SM4 algorithm implementation method and system of dual variable wheel structure

By using the combination of dual variable wheel structure and RISC-V processor in the SM4 algorithm, the resource and power consumption problems implemented by the SM4 algorithm in the Internet of Things devices are solved, and the encryption and decryption function with high efficiency and low power consumption is realized.

CN120165839AActive Publication Date: 2025-06-17NAT UNIV OF DEFENSE TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510132230.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-06-17
Estimated Expiration
2045-02-06

AI Technical Summary

Technical Problem

The hardware implementation of the existing SM4 algorithm is difficult to balance throughput, power consumption and hardware resource consumption in low clock rate, low data volume IoT devices, and it is difficult to meet the needs of high real-time and low power consumption.

Method used

The SM4 algorithm implementation method adopts a dual variable wheel structure, transmits configuration data and calculation results through the ICB bus, and combines the modular and low-power characteristics of the RISC-V processor to flexibly configure the number of encryption wheels to balance throughput and resource consumption.

Benefits of technology

It realizes efficient encryption and decryption on small and low-clock IoT devices, reduces power consumption, improves system response speed, and is suitable for efficient encryption and decryption in low-power IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165839A_ABST
    Figure CN120165839A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of hardware security, and discloses an SM4 algorithm implementation method and system of a dual variable wheel structure, and the method comprises the steps: transmitting configuration data needed by a host to an SM4 algorithm core through an ICB bus; and transmitting the data calculated by the SM4 algorithm core to a host. According to the dual variable wheel structure provided by the invention, the SM4 algorithm can flexibly configure the encryption round number so as to balance the throughput and the resource consumption. The number of rounds is increased under the requirement of high throughput so as to improve the encryption and decryption speed; and the number of turns is reduced under the low power consumption requirement to prolong the battery life. According to the design, the modularization and low power consumption characteristics of the RISC-V are combined, and efficient and flexible technical support is provided for encryption processing in diversified Internet of Things scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of hardware security, and particularly relates to a method and system for implementing the SM4 algorithm with a dual variable-round structure. Background Art

[0002] The SM4 block cipher algorithm is a symmetric encryption algorithm independently designed in China and is widely used for data encryption protection of various Internet of Things (IoT) devices. However, with the rapid development of IoT technology, the data encryption and decryption requirements of these devices at low clock rates have become increasingly complex, and many limitations of traditional SM4 implementation methods have been exposed in this scenario. Currently, the implementation of the SM4 algorithm is mainly divided into software encryption and hardware encryption. Although software encryption is simple to implement, it is difficult to provide smooth encryption and decryption services under low clock rate conditions, with insufficient computing efficiency and relatively low security, which is likely to become a bottleneck in system performance. On the other hand, although hardware encryption has higher performance, it often requires more hardware resource support and brings higher power consumption, making it difficult for small-sized and low-cost IoT devices to bear. Therefore, the existing implementation methods are difficult to meet the requirements of IoT scenarios with low clock rates and low data volumes in terms of resources and power consumption.

[0003] In addition, the current hardware implementation of SM4 also faces two deficiencies. First, it is difficult to balance throughput and hardware resource consumption in hardware implementation. The 32-round pipeline structure can significantly improve encryption throughput, but its consumption of hardware resources also increases correspondingly, limiting its application in small-sized and low-cost IoT devices. The 32-round loop iteration structure, although it can reduce hardware resource consumption, leads to a significant increase in processing time, affecting the system's response speed and is not suitable for high-real-time scenarios. Second, power consumption control is also an important problem. Most IoT devices rely on battery power supply and have strict requirements for energy consumption. The hardware implementation of the SM4 algorithm may bring relatively high energy consumption, affecting the battery life performance. Therefore, under the premise of meeting the encryption and decryption requirements, how to reduce power consumption to ensure the long-term stable operation of the device has become a key problem that urgently needs to be solved. Summary of the Invention

[0004] To solve the problems existing in the prior art, the present invention provides a method and system for implementing the SM4 algorithm with a dual variable-round structure. This variable structure design not only effectively balances throughput, power consumption, and hardware resource consumption, but also improves the system's response speed, making the SM4 algorithm more adaptable to meet the application requirements of small-sized and low clock rate IoT devices, and providing a secure and reliable technical guarantee for efficient encryption and decryption in low-power IoT devices.

