Encryption / decryption device

By introducing a verification mechanism in the encryption/decryption device, the correctness of multiplication inverse elements and binary field multiplication operations is solved, and the error problem in the prior art is difficult to effectively verify the execution of the high-order encryption standard AES, achieving higher security and reliability.

CN120165838APending Publication Date: 2025-06-17NUVOTON
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411773366.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-14
Filing Date
2024-12-04
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Existing encryption/decryption devices are difficult to effectively verify the correctness of the high-order encryption standard AES during execution, especially in bitgroup replacement conversion and mixed line operations, where errors may exist and are not detected.

Method used

An encryption/decryption device is designed, including a bit group replacement unit, a mixed row unit, a round key addition unit and a verification unit. By detecting whether the operation is incorrect when the input value of the multiplication inverse element is 0x0, and verifying whether the binary field multiplication operation in the mixed row and the inverse mixed row operation is correct.

Benefits of technology

It realizes effective verification of the encryption/decryption process, ensures the correct execution of the high-order encryption standard AES, and improves the security and reliability of the encryption device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165838A_ABST
    Figure CN120165838A_ABST
Patent Text Reader

Abstract

The invention discloses an encryption / decryption device. The encryption / decryption device comprises a bit group replacement / anti-bit group replacement unit, a mixed row / anti-mixed row unit, a first verification unit and a controller, the bit group replacement / anti-bit group replacement unit converts an input state array to generate an output state array. The hybrid line / inverse hybrid line unit performs hybrid line operation / inverse hybrid line operation on the output state array to generate a hybrid / inverse hybrid array, wherein the hybrid line operation / inverse hybrid line operation comprises binary field multiplication operation. The first verification unit determines whether the output state array and the hybrid / anti-hybrid array conform to the corresponding relationship, and generates a first verification signal. The controller determines whether the binary field multiplication performed by the hybrid row / inverse hybrid row unit is correct according to the first verification signal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an encryption / decryption device based on the Advanced Encryption Standard (AES), and particularly to an encryption / decryption device for verifying whether the Advanced Encryption Standard performs correct encryption / decryption. Background Art

[0002] In cryptography, the term "encryption" refers to the process of protecting the content by changing plaintext into ciphertext that is difficult to understand. Only a device with a decryption method can restore the ciphertext to normal readable content through the decryption process. Ideally, only authorized personnel can read the information conveyed by the ciphertext. Encryption itself cannot prevent the interception of information transmission, but can prevent the interceptor from understanding the content of the information.

[0003] In order to prevent the ciphertext from being leaked due to an attack on the encryption / decryption device, it is necessary to verify the correctness of each encryption step and decryption step, so as to ensure the security of the encryption / decryption device. Summary of the Invention

[0004] The present invention provides an encryption / decryption device with a verification mechanism, which is applicable to any implementation manner of byte substitution transformation. Although there are many implementation manners of byte substitution transformation or inverse byte substitution transformation, the verification mechanism of the encryption / decryption device of the present invention can detect whether an error occurs in the operation when the input value of the multiplicative inverse is 0x0, and can detect whether an error occurs in the binary field multiplication operation in the mix columns operation and the inverse mix columns operation. In addition, the verification mechanism proposed by the present invention can also protect the decryption program to ensure the security of the encrypted or decrypted data.

[0005] In view of this, the present invention provides an encryption device, including a byte substitution unit, a mix columns unit, an add round key unit, a first verification unit, and a controller. The byte substitution unit converts an input state array to generate an output state array. The mix columns unit performs a mix columns operation on the output state array to generate a mixed array, where the mix columns operation includes a multiplication operation. The add round key unit performs a binary field addition operation on the mixed array and a round key to generate a result data. The first verification unit determines whether the output state array and the mixed array conform to a corresponding relationship, and generates a first verification signal. The controller determines whether the binary field multiplication operation performed by the mix columns unit is correct according to the first verification signal.

[0006] The present invention further provides a decryption device, comprising an inverse byte substitution unit, an inverse mix row unit, a round key addition unit, a first verification unit, and a controller. The above-mentioned inverse byte substitution unit performs a conversion on an input state array to generate an output state array. The above-mentioned inverse mix row unit performs an inverse mix row operation on the above-mentioned output state array to generate an inverse mix array, wherein the above-mentioned inverse mix row operation includes a multiplication operation. The above-mentioned round key addition unit performs a binary field addition operation on the above-mentioned inverse mix array and a round key to generate a result data. The above-mentioned first verification unit determines whether the above-mentioned output state array and the above-mentioned inverse mix array conform to a corresponding relationship, and generates a first verification signal. The above-mentioned controller determines whether the above-mentioned binary field multiplication operation performed by the above-mentioned inverse mix row unit is correct according to the above-mentioned first verification signal.

[0007] The present invention further provides an encryption device, comprising a byte substitution unit, a mix row unit, a round key addition unit, a second verification unit, and a controller. The above-mentioned byte substitution unit performs a conversion on an input state array to generate an output state array. The above-mentioned mix row unit performs a mix row operation on the above-mentioned output state array to generate a mix array. The above-mentioned round key addition unit performs a binary field addition operation on the above-mentioned mix array and a round key to generate a result data. The above-mentioned second verification unit verifies the corresponding relationship between the above-mentioned input state array and the above-mentioned output state array, and generates a second verification signal. The above-mentioned controller determines whether the above-mentioned conversion performed by the above-mentioned byte substitution unit is correct according to the above-mentioned second verification signal.

[0008] The present invention further provides a decryption device, comprising an inverse byte substitution unit, an inverse mix row unit, a round key addition unit, a second verification unit, and a controller. The above-mentioned inverse byte substitution unit performs a conversion on an input state array to generate an output state array. The above-mentioned inverse mix row unit performs an inverse mix row operation on the above-mentioned output state array to generate an inverse mix array. The above-mentioned round key addition unit performs a binary field addition operation on the above-mentioned inverse mix array and a round key to generate a result data. The above-mentioned second verification unit verifies the corresponding relationship between the above-mentioned input state array and the above-mentioned output state array, and generates a second verification signal. The above-mentioned controller determines whether the above-mentioned conversion performed by the above-mentioned inverse byte substitution unit is correct according to the above-mentioned second verification signal.

[0009] The present invention further provides an encryption device, including a byte substitution unit, a mix column unit, a round key addition unit, a third verification unit, and a controller. The byte substitution unit converts an input state array to generate an output state array. The mix column unit performs a mix column operation on the output state array to generate a mixed array. The round key addition unit performs a binary field addition operation on the mixed array and a round key to generate a result data. The third verification unit verifies the correspondence between the result data and the output state array to generate a third verification signal. The controller determines whether the mix column operation performed by the mix column unit and the binary field addition operation performed by the round key addition unit are correct according to the third verification signal.

[0010] The present invention further provides a decryption device, including an inverse byte substitution unit, an inverse mix column unit, a round key addition unit, a third verification unit, and a controller. The inverse byte substitution unit converts an input state array to generate an output state array. The inverse mix column unit performs an inverse mix column operation on the output state array to generate an inverse mixed array. The round key addition unit performs a binary field addition operation on the inverse mixed array and a round key to generate a result data. The third verification unit verifies the correspondence between the result data and the output state array to generate a third verification signal. The controller determines whether the inverse mix column operation performed by the inverse mix column unit and the binary field addition operation performed by the round key addition unit are correct according to the third verification signal. Brief Description of the Drawings

[0011] Figure 1 Showing a block diagram of the encryption / decryption device according to an embodiment of the present invention;

[0012] Figure 2 Showing a block diagram of the byte substitution / inverse byte substitution unit according to an embodiment of the present invention;

[0013] Figure 3 Showing a schematic diagram of the first verification unit according to an embodiment of the present invention;

[0014] Figure 4 Showing a schematic diagram of the divide-by-two circuit according to an embodiment of the present invention;

[0015] Figure 5 Showing a schematic diagram of the second verification unit according to an embodiment of the present invention;

[0016] Figure 6 Showing a schematic diagram of the third verification unit according to an embodiment of the present invention;

[0017] Figure 7 Displays a block diagram of an encryption / decryption device according to another embodiment of the present invention.

