Key management method and device

By non-linear transformation of the standard replacement box to generate the target replacement box, masking the intermediate value in the key expansion process, the problem of insufficient security in side channel attacks in the prior art is solved, and the high security of the round key is achieved.

CN120074800APending Publication Date: 2025-05-30PHYTIUM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510265793.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When existing cryptographic devices face side channel attacks, the security of the key is threatened, especially in finite domain multiplication, when external inputs are all 0, the mask fails, resulting in the risk of key leakage.

Method used

A random masking method based on the replacement box lookup table is adopted to perform nonlinear transformation of the standard replacement box to generate a target replacement box, which is used to mask the intermediate value during the key expansion process, thereby resisting side channel attacks.

Benefits of technology

By randomly masking the intermediate value, ensure that the wheel key does not appear plaintext during the entire expansion process, avoid side channel attacks, and improve the security of the key.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074800A_ABST
    Figure CN120074800A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a key management method, which performs mask protection on key expansion operation, so that intermediate values in the key expansion process are randomly masked, and a round key with a random mask is directly generated, so that in the whole life cycle (key expansion, encryption and decryption), the round key does not have a plaintext, and the key expansion efficiency is improved. And any side channel information related to the round key is not leaked, so that the security of the key in the side channel attack is ensured to the greatest extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer application technologies. Specifically, it relates to encryption technologies in the field of computer application technologies, and more specifically, to a key management method and apparatus. Background Art

[0002] Keys are the core elements to ensure the security and effectiveness of encryption algorithms, and various key generation algorithms are widely used in various cryptographic devices. However, due to the emergence and exploitation of side-channel attack methods, these cryptographic devices are facing a serious threat from side-channel attacks. Summary of the Invention

[0003] Embodiments of this specification provide a key management method and related apparatus to improve the performance of keys against side-channel attacks.

[0004] To achieve the above technical objectives, the embodiments of this specification provide the following technical solutions:

[0005] In a first aspect, an embodiment of this specification provides a key management method, including:

[0006] Responding to a key generation request carrying first input data, and performing multiple rounds of iteration processes to obtain multiple groups of round keys; the first input data includes a random array, a first mask, and a random number data table;

[0007] The iteration process includes:

[0008] Based on a first non-linear transformation result, obtaining the i-th group of round keys, where i is an integer greater than or equal to 0;

[0009] The first non-linear transformation result includes a first result, which is obtained by performing a first non-linear transformation on a first target parameter by a group of target substitution boxes. The first target parameter includes: a first iteration parameter, a second iteration parameter, and the random number data table; the first iteration parameter is obtained based on an initial iteration key and the random array, and the second iteration parameter is obtained based on the random array and the first mask.

[0010] In combination with the first aspect, in some embodiments of the first aspect, the first non-linear transformation includes: determining target elements of each of the target substitution boxes based on element values in the first iteration parameter, where the target elements of the target substitution boxes are obtained based on the j-th element of a standard substitution box and the X-th element in the random number data table, and X is obtained based on j and elements in the second iteration parameter.

[0011] In combination with the first aspect, in some embodiments of the first aspect, the target element of the target substitution box is the X-th element in the target substitution box;

[0012] The target element of the target replacement box is equal to the XOR result of the j-th element of the standard replacement box and the X-th element in the random number data table;

[0013] X is equal to the XOR result of j and the element in the second iteration parameter.

[0014] In combination with the first aspect, in some embodiments of the first aspect, the first non-linear transformation result further includes a second result, which is obtained by performing a second non-linear transformation on the first iteration parameter by the random number data table.

[0015] In combination with the first aspect, in some embodiments of the first aspect, the second non-linear transformation includes:

[0016] Based on the element value of the first iteration parameter, determine the N-th element in the random number data table as the second result.

[0017] In combination with the first aspect, in some embodiments of the first aspect, obtaining the i-th set of round keys based on the first non-linear transformation result includes:

[0018] Perform an XOR operation on the round key obtained in the previous iteration and the first target result to obtain the i-th set of round keys;

[0019] The first target result includes the first linear transformation result of the first result.

[0020] In combination with the first aspect, in some embodiments of the first aspect, it further includes:

[0021] In response to an encryption request carrying second input data, perform an encryption process on the data to be encrypted; the second input data includes a second mask and the random number data table;

[0022] The encryption process includes:

[0023] Based on the i-th encryption iteration result and the second non-linear transformation result, perform multiple rounds of iteration to obtain the (i + n)-th encryption iteration result. The first set of encryption iteration results is obtained based on the data to be encrypted and the second mask, and n is the number of the data to be encrypted;

[0024] Based on the encryption iteration result obtained in the last round and the second mask, obtain the final encryption result;

[0025] The second non-linear transformation result includes a third result, which is obtained by performing the third non-linear transformation on second target parameters by the set of target substitution boxes. The second target parameters include: a third iteration parameter, a fourth iteration parameter, and the random number data table. The third iteration parameter is obtained based on the encrypted iteration result and the i-th round key, and the fourth iteration parameter is obtained based on the second mask and the first mask;

[0026] The second non-linear transformation includes: determining the target elements of the target substitution boxes based on the respective element values in the third iteration parameter. The target elements of the target substitution boxes are obtained based on the j-th element of the standard substitution box and the X-th element in the random number data table, where X is obtained based on j and the elements in the fourth iteration parameter.

[0027] In combination with the first aspect, in some embodiments of the first aspect, when the first non-linear transformation result further includes a second result, the second result is obtained by performing a second non-linear transformation on the first iteration parameter by the random number data table;

[0028] The second non-linear transformation result further includes: a fourth result, which is obtained by performing a fourth non-linear transformation on the third iteration parameter by the random number data table.

