the target data group D4 is received, perform an exclusive OR operation on the target data group D4 and the above-saved latest internal state vector T1, and input the result of the exclusive OR operation into the f function to obtain the latest internal state vector T6 corresponding to the target encryption algorithm.
[0056] In the above embodiments, the target pseudo-data group and the target pseudo-state vector do not participate in the update of the internal state vector of the target encryption algorithm, which can avoid the tampering of the data to be encrypted, thereby ensuring the accuracy of encryption.
[0057] The following describes how to reduce the hardware resource consumption of the integrated circuit 200.
[0058] In some embodiments, the integrated circuit 200 supports multiple encryption algorithms, and at least some of the data group lengths corresponding to the encryption algorithms are different. The target encryption algorithm is any one of the multiple encryption algorithms supported by the integrated circuit. For example, the multiple encryption algorithms can be 6 sub-encryption algorithms included in the SHA3 encryption algorithm. The target encryption algorithm can be any one of the 6 sub-encryption algorithms.
[0059] With reference to Figure 2 ... The encryption module 22 may include a shared cache 221, and the capacity of the shared cache 221 matches the maximum data group length corresponding to the multiple encryption algorithms. Specifically, the shared cache 221 can be used to store the data groups obtained after splitting the data to be encrypted. The maximum data group length refers to the maximum value among the data group lengths corresponding to each encryption algorithm. The capacity of the shared cache 221 matching the maximum data group length means that the capacity of the shared cache 221 is equal to the maximum data group length. For example, taking SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE-128, and SHAKE-256 as examples. The data group length corresponding to SHA3-224 is 1152, the data group length corresponding to SHA3-256 is 1088, the data group length corresponding to SHA3-384 is 832, the data group length corresponding to SHA3-512 is 576, the data group length corresponding to SHAKE-128 is 1344, and the data group length corresponding to SHAKE-256 is 1088. Then, the maximum data group length corresponding to the multiple encryption algorithms is 1152.
[0060] In this embodiment, since the capacity of the shared cache 221 is equal to the maximum data group length, when performing encryption operations based on any encryption algorithm in the integrated circuit 200, the shared cache 221 can at least store one data group corresponding to the encryption algorithm. That is, the shared cache 221 can be applicable to any encryption algorithm supported by the integrated circuit 200. In this way, it is not necessary to separately set cache areas for each encryption algorithm in the integrated circuit 200, achieving the purpose of reducing hardware resource consumption and reducing the area of the integrated circuit 200.
[0061] Based on the above description, the data processing module 21 is further configured to save the target data group into the shared cache 221, and the encryption module 22 is further configured to read the target data group from the shared cache 221. Specifically, the data processing module 21 can save the target data group into the shared cache 221 through the bus. When the encryption module 22 detects that data is placed in the shared cache 221, it indicates that the target data group is received.
[0062] In some embodiments, when the data processing module 21 saves the target data group into the shared cache 221 through the bus, it can transmit the target data group according to the data bit width supported by the bus. Among them, the data bit width refers to the amount of data that the bus can transmit in a single clock cycle, and its unit is bit. The data bit width usually includes 8bit, 16bit, 32bit, 64bit, 128bit, etc. Since the minimum length of the target data group is 576bit (much larger than the data bit width of the bus), the data processing module 21 can divide the target data group into multiple sub-data groups according to the data bit width of the bus and save the target data group into the shared cache 221 in multiple clock cycles.
[0063] Based on the above description, with reference to Figure 3 , a schematic diagram of the module of the shared cache 221 provided in some embodiments of the present application. Figure 3 In, the shared cache 221 includes multiple cache units, and the capacity of each cache unit can be the data bit width of the bus. The data processing module 21 can write the target data group from the first cache end P1 of the shared cache 221, and the data written in each clock cycle can fill one cache unit. The data written into the cache unit can gradually move towards the second cache end P2 of the shared cache 221. In this way, the cache unit at the first cache end P1 can be emptied to facilitate the data processing module 21 to write new data. For example Figure 3 In, in the first clock cycle, the data processing module 21 writes the data M1 into the first cache unit at the first cache end P1; in the second clock cycle, the data processing module 21 moves the data M1 to the next cache unit along the direction pointing to the second cache end P2, and writes the data M2 into the first cache unit at the first cache end P1, and so on. After multiple fillings, the data M1 will be moved to the first cache unit at the second cache end P2. In this way, the encryption module 22 can start to read the target data group from the second cache end P2 of the shared cache 221.