[0005] To achieve the above object, the present invention provides the following solutions:

[0006] A method for implementing the SM4 algorithm with a dual-variable wheel structure, the method comprising:

[0007] Transmit the configuration data required by the host to the SM4 algorithm core through the ICB bus;

[0008] Transmit the data calculated by the SM4 algorithm core to the host.

[0009] Preferably, the configuration data required by the host includes: the data to be encrypted / decrypted, the encryption / decryption selection signal, and the round number selection signal.

[0010] Preferably, the SM4 algorithm core includes: a control module, a parameter storage module, an S-box module, an encryption / decryption module, a key expansion module, and a round buffer module.

[0011] Preferably, the control module is used to implement the bit-width matching and signal allocation functions, and is in the form of a state machine, which is divided into an idle state (i.e., IDLE), an encryption state (i.e., EC_EN), a decryption state (i.e., DEC_EN), a key preparation state (i.e., PRE_KEY), and a key expansion state (i.e., KEY_EXP); when receiving the status data (i.e., EN_SEL) transmitted by the ICB bus, through parsing, it is passed to the corresponding module, and the state machine will enter the corresponding state from the IDLE state; if EN_SEL is 00, it is the reset state and enters the IDLE state; if EN_SEL is 11, the state machine jumps from the IDLE state to the PRE_KEY state, and then jumps to the KEY_EXP state; if EN_SEL is 01, the state machine jumps from the IDLE state to the EN_EN state; if EN_SEL is 10, the state machine jumps from the IDLE state to the DEC_EN state.

[0012] Preferably, the parameter storage module is used to store the system parameter FK and the fixed parameter CK required during the key expansion process of the SM4 algorithm, and when the control module gives an enable signal, the parameter is transmitted to the key expansion module.

[0013] Preferably, the S-box module is used to store the mapping data during the non-linear transformation process of key expansion and encryption / decryption, and the conversion of the S-box is implemented by the look-up table method.

[0014] Preferably, the encryption / decryption module is divided into two parts: round transformation and reverse order transformation. Each round transformation includes shift, S-box conversion, and corresponding XOR operations; in the form of a combination of pipeline and loop iteration, when receiving the round number selection signal parsed by the control module, the loop number and the pipeline structure are adjusted; the decryption key input is the reverse order of the encryption.

[0015] Preferably, the key expansion module is a round transformation part, and each round transformation also includes a shift, an S-box transformation, and corresponding exclusive OR operations; the class adopts a form combining pipelining and loop iteration, and adjusts the number of loop rounds and the pipeline structure when receiving the round number selection signal parsed by the control module.

[0016] The present invention also provides a system for implementing the SM4 algorithm with a dual variable round structure, which is used to implement any of the above methods. The system includes: a first transmission module and a second transmission module;

[0017] The first transmission module is used to transmit the configuration data required by the host to the SM4 algorithm core through the ICB bus;

[0018] The second transmission module is used to transmit the data calculated by the SM4 algorithm core to the host.

[0019] Compared with the prior art, the beneficial effects of the present invention are:

[0020] The present invention discloses an IP of the SM4 algorithm with a dual variable round structure based on the RISC-V processor, which is applicable to Internet of Things devices operating at a low clock rate and with a small amount of encrypted and decrypted data. Existing SM4 implementation methods are usually divided into software encryption and hardware encryption. The former is limited by low security and efficiency, while the latter, although having excellent performance, requires more resources and higher power consumption, and it is difficult to meet the needs of small low-power devices. To address the above deficiencies, the dual variable round structure proposed by the present invention enables the SM4 algorithm to flexibly configure the number of encryption rounds to balance throughput and resource consumption. Increase the number of rounds to improve the encryption and decryption speed under high throughput requirements; reduce the number of rounds to extend the battery life under low power consumption requirements. This design combines the modular and low-power characteristics of RISC-V to provide efficient and flexible technical support for encryption processing in diverse Internet of Things scenarios. Description of the Drawings

[0021] In order to more clearly illustrate the technical solutions of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the following described drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0022] Figure 1 Schematic diagram of the hardware structure for implementing the SM4 algorithm with a dual variable round structure according to an embodiment of the present invention;

[0023] Figure 2 State transition diagram of the control module according to an embodiment of the present invention;

[0024] Figure 3 Principle block diagram of SM4 - n rounds combined into 1 according to an embodiment of the present invention;

[0025] Figure 4 This is the principle block diagram of SM4-4-round combination 1 in the embodiments of the present invention;

[0026] Figure 5 This is the principle block diagram of SM4-32-round iteration in the embodiments of the present invention. Specific embodiments

[0027] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0028] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.