[0018] Symbol Explanation

[0019] 100, 700: Encryption / Decryption Device

[0020] 110: Includes a bus interface

[0021] 120: Input / Output Buffer

[0022] 130: Controller

[0023] 140: Encryption / Decryption Circuit

[0024] 141: Key Expansion Unit

[0025] 142: Inverse Mixing Row Unit

[0026] 143: Column Shift / Inverse Column Shift Unit

[0027] 144: Register

[0028] 145, 200: Byte Substitution / Inverse Byte Substitution Unit

[0029] 146: Mixing Row / Inverse Mixing Row Unit

[0030] 147: Round Key Addition Unit

[0031] 210: Inverse Affine Transformation Unit

[0032] 220: Multiplicative Inverse Element Unit

[0033] 230: Affine Transformation Unit

[0034] 300, 701: First Verification Unit

[0035] 301: First Divide-by-Two Circuit

[0036] 302: Second Divide-by-Two Circuit

[0037] 303: Third Divide-by-Two Circuit

[0038] 400: Divide-by-Two Circuit

[0039] 500, 702: Second Verification Unit

[0040] 501: First Numerical Generator

[0041] 502: Second Numerical Generator

[0042] 503: Inverse Affine Transformation Unit

[0043] 504: Multiplier

[0044] 600,703: Third Verification Unit

[0045] 601: First Bit Group Division Device

[0046] 602: Second Bit Group Division Device

[0047] 603: Third Bit Group Division Device

[0048] 604: First Logic Operation Unit

[0049] 605: Second Logic Operation Unit

[0050] 606: Third Logic Operation Unit

[0051] 607: Fourth Logic Operation Unit

[0052] MUX0: First Multiplexer

[0053] MUX1: Second Multiplexer

[0054] MUX2: Third Multiplexer

[0055] MUX3: Fourth Multiplexer

[0056] MUX4: Fifth Multiplexer

[0057] MUX5: Sixth Multiplexer

[0058] MUX6: Seventh Multiplexer

[0059] DIN: Input Data

[0060] BUS: Bus

[0061] KEY: Key

[0062] DOUT: Encrypted / Decrypted Data

[0063] RK: Round Key

[0064] ARK: Result Data

[0065] SR: Shift Data

[0066] SBI,ISBI,SI: Input Status Array

[0067] SBO,ISBO,SO: Output Status Array

[0068] CMP1: First Comparator

[0069] CMP2: Second Comparator

[0070] CMP3: The third comparator

[0071] CMP4: The fourth comparator

[0072] CMP5: The fifth comparator

[0073] CMP6: The sixth comparator

[0074] CMP7: The seventh comparator

[0075] LG: Logic gate

[0076] M: Multiplicand array

[0077] MX2: Multiply-by-two array

[0078] MX4: Multiply-by-four array

[0079] MX8: Multiply-by-eight array

[0080] MC: Mixing / anti-mixing array

[0081] DIV2(MX2): The first result

[0082] DIV2(MX4): The second result

[0083] DIV2(MX8): The third result

[0084] CM1: The first comparison result

[0085] CM2: The second comparison result

[0086] CM3: The third comparison result

[0087] CM4: The fourth comparison result

[0088] CM5: The fifth comparison result

[0089] CM6: The sixth comparison result

[0090] IN[7:0]: Input array

[0091] INV: Inverse element

[0092] OUT[7:0]: Output array

[0093] XOR1: The first exclusive-OR gate

[0094] XOR2: The second exclusive-OR gate

[0095] XOR3: The third exclusive-OR gate

[0096] CI: The first given value

[0097] CO: The second given value

[0098] V2: Second value

[0099] SEL1: First selection array

[0100] SEL2: Second selection array

[0101] R4: Fourth result

[0102] R5: Fifth result

[0103] R6: Sixth result

[0104] SBOXi[7:0]: Simplified output status array

[0105] RKXi[7:0]: Simplified return alloy key

[0106] ARKXi[7:0]: Simplified result data

[0107] VF1: First verification signal

[0108] VF2: Second verification signal

[0109] VF3: Third verification signal Detailed implementation manners

[0110] The following description is of the embodiments of the present disclosure. Its purpose is to illustrate the general principles of the present disclosure by way of examples and should not be regarded as a limitation of the present disclosure. The scope of the present disclosure shall be defined by the scope of the patent application.

[0111] It should be noted that the following disclosed content can provide multiple embodiments or examples for practicing different features of the present disclosure. The specific device examples and arrangements described below are only used to briefly elaborate the spirit of the present disclosure and are not used to limit the scope of the present disclosure. In addition, the following specification may reuse the same device symbols or words in multiple examples. However, the purpose of the reuse is only to provide a simplified and clear description and is not used to limit the relationship between the multiple embodiments and / or configurations discussed below.

[0112] In addition, the descriptions in the following specification such as one feature being connected to, coupled to, and / or formed on another feature may actually include multiple different embodiments, including the direct contact of these features, or other additional features being formed between these features, etc., such that these features are not in direct contact.

[0113] In addition, relative terms such as "lower" or "bottom" and "higher" or "top" may be used in the embodiments to describe the relative relationship of one device in the figure to another device. It can be understood that if the device in the figure is flipped so that it is upside down, the device described on the "lower" side will become the device on the "higher" side.

[0114] It is understood that although terms such as "first", "second", "third", etc. may be used herein to describe various devices, components, regions, layers, and / or parts, these devices, components, regions, layers, and / or parts should not be limited by these terms, and these terms are only used to distinguish different devices, components, regions, layers, and / or parts. Therefore, a first device, component, region, layer, and / or part discussed below may be referred to as a second device, component, region, layer, and / or part without departing from the teachings of some embodiments of the present disclosure.

[0115] Some embodiments of the present disclosure can be understood in conjunction with the drawings, and the drawings of the embodiments of the present disclosure are also regarded as a part of the description of the embodiments of the present disclosure. It should be understood that the drawings of the embodiments of the present disclosure are not drawn to the scale of actual devices and components. The shapes and thicknesses of the embodiments may be exaggerated in the drawings for the purpose of clearly showing the features of the embodiments of the present disclosure. In addition, the structures and devices in the drawings are shown in a schematic manner for the purpose of clearly showing the features of the embodiments of the present disclosure.

[0116] Herein, the terms "about", "approximately", "substantially" generally mean within 20% of a given value or range, preferably within 10%, more preferably within 5%, or 3%, or 2%, or 1%, or 0.5%. The quantity given herein is an approximate quantity, that is, the meaning of "about", "approximately", "substantially" may still be implied even without specifically stating "about", "approximately", "substantially".

[0117] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which this disclosure belongs. It is understood that these terms, such as those defined in a commonly used dictionary, should be interpreted to have a meaning consistent with the relevant technology and the background or context of the present disclosure, and should not be interpreted in an idealized or overly formal manner, unless specifically defined in the embodiments of the present disclosure.

[0118] In some embodiments of the present disclosure, terms related to joining and connecting, such as "connect", "interconnect", etc., unless specifically defined, may mean that two structures are in direct contact, or may also mean that two structures are not in direct contact, and other structures are provided between these two structures. And these terms related to joining and connecting may also include the cases where both structures can move, or both structures are fixed.

[0119] In the drawings, similar devices and / or features may have the same device symbols. Various devices of the same type can be distinguished by adding letters or numbers after the device symbols for distinguishing similar devices and / or similar features.

[0120] Figure 1 A block diagram of an encryption / decryption device according to an embodiment of the present invention is shown. As Figure 1 shown, the encryption / decryption device 100 includes a bus interface 110, an input / output buffer 120, a controller 130, and an encryption / decryption circuit 140. Input data DIN is temporarily stored in the input / output buffer 120 via the bus interface 110 through the bus BUS. When the bus interface 110 receives the input of the input data DIN, the controller 130 generates a key KEY and provides it to the encryption / decryption circuit 140, and controls the encryption / decryption circuit 140 to generate encrypted / decrypted data DOUT based on the input data DIN and the key KEY.

[0121] According to some embodiments of the present invention, the encryption / decryption circuit 140 uses the Advanced Encryption Standard (AES) to perform an encryption process or a decryption process on the input data DIN to generate the encrypted / decrypted data DOUT. As Figure 1 shown, the encryption / decryption circuit 140 includes a key expansion unit 141, an InvMixColumns unit 142, and a first multiplexer MUX0. According to an embodiment of the present invention, when the encryption / decryption circuit 140 performs an encryption process, the first multiplexer MUX0 outputs the result output by the key expansion unit 141 according to the key KEY as the round key RK. According to another embodiment of the present invention, when the encryption / decryption circuit 140 performs a decryption process, the first multiplexer MUX0 selects to output the result generated by the key KEY through the key expansion unit 141 and the InvMixColumns unit 142 as the round key RK.

[0122] As Figure 1 shown, the encryption / decryption circuit 140 further includes a ShiftRow / InvShiftRow unit 143, a register 144, a SubbBytes / InvSubBytes unit 145, a MixColumns / InvMixColumns unit 146, a second multiplexer MUX1, and an addroundkey unit 147.