[0064] For ease of understanding, assume that the maximum data group length is 1344bit (i.e., the length of the shared cache 221 is 1344bit), and the data bit width of the bus is 64bit (i.e., the capacity of a single cache unit is 64bit). Then, after 21 fillings, the shared cache 221 can be filled.
[0065] Still taking the maximum data group length = 1344 bit and the data bit width of the bus = 64 bit as an example. Referring to Figure 3 . It can be understood that if the data group length corresponding to the target encryption algorithm is 1344 bit, then after 21 times of filling by the data processing module 21, the transmission of a target data group can be exactly completed, and the data M1 exactly reaches the first cache unit of the second cache end P2. In this case, when the encryption module 22 detects that there is data in the first cache unit of the second cache end P2, it means that the data processing module 21 has completed the transmission of a target data group, and thus can start reading the data in the first cache unit of the second cache end P2 from the 21st clock cycle. After the data in the first cache unit of the second cache end P2 is read, the data in the second cache unit of the second cache end P2 can be moved to the first cache unit of the second cache end P2. In this way, within the 21st to 41st clock cycles, the encryption module 22 can successively read the data in the first cache unit of the second cache end P2, and summarize the data read within the 21st to 41st clock cycles to obtain the first target data group transmitted by the data processing module 21. For example, after the encryption module 22 reads the data M1 in the 21st clock cycle, the data M2 can be moved to the first cache unit of the second cache end P2, and then within the 22nd clock cycle, the encryption module 22 can continue to read the data in the first cache unit of the second cache end P2 to obtain the data M2. And so on. Similar to the 21st to 41st clock cycles, the encryption module 22 can summarize the data read within the 42nd to 62nd clock cycles to obtain the second target data group transmitted by the data processing module 21. And so on.
[0066] It should be noted that the above description is based on the assumption that the data processing module 21 can be selected by the arbiter and obtain the bus access right in each clock cycle. If the data processing module 21 does not obtain the bus access right in some clock cycles, then the above clock cycles may be discontinuous. For example, assume that the data processing module 21 obtains the bus access right within the 1st to 3rd and 6th to 23rd clock cycles, then the data processing module 21 will not perform data transmission within the 4th and 5th clock cycles, and moreover, within the 4th and 5th clock cycles, the data in the cache unit will not move to the second cache end P2. In this way, the data M1 needs to be transmitted to the first cache unit of the second cache end P2 in the 23rd clock cycle, and the encryption module 22 can start reading the data from the 23rd clock cycle.
[0067] Further, the above description is for the case where the data group length corresponding to the target encryption algorithm is equal to the maximum data group length. The following describes the case where the data group length corresponding to the target encryption algorithm is less than the maximum data group length.
[0068] Continue to refer to Figure 3 . When the data group length corresponding to the target encryption algorithm is less than the maximum data group length, it means that after 21 times of filling by the data processing module 21, the transmission of more than one target data group has been completed. For example, the transmission of 1.5 target data groups has been completed, or the transmission of 2 target data groups has been completed. In other words, when the data processing module 21 completes the transmission of one target data group, the data M1 has not reached the first cache unit of the second cache end P2. In this way, the encryption module 22 cannot determine whether the data processing module 21 has completed the transmission of one target data group by monitoring whether there is data in the first cache unit of the second cache end P2.
[0069] In view of this, in some embodiments, if the data group length corresponding to the target encryption algorithm is less than the maximum data group length, the data processing module 21 is further configured to move the target data group in the direction pointing to the second cache end P2 after writing the target data group into the first cache end P1. Specifically, when moving the target data group in the direction pointing to the second cache end P2, the target data group is moved as a whole to the second cache end P2, and the highest-bit data of the target data group is located in the first cache unit of the second cache end P2. For easy understanding, take the maximum data group length = 1344 bit, the data bit width of the bus = 64 bit, and the data group length corresponding to the target encryption algorithm = 128 bit as an example. Combine and refer to Figure 3 . When the data group length corresponding to the target encryption algorithm is 128 bit, it means that after two data fillings in the shared cache 221 by the data processing module 21, one target data group is written, that is, the transmission of one target data group is completed in the second clock cycle, and the first target data group is composed of the data M1 and the data M2. However, Figure 3 it can be seen that in the second clock cycle, the data M1 has not moved to the first cache unit of the second cache end P2. In this case, the encryption module 22 will not perform data reading. In view of this, in the third clock cycle, the data M1 and the data M2 can be moved as a whole to the first and second cache units of the second cache end P2, and the Figure 4 shown data storage schematic diagram is obtained. In this way, when the encryption module 22 monitors that there is data in the first cache unit of the second cache end P2, it can perform data reading.