[0029] Embodiment 1

[0030] In the ECB working mode, there are usually three schemes for the hardware implementation of the round function of the SM4 algorithm. The first is the pipeline structure, which consists of 32 cascaded encryption and decryption modules. When the key of each round is known, it only takes one clock cycle to complete one encryption and decryption. The second is the loop iteration structure, which loops 32 times through the same set of encryption and decryption modules to complete encryption and decryption on the premise of knowing the key, but it requires 32 clock cycles. The third scheme combines the pipeline and loop structures, combines n rounds in 32 rounds into a "n-round combination" circuit, and runs it in a loop. The advantage of this method is to reduce the circuit area, but the intermediate results generated in each cycle need to be stored in registers, and a multiplexer is required during the loop. The present invention selects the third scheme for implementation.

[0031] In response to the problems of the prior art, the present invention proposes an SM4 algorithm IP with a dual variable round structure based on the RISC-V processor. RISC-V is an emerging open source instruction set architecture with the characteristics of modularity and low power consumption, and is particularly suitable for embedded and Internet of Things devices. The dual variable round structure endows the SM4 algorithm with a highly flexible adjustment ability: in scenarios with high throughput requirements, the algorithm can increase the number of rounds to improve the encryption speed to cope with large amounts of data; while in low power consumption scenarios, the number of rounds can be reduced to reduce energy consumption and extend the battery life of the device. This variable structure design not only effectively balances the throughput, power consumption, and consumption of hardware resources, but also improves the response speed of the system, making the SM4 algorithm more adaptable to meet the application requirements of small, low clock rate Internet of Things devices, and providing a secure and reliable technical guarantee for efficient encryption and decryption in low power consumption Internet of Things devices.

[0032] The implementation of the SM4 algorithm with a dual variable wheel structure designed in the present invention is divided into the ICB bus part and the SM4 algorithm core part. The entire hardware implementation structure is as Figure 1 shown.

[0033] The ICB bus part is mainly the read-write protocol, which transmits the data (data) that the host needs to encrypt and decrypt, the encryption and decryption selection signal (encdec_sel), the round number selection signal (round_sel), and other configuration data to the SM4 algorithm core, and then transmits the data (out_data) calculated by the algorithm core to the host.

[0034] Specifically, the calculation process is mainly divided into encryption and decryption operations and key expansion operations. The encryption process includes 32 rounds of non-linear iteration and an inverse order transformation. Each round of iteration is implemented through round key addition and composite permutation. In each round of iteration, the round key rk i is used for exclusive OR operation, and the round key is generated by the key expansion algorithm. Specifically, for each round of iteration, from X i to X i+4 in the state update, a non-linear transformation is performed through the composite permutation function T, and the formula is as follows:

[0035]

[0036] Among them, the composite permutation function is T(·) = L(τ(·)), τ(m) = S(m) represents S-box substitution, represents linear transformation. After 32 rounds of iteration, the state vector (X 32 , X 33 , X 34 , X 35 ) is reversed to obtain the ciphertext output (Y0, Y1, Y2, Y3). The decryption operation is the inverse process of encryption.

[0037] The generation process of the round key is the key expansion process. This process is similar to the encryption process, and the main difference lies in the different linear shift operations. Specifically, the key expansion generates 32 rounds of round keys rk i , and shares an S-box with the encryption and decryption processes. This algorithm uses the system parameter FK = (FK0, FK1, FK2, FK3) and the fixed parameter CK i (round constant) to initialize the non-linear iterative calculation of the key.

[0038] The initial key (k0, k1, k2, k3) of the key expansion is obtained by exclusive ORing the user key K = (K0, K1, K2, K3) with the system parameter FK, that is:

[0039]

[0040] In each iteration, the round key rk i is generated by the following formula:

[0041]

[0042] where T(·) = L(τ(·)), τ(m) = S(m) represents the S-box substitution, and represents the linear transformation. After 32 iterations, the generated rk i values will be used as the round keys required for each round in the encryption and decryption processes.