[0029] In combination with the first aspect, in some embodiments of the first aspect, it further includes:

[0030] In response to a decryption request carrying third input data, performing a decryption process on the data to be decrypted; the third input data includes a second mask and the random number data table;

[0031] The decryption process includes:

[0032] Based on the i-th decryption iteration result and the third non-linear transformation result, obtaining the (i + n)-th decryption iteration result. The first set of decryption iteration results is obtained based on the data to be decrypted and the second mask, and n is the number of the data to be decrypted;

[0033] Based on the decryption iteration result obtained from the last round of iteration and the second mask, obtaining the final decryption result;

[0034] The third non-linear transformation result includes a fifth result, which is obtained by performing the fifth non-linear transformation on third target parameters by the set of target substitution boxes. The third target parameters include: a fifth iteration parameter, a sixth iteration parameter, and the random number data table. The fifth iteration parameter is obtained based on the decryption iteration result and the i-th round key, and the sixth iteration parameter is obtained based on the second mask and the first mask;

[0035] The third non - linear transformation includes: determining the target elements of the target substitution boxes based on the respective element values in the fifth iteration parameter, where the target element of the target substitution box is obtained based on the j - th element of the standard substitution box and the X - th element in the random number data table, and X is obtained based on j and the elements in the sixth iteration parameter.

[0036] In combination with the first aspect, in some embodiments of the first aspect, when the first non - linear transformation result further includes a second result, the second result is obtained by performing a second non - linear transformation on the first iteration parameter using the random number data table;

[0037] The third non - linear transformation result further includes: a sixth result, which is obtained by performing a sixth non - linear transformation on the fifth iteration parameter using the random number data table.

[0038] In a second aspect, an embodiment of the present specification provides a key management device, including:

[0039] A key expansion module, configured to, in response to a key generation request carrying first input data, perform multiple rounds of iteration processes to obtain multiple groups of round keys; the first input data includes a random number array, a first mask, and a random number data table;

[0040] The iteration process includes:

[0041] Based on the first non - linear transformation result, obtaining the i - th group of round keys, where i is an integer greater than or equal to 0;

[0042] The first non - linear transformation result includes a first result, which is obtained by performing a first non - linear transformation on a first target parameter using a group of target substitution boxes, and the first target parameter includes: a first iteration parameter, a second iteration parameter, and the random number data table; the first iteration parameter is obtained based on an initial iteration key and the random number array, and the second iteration parameter is obtained based on the random number array and the first mask.

[0043] In combination with the second aspect, in some embodiments of the second aspect, the first non - linear transformation includes: determining the target elements of the target substitution boxes based on the respective element values in the first iteration parameter, where the target element of the target substitution box is obtained based on the j - th element of the standard substitution box and the X - th element in the random number data table, and X is obtained based on j and the elements in the second iteration parameter.

[0044] In combination with the second aspect, in some embodiments of the second aspect, the target element of the target substitution box is the X - th element in the target substitution box;

[0045] The target element of the target replacement box is equal to the XOR result of the j-th element of the standard replacement box and the X-th element in the random number data table;

[0046] X is equal to the XOR result of j and the element in the second iteration parameter.

[0047] Combined with the second aspect, in some embodiments of the second aspect, the first non-linear transformation result further includes a second result, which is obtained by performing a second non-linear transformation on the first iteration parameter by the random number data table.

[0048] Combined with the second aspect, in some embodiments of the second aspect, the second non-linear transformation includes:

[0049] Based on the element value of the first iteration parameter, determine the N-th element in the random number data table as the second result.

[0050] Combined with the second aspect, in some embodiments of the second aspect, the key expansion module obtains the i-th group of round keys based on the first non-linear transformation result, specifically for: performing an XOR operation on the round key obtained in the previous iteration and the first target result to obtain the i-th group of round keys;

[0051] The first target result includes the first linear transformation result of the first result.

[0052] Combined with the second aspect, in some embodiments of the second aspect, it further includes:

[0053] A data encryption module, configured to perform an encryption process on the data to be encrypted in response to an encryption request carrying second input data; the second input data includes a second mask and the random number data table;

[0054] The encryption process includes:

[0055] Performing multiple rounds of iteration based on the i-th encryption iteration result and the second non-linear transformation result to obtain the (i + n)-th encryption iteration result, the first group of encryption iteration results is obtained based on the data to be encrypted and the second mask, and n is the number of the data to be encrypted;

[0056] Based on the encryption iteration result obtained in the last round and the second mask, obtain the final encryption result;

[0057] The second non-linear transformation result includes a third result, which is obtained by performing the third non-linear transformation on second target parameters by the set of target substitution boxes. The second target parameters include: a third iteration parameter, a fourth iteration parameter, and the random number data table. The third iteration parameter is obtained based on the encrypted iteration result and the round key of the i-th round. The fourth iteration parameter is obtained based on the second mask and the first mask.

[0058] The second non-linear transformation includes: determining target elements of each of the target substitution boxes based on respective element values in the third iteration parameter. The target element of the target substitution box is obtained based on the j-th element of the standard substitution box and the X-th element in the random number data table, where X is obtained based on j and an element in the fourth iteration parameter.

[0059] In combination with the second aspect, in some embodiments of the second aspect, when the first non-linear transformation result further includes a second result, the second result is obtained by performing a second non-linear transformation on the first iteration parameter by the random number data table.

[0060] The second non-linear transformation result further includes: a fourth result, which is obtained by performing a fourth non-linear transformation on the third iteration parameter by the random number data table.

[0061] In combination with the second aspect, in some embodiments of the second aspect, it further includes:

[0062] A data decryption module, configured to perform a decryption process on data to be decrypted in response to a decryption request carrying third input data. The third input data includes a second mask and the random number data table.

[0063] The decryption process includes:

[0064] Based on the i-th decryption iteration result and the third non-linear transformation result, obtaining the (i + n)-th decryption iteration result. The first set of decryption iteration results is obtained based on the data to be decrypted and the second mask, where n is the number of the data to be decrypted.

[0065] Based on the decryption iteration result obtained from the last round of iteration and the second mask, obtaining the final decryption result.

[0066] The third non-linear transformation result includes a fifth result, which is obtained by performing the fifth non-linear transformation on third target parameters by the set of target substitution boxes. The third target parameters include: a fifth iteration parameter, a sixth iteration parameter, and the random number data table. The fifth iteration parameter is obtained based on the decryption iteration result and the round key of the i-th round. The sixth iteration parameter is obtained based on the second mask and the first mask.

[0067] The third non-linear transformation includes: determining the target elements of the respective target substitution boxes based on the respective element values in the fifth iteration parameter, where the target element of the target substitution box is obtained based on the j-th element of the standard substitution box and the X-th element in the random number data table, and X is obtained based on j and the element in the sixth iteration parameter.