[0070] The present application also provides an encryption method. The encryption method can be applied to Figure 2 the encryption module 22 inFigure 5 , which is a schematic flowchart of the encryption method provided for some embodiments of the present application. Figure 5 In [it], the encryption method includes the following steps:
[0071] Step S501, receive the target data group sent by the data processing module, where the target data group is obtained by the data processing module dividing the data to be encrypted according to the target data group length corresponding to the target encryption algorithm.
[0072] Step S502, if the target data group is received, update the internal state vector of the target encryption algorithm according to the received target data group.
[0073] Step S503, if the target data group is not received, obtain the pseudo data group and pseudo state vector generated by the data generator, and update the pseudo state vector according to the pseudo data group, where the operation of updating the pseudo state vector according to the pseudo data group is used to simulate the operation of updating the internal state vector according to the target data group.
[0074] In some embodiments, the data generator is used to generate pseudo data groups at multiple time points, and generate pseudo state vectors at multiple time points, and there are at least two different pseudo data groups at different time points, and there are at least two different pseudo state vectors at different time points;
[0075] The above-mentioned obtaining the pseudo data group and pseudo state vector generated by the data generator, and updating the pseudo state vector according to the pseudo data group includes:
[0076] Obtain the latest target pseudo data group and target pseudo state vector generated by the data generator;
[0077] Update the target pseudo state vector according to the target pseudo data group.
[0078] In some embodiments, the data generator is further used to generate a flag bit for indicating whether to update the pseudo state vector when generating the pseudo data group, and each pseudo data group has its own corresponding flag bit;
[0079] Updating the target pseudo state vector according to the target pseudo data group includes:
[0080] If the flag bit of the target pseudo data group is the first value, update the target pseudo state vector according to the target pseudo data group;
[0081] If the flag bit of the target pseudo data group is the second value, stop updating the target pseudo state vector.
[0082] In some embodiments, the pseudo data groups and pseudo state vectors at each time point are randomly generated by the data generator;
[0083] And / or, the flag bit values corresponding to each pseudo-data group are randomly generated by the data generator.
[0084] In some embodiments, the encryption method further includes:
[0085] Before updating the target pseudo-state vector, save the internal state vector of the target encryption algorithm;
[0086] After updating the target pseudo-state vector, if the target data group is received, perform a specified operation on the received target data group and the saved internal state vector, and use the result of the specified operation as the updated internal state vector of the target encryption algorithm.
[0087] For the related description of the encryption method, reference can be made to the description of the above integrated circuit, which will not be elaborated here.
[0088] Refer to Figure 6 , which is a schematic diagram of the modules of the encryption device 600 provided by some embodiments of the present application. Figure 6 In, the encryption device 600 includes the above integrated circuit 200.
[0089] Since the encryption device 600 includes the integrated circuit 200, it has the same beneficial effects as the integrated circuit 200, which will not be elaborated here.
[0090] The above has introduced in detail an integrated circuit, an encryption method, and an encryption device for encryption provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. An integrated circuit for encryption, characterized in that, The integrated circuit includes: A data processing module, configured to obtain data to be encrypted and divide the data to be encrypted into at least one target data group according to the length of a target data group corresponding to a target encryption algorithm; A data generator, configured to generate a pseudo data group and a pseudo state vector; An encryption module, configured to sequentially receive the target data groups sent by the data processing module, and when a target data group is received, update an internal state vector of the target encryption algorithm according to the received target data group, and when no target data group is received, update the pseudo state vector according to the pseudo data group, wherein the operation of updating the pseudo state vector according to the pseudo data group is used to simulate the operation of updating the internal state vector according to the target data group.
2. The integrated circuit according to claim 1, wherein The data generator is configured to generate a pseudo data group at multiple time points and generate a pseudo state vector at multiple time points, and there are at least two different pseudo data groups at at least two time points, and there are at least two different pseudo state vectors at at least two time points; The encryption module is configured to, when no target data group is received, obtain the latest target pseudo data group and target pseudo state vector generated by the data generator, and update the target pseudo state vector according to the target pseudo data group.
3. The integrated circuit according to claim 2, wherein The data generator is further configured to generate a flag bit for indicating whether to update the pseudo state vector when generating the pseudo data group, and each pseudo data group has its own corresponding flag bit; The encryption module is configured to update the target pseudo state vector according to the following logic: If the flag bit of the target pseudo data group is a first value, update the target pseudo state vector according to the target pseudo data group; If the flag bit of the target pseudo data group is a second value, stop updating the target pseudo state vector.