[0123] According to an embodiment of the present invention, when the input data DIN is just input to the encryption / decryption circuit 140, the second multiplexer MUX1 provides the input data DIN to the round key addition unit 147, such that the round key addition unit 147 performs a binary field addition operation on the input data DIN and the round key RK, and generates the result data ARK, and provides the generated result data ARK to the column shift / inverse column shift unit 143. According to an embodiment of the present invention, when the round key addition unit 147 performs a binary field addition operation on the input data DIN and the round key RK, the round key addition unit 147 performs an exclusive OR operation on the input data DIN and the round key RK, and generates the result data ARK.

[0124] The column shift / inverse column shift unit 143 cyclically shifts each row in the result data ARK, and generates the shifted data SR. The register 144 stores the shifted data SR, and provides the shifted data SR as the input state array SBI / ISBI to the byte substitution / inverse byte substitution unit 145. The byte substitution / inverse byte substitution unit 145 converts the input state array SBI / ISBI, and generates the output state array SBO / ISBO.

[0125] According to an embodiment of the present invention, when the encryption / decryption circuit 140 performs an encryption program, the byte substitution / inverse byte substitution unit 145 performs a byte substitution conversion on the input state array SBI, and generates the output state array SBO. According to another embodiment of the present invention, when the encryption / decryption circuit 140 performs a decryption program, the byte substitution / inverse byte substitution unit 145 performs an inverse byte substitution conversion on the input state array ISBI, and generates the output state array ISBO. According to some embodiments of the present invention, the byte substitution conversion and the inverse byte substitution conversion are inverse functions of each other, and both the byte substitution conversion and the inverse byte substitution conversion include linear conversion and non-linear conversion.

[0126] Figure 2 Show a block diagram of the byte substitution / inverse byte substitution unit according to an embodiment of the present invention. As Figure 2 shown, the byte substitution / inverse byte substitution unit 200 includes an inverse affine transformation unit 210, a third multiplexer MUX2, a multiplicative inverse unit 220, an affine transformation unit 230, and a fourth multiplexer MUX3. According to an embodiment of the present invention, the byte substitution / inverse byte substitution unit 200 corresponds to Figure 1 the byte substitution / inverse byte substitution unit 145.

[0127] According to an embodiment of the present invention, when Figure 1 the encryption / decryption circuit 140 executes an encryption program, the third multiplexer MUX2 provides the input state array SBI to the multiplicative inverse element unit 220. The multiplicative inverse element unit 220 performs a non-linear transformation on the input state array SBI to generate an inverse element INV. Then, the affine transformation unit 230 performs an affine transformation on the inverse element INV to generate an output state array SBO. Subsequently, the fourth multiplexer MUX3 outputs the output state array SBO.

[0128] According to another embodiment of the present invention, when Figure 1 the encryption / decryption circuit 140 executes a decryption program, the third multiplexer MUX2 provides the result of the inverse affine transformation performed by the inverse affine transformation unit 210 on the input state array ISBI to the multiplicative inverse element unit 220. The multiplicative inverse element unit 220 performs a non-linear transformation on the result of the inverse affine transformation performed by the inverse affine transformation unit 210 to generate an inverse element INV. Subsequently, the fourth multiplexer MUX3 outputs the inverse element INV as an output state array ISBO.

[0129] According to some embodiments of the present invention, since the byte substitution / inverse byte substitution unit 200 shares the most complex multiplicative inverse element unit 220 during the encryption program and the decryption program, for the convenience of subsequent explanation, the input state array and the output state array of the encryption program are respectively labeled as SBI and SBO, and the input state array and the output state array of the decryption program are respectively labeled as ISBI and ISBO.

[0130] Returning to Figure 1 , the mix row / inverse mix row unit 146 performs a mix row / inverse mix row operation on the output state array SBO / ISBO to generate a mixed / inverse mixed array MC. The round key addition unit 147 performs a binary field addition operation on the mixed / inverse mixed array MC (or the output state array SBO / ISBO) and the round key RK to generate a result data ARK. According to an embodiment of the present invention, the binary field addition operation is a logical exclusive OR operation. According to some embodiments of the present invention, when the shift / inverse column shift unit 143, the register 144, the byte substitution / inverse byte substitution unit 145, the mix row / inverse mix row unit 146, and the round key addition unit 147 execute multiple rounds, the round key addition unit 147 generates encrypted / decrypted data DOUT and outputs it through the input / output buffer 120, the bus interface 110, and the bus BUS.

[0131] To ensure the correctness of the encryption / decryption circuit 140 when executing the encryption program and the decryption program and to prevent the differential fault analysis method from stealing the key, the encryption / decryption circuit 140 requires a strong countermeasure to detect the occurrence of errors.

[0132] As Figure 2 shown, when performing the encryption program, it is assumed that the input state array SBI[7:0] and the output state array SBO[7:0] are the input value and the output value of the byte substitution / inverse byte substitution unit 200 during the encryption program respectively. The transformation performed by the multiplicative inverse element 220 is denoted as the -1 power, and the affine transformation performed by the affine transformation unit 230 is denoted as AT. Therefore, the relationship between the input state array SBI[7:0] and the output state array SBO[7:0] is as shown in Equation 1:

[0133] SBO[7:0] = AT((SBI[7:0]) -1 ) (Equation 1)

[0134] Performing the inverse affine transformation (i.e., AT -1 ) on both sides of Equation 1 results in Equation 2.

[0135] AT -1 (SBO[7:0]) = (SBI[7:0]) -1 (Equation 2) Next, multiplying both sides of Equation 2 by the input state array SBI[7:0] results in Equation 3.

[0136] AT -1 (SBO[7:0]) * (SBI[7:0]) = 0x1, where SBI[7:0]

[0137] ≠ 0x0 during encryption

[0138] AT -1 (SBO[7:0]) * (SBI[7:0]) = 0x0, where SBI[7:0]

[0139] = 0x0 during encryption

[0140] (Equation 3)

[0141] According to an embodiment of the present invention, when the input state array SBI[7:0] is 0x0, the result of the binary field multiplication operation must be 0x0. According to another embodiment of the present invention, when the input state array SBI[7:0] is not 0x0, the result of the binary field multiplication operation must be 0x1. However, when the input state array SBI[7:0] is 0x0, no matter what wrong value the attacker inserts for AT -1 (SBO[7:0]), Equation 3 will hold. In other words, Equation 3 cannot detect the operation error that occurs when the input state array SBI[7:0] is 0x0.

[0142] To overcome the above - mentioned drawbacks, when the input status array SBI[7:0] is 0x0, the output status array SBO[7:0] is set to 0x63 according to the look - up table. Therefore, the detection method of Formula 3 can be modified to determine whether the input status array SBI[7:0] is 0x0. When the input status array SBI[7:0] is 0x0, determine whether the output status array SBO[7:0] is 0x63. When the output status array SBO[7:0] is 0x63, it means that the operation of the byte substitution / inverse byte substitution unit 200 is correct. When the output status array SBO[7:0] is not 0x63, it means that the operation of the byte substitution / inverse byte substitution unit 200 is incorrect.

[0143] When the input status array SBI[7:0] is not 0x0, judge AT -1 whether the product of (SBO[7:0]) and the input status array SBI[7:0] is 0x1. When AT -1 the product of (SBO[7:0]) and the input status array SBI[7:0] is 0x1, it means that the operation of the byte substitution / inverse byte substitution unit 200 is correct. When AT -1 the product of (SBO[7:0]) and the input status array SBI[7:0] is not 0x1, it means that the operation of the byte substitution / inverse byte substitution unit 200 is incorrect.

[0144] The above - mentioned judgment method can be described as Formula 4, where Formula 4 is as follows:

[0145] (SBI[7:0] == 0x0)? (SBO[7:0] == 0x63) : (AT -1 (SBO[7:0]) * (SBI[7:0]) == 0x1)

[0146] (Formula 4)

[0147] Among them, the combination of the question mark (i.e.,?) and the colon (i.e., :) in Formula 4 is a ternary operator. The left - hand side of the question mark is the condition of the ternary operator, and the right - hand side is the corresponding result when the ternary operator condition holds or not. When the condition holds, the left - hand side of the colon is returned as the result. When the condition does not hold, the right - hand side of the colon is returned. So when the input status array SBI[7:0] is 0x0, Formula 4 returns the result of whether the output status array SBO[7:0] is equal to 0x63. When the input status array SBI[7:0] is not 0x0, it returns the result of whether the binary field multiplication result is equal to 0x1. Therefore, the conversion operation of the byte substitution / inverse byte substitution unit 200 during the encryption process can be detected by Formula 4.

[0148] Such as Figure 2As shown, when performing the decryption program, assume that the input state array ISBI[7:0] and the output state array ISBO[7:0] are the input value and the output value of the byte substitution / inverse byte substitution unit 200 during the decryption program respectively. The inverse affine transformation performed by the inverse affine transformation unit 210 is denoted as AT -1 , the transformation performed by the multiplicative inverse element 220 is denoted as the -1 power. Therefore, the relationship between the input state array ISBI[7:0] and the output state array ISBO[7:0] is as shown in Equation 5:

[0149] ISBO[7:0] = (AT -1 (ISBI[7:0])) -1 (Equation 5)

[0150] Multiply both sides of Equation 5 by AT -1 (ISBI[7:0]) to form Equation 6.