[0068] Combined with the second aspect, in some embodiments of the second aspect, when the first non-linear transformation result further includes a second result, the second result is obtained by performing a second non-linear transformation on the first iteration parameter using the random number data table;

[0069] The third non-linear transformation result further includes: a sixth result, which is obtained by performing a sixth non-linear transformation on the fifth iteration parameter using the random number data table.

[0070] In a third aspect, an embodiment of the present specification further provides a system-on-chip, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, the key management method described above is implemented.

[0071] In a fourth aspect, an embodiment of the present specification further provides a computing device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, the key management method described above is implemented.

[0072] In a fifth aspect, an embodiment of the present specification further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the key management method described above is implemented.

[0073] In a sixth aspect, an embodiment of the present specification provides a computer program product or a computer program, the computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium; a processor of the computer device reads the computer program from the computer-readable storage medium, and when the processor executes the computer program, the steps of the key management method described above are implemented.

[0074] As can be seen from the above technical solution, in the process of key expansion of the encryption key provided by the embodiment of this specification, the i-th round key is obtained based on the first non-linear transformation result, where i is an integer greater than or equal to 0; the first non-linear transformation result includes a first result, and the first result is obtained by performing a first non-linear transformation on a first target parameter by a group of target substitution boxes. The first target parameter includes: a first iteration parameter, a second iteration parameter, and the random number data table; the first iteration parameter is obtained based on an initial iteration key and the random number array, and the second iteration parameter is obtained based on the random number array and the first mask; the first non-linear transformation includes: determining the target elements of the target substitution boxes based on the element values in the first iteration parameter, and the target elements of the target substitution boxes are obtained based on the j-th element of the standard substitution box and the X-th element in the random number data table, where X is obtained based on j and the elements in the second iteration parameter. In this way, the intermediate values (such as the first iteration parameter and the second iteration parameter) in the process of round key expansion are all randomly masked, and a round key carrying the random number data table as a mask is directly generated, so that during the entire round key expansion process, no plaintext of the round key appears, and no side-channel information related to the round key will be leaked, improving the security of the round key in side-channel attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0075] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings.

[0076] Figure 1 Schematic diagram of the architecture of a system on a chip provided by an embodiment of this specification;

[0077] Figure 2 Schematic diagram of the architecture of another system on a chip provided by an embodiment of this specification;

[0078] Figure 3 Schematic flowchart of a key management method provided by an embodiment of this specification;

[0079] Figure 4 Schematic diagram of a key expansion process provided by an embodiment of this specification;

[0080] Figure 5 Schematic diagram of an encryption process provided by an embodiment of this specification;

[0081] Figure 6A schematic diagram of a decryption process provided for an embodiment of this specification;

[0082] Figure 7 A schematic diagram of the structure of a computing device provided for an embodiment of this specification. Detailed implementation manners

[0083] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of this specification shall have the ordinary meanings understood by those of ordinary skill in the field to which this specification belongs. The "first", "second" and similar terms used in the embodiments of this specification do not denote any order, quantity or importance, but are only used to avoid confusion of components.

[0084] Unless otherwise required by the context, throughout this specification, "a plurality of" means "at least two", and "including" is interpreted in an open, inclusive sense, that is, "including, but not limited to". In the description of this specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples", etc., are intended to indicate that specific features, structures, materials or characteristics related to the embodiment or example are included in at least one embodiment or example of this specification. The schematic representations of the above terms do not necessarily refer to the same embodiment or example.

[0085] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without creative efforts shall fall within the protection scope of this specification.

[0086] Overview

[0087] The SM4 (Standardized Mechanism No.4) algorithm can be an algorithm based on the ISO / IEC 18033-3:2010 / AMD1:2021 "Information technology - Security techniques - Encryption algorithms - Part 3: Block ciphers - Amendment 1: SM4" standard. This algorithm is a block algorithm with a block length of 128 bits and a key length of 128 bits. Both the encryption algorithm and the key expansion algorithm adopt a 32-round non-linear iterative structure. In related technologies, during the process of key expansion and generation based on the SM4 algorithm, an attacker may obtain the generated key information by analyzing side-channel information such as the running time of the algorithm and the power consumption of the device during the operation of the algorithm. To enhance the security of the generated key, related technologies have attempted to use finite field multiplication and inversion to mask and unmask the plaintext to achieve the purpose of enhancing the security of the key. However, the inventor's research found that in finite field multiplication, if the multiplier is 0, the result must also be 0. An attacker can make the value after masking the input must be all 0 by setting the external input to all 0, which will cause the mask to completely fail.

[0088] To solve this problem, the inventors provide a random masking method based on look-up tables of substitution boxes (S-Boxes, also known as S-boxes), which avoids the problem that when masking based on finite field multiplication, the input being all 0 results in the output also being all 0. By performing a random transformation on the original substitution box, the purpose of masking all intermediate data during the round key expansion process is achieved, thereby resisting side-channel attacks and improving the security of the round key. Specifically, during the process of expanding the encryption key in the key management method provided by the inventors, based on the first non-linear transformation result, the i-th group of round keys is obtained, where i is an integer greater than or equal to 0; the first non-linear transformation result includes a first result, and the first result is obtained by performing a first non-linear transformation on a first target parameter by a group of target substitution boxes. The first target parameter includes: a first iteration parameter, a second iteration parameter, and the random number data table; the first iteration parameter is obtained based on the initial iteration key and the random number array, and the second iteration parameter is obtained based on the random number array and the first mask; thus, the intermediate values during the round key expansion process (such as the first iteration parameter and the second iteration parameter, both of which are obtained based on the random number array) are masked by the random number array, and the round key carrying the random number data table as a mask is directly generated, such that during the entire round key expansion process, the round key never appears in plaintext, and no side-channel information related to the round key is leaked, enhancing the security of the round key in side-channel attacks. In some embodiments, the first non-linear transformation includes: determining the target elements of each of the target substitution boxes based on the element values in the first iteration parameter, and the target elements of the target substitution boxes are obtained based on the j-th element of the standard substitution box and the M-th element in the random number data table, where j is obtained based on M and the elements in the second iteration parameter.

[0089] Based on the above concept, embodiments of this specification provide a key management method. Below, the key management method provided by the embodiments of this specification will be described exemplarily with reference to the accompanying drawings.