4. The integrated circuit according to claim 3, wherein The data generator is further configured to randomly generate a pseudo data group at each time point according to the length of the target data group, and randomly generate a pseudo state vector at each time point according to the length of the internal state vector; And / or, the data generator is further configured to randomly generate the flag bit value of each pseudo data group when generating the pseudo data group.
5. The integrated circuit according to claim 2, wherein The encryption module is further configured to save the internal state vector of the target encryption algorithm before updating the target pseudo state vector, and after updating the target pseudo state vector, if a target data group is received, perform a specified operation on the received target data group and the saved internal state vector, and use the result of the specified operation as the updated internal state vector of the target encryption algorithm.
6. The integrated circuit according to claim 1, characterized in that, The integrated circuit supports multiple encryption algorithms, and at least some of the data group lengths corresponding to the encryption algorithms are different, and the target encryption algorithm is any one of the multiple encryption algorithms supported by the integrated circuit; The encryption module includes a shared cache, and the capacity of the shared cache matches the maximum data group length corresponding to the multiple encryption algorithms; The data processing module is further configured to save the target data group to the shared cache, and the encryption module is further configured to read the target data group from the shared cache.
7. The integrated circuit according to claim 6, wherein, The shared cache is connected to the data processing module through a bus. The shared cache includes a plurality of cache units, and the capacity of each cache unit is the data bit width of the bus; The data processing module is further configured to write a target data group from a first cache end of the shared cache, and the encryption module is further configured to read the target data group from a second cache end of the shared cache.
8. The integrated circuit according to claim 7, characterized in that, If the length of the data group corresponding to the target encryption algorithm is less than the maximum data group length, after writing the target data group at the first cache end, the data processing module is further configured to move the target data group in a direction pointing to the second cache end.
9. The integrated circuit according to claim 1, wherein, If the data length of the data to be encrypted is not an integer multiple of the length of the target data group, the data processing module is further configured to add padding data to the last target data group obtained by cutting, so that the data length of the data to be encrypted is an integer multiple of the length of the target data group.
10. An encryption method, characterized in that, The method includes: Receiving a target data group sent by a data processing module, where the target data group is obtained by splitting data to be encrypted by the data processing module according to the length of a target data group corresponding to a target encryption algorithm; If a target data group is received, updating an internal state vector of the target encryption algorithm according to the received target data group; If a target data group is not received, obtaining a pseudo data group and a pseudo state vector generated by a data generator, and updating the pseudo state vector according to the pseudo data group, where the operation of updating the pseudo state vector according to the pseudo data group is used to simulate the operation of updating the internal state vector according to the target data group.
11. The method according to claim 10, wherein The data generator is configured to generate pseudo data groups at multiple time points, and generate pseudo state vectors at multiple time points, and at least two time points have different pseudo data groups, and at least two time points have different pseudo state vectors; The obtaining the pseudo data group and the pseudo state vector generated by the data generator, and updating the pseudo state vector according to the pseudo data group includes: Obtaining the latest target pseudo data group and target pseudo state vector generated by the data generator; Updating the target pseudo state vector according to the target pseudo data group.
12. The method according to claim 11, wherein The data generator is further configured to generate a flag bit for indicating whether to update the pseudo state vector when generating the pseudo data group, and each pseudo data group has its own corresponding flag bit; The updating the target pseudo state vector according to the target pseudo data group includes: If the flag bit of the target pseudo data group is a first value, updating the target pseudo state vector according to the target pseudo data group; If the flag bit of the target pseudo data group is a second value, stopping updating the target pseudo state vector.
13. The method according to claim 12, wherein The pseudo data groups and pseudo state vectors at each time point are randomly generated by the data generator; And / or, the flag bit values corresponding to each pseudo data group are randomly generated by the data generator.
14. The method according to claim 11, wherein The method further includes: Before updating the target pseudo state vector, saving the internal state vector of the target encryption algorithm; After updating the target pseudo-state vector, if a target data group is received, a specified operation is performed on the received target data group and the saved internal state vector, and the result of the specified operation is used as the updated internal state vector of the target encryption algorithm.
15. An encryption device, characterized in that, The encryption device integrates the integrated circuit for encryption as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Data encryption method and device, storage medium and electronic equipment
CN118354147A
Hardware attack detection method and device, storage medium and product
CN119885169A