[0151] ISBO[7:0] * AT -1 (ISBI[7:0]) = 0 * 1, where ISBI[7:0]

[0152] ≠ 0x63 during decryption

[0153] ISBO[7:0] * AT -1 (ISBI[7:0]) = 0x0, where ISBI[7:0]

[0154] = 0x63 during decryption

[0155] (Equation 6)

[0156] When the input state array ISBI[7:0] is 0x63, the result of the binary field multiplication operation must be 0x0, and vice versa must be 0x1. In addition, according to Figure 14 of FIPS197, Advanced Encryption Standard (AES) on November 26, 2001, when the input state array ISBI[7:0] is 0x63, the output state array ISBO[7:0] must be 0x0. Therefore, we can rewrite Equation 6 as Equation 7.

[0157] (ISBI[7:0] == 0x63)? (ISBO[7:0] == 0x0) : ISBO[7:0] * AT -1 (ISBI[7:0])

[0158] == 0x1

[0159] (Equation 7)

[0160] As shown in Equation 7, when the input status array ISBI[7:0] is 0x63, the comparison result of whether the backhaul output status array ISBO[7:0] is equal to 0x0 is returned. Conversely, the result of whether the binary field multiplication operation result is equal to 0x1 is returned. Therefore, it is possible to detect whether an error occurs in the conversion operation of the byte substitution / inverse byte substitution unit 200 during the decryption process by means of Equation 7.

[0161] In other words, it is possible to separately determine by means of Equation 4 and Equation 7 Figure 1 whether an error occurs in the conversion operation of the byte substitution / inverse byte substitution unit 145 during the encryption process and the decryption process. Moreover, when the input status array ISBI[7:0] is 0x63 or the input status array SBI[7:0] is equal to 0x0, it is also possible to determine by means of Equation 4 and Equation 7 whether an error occurs in the conversion operation of the byte substitution / inverse byte substitution unit 145 during the encryption process and the decryption process. In addition, there is still a lack of an error verification method for the mix row / inverse mix row unit 146 and the round key addition unit 147.

[0162] Assume Figure 2 the inverse element INV[127:0], the round key RK[127:0], and the result data ARK[127:0] generated by the multiplicative inverse element unit 220 of

[0163] INV[127:0] = {INV3[31:0], INV1[31:0}, INV2[31:0], INV0[31:0]}

[0164] RK[127:0] = {RK3[31:0], RK1[31:0}, RK2[31:0], RK0[31:0]}

[0165] AK[127:0] = {ARK3[31:0], ARK1[31:0], ARK2[31:0], ARK0[31:0]}

[0166] (Equation 8)

[0167] The 4 byte groups (i.e., I0, I1, I2, I3) of the inverse element INV[127:0] are subjected to 3 binary field addition operations (i.e., exclusive OR operations) to form a simplified inverse element INVXi[7:0] as shown in Equation 9.

[0168] INVXi[7:0] = (INVi[31:24] ⊕ INVi[23:16} ⊕ INVi[15:8] ⊕ INVi[7:0])

[0169] = I3 ⊕ I2 ⊕ I1 ⊕ I0, where 0 ≤ i ≤ 3

[0170] (Formula 9)

[0171] Formula 10 performs three binary field addition operations on four byte groups (i.e., R0, R1, R2, R3) of the round key RK[127:0] to form the simplified round key RKXi[7:0].

[0172] RKXi[7:0] = (RKi[31:24] ⊕ RKi[23:16} ⊕ RKi[15:8] ⊕ RKi[7:0])

[0173] = R3 ⊕ R2 ⊕ R1 ⊕ R0, where 0 ≤ i ≤ 3

[0174] (Formula 10)

[0175] Formula 11 performs three binary field addition operations on four byte groups (i.e., A0, A1, A2, A3) of the result data ARK[127:0] to form the simplified result data ARKXi[7:0].

[0176] ARKXi[7:0] = (ARKi[31:24] ⊕ ARKi[23:16} ⊕ ARKi[15:8] ⊕ ARKi[7:0])

[0177] = A3 ⊕ A2 ⊕ A1 ⊕ A0, where 0 ≤ i ≤ 3

[0178] (Formula 11)

[0179] Figure 2 The affine transformation performed by the affine transformation unit 230 is to perform matrix multiplication (hereinafter marked as MM operation) on the simplified inverse element INVXi[7:0] and then perform a binary field addition operation (i.e., the result of the MM operation is exclusive-ORed with 0x63). The result of the simplified inverse element INVXi[7:0] obtained through the affine transformation unit 230, the mix row / inverse mix row unit 146, and the round key addition unit 147 is as shown in Formula 12.

[0180] A0 = (0x2 * (MM(I0) ⊕ 0x63)) ⊕ (0x3 * (MM(I1) ⊕ 0x63))

[0181] ⊕ (0x1 * (MM(I2) ⊕ 0x63)) ⊕ (0x1 * (MM(I3)

[0182] (⊕0x63))⊕R0;

[0183] A1 = (0x1 * (MM(I0)⊕0x63))⊕(0x2 * (MM(I1)⊕0x63))

[0184] ⊕(0x3 * (MM(I2)⊕0x63))⊕(0x1 * (MM(I3)

[0185] (⊕0x63))⊕R1;

[0186] A2 = (0x1 * (MM(I0)⊕0x63))⊕(0x1 * (MM(I1)⊕0x63))

[0187] ⊕(0x2 * (MM(I2)⊕0x63))⊕(0x3 * (MM(I3)

[0188] (⊕0x63))⊕R2;

[0189] A3 = (0x3 * (MM(I0)⊕0x63))⊕(0x1 * (MM(I1)⊕0x63))

[0190] ⊕(0x1 * (MM(I2)⊕0x63))⊕(0x2 * (MM(I3)

[0191] (⊕0x63))⊕R3;

[0192] (Equation 12)

[0193] The simplified result data ARKXi[7:0] is as shown in Equation 13.

[0194] ARKXi = A0⊕A1⊕A2⊕A3

[0195] = MM(I0)⊕MM(I1)⊕MM(I2)⊕MM(I3)⊕R0⊕R1

[0196] ⊕R2⊕R3

[0197] = MM(I0⊕I1⊕I2⊕I3)⊕R0⊕R1⊕R2⊕R3

[0198] (Equation 13) Substituting Equation 9 and Equation 10 into Equation 13 gives Equation 14.

[0199] ARKXi = MM(INVXi)⊕RKXi, where 0 ≤ i ≤ 3 (Equation 14)

[0200] Assume that the variable MMI0 is the output byte of the affine transformation (i.e., the input byte of the mix row / inverse mix row unit 146), as shown in Equation 15.

[0201] MMI0 = (MM(I0) ⊕ 0x63) (Equation 15)

[0202] To optimize software performance or hardware area, for the binary field multiply-by-two operation, the multiplicand MMI0 will be shifted left first. If the most significant bit (i.e., MSB) of MMI0 is 0x1, then the remainder is taken using the irreducible polynomial (i.e., 0x11B), as shown in Equation 16.

[0203] 0x2 * MMI0 = (MMI0 << 0x1) ⊕ 0x11B, where the MSB of MMI0 = 0x1 0x2 * MMI0 = (MMI0 << 0x1), where the MSB of MMI0 = 0x0

[0204] (Equation 16)

[0205] As for the simplest method of the binary field multiply-by-three operation in Equation 12, it is to add the result of the binary field multiply-by-two operation to MMI0, as shown in Equation 17.

[0206] 0x3 * MMI0 = (0x2 * MMI0) ⊕ MMI0 (Equation 17) If an attacker can insert an error value Er during the binary field multiply-by-two operation, as shown in Equation 18.

[0207] (0x2 * MMI0) ⊕ Er (Equation 18) This will also cause an error value Er to be inserted into the result of the binary field multiply-by-three operation, as shown in Equation 19.

[0208] (0x2 * MMI0) ⊕ Er ⊕ MMI0 = (0x3 * MMI0) ⊕ Er (Equation 19)

[0209] According to Equation 12, the above two error values Er will accumulate to A0 and A3, forming the variables A0' and A3' in Equation 20.

[0210] A0′ = A0 ⊕ Er

[0211] A3 ′ = A3 ⊕ Er

[0212] (Equation 20)

[0213] When Equation 14 is executed, the actual value of the information redundancy mechanism (i.e., ARKXi') will cancel out the two error values Er, making the actual value equal to the predicted value (i.e., MM(INVXi) ⊕ RKXi), as shown in Equation 21.