[0090] Exemplary Application Scenarios

[0091] Reference Figure 1 , Figure 1 shows a feasible usage scenario of the key management method. In Figure 1Among them, the system-on-chip may include a Rich Execution Environment (REE) subsystem and a Trusted Execution Environment (TEE) subsystem. The REE subsystem and the TEE subsystem may be implemented based on the same processor core in the processor, or may be implemented based on different processor cores. The REE subsystem and the TEE subsystem provide execution environments with different security levels. The REE subsystem can be used to run system firmware of the computing device, an operating system (OS), and ordinary applications (also referred to as client applications (CA)), etc. The system firmware may be implemented as a Unified Extensible Firmware Interface (UEFI) for desktop, server, and other fields, or may be implemented as a boot loader (U-Boot) for the embedded field. In addition, the basic firmware, the system firmware, and the operating system OS can communicate with the out-of-band control system.

[0092] The TEE subsystem provides an independent and highly secure operating environment, which can be used to process sensitive information and execute critical security tasks. These security tasks include, but are not limited to, authentication, key management, and encryption operations. The TEE subsystem may include a secure operating system (TEE OS) on which the TEE subsystem depends. In some embodiments, trusted applications (TA) may also run in the TEE subsystem. The TEE subsystem may include a cryptographic module, and the keys in the cryptographic module can be managed and maintained by the TEE subsystem. When the keys in the cryptographic module need to be generated or updated, the TEE subsystem can generate keys based on the key management method provided in the embodiments of this specification. In addition, when the TEE subsystem performs other encryption and decryption tasks, the key management method provided in the embodiments of this specification can be used for key generation and use.

[0093] In addition to the system-on-chip as Figure 1 shown, in some embodiments, referring to Figure 2 , the system-on-chip may also include a Secure Element (SE) subsystem. The SE subsystem may also include a cryptographic module, and the keys in the cryptographic module can also be generated based on the key management method provided in the embodiments of this specification. The SE subsystem can be used to store important resources such as root keys, and ensure the security of the important resources stored in the SE subsystem through means such as permission verification and cryptographic techniques.

[0094] Since the key management method provided by the embodiments of this specification can protect the keys used in the processor from the threat of side-channel attacks, it is beneficial to improve the security of the system. The above REE subsystem, TEE subsystem, and SE subsystem can be implemented based on the same processor core or different processor cores. This specification does not limit this and depends on the actual situation.

[0095] It can be understood that Figure 1 and Figure 2 are only used to exemplarily represent the possible application scenarios of the key management method provided by the embodiments of this specification, and are not used to limit any application scenarios of the key management method provided by the embodiments of this specification. In some embodiments, the key management method can also be used for key generation and management in trusted computing devices such as Trusted Platform Module (TPM) and Trusted Cryptography Module (TCM). This specification does not limit this and depends on the actual situation.

[0096] Exemplary Method

[0097] The embodiments of this specification provide a key management method, as Figure 3 shown, including:

[0098] S101: In response to a key generation request carrying first input data, perform multiple rounds of iteration processes to obtain multiple groups of round keys; the first input data includes a random array, a first mask, and a random number data table;

[0099] The iteration process includes:

[0100] S1011: Based on the first non-linear transformation result, obtain the i-th group of round keys, where i is an integer greater than or equal to 0;

[0101] The first non-linear transformation result includes a first result, which is obtained by performing a first non-linear transformation on a first target parameter by a group of target substitution boxes. The first target parameter includes: a first iteration parameter, a second iteration parameter, and the random number data table; the first iteration parameter is based on an initial iteration key and the random array, and the second iteration parameter is based on the random array and the first mask;

[0102] The first non-linear transformation includes: determining the target elements of each target substitution box based on the element values in the first iteration parameter. The target elements of the target substitution box are obtained based on the j-th element of the standard substitution box and the X-th element in the random number data table, and X is based on j and the elements in the second iteration parameter.

[0103] A Substitution box (S-box) is an important component in many block cipher algorithms and is used to provide non-linear transformation. The S-box increases the complexity of the encryption process by mapping the input elements to other elements. In this embodiment, a non-linear transformation is performed on the standard S-box in the SM4 algorithm to obtain a target S-box, and the round keys are generated based on the target S-box. In one embodiment, during the round key generation process, a non-linear transformation is performed on the input based on a set of target S-boxes. Let τ0 represent this non-linear transformation. Then, for the input Input Output in the case of, a set of target S-boxes may include four S-boxes, and the output B can be expressed as:

[0104] B = τ0(A, R, M) = (Sbox0(a0), Sbox1(a1), Sbox2(a2), Sbox3(a3));

[0105] where Sbox0 to Sbox3 can be randomized data tables of 256 bytes (i.e., target S-boxes), Sbox0(a0) represents the a0-th element in the Sbox. For j = 0 to 255, the following relationship exists:

[0106]

[0107] where, represents a set of binary sequence sets with a bit length of 8 for 4 bits, ⊕ represents exclusive OR (XOR), M can be a randomized data table of random numbers. In some embodiments, M can be a randomized data table of 256 bytes of random numbers, and Sbox(j) represents the j-th element in the standard S-box.

[0108] That is, in an alternative embodiment, the target element (e.g., the a 0 -th element) of the target S-box is the X-th element (where X can be equal to, for example, ) in the target S-box;

[0109] the target element of the target S-box is equal to the exclusive OR result of the j-th element (Sbox(j)) in the standard S-box and the X-th element in the randomized data table of random numbers;

[0110] X is equal to the exclusive OR result of j and the element in the second iteration parameter.

[0111] In the above non - linear transformation process, the role of the random number data table is to mask the standard substitution box. Through non - linear transformation, the random number data table is used as a mask and masked into the output B. At the same time, the first mask R attached in A is removed through calculation, so that the output B no longer carries the first mask R. In this way, it is possible to directly obtain the output result with the random number data table M as the mask, avoiding the appearance of the plaintext of the output result during the iteration process.

[0112] When the input data is the first target parameter, this group of target substitution boxes can perform a first non - linear transformation on the first target parameter.