[0043] The SM4 algorithm core mainly includes a control module, a parameter storage module, an S-box module, an encryption and decryption module, a key expansion module, and a round buffer module. The descriptions of each functional module are as follows:

[0044] 1. Control module

[0045] The control module implements the bit-width matching and signal distribution functions and is in the form of a state machine. Specifically, as Figure 2 shown, it is divided into an idle state (IDLE), an encryption state (EC_EN), a decryption state (DEC_EN), a key preparation state (PRE_KEY), and a key expansion state (KEY_EXP). When receiving the status data (EN_SEL) transmitted through the ICB bus, after parsing, it is passed to the corresponding module, and the state machine will enter the corresponding state from the IDLE state. If EN_SEL is 00, it is the reset state and enters the IDLE state; if EN_SEL is 11, the state machine jumps from IDLE to the PRE_KEY state and then to the KEY_EXP state; if EN_SEL is 01, the state machine jumps from IDLE to the EN_EN state; if EN_SEL is 10, the state machine jumps from IDLE to the DEC_EN state.

[0046] 2. Parameter storage module

[0047] The parameter storage module mainly stores the system parameter FK and the fixed parameter CK required in the SM4 algorithm key expansion process. When the control module gives an enable signal, this parameter is transmitted to the key expansion module.

[0048] 3. S-box module

[0049] The S-box module stores the mapping data in the non-linear transformation process during key expansion and encryption / decryption, and implements the conversion of the S-box using the look-up table method. Since the same S-box is used for key expansion and encryption / decryption, in order to save hardware resources, the two modules share one S-box module.

[0050] 4. Encryption and decryption module

[0051] The encryption and decryption module is divided into two parts: round transformation and reverse order transformation. Each round of transformation includes shift, S-box transformation, and corresponding XOR operations. If there is only one round structure, the round transformation needs to go through 32 rounds of iteration. If a combination of pipeline and loop iteration is adopted, the purpose of improving throughput can be achieved. For example, a four-stage pipeline combined with eight rounds of iteration. When receiving the round number selection signal parsed by the control module, the number of loop rounds and the pipeline structure are adjusted. Since the encryption and decryption processes are exactly the same except for the order, encryption and decryption multiplexing is performed to reduce area consumption. Therefore, the key input for decryption is the reverse order of that for encryption.

[0052] 5. Key Expansion Module

[0053] The key expansion module is mainly the round transformation part. Each round of transformation also includes shift, S-box transformation, and corresponding XOR operations. Similarly, a combination of pipeline and loop iteration is adopted. When receiving the round number selection signal parsed by the control module, the number of loop rounds and the pipeline structure are adjusted.

[0054] 6. Round Buffer Module

[0055] The round buffer module is mainly composed of a register array, a data selector, and timing control logic, and is used to store the intermediate data generated by the encryption and decryption module and the key expansion module in each round.

[0056] Since the encryption and decryption processes are the same, only the order is reversed, so the encryption and decryption processes are multiplexed to reduce area consumption. At the same time, in this design, a "variable rounds combined into one" structure is introduced, enabling the encryption and decryption module and the key expansion module to flexibly set the number of combined rounds. The specific configurable information is shown in Table 1. The overall system block diagram is as Figure 3 shown. After the key expansion module completes a set of round operations, it stores the key intermediate result in a register for use by the encryption and decryption module, thereby reducing the number of registers. At the same time, the key expansion module and the encryption and decryption module can work in parallel in most rounds, effectively improving the execution efficiency of the algorithm.

[0057] Table 1 Key Expansion and Encryption / Decryption Round Number Configuration Table

[0058]

[0059] Example 2

[0060] The SM4 algorithm IP proposed by the present invention has the ability of dynamic configuration, which can be flexibly adjusted according to the Internet of Things application scenarios to meet different performance and resource requirements, thus improving the practicability and efficiency of the algorithm. This IP is particularly suitable for scenarios with low clock rates and small amounts of data. For example, in the scenario of intelligent environmental monitoring sensors, devices usually upload a small amount of data under specific conditions, such as air quality or temperature and humidity data. This IP can operate efficiently at low clock rates, providing secure data encryption processing for such low-power devices and ensuring the security of data transmission. Its flexible configuration characteristics enable this IP to adapt to the encryption performance requirements of different devices in diverse Internet of Things environments and meet the requirements of efficient and secure data transmission.