[0214] ARKXi ′ = A0 ′ ⊕ A1 ⊕ A2 ⊕ A3 ′

[0215] = A0 ⊕ Er ⊕ A1 ⊕ A2 ⊕ A3 ⊕ Er

[0216] = A0 ⊕ A1 ⊕ A2 ⊕ A3

[0217] = ARKXi = MM(INVX0) ⊕ RKX0

[0218] (Equation 21)

[0219] As shown in Equation 21, since the two error values Er will cancel each other out after performing a binary field addition operation, an effective verification method is required to facilitate the detection of errors in the binary field multiplication by two operation.

[0220] In the encryption program, the output state array SBO generated by the byte substitution / inverse byte substitution unit 145 through byte substitution conversion is as shown in Equation 22.

[0221] SBO[127:0] = {SBO3[31:0], SBO1[31:0], SBO2[31:0], SBO0[31:0]}

[0222] (Equation 22)

[0223] Since the mix row / inverse mix row unit 146 performs mix row conversion in units of 32 bits, SBO[127:0] in Equation 22 will be divided into 4 representations of 32 bits. Equation 23 is to perform 3 binary field addition operations on SBO0, SBO1, SBO2, and SBO3 to generate the simplified output state array SBOXi[7:0].

[0224] SBOXi[7:0] = (SBOi[31:24] ⊕ SBOi[23:16] ⊕ SBOi[15:8]

[0225] ⊕ SBOi[7:0]), where 0 ≤ i ≤ 3

[0226] = (MM(I3) ⊕ 0x63) ⊕ (MM(I2) ⊕ 0x63) ⊕ (MM(I1) ⊕ 0x63)

[0227] ⊕ (MM(I0) ⊕ 0x63)

[0228] = MM(I3) ⊕ MM(I2) ⊕ MM(I1) ⊕ MM(I0)

[0229] = MM(I3 ⊕ I2 ⊕ I1 ⊕ I0)

[0230] = MM(INVXi)

[0231] (Equation 23)

[0232] AsFigure 2 As shown, since the byte substitution / inverse byte substitution operation of the byte substitution / inverse byte substitution unit 145 is composed of the multiplicative inverse element unit 220 and the affine transformation unit 230, and the affine transformation performed by the affine transformation unit 230 is composed of a matrix multiplication operation (i.e., the MM operation in Formula 12) and a binary field addition operation (i.e., the result of the MM operation is exclusive-ORed with 0x63). Therefore, Formula 23 can also be represented by I0, I1, I2, I3, and the MM operation.

[0233] Finally, through the optimization process of Formula 23, we can know that the simplified output state array SBOXi[7:0] is equal to the value of MM(INVXi). Substituting the result of Formula 23 into Formula 14 forms Formula 24. In addition, errors in the mix column / inverse mix column transformation performed by the mix column / inverse mix column unit 146 and the transformation performed by the round key addition unit 147 can be detected through Formula 24.

[0234] ARKXi = MM(INVXi) ⊕ RKXi = SBOXi ⊕ RKXi, where 0 ≤ i ≤ 3

[0235] (Formula 24)

[0236] On the other hand, in the decryption program, the output state array ISBO generated by the inverse byte substitution transformation of the byte substitution / inverse byte substitution unit 145 is as shown in Formula 25.

[0237] ISBO[127:0] = {ISBO3[31:0], ISBO1[31:0], ISBO2[31:0], ISBO0[31:0]}

[0238] (Formula 25)

[0239] Since the mix column / inverse mix column unit 146 performs the inverse mix column transformation in units of 32 bits, the ISBO[127:0] in Formula 25 is divided into 4 32-bit units. Formula 262 performs 3 binary field addition operations (i.e., Z0 ⊕ Z1 ⊕ Z2 ⊕ Z3) on ISBO0, ISBO1, ISBO2, and ISBO3 to generate the simplified output state array ISBOXi[7:0].

[0240] ISBOXi[7:0] = (ISBOi[31:24] ⊕ ISBOi[23:16] ⊕ ISBOi[15:8] ⊕ ISBOi[7:0])

[0241] = Z0 ⊕ Z1 ⊕ Z2 ⊕ Z3, where 0 ≤ i ≤ 3

[0242] (Equation 26) Next, the inverse row mixing transformation performed by the mix row / inverse mix row unit 146 is as shown in Equation 27.

[0243] A0 = (0xE * Z0) ⊕ (0xB * Z1)) ⊕ (0xD * Z2)) ⊕ (0x9 * Z3))

[0244] ⊕ R0;

[0245] A1 = (0x9 * Z0) ⊕ (0xE * Z1)) ⊕ (0xB * Z2)) ⊕ (0xD * Z3))

[0246] ⊕ R1;

[0247] A2 = (0xD * Z0) ⊕ (0x9 * Z1)) ⊕ (0xE * Z2)) ⊕ (0xB * Z3))

[0248] ⊕ R2;

[0249] A3 = (0xB * Z0) ⊕ (0xD * Z1)) ⊕ (0x9 * Z2)) ⊕ (0xE * Z3))

[0250] ⊕ R3;

[0251] (Equation 27)

[0252] From Equation 11, it can be seen that the result of adding up A0, A1, A2, and A3 in Equation 27 is equal to the simplified result data ARKXi[7:0], as shown in Equation 28. The simplified result data ARKXi will be equal to the sum of the four output byte groups of the simplified output state array ISBOXi[7:0] (i.e., ISBOXi = Z0 ⊕ Z1 ⊕ Z2 ⊕ Z3), plus the sum of each byte group of the simplified round key RKXi[7:0] as shown in Equation 10 (i.e., RKXi = R0 ⊕ R1 ⊕ R2 ⊕ R3).

[0253] ARKXi = A0 ⊕ A1 ⊕ A2 ⊕ A3

[0254] = Z0 ⊕ Z1 ⊕ Z2 ⊕ Z3 ⊕ R0 ⊕ R1 ⊕ R2 ⊕ R3

[0255] = ISBOXi[7:0] ⊕ RKXi; where 0 ≤ i ≤ 3

[0256] (Equation 28)

[0257] Therefore, Equation 28 can detect errors that occur in the inverse row mixing transformation performed by the mix row / inverse mix row unit 146 and the transformation performed by the round key addition unit 147.

[0258] To detect whether the binary field multiply-by-two operation, binary field multiply-by-four operation, and binary field multiply-by-eight operation of the hybrid row / inverse hybrid row unit 146 are correct, the binary field multiply-by-two operation is as shown in Formula 29.

[0259] MX2[7:0] = 0x2 * M[7:0] = (M << 1) ⊕ (0x11B & {9{M[7]}})

[0260] = {M[7:0], 0x0}

[0261] ⊕ {M[7], 0x0, 0x0, 0x0, M[7], M[7], 0x0, M[7], M[7]})

[0262] = {M[6:4], (M[3] ⊕ M[7]), (M[2] ⊕ M[7]), M[1], (M[0]

[0263] ⊕ M[7]), M[7]})

[0264] (Formula 29)

[0265] Assume that the multiply-by-two array MX2 is the result of the binary field multiply-by-two operation on the multiplicand array M. For optimization, the binary field multiply-by-two operation will first perform a left shift on the multiplicand array M. If the most significant bit of the multiplicand array M (i.e., M[7]) is 0x1, then the irreducible polynomial (i.e., 0x11B) is added and the remainder is taken. Therefore, the multiply-by-two array MX2 can be simplified to a value composed only of the bits of the multiplicand array M, as shown in Formula 29.

[0266] Among them, {9{MX2[7]}} in Formula 29 refers to the 9-bit repetition of the 8th bit (i.e., the most significant bit) of the multiply-by-two array MX2. In other words, {9{MX2[7]}} is equal to {MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7]}. For the convenience of subsequent description, hereinafter, MUL2() is used to represent the binary field multiply-by-two operation, as shown in Formula 30.

[0267] MUL2(M) = {M[6:4], (M[3] ⊕ M[7]), (M[2] ⊕ M[7]), M[1], (M[0]

[0268] ⊕ M[7]), M[7]} = MX2[7:0]

[0269] (Formula 30)

[0270] As shown in Equation 30, each bit value of the multiply-by-two array MX2 can be composed of the bit values of the multiplicand array M. In other words, each bit value of the multiplicand array M can also be composed of the bit values of the multiply-by-two array MX2.

[0271] M[6] = MX2[7];

[0272] M[5] = MX2[6];

[0273] M[4] = MX2[5];

[0274] M[1] = MX2[2];

[0275] M[7] = MX2[0];

[0276] (Equation 31)

[0277] First, in Equation 31, find the part of the one-to-one conversion correspondence between the values of the multiplicand array M and the values of the multiply-by-two array MX2. At this time, we can know that the 7th, 6th, 5th, 2nd, and 8th bits of the multiplicand array M correspond to the 8th, 7th, 6th, 3rd, and 1st bits of the multiply-by-two array MX2 respectively.