[0113] During the key expansion process, the first mask in the first input data can be a 128 - bit random mask to make up for the insufficient strength of the 32 - bit random mask. The first mask can be expressed as: It can represent a set of 4 binary sequences with a bit length of 32. The random array can be a 32 - bit random array, denoted as R3

[32] . The random number data table can be a 256 - byte random number data table M. Let the encryption key be Mask the encryption key with the first mask to obtain the initial iteration key In one embodiment, the first iteration parameter A1 can be expressed as The second iteration parameter R1 can be expressed as % represents a modulo operation, for example, (i+1)%4 is used to represent the remainder after (i+1) is divided by 4. According to the above introduction, the first result can be expressed as: τ0(A1, R1, M). The first result obtained by performing the first nonlinear transformation on the first target parameter can achieve the purpose of masking the first result. Iteration based on the first nonlinear transformation result including the first result is performed to obtain the i-th group of round keys, which can achieve the purpose of directly obtaining the round key carrying the mask, avoiding the situation where the round key plaintext appears, and increasing the security of the round key. In addition, the nonlinear transformation process avoids the problem that the output of the finite field multiplication is all 0 when the external input is all 0, which is conducive to improving the security of the round key generation process. Further, the intermediate values ​​(such as the first iteration parameter and the second iteration parameter) in the round key expansion process are randomly masked (the first iteration parameter is masked by the random array, and the second iteration parameter is masked by the first mask), avoiding the security risks that may be caused by the leakage of the intermediate results. In an optional embodiment, the first nonlinear transformation result also includes a second result, and the second result is obtained by performing a second nonlinear transformation on the first iteration parameter by the random number data table. The second nonlinear transformation is used to remove the mask (random number data table) added in the first nonlinear transformation in subsequent encryption and decryption calculations, that is, to unmask. Optionally, the second nonlinear transformation includes: based on the element value of the first iteration parameter, determining the Nth element in the random number data table as the second result. For example, in one embodiment, the second nonlinear transformation can be expressed as τ1. Assuming that the input of the second nonlinear transformation is Output Then: B=τ1(A,M)=(M(a 0 ),M(a 1 ),M(a 2 ),M(a 3 )). Among them, M(a k ) represents the ath in the random number data table M k elements, k is an integer from 0 to 3. In an optional embodiment, the obtaining of the i-th group of round keys based on the first nonlinear transformation result includes: performing an XOR process on the round key obtained in the previous iteration with the first target result to obtain the i-th group of round keys; the first target result includes the first linear transformation result of the first result. At the beginning of the first iteration (i.e., when i=0), the round key obtained in the previous iteration can be obtained based on the initial iteration key, and the process may include: Among them, FK i is a fixed parameter pre-set in algorithms such as SM4, (K 0 ,K 1 ,K 2 ,K 3) can be the round key obtained from the previous iteration when i = 0.

[0114] In an alternative embodiment, the first target result further includes a first linear transformation result of the second result.

[0115] For example, during the i-th iteration, the i-th group of round keys rk i ’s generation process can be expressed as:

[0116]

[0117] where L1() represents the first linear transformation in the SM4 algorithm, L1(τ0(A,R,M) represents the first linear transformation result of the first result, and K i represents the i-th initial iteration parameter, and L1(τ1(A,M)) represents the first linear transformation result of the second result.

[0118] In an alternative embodiment, let the input of the first linear transformation output C, then:

[0119]

[0120] where B <<< I represents circularly shifting the input B left by I bits, and I can be 13 or 23.

[0121] Refer to Figure 4 , Figure 4 which shows a schematic diagram of a feasible key expansion process. The encryption key MK to be expanded can be a 128-bit key, the first mask R1 used can be a 128-bit mask, the parameter FK in the SM4 algorithm can be 128 bits, and the schematic diagram of each iteration process is shown in the dashed box. The relevant introductions of parameters such as τ0 and τ1 can refer to the previous descriptions.

[0122] In addition to the key expansion process mentioned above, an embodiment of this specification also provides an encryption process based on the expanded round keys. Specifically, the key management method further includes:

[0123] In response to an encryption request carrying second input data, performing an encryption process on the data to be encrypted; the second input data includes a second mask and the random number data table;

[0124] The encryption process includes:

[0125] Based on the i-th encryption iteration result and the second non-linear transformation result, performing multiple rounds of iteration to obtain the (i + n)-th encryption iteration result. The first group of encryption iteration results is obtained based on the data to be encrypted and the second mask, and n is the number of the data to be encrypted;

[0126] Based on the encrypted iteration result obtained from the last round of iteration and the second mask, obtain the final encrypted result;

[0127] The second non - linear transformation result includes a third result, which is obtained by performing the third non - linear transformation on the second target parameter by the set of target substitution boxes. The second target parameter includes: a third iteration parameter, a fourth iteration parameter, and the random number data table. The third iteration parameter is based on the encrypted iteration result and the i - th round key, and the fourth iteration parameter is based on the second mask and the first mask;

[0128] The second non - linear transformation includes: determining the target elements of each of the target substitution boxes based on the element values in the third iteration parameter. The target element of the target substitution box is obtained based on the j - th element of the standard substitution box and the X - th element in the random number data table, where X is based on j and the elements in the fourth iteration parameter.

[0129] Optionally, when the first non - linear transformation result further includes a second result, the second result is obtained by performing a second non - linear transformation on the first iteration parameter by the random number data table;

[0130] The second non - linear transformation result further includes: a fourth result, which is obtained by performing a fourth non - linear transformation on the third iteration parameter by the random number data table.

[0131] In one embodiment, referring to Figure 5 , Figure 5 shows a feasible encryption process. The second mask R2 can be a 128 - bit random number mask, and the second mask can be expressed as: The random number data table can be expressed as M.

[0132] Let the plaintext input The length of the plaintext X can be 128 bits, and the ciphertext output Round key The first mask used when generating the round key Let the third iteration parameter Fourth iteration parameter Then the process of obtaining the (i + n) - th encrypted iteration result based on the i - th encrypted iteration result and the second non - linear transformation result can be expressed as:

[0133]

[0134] where L0 represents the second linear transformation. In one embodiment, let the input Output C, then:

[0135]

[0136] The third non - linear transformation can refer to the first non - linear transformation in the above text. The difference from the first non - linear transformation is only the input. The transformation process can refer to the introduction of τ0. The fourth non - linear transformation can refer to the second non - linear transformation in the above text. The difference from the second non - linear transformation is only the input. The transformation process can refer to the introduction of τ1.