[0061] In the data transmission part, the design adopts the connection method of the custom bus ICB (Internal Compact Bus) of the Hummingbird E203 processor to connect the designed SM4 algorithm IP with the Hummingbird E203. Compared with the traditional AXI and AHB protocols, the ICB protocol is simpler and easier to control, making it suitable for Internet of Things devices with limited resources. The ICB bus only contains two independent channels: the command channel and the result return channel. The read and write operations share the command and return channels, greatly simplifying the communication structure.

[0062] The timing control of the ICB is also very simple: the master device sends a write operation request to the slave device through the command channel of the ICB. When the signal icb_cmd_read is low (write request) or high (read request), the slave device immediately accepts the request and sets the icb_cmd_ready signal to high when the request is valid, indicating that the request has been successfully received. If the slave device returns the correct feedback result in the same clock cycle, the icb_rsp_ready signal is set to high, and the master device can immediately receive this result. Through this compact and clear control method, the ICB achieves a low-latency transmission response, reduces the complexity of data transmission, and enables the IP core to efficiently perform data interaction.

[0063] In the encryption and decryption part, when Internet of Things devices need high-speed encryption while being restricted by hardware resources, the present invention provides an efficient hardware configuration scheme. The number of rounds of key expansion and encryption / decryption can be configured to 4 rounds, and an 8-stage pipeline structure is adopted to improve the throughput. The system block diagram of four rounds in one is as Figure 4As shown. In this structure, the key expansion module (keyexpansion) consists of multiple "one round for exp" sub-modules. Each sub-module performs one round of key expansion, successively completing the generation and update of the round keys. The multiplexer MUX1 is used to configure the register addresses to facilitate storing the intermediate results in the appropriate registers during the iterative key generation process. While MUX2 and MUX3 are used to switch the input data for the first round of iteration and subsequent iterations. The advantage of this design is that it can flexibly adjust the number of encryption and decryption rounds, thereby adjusting the balance between hardware consumption and computing speed in different scenarios. Assume the data to be encrypted is date_in = (X0, X1, X2, X3), and the initial round key rk = (r0, r1, r2, r3).

[0064] Step 1: The CPU sends the encryption / decryption request and configuration information through the ICB bus.

[0065] Step 2: After receiving the information, the SM4 algorithm IP core starts to configure the number of encryption / decryption rounds and reads the data to be encrypted.

[0066] Step 3: After the data preparation is completed, first perform the 8-stage pipeline of the key expansion for the first round, and temporarily store the output of each stage of the pipeline in the round buffer module.

[0067] Step 4: Use the key in the round buffer module to perform the encryption / decryption operation of the 8-stage pipeline for the first round, and at the same time perform the key expansion of the 8-stage pipeline for the second round, and save the intermediate data to the round buffer module.

[0068] Step 5: Repeat Step 4 three times.

[0069] Step 6: After the 4-round repetition is completed, return the output data to the memory through the ICB bus.

[0070] When the Internet of Things device is in a scenario with extremely scarce hardware resources, at this time, the number of key expansions and encryption / decryption rounds to be configured is set to 32 rounds, that is, 32 rounds of iteration. The specific structure is as Figure 5 shown. At this time, it is equivalent to ordinary SM4 encryption / decryption. However, the difference is that except for the key expansion in the first round and the encryption / decryption calculation in the last round, the rest of the rounds are almost parallel, saving resources while ensuring speed. Assume the data to be encrypted is date_in = (X0, X1, X2, X3), and the initial round key rk = (r0, r1, r2, r3).

[0071] Step 1: The CPU sends the encryption / decryption request and configuration information through the ICB bus.

[0072] Step 2: After receiving the information, the SM4 algorithm IP core starts to configure the number of encryption / decryption rounds and reads the data to be encrypted.

[0073] Step 3: After the data preparation is completed, first perform the first round of key expansion, and temporarily store the output in the round buffer module.