[0278] Next, substitute the known bit values of the multiplicand array M into the non-one-to-one conversion bits of Equation 30 to find the remaining unknown bit values of the multiplicand array M. From Equation 30, we know that MX2[4] = (M[3] ⊕ M[7]). Adding M[7] to both sides of the equation gives M[3] = (MX2[4] ⊕ M[7]), as shown in Equation 32.

[0279] MX2[4] = (M[3] ⊕ M[7])

[0280] M[3] = MX2[4] ⊕ M[7] = MX2[4] ⊕ MX2[0]

[0281] (Equation 32)

[0282] M[2] is as shown in Equation 33.

[0283] MX2[3] = (M[2] ⊕ M[7])

[0284] M[2] = MX2[3] ⊕ M[7] = MX2[3] ⊕ MX2[0]

[0285] (Equation 33)

[0286] M[0] is as shown in Equation 34.

[0287] MX2[1] = (M[0] ⊕ M[7])

[0288] M[0] = MX2[1] ⊕ M[7] = MX2[1] ⊕ MX2[0]

[0289] (Formula 34)

[0290] DIV2() represents the binary field division-by-two operation. Formula 35 represents each bit of DIV2(MX2) (i.e., the division-by-two operation on the multiply-by-two array MX2) in terms of the bit values of the multiply-by-two array MX2.

[0291] DIV2(MX2) = {MX2[0], MX2[7:5], (MX2[0] ⊕ MX2[4]), (MX2[0]

[0292] ⊕ MX2[3]), MX2[2], (MX2[0] ⊕ MX2[1])}

[0293] = M

[0294] (Formula 35)

[0295] In other words, it is possible to detect whether the result of the binary field multiply-by-two operation (i.e., the multiply-by-two array MX2) is correct through Formula 35.

[0296] Assume that the multiply-by-four array MX4 is the result of the multiply-by-four operation on the binary field multiplicand array M value. As shown in Formula 36, the multiply-by-four array MX4 is the result of the multiply-by-two array MX2 after MUL2(), where MUL2() represents the binary field multiply-by-two operation.

[0297] MX4 = (MX2 << 1) ⊕ (0x11B & {9{MX2[7]}}) = MUL2(MX2)

[0298] (Formula 36)

[0299] Next, assume that the multiply-by-eight array MX8 is the result of the binary field multiply-by-eight operation on the multiplicand array M. As shown in Formula 37, the multiply-by-eight array MX8 is the result of the multiply-by-four array MX4 after MUL2(), as shown in Formula 37.

[0300] MX8 = (MX4 << 1) ⊕ (0x11B & {9{MX4[7]}})

[0301] = MUL2(MX4)

[0302] (Formula 37) As shown in Formula 38, the value of the multiply-by-four array MX4 can be obtained after the multiply-by-eight array MX8 goes through DIV2().

[0303] DIV2(MX8) = MX4 (Formula 38) Similarly, as shown in Formula 39, the value of the multiply-by-two array MX2 can be obtained after the multiply-by-four array MX4 goes through DIV2().

[0304] DIV2(MX4) = MX2 (Formula 39)

[0305] In other words, the binary field multiplication by two, multiplication by four, and multiplication by eight operations can be checked by Formula 35, Formula 38, and Formula 39, as shown in Formula 40.

[0306] VF1 = (DIV2(MX2) == M) & (DIV2(MX4) == MX2) & (DIV2(MX8) == MX4)

[0307] (Formula 40)

[0308] Figure 3 Schematic diagram showing the first verification unit according to an embodiment of the present invention. According to an embodiment of the present invention, Figure 3 the first verification unit 300 is used to execute Formula 40. As Figure 3 shown, the first verification unit 300 includes a first divide-by-two circuit 301, a second divide-by-two circuit 302, a third divide-by-two circuit 303, a first comparator CMP1, a second comparator CMP2, a third comparator CMP3, and a logic gate LG.

[0309] The first divide-by-two circuit 301 performs a divide-by-two operation on the multiply-by-two array MX2 to generate a first result DIV2(MX2). The second divide-by-two circuit 302 performs a divide-by-two operation on the multiply-by-four array MX4 to generate a second result DIV2(MX4). The third divide-by-two circuit 303 performs a divide-by-two operation on the multiply-by-eight array MX8 to generate a third result DIV2(MX8).

[0310] The first comparator CMP1 compares the multiplicand array M and the first result DIV2(MX2) to generate a first comparison result CM1. When the multiplicand array M and the first result DIV2(MX2) are equal, the first comparison result CM1 is at a first logic level.

[0311] The second comparator CMP2 compares the multiply-by-two array MX2 and the second result DIV2(MX4) to generate a second comparison result CM2. When the multiply-by-two array MX2 is equal to the second result DIV2(MX4), the second comparison result CM2 is at a first logic level.

[0312] The third comparator CMP3 compares the multiply-by-four array MX4 and the third result DIV2(MX8) to generate a third comparison result CM3. When the multiply-by-four array MX4 is equal to the third result DIV2(MX8), the third comparison result CM3 is at a first logic level.

[0313] According to an embodiment of the present invention, when the first comparison result CM1, the second comparison result CM2, and the third comparison result CM3 are all at the first logic level, the logic gate LG outputs a first verification signal VF1 at the first logic level. According to other embodiments of the present invention, when at least one of the first comparison result CM1, the second comparison result CM2, and the third comparison result CM3 is not at the first logic level, the first verification signal VF1 is not at the first logic level.

[0314] Figure 4 Shows a schematic diagram of a divide-by-two circuit according to an embodiment of the present invention. According to an embodiment of the present invention, Figure 4 the divide-by-two circuit 400 corresponds to Figure 3 any one of the first divide-by-two circuit 301, the second divide-by-two circuit 302, and the third divide-by-two circuit 303. According to an embodiment of the present invention, the divide-by-two circuit 400 is used to perform the divide-by-two operation shown in Equation 35.

[0315] As Figure 4 shown, the divide-by-two circuit 400 is used to perform the divide-by-two operation shown in Equation 35 on the input array IN[7:0], and generate the output array OUT[7:0]. The divide-by-two circuit 400 takes the first bit IN[0] (i.e., the least significant bit) of the input array as the eighth bit OUT[7] (i.e., the most significant bit) of the output array; the divide-by-two circuit 400 takes the eighth bit IN[7] (i.e., the most significant bit) of the input array as the seventh bit OUT[6] of the output array; the divide-by-two circuit 400 takes the seventh bit IN[6] of the input array as the sixth bit OUT[5] of the above output array.

[0316] The divide-by-two circuit 400 takes the sixth bit IN[5] of the input array as the fifth bit OUT[4] of the output array; the first exclusive-OR gate XOR1 of the divide-by-two circuit 400 performs an exclusive-OR operation on the fifth bit IN[4] of the input array and the first bit IN[0] of the input array, and uses it as the fourth bit OUT[3] of the output array; the second exclusive-OR gate XOR2 of the divide-by-two circuit 400 performs an exclusive-OR operation on the fourth bit IN[3] of the input array and the first bit IN[0] of the input array, and uses it as the third bit OUT[2] of the output array.

[0317] The divide-by-two circuit 400 takes the third bit IN[2] of the input array as the second bit OUT[1] of the output array; the third exclusive-OR gate XOR3 of the divide-by-two circuit 400 performs an exclusive-OR operation on the second bit IN[1] of the input array and the first bit IN[0] of the input array, and uses it as the first bit OUT[0] (i.e., the least significant bit) of the output array.

[0318] According to some embodiments of the present invention, Formula 4 and Formula 7 can be optimized. The first predetermined value CI[7:0] can be composed of the first value V1 and 0x0, as shown in detail in Formula 41.

[0319] CI[7:0] = {0x0, V1, V1, 0x0, 0x0, 0x0, V1, V1} (Formula 41)

[0320] The second predetermined value CO[7:0] can be composed of the second value V2 and 0x0, as shown in detail in Formula 42, where the second value V2 is the inverse of the first value V1.

[0321] CO[7:0] = {0x0, V2, V2, 0x0, 0x0, 0x0, V2, V2} (Formula 42)

[0322] According to an embodiment of the present invention, when Figure 1 the encryption / decryption circuit 140 executes the encryption program, the first value V1 is 0x0 and the second value V2 is 0x1. Therefore, the first predetermined value CI[7:0] is 0x0 and the second predetermined value CO[7:0] is 0x63. According to another embodiment of the present invention, when Figure 1 the encryption / decryption circuit 140 executes the decryption program, the first value V1 is 0x1 and the second value V2 is 0x0. Therefore, the first predetermined value CI[7:0] is 0x63 and the second predetermined value CO[7:0] is 0x0.