[0137] In one embodiment, a feasible process for decrypting data is also provided. Specifically, the key management method further includes:

[0138] In response to a decryption request carrying third input data, perform a decryption process on the data to be decrypted; the third input data includes a second mask and the random number data table;

[0139] The decryption process includes:

[0140] Based on the i - th decryption iteration result and the third non - linear transformation result, obtain the (i + n) - th decryption iteration result. The first set of decryption iteration results is obtained based on the data to be decrypted and the second mask, where n is the number of the data to be decrypted;

[0141] The third non - linear transformation result includes a fifth result, which is obtained by performing the fifth non - linear transformation on the third target parameter by a set of target substitution boxes. The third target parameter includes: a fifth iteration parameter, a sixth iteration parameter, and the random number data table. The fifth iteration parameter is based on the decryption iteration result and the i - th round key, and the sixth iteration parameter is based on the second mask and the first mask;

[0142] Based on the decryption iteration result obtained from the last round of iteration and the second mask, obtain the final decryption result;

[0143] The third non - linear transformation includes: determining the target elements of each of the target substitution boxes based on the element values in the fifth iteration parameter. The target elements of the target substitution boxes are obtained based on the j - th element of the standard substitution box and the X - th element in the random number data table, where X is obtained based on j and the elements in the sixth iteration parameter.

[0144] Optionally, when the first non - linear transformation result further includes a second result, the second result is obtained by performing a second non - linear transformation on the first iteration parameter by the random number data table;

[0145] The third non - linear transformation result further includes: a sixth result, which is obtained by performing a sixth non - linear transformation on the fifth iteration parameter by the random number data table.

[0146] In one embodiment, referring to Figure 6 , Figure 6 shows a feasible decryption process. The second mask R2 can be a 128-bit random number mask, and the second mask can be expressed as: The random number data table can be expressed as M.

[0147] Let the ciphertext input The length of the ciphertext can be 128 bits, the plaintext output Round key The first mask used when generating the round key Let the fifth iteration parameter The sixth iteration parameter R6 = (r2 (i+1)%4 ⊕ r2 (i+2)%4 ⊕ r2 (i+3)%4 ⊕ r1 (31– Then, the process of obtaining the (i + n)-th decryption iteration result based on the i-th decryption iteration result and the third non-linear transformation result can be expressed as:

[0148]

[0149] For i 0 - 31

[0150]

[0151] Obtaining the final decryption result based on the decryption iteration result obtained from the last round of iteration and the second mask may include:

[0152] where L0 represents the second linear transformation. In one embodiment, let the input Output C, then:

[0153]

[0154] The fifth non-linear transformation can refer to the first non-linear transformation in the above text. The difference from the first non-linear transformation is only the input. The transformation process can refer to the introduction of τ0. The sixth non-linear transformation can refer to the second non-linear transformation in the above text. The difference from the second non-linear transformation is only the input. The transformation process can refer to the introduction of τ1.

[0155] During the encryption process, the purpose of masking and unmasking the plaintext can be achieved based on the fourth iteration parameter. Specifically, in the XOR operation, if a value is XORed with another value twice, the result remains unchanged. Additionally, the XOR operation conforms to the commutative law, and the calculation order can be exchanged without affecting the result. Based on these two principles, the masking operation is completed through multiple XOR operations at the beginning. When the calculation is completed, the same value as at the beginning is XORed through multiple XOR operations, and the result remains unchanged. R4 is generated by XORing all the masks of the input A3, and naturally, all the masks attached to the input A3 can be removed. The above process can be roughly described as follows: At step L0(τ0(A3, R4, M)), the mask attached to A3 is removed by R4, and at the same time, the mask M is added; at step The output has an additional X' i attached mask; finally, L0(τ1(A3, M)) generates the decoded data of the mask M, removes the mask M, and the generated result only has the mask attached to X' i attached mask. Throughout the process, there is always at least one mask, and no plaintext appears in the intermediate values. In the last step, the mask attached to X' is removed again i to obtain the true final encryption result. For the decryption process, similarly, the purpose of masking and unmasking the plaintext can be achieved based on the sixth iteration parameter.

[0156] In summary, the embodiments of this specification provide a key management method to perform mask protection on the key expansion operation, so that the intermediate values in the key expansion process are all randomly masked, and the round keys with random masks are directly generated, so that during the entire life cycle (key expansion, encryption, decryption), no plaintext appears in the round keys, and no side-channel information related to the round keys will be leaked, ensuring the security of the key in side-channel attacks to the greatest extent.

[0157] Exemplary Device

[0158] In an exemplary embodiment of this specification, a key management device is further provided, including:

[0159] A key expansion module, configured to execute a multi-round iteration process in response to a key generation request carrying first input data to obtain multiple groups of round keys; the first input data includes a random array, a first mask, and a random number data table;

[0160] The iteration process includes:

[0161] Based on the first non-linear transformation result, obtain the i-th group of round keys, where i is an integer greater than or equal to 0;

[0162] The first non - linear transformation result includes a first result, which is obtained by performing a first non - linear transformation on first target parameters by a set of target substitution boxes. The first target parameters include: a first iteration parameter, a second iteration parameter, and the random number data table; the first iteration parameter is obtained based on an initial iteration key and the random number array, and the second iteration parameter is obtained based on the random number array and the first mask;

[0163] The first non - linear transformation includes: determining target elements of each of the target substitution boxes based on the element values in the first iteration parameter. The target element of the target substitution box is obtained based on the j - th element of the standard substitution box and the X - th element in the random number data table, where X is obtained based on j and the elements in the second iteration parameter.

[0164] Optionally, in some embodiments, the target element of the target substitution box is the X - th element in the target substitution box;

[0165] The target element of the target substitution box is equal to the exclusive - OR result of the j - th element of the standard substitution box and the X - th element in the random number data table;

[0166] X is equal to the exclusive - OR result of j and the elements in the second iteration parameter.

[0167] Optionally, in some embodiments, the first non - linear transformation result further includes a second result, which is obtained by performing a second non - linear transformation on the first iteration parameter by the random number data table.