[0323] Next, as Figure 1 shown, since both the input state array SBI and the input state array ISBI can be inputs to the byte substitution / inverse byte substitution unit 145, and both the output state array SBO and the output state array ISBO can be outputs of the byte substitution / inverse byte substitution unit 145, the input of the byte substitution / inverse byte substitution unit 145 is defined as the input state array SI and the output of the byte substitution / inverse byte substitution unit 145 is defined as the output state array SO hereinafter. In other words, when the encryption / decryption circuit 140 executes the encryption program, SI is SBI and SO is SBO. When the encryption / decryption circuit 140 executes the decryption program, SI is ISBI and SO is ISBO.

[0324] As shown in Formula 43, when the second value V2 is 0x1, the first selection array SEL1 is the input state array SI; when the second value V2 is 0x0, the first selection array SEL1 is the output state array SO. In other words, when the encryption / decryption circuit 140 executes the encryption program, the second value V2 is 0x1 and the first selection array SEL1 is the input state array SI; when the encryption / decryption circuit 140 executes the decryption program, the second value V2 is 0x0 and the first selection array SEL1 is the output state array SO.

[0325] SEL1 = V2? SI : SO (Equation 43)

[0326] As shown in Equation 44, when the second value V2 is 0x1, the second selection array SEL2 is the output state array SO; when the second value V2 is 0x0, the second selection array SEL2 is the input state array SI. In other words, when the encryption and decryption circuit 140 executes the encryption program, the second value V2 is 0x1 and the second selection array SEL2 is the output state array SO; when the encryption and decryption circuit 140 executes the decryption program, the second value V2 is 0x0 and the second selection array SEL2 is the input state array SI.

[0327] SEL2 = V2? SO : SI (Equation 44)

[0328] According to Equations 41 to 44, Equation 4 and Equation 7 can be optimized to Equation 45.

[0329] VF2 = (SI[7:0] == CI)? (SO[7:0] == C0) : (SEL1 * AT -1 (SEL2)) == 0x1)

[0330] (Equation 45)

[0331] Comparing Equation 45 with Equation 4 and Equation 7, the encryption program and the decryption program can share the same binary field multiplier and the inverse affine transformation unit, thereby saving a binary field multiplier and an inverse affine transformation unit.

[0332] Figure 5 Schematic diagram showing the second verification unit according to an embodiment of the present invention. According to an embodiment of the present invention, Figure 5 the second verification unit 500 is used to execute Equation 45.

[0333] As Figure 5 shown, the second verification unit 500 includes a first value generator 501, a second value generator 502, a fourth comparator CMP4, a fifth comparator CMP5, a fifth multiplexer MUX4, a sixth multiplexer MUX5, an inverse affine transformation unit 503, a multiplier 504, a sixth comparator CMP6, and a seventh multiplexer MUX6.

[0334] The first value generator 501 is used to execute formula 41 to generate a first predetermined value CI, where the most significant bit to the least significant bit of the first predetermined value CI are 0x0, the first value V1, the first value V1, 0x0, 0x0, 0x0, the first value V1, and the first value V1 in sequence. The second value generator 502 is used to execute formula 42 to generate a second predetermined value CO, where the most significant bit to the least significant bit of the second predetermined value CO are 0x0, the second value V2, the second value V2, 0x0, 0x0, 0x0, the second value V2, and the second value V2 in sequence.

[0335] The fourth comparator CMP4 compares whether the input status array SI is equal to the first predetermined value CI to generate a fourth comparison result CM4. When the input status array SI is equal to the first predetermined value CI, the fourth comparison result CM4 is the first logic level. The fifth comparator CMP5 compares the output status array SO and the second predetermined value CO to generate a fifth comparison result CM5. When the output status array SO is equal to the second predetermined value CO, the fifth comparison result CM5 is the first logic level.

[0336] The fifth multiplexer MUX4 executes formula 43 to select the input status array SI or the output status array SO as the first selection array SEL1 based on the second value V2. According to an embodiment of the present invention, when Figure 1 the encryption and decryption circuit 140 executes the encryption program, the first selection array SEL1 is the input status array SI. According to another embodiment of the present invention, when Figure 1 the encryption and decryption circuit 140 executes the decryption program, the first selection array SEL1 is the output status array SO.

[0337] The sixth multiplexer MUX5 executes formula 44 to select the input status array SI or the output status array SO as the second selection array SEL2 based on the second value V2. According to an embodiment of the present invention, when Figure 1 the encryption and decryption circuit 140 executes the encryption program, the second selection array SEL2 is the output status array SO. According to another embodiment of the present invention, when Figure 1 the encryption and decryption circuit 140 executes the decryption program, the second selection array SEL2 is the input status array SI.

[0338] The inverse affine transformation unit 503 performs an inverse affine transformation (i.e., AT -1 ) on the second selection array SEL2 to generate a fourth result R4. The multiplier 504 multiplies the first selection array SEL1 by the fourth result R4 to generate a fifth result R5. The sixth comparator CMP6 compares the fifth result R5 and 0x1 to generate a sixth comparison result CM6. When the fifth result R5 is equal to 0x1, the sixth comparison result CM6 is the first logic level.

[0339] The sixth multiplexer MUX6 outputs the fifth comparison result CM5 or the sixth comparison result CM6 as the second verification signal VF2 based on the fourth comparison result CM4. According to an embodiment of the present invention, when the second verification signal VF2 is at the first logic level, it represents that Figure 1 the byte substitution / anti-byte substitution conversion performed by the byte substitution / anti-byte substitution unit 145 is correct. According to another embodiment of the present invention, when the second verification signal VF2 is not at the first logic level, it represents that Figure 1 the byte substitution / anti-byte substitution conversion performed by the byte substitution / anti-byte substitution unit 145 is incorrect.

[0340] Equation 24 can detect errors that occur in the mixing row conversion performed by the mixing row / anti-mixing row unit 146 and the conversion performed by the round key addition unit 147, and equation 28 can detect errors that occur in the anti-mixing row conversion performed by the mixing row / anti-mixing row unit 146 and the conversion performed by the round key addition unit 147, where equation 24 and equation 28 can be optimized to equation 46.

[0341] VF3 = (ARKXi == (ISBOXi[7:0] ⊕ RKXi))

[0342] = (ARKXi == (SBOXi[7:0] ⊕ RKXi))

[0343] = (ARKXi == (SOXi[7:0] ⊕ RKXi)), where 0 ≤ i ≤ 3

[0344] (Equation 46)

[0345] Figure 6 A schematic diagram showing a third verification unit according to an embodiment of the present invention is shown. According to an embodiment of the present invention, Figure 6 the third verification unit 600 is used to execute equation 46 to detect Figure 1 whether the conversions performed by the mixing row / anti-mixing row unit 146 and the round key addition unit 147 are correct.

[0346] As Figure 6 shown, the third verification unit 600 includes a first byte group division device 601, a second byte group division device 602, a third byte group division device 603, a first logic operation unit 604, a second logic operation unit 605, a third logic operation unit 606, a fourth logic operation unit 607, and a seventh comparator CMP7.

[0347] The first bit - group partitioning device 601 partitions the output status array SO (including SBO and ISBO) into bit - groups to generate the partitioned output status arrays SO[7:0], SO[15:8], SO[23:16], SO[31:24]. The second bit - group partitioning device 602 partitions the round key RK into bit - groups to generate the partitioned round keys RK[7:0], RK[15:8], RK[23:16], RK[31:24]. The third bit - group partitioning device 603 partitions the result data ARK into bit - groups to generate the partitioned result data ARK[7:0], ARK[15:8], ARK[23:16], ARK[31:24].

[0348] The first logic operation unit 604 performs an exclusive - OR operation on the partitioned output status arrays SO[7:0], SO[15:8], SO[23:16], SO[31:24] to generate the simplified output status array SBOXi[7:0]. The second logic operation unit 605 performs an exclusive - OR operation on the partitioned round keys RK[7:0], RK[15:8], RK[23:16], RK[31:24] to generate the simplified round key RKXi[7:0]. The third logic operation unit 606 performs an exclusive - OR operation on the partitioned result data ARK[7:0], ARK[15:8], ARK[23:16], ARK[31:24] to generate the simplified result data ARKXi[7:0].

[0349] The fourth logic operation unit 607 performs an exclusive - OR operation on the simplified output status array SBOXi[7:0] and the simplified round key RKXi[7:0] to generate the sixth result R6. The seventh comparator CMP7 compares the sixth result R6 and the simplified result data ARKXi[7:0] to generate the third verification signal VF3.

[0350] Figure 7 Displays a block diagram of the encryption / decryption device according to another embodiment of the present invention. The Figure 7 encryption / decryption device 700 of Figure 1 is compared with the encryption / decryption device 100 of

[0351] According to an embodiment of the present invention, the first verification unit 701 is the corresponding Figure 3 first verification unit 300, which is used to execute formula 40. When the first verification signal VF1 is at the first logic level, the controller 130 determines that the binary field multiplication - by - two operation, multiplication - by - four operation, and multiplication - by - eight operation performed by the hybrid row / inverse - hybrid row unit 146 are correct.

[0352] According to an embodiment of the present invention, the second verification unit 702 corresponds to Figure 5 the second verification unit 500, and is used to execute Equation 45. When the second verification signal VF2 is at the first logic level, the controller 130 determines that the byte substitution transformation or the inverse byte substitution transformation performed by the byte substitution / inverse byte substitution unit 145 is correct.

[0353] According to an embodiment of the present invention, the third verification unit 703 corresponds to Figure 6 the third verification unit 600, and is used to execute Equation 46. When the third verification signal VF3 is at the first logic level, the controller 130 determines that the mix row transformation or the inverse mix row transformation performed by the mix row / inverse mix row unit 146 and the transformation performed by the round key addition unit 147 are correct.

[0354] The present invention provides an encryption / decryption device with a verification mechanism, which is applicable to any implementation manner of byte substitution transformation. Although there are many implementation manners of byte substitution transformation or inverse byte substitution transformation, the verification mechanism of the encryption / decryption device of the present invention can detect whether an error occurs in the operation when the input value of the multiplicative inverse is 0x0, and can detect whether an error occurs in the binary field multiplication operation in the mix row operation and the inverse mix row operation. In addition, the verification mechanism proposed by the present invention can also protect the decryption program to ensure the security of the encrypted or decrypted data.

[0355] Although the embodiments of the present disclosure and their advantages have been disclosed above, it should be understood that any person skilled in the art can make changes, substitutions and modifications without departing from the spirit and scope of the present disclosure. In addition, the protection scope of the present disclosure is not limited to the processes, machines, manufactures, compositions of matter, devices, methods and steps in the specific embodiments described in the specification. Any person skilled in the art can understand the processes, machines, manufactures, compositions of matter, devices, methods and steps developed currently or in the future from the disclosure content of some embodiments of the present disclosure. As long as they can implement substantially the same functions or obtain substantially the same results in the embodiments described herein, they can be used according to some embodiments of the present disclosure. Therefore, the protection scope of the present disclosure includes the above-mentioned processes, machines, manufactures, compositions of matter, devices, methods and steps. In addition, each patent application scope constitutes an individual embodiment, and the protection scope of the present disclosure also includes the combination of each patent application scope and embodiment.

Claims

1. An encryption device, characterized in that: include: A one-bit group replacement unit performs a conversion on an input state array to generate an output state array; a mixing row unit, performing a mixing row operation on the output state array to generate a mixing array, wherein the mixing row operation includes a multiplication operation; A round key addition unit performs a binary field addition operation on the mixed array and a round key to generate a result data; a first verification unit, determining whether the output state array and the mixed array conform to a corresponding relationship, and generating a first verification signal; and A controller determines whether the binary field multiplication operation performed by the mixed row unit is correct according to the first verification signal.

2. The encryption device according to claim 1, characterized in that When the mixed row unit performs the binary field multiplication operation on a multiplicand array and multiplies the multiplicand array by two, the multiplicand array is shifted left by one position to generate a left-shifted array; wherein a most significant bit of the multiplicand array copies a first digit to generate a first value, wherein the number of bits of the multiplicand array is the first digit minus 1; A first predetermined value is ANDed with the first value to generate a second value; The left shift array and the second value perform an exclusive OR operation to generate a one-by-two array.

3. The encryption device according to claim 2, characterized in that: When the first digit is 8, each bit of the multiplier array and each bit of the multiplicand array have the above corresponding relationship; The above correspondence includes: The eighth bit of the multiplier array is equal to the seventh bit of the multiplicand array; The seventh bit of the multiplier array is equal to the sixth bit of the multiplicand array; The sixth bit of the multiplier array is equal to the fifth bit of the multiplicand array; The fifth bit of the multiplier array is equal to the result of the exclusive OR operation of the fourth bit of the multiplicand array and the eighth bit of the multiplicand array; The fourth bit of the multiplier array is equal to the result of the exclusive OR operation of the third bit of the multiplicand array and the eighth bit of the multiplicand array; The third bit of the multiplier array is equal to the second bit of the multiplicand array; The second bit of the multiplier array is equal to the result of the exclusive OR operation of the first bit of the multiplicand array and the eighth bit of the multiplicand array; The first bit of the multiplier array is equal to the eighth bit of the multiplicand array.

4. The encryption device according to claim 2, characterized in that: The first verification circuit comprises: a first divide-by-two circuit for performing a one-by-two operation on the one-by-two array to generate a first result; a second divide-by-two circuit for performing the divide-by-two operation on the one-by-four array to generate a second result; a third divide-by-two circuit, performing the above divide-by-two operation on the one-by-eight array to generate a third result; a first comparator, comparing the multiplicand array and the first result to generate a fourth result, wherein when the multiplicand array and the first result are equal, the fourth result is a first logic level; a second comparator, comparing the multiplied-by-two array and the second result to generate a fifth result, wherein when the multiplied-by-two array is equal to the second result, the fifth result is the first logic level; a third comparator, comparing the multiplied-by-four array and the third result to generate a sixth result, wherein when the multiplied-by-four array is equal to the third result, the sixth result is the first logic level; and a logic gate, wherein when the fourth result, the fifth result, and the sixth result are all at the first logic level, the logic gate outputs the first verification signal at the first logic level; The controller determines whether the binary field multiplication operation performed by the mixed column unit is correct based on the first verification signal at the first logic level.

5. A decryption device, characterized in that: include: a bit-reversal unit, which performs a conversion on an input state array to generate an output state array; an anti-mixing row unit, performing an anti-mixing row operation on the output state array to generate an anti-mixing array, wherein the anti-mixing row operation includes a multiplication operation; A round key addition unit performs a binary field addition operation on the anti-mixing array and a round key to generate a result data; a first verification unit, determining whether the output state array and the anti-mixing array conform to a corresponding relationship, and generating a first verification signal; and A controller determines whether the binary field multiplication operation performed by the anti-mixing row unit is correct according to the first verification signal.

6. An encryption device, characterized in that: include: A one-bit group replacement unit performs a conversion on an input state array to generate an output state array; a mixing row unit, performing a mixing row operation on the output state array to generate a mixing / de-mixing array; A round key addition unit performs a binary field addition operation on the mixed array and a round key to generate a result data; a second verification unit, verifying the correspondence between the input state array and the output state array to generate a second verification signal; and A controller determines whether the conversion performed by the bit replacement unit is correct according to the second verification signal.

7. The encryption device according to claim 6, characterized in that: When the encryption device performs an encryption procedure, the second verification unit determines whether the input state array is a first predetermined value; When the input state array is the first predetermined value, the second verification unit determines whether the output state array is a second predetermined value; When the input state array is the first predetermined value and the output state array is the second predetermined value, the second verification unit determines that the conversion is correct; When the input state array is the first predetermined value and the output state array is not the second predetermined value, the second verification unit determines that the conversion is incorrect.

8. A decryption device, characterized in that: include: a bit-reversal unit, which performs a conversion on an input state array to generate an output state array; an anti-mixing row unit, performing an anti-mixing row operation on the output state array to generate an anti-mixing array; A round key addition unit performs a binary field addition operation on the anti-mixing array and a round key to generate a result data; a second verification unit, verifying the correspondence between the input state array and the output state array to generate a second verification signal; and A controller determines whether the conversion performed by the bit-reversing unit is correct according to the second verification signal.

9. An encryption device, characterized in that: include: A one-bit group replacement unit performs a conversion on an input state array to generate an output state array; a mixing row unit, performing a mixing row operation on the output state array to generate a mixing array; A round key addition unit performs a binary field addition operation on the mixed array and a round key to generate a result data; a third verification unit, verifying the corresponding relationship between the result data and the output state array, and generating a third verification signal; and A controller determines whether the mixed row operation performed by the mixed row unit and the binary field addition operation performed by the round key addition unit are correct according to the third verification signal.

10. A decryption device, characterized in that: include: a bit-reversal unit, which performs a conversion on an input state array to generate an output state array; an anti-mixing row unit, performing an anti-mixing row operation on the output state array to generate an anti-mixing array; A round key addition unit performs a binary field addition operation on the anti-mixing array and a round key to generate a result data; a third verification unit, verifying the corresponding relationship between the result data and the output state array, and generating a third verification signal; and A controller determines whether the demixing row operation performed by the demixing row unit and the binary field addition operation performed by the round key addition unit are correct according to the third verification signal.