[0168] Optionally, in some embodiments, the second non - linear transformation includes:

[0169] Based on the element values of the first iteration parameter, determining the N - th element in the random number data table as the second result.

[0170] Optionally, in some embodiments, the key expansion module obtains the i - th round key based on the first non - linear transformation result, specifically by: performing an exclusive - OR operation on the round key obtained from the previous iteration and the first target result to obtain the i - th round key;

[0171] The first target result includes the first linear transformation result of the first result.

[0172] Optionally, in some embodiments, it further includes:

[0173] A data encryption module, configured to perform an encryption process on data to be encrypted in response to an encryption request carrying second input data; the second input data includes a second mask and the random number data table;

[0174] The encryption process includes:

[0175] Perform multiple rounds of iteration based on the i-th encryption iteration result and the second non-linear transformation result to obtain the (i + n)-th encryption iteration result. The first set of encryption iteration results is obtained based on the data to be encrypted and the second mask, where n is the number of the data to be encrypted;

[0176] Obtain the final encryption result based on the encryption iteration result obtained from the last round of iteration and the second mask;

[0177] The second non-linear transformation result includes a third result, which is obtained by performing the third non-linear transformation on the second target parameter by a set of target substitution boxes. The second target parameter includes: a third iteration parameter, a fourth iteration parameter, and the random number data table. The third iteration parameter is based on the encryption iteration result and the i-th round key, and the fourth iteration parameter is based on the second mask and the first mask;

[0178] The second non-linear transformation includes: determining the target elements of each of the target substitution boxes based on the element values in the third iteration parameter. The target elements of the target substitution boxes are obtained based on the j-th element of the standard substitution box and the X-th element in the random number data table, where X is based on j and the elements in the fourth iteration parameter.

[0179] Optionally, in some embodiments, when the first non-linear transformation result further includes a second result, the second result is obtained by performing a second non-linear transformation on the first iteration parameter by the random number data table;

[0180] The second non-linear transformation result further includes: a fourth result, which is obtained by performing a fourth non-linear transformation on the third iteration parameter by the random number data table.

[0181] Optionally, in some embodiments, further includes:

[0182] A data decryption module, configured to perform a decryption process on the data to be decrypted in response to a decryption request carrying third input data; the third input data includes a second mask and the random number data table;

[0183] The decryption process includes:

[0184] Based on the i-th decryption iteration result and the third non-linear transformation result, obtain the (i + n)-th decryption iteration result. The first set of decryption iteration results is obtained based on the data to be decrypted and the second mask, where n is the number of the data to be decrypted;

[0185] Obtain the final decryption result based on the decryption iteration result obtained from the last round of iteration and the second mask;

[0186] The third non - linear transformation result includes a fifth result, which is obtained by performing the fifth non - linear transformation on third target parameters by the set of target substitution boxes. The third target parameters include: a fifth iteration parameter, a sixth iteration parameter, and the random number data table. The fifth iteration parameter is obtained based on the decryption iteration result and the round key of the i - th round, and the sixth iteration parameter is obtained based on the second mask and the first mask.

[0187] The third non - linear transformation includes: determining the target elements of each of the target substitution boxes based on the element values in the fifth iteration parameter. The target element of the target substitution box is obtained based on the j - th element of the standard substitution box and the X - th element in the random number data table, where X is obtained based on j and the elements in the sixth iteration parameter.

[0188] Optionally, in some embodiments, when the first non - linear transformation result further includes a second result, the second result is obtained by performing a second non - linear transformation on the first iteration parameter by the random number data table.

[0189] The third non - linear transformation result further includes: a sixth result, which is obtained by performing a sixth non - linear transformation on the fifth iteration parameter by the random number data table.

[0190] For the specific limitations of the key management device, reference can be made to the limitations of the key management method in the above text, which will not be elaborated here. Each module in the above - mentioned key management device can be implemented in whole or in part by software, hardware, and their combination. The above - mentioned modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above - mentioned modules.

[0191] Exemplary Equipment

[0192] An embodiment of the present application also proposes a system - on - chip, including: a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the key management method as described in any of the above - mentioned embodiments is implemented.

[0193] Another embodiment of the present application also proposes a computing device. Refer to Figure 7 As shown, an exemplary embodiment of this specification also provides a computing device, including: a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it executes the steps in the key management method according to various embodiments of this specification described in the above - mentioned embodiments of this specification.

[0194] The internal structure of this computing device can be asFigure 7 As shown, the computing device includes a processor, a memory, a network interface, and an input device connected via a system bus. Among them, the processor of the computing device is used to provide computing and control capabilities. The memory of the computing device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface of the computing device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it performs the steps in the key management method according to various embodiments of this specification described in the above embodiments of this specification.

[0195] The processor may include a main processor, and may also include a baseband chip, a modem, etc.

[0196] The memory stores a program for implementing the technical solution of the present invention, and may also store an operating system and other critical services. Specifically, the program may include program code, and the program code includes computer operation instructions. More specifically, the memory may include a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, a disk memory, a flash memory, etc.

[0197] The processor may be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present invention. It may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0198] The input device may include a device for receiving user input data and information, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer, or a gravity sensor, etc.

[0199] The output device may include a device for allowing output of information to the user, such as a display screen, a printer, a speaker, etc.

[0200] The communication interface may include a device of any transceiver type for communicating with other devices or communication networks, such as Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc.

[0201] The processor executes the program stored in the memory and calls other devices, which can be used to implement each step of any one of the key management methods provided in the foregoing embodiments of the present application.

[0202] The computing device may further include a display component and a voice component. The display component may be a liquid crystal display screen or an electronic ink display screen. The input device of the computing device may be a touch layer covered on the display component, or a button, a trackball or a touchpad provided on the housing of the computing device, or an external keyboard, touchpad or mouse, etc.

[0203] Those skilled in the art can understand that Figure 7 the structure shown in

[0204] Exemplary Computer Program Product and Storage Medium

[0205] is only a block diagram of some structures related to the solution of this specification, and does not constitute a limitation on the computing device to which the solution of this specification is applied. The specific computing device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0206] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of this specification. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0207] In addition, the embodiments of this specification further provide a computer-readable storage medium, on which a computer program is stored, and the computer program is executed by the processor to perform the steps of the key management method according to various embodiments of this specification described in the foregoing "Exemplary Method" section.

[0208] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in this specification can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0209] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0210] The above-described embodiments merely represent several implementation manners of this specification. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the solutions provided by the embodiments of this specification. It should be noted that for those of ordinary skill in the art, without departing from the concept of this specification, several modifications and improvements can still be made, and these all belong to the protection scope of this specification. Therefore, the protection scope of the patent of this specification should be subject to the appended claims.

Claims

1. A key management method, characterized in that: Applied to a processor, the key management method comprises: In response to a key generation request carrying first input data, executing multiple rounds of iterations to obtain multiple sets of round keys; the first input data includes a random number array, a first mask and a random number data table; The iterative process includes: Based on the first nonlinear transformation result, obtaining the i-th group of round keys, where i is an integer greater than or equal to 0; The first nonlinear transformation result includes a first result, which is obtained by performing a first nonlinear transformation on a first target parameter by a set of target replacement boxes, and the first target parameter includes: a first iteration parameter, a second iteration parameter and the random number data table; the first iteration parameter is obtained based on an initial iteration key and the random array, and the second iteration parameter is obtained based on the random array and the first mask.

2. The method according to claim 1, characterized in that The first nonlinear transformation includes: determining the target element of each target replacement box based on the value of each element in the first iteration parameter, the target element of the target replacement box is obtained based on the j-th element of the standard replacement box and the X-th element in the random number data table, and X is obtained based on j and the elements in the second iteration parameter.

3. The method according to claim 1, characterized in that The target element of the target replacement box is the Xth element in the target replacement box; The target element of the target replacement box is equal to the XOR result of the jth element of the standard replacement box and the Xth element in the random number data table; X is equal to the exclusive OR result of j and the elements in the second iteration parameter.

4. The method according to claim 1, characterized in that: The first nonlinear transformation result also includes a second result, and the second result is obtained by performing a second nonlinear transformation on the first iteration parameter by the random number data table.

5. The method according to claim 4, characterized in that The second nonlinear transformation comprises: Based on the element value of the first iteration parameter, determine the Nth element in the random number data table as the second result.

6. The method according to claim 1, characterized in that The obtaining, based on the first nonlinear transformation result, the i-th group of round keys comprises: XOR the round key obtained in the previous iteration with the first target result to obtain the i-th group of round keys; The first target result includes a first linear transformation result of the first result.

7. The method according to any one of claims 1 to 6, characterized in that: Also includes: In response to an encryption request carrying second input data, performing an encryption process on the data to be encrypted; The second input data includes a second mask and the random number data table; The encryption process includes: Perform multiple rounds of iterations based on the i-th encryption iteration result and the second nonlinear transformation result to obtain the i+n-th encryption iteration result, where the first group of encryption iteration results is obtained based on the data to be encrypted and the second mask, and n is the number of the data to be encrypted; Obtaining a final encryption result based on the encryption iteration result obtained in the last round of iteration and the second mask; The second nonlinear transformation result includes a third result, and the third result is obtained by performing a third nonlinear transformation on the second target parameter by the set of target replacement boxes, and the second target parameter includes: a third iteration parameter, a fourth iteration parameter and the random number data table, the third iteration parameter is obtained based on the encryption iteration result and the i-th round key, and the fourth iteration parameter is obtained based on the second mask and the first mask; The second nonlinear transformation includes: determining the target element of each target replacement box based on the value of each element in the third iteration parameter, the target element of the target replacement box is obtained based on the j-th element of the standard replacement box and the X-th element in the random number data table, and X is obtained based on j and the elements in the fourth iteration parameter.

8. The method according to claim 7, characterized in that When the first nonlinear transformation result also includes a second result, the second result is obtained by performing a second nonlinear transformation on the first iteration parameter by the random number data table; The second nonlinear change result also includes: a fourth result, and the fourth result is obtained by performing a fourth nonlinear transformation on the third iteration parameter by the random number data table.

9. The method according to any one of claims 1 to 6, characterized in that: Also includes: In response to a decryption request carrying the third input data, performing a decryption process on the data to be decrypted; The third input data includes a second mask and the random number data table; The decryption process includes: Based on the i-th decryption iteration result and the third nonlinear transformation result, an i+n-th decryption iteration result is obtained, where the first group of decryption iteration results is obtained based on the data to be decrypted and the second mask, and n is the number of the data to be decrypted; Obtaining a final decryption result based on the decryption iteration result obtained in the last round of iteration and the second mask; The third nonlinear transformation result includes a fifth result, and the fifth result is obtained by performing a fifth nonlinear transformation on the third target parameter by the set of target replacement boxes, and the third target parameter includes: a fifth iteration parameter, a sixth iteration parameter and the random number data table, the fifth iteration parameter is obtained based on the decryption iteration result and the i-th round key, and the sixth iteration parameter is obtained based on the second mask and the first mask; The third nonlinear transformation includes: determining the target element of each target replacement box based on the value of each element in the fifth iteration parameter, the target element of the target replacement box is obtained based on the j-th element of the standard replacement box and the X-th element in the random number data table, and X is obtained based on j and the elements in the sixth iteration parameter.

10. The method according to claim 9, characterized in that When the first nonlinear transformation result also includes a second result, the second result is obtained by performing a second nonlinear transformation on the first iteration parameter by the random number data table; The third nonlinear change result also includes: a sixth result, and the sixth result is obtained by performing a sixth nonlinear transformation on the fifth iteration parameter by the random number data table.

11. A key management device, characterized in that: include: A key expansion module, configured to execute a plurality of round iterations in response to a key generation request carrying the first input data to obtain a plurality of sets of round keys; The first input data includes a random number array, a first mask and a random number data table; The iterative process includes: Based on the first nonlinear transformation result, obtaining the i-th group of round keys, where i is an integer greater than or equal to 0; The first nonlinear transformation result includes a first result, which is obtained by performing a first nonlinear transformation on a first target parameter by a set of target replacement boxes, and the first target parameter includes: a first iteration parameter, a second iteration parameter and the random number data table; the first iteration parameter is obtained based on an initial iteration key and the random array, and the second iteration parameter is obtained based on the random array and the first mask.

12. A system on chip, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the key management method according to any one of claims 1 to 10 when executing the computer program.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the key management method according to any one of claims 1 to 10 is implemented.