[0074] Step 4: Use the key in the round buffer module to perform the encryption and decryption operations in the first round, and at the same time perform the second round of key expansion, and save all the intermediate data to the round buffer module.

[0075] Step 5: Repeat step 4 for 31 rounds.

[0076] Step 6: After 32 rounds of repetition, return the output data to the memory through the ICB bus.

[0077] Embodiment III

[0078] The present invention also provides an SM4 algorithm implementation system with a dual variable round structure. The system is used to implement any one of the above methods. The system includes: a first transmission module and a second transmission module;

[0079] The first transmission module is used to transmit the configuration data required by the host to the SM4 algorithm core through the ICB bus;

[0080] The second transmission module is used to transmit the data calculated by the SM4 algorithm core to the host.

[0081] The above embodiments are only descriptions of the preferred embodiments of the present invention, and do not limit the scope of the present invention. Without departing from the design spirit of the present invention, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present invention shall fall within the protection scope determined by the claims of the present invention.

Claims

1. A method for implementing the SM4 algorithm with a dual variable wheel structure, characterized in that: The method comprises: The configuration data required by the host is transmitted to the SM4 algorithm core through the ICB bus; The data calculated by the SM4 algorithm core is transmitted to the host.

2. The method according to claim 1, characterized in that The configuration data required by the host includes: encrypted and decrypted data, encryption and decryption selection signals, and round number selection signals.

3. The method according to claim 1, characterized in that: The SM4 algorithm core includes: control module, parameter storage module, S-box module, encryption and decryption module, key expansion module and round buffer module.

4. The method according to claim 3, characterized in that The control module is used to realize the bit width matching and signal distribution functions. It is in the form of a state machine, which is divided into an idle state, namely IDLE, an encryption state, namely EC_EN, a decryption state, namely DEC_EN, a key preparation state, namely PRE_KEY, and a key expansion state, namely KEY_EXP. When the status data transmitted by the ICB bus, namely EN_SEL, is received, it is parsed and transmitted to the corresponding module, and the state machine will enter the corresponding state from the IDLE state; if EN_SEL is 00, it is a reset state and enters the IDLE state; if EN_SEL is 11, the state machine jumps from IDLE to PRE_KEY state, and then jumps to KEY_EXP state; if EN_SEL is 01, the state machine jumps from IDLE to EN_EN state; if EN_SEL is 10, the state machine jumps from IDLE to DEC_EN state.

5. The method according to claim 3, characterized in that: The parameter storage module is used to store the system parameters FK and fixed parameters CK required in the key expansion process of the SM4 algorithm. When the control module gives an enable signal, the parameters are transmitted to the key expansion module.

6. The method according to claim 3, characterized in that The S-box module is used to store the mapping data in the process of key expansion and nonlinear transformation during encryption and decryption, and uses a table lookup method to implement the S-box conversion.

7. The method according to claim 3, characterized in that The encryption and decryption module is divided into two parts: round transformation and inverse transformation. Each round transformation includes shift, S-box conversion and corresponding XOR operation. It adopts a combination of pipeline and loop iteration. When receiving the round selection signal analyzed by the control module, the number of loop rounds and pipeline structure are adjusted. The decryption key input is in the reverse order of encryption.

8. The method according to claim 3, characterized in that The key expansion module is the round transformation part, and each round transformation also includes shift, S-box conversion and corresponding XOR operation; the class adopts the combination of pipeline and loop iteration, and adjusts the number of loop rounds and pipeline structure when receiving the round selection signal parsed by the control module.

9. A dual variable wheel structure SM4 algorithm implementation system, the system is used to implement the method according to any one of claims 1 to 8, characterized in that: The system comprises: a first transmission module and a second transmission module; The first transmission module is used to transmit the configuration data required by the host to the SM4 algorithm core through the ICB bus; The second transmission module is used to transmit the data calculated by the SM4 algorithm core to the host.

Citation Information

Patent Citations

  • Configurable secret key SM4 encryption and decryption system based on FPGA

    CN116506106A

  • SM4 encryption method based on FPGA

    CN119201832A

  • SM4 acceleration processors, methods, systems, and instructions

    US20160026468A1

  • Instructions and logic to provide SIMD SM4 cryptographic block cipher functionality

    US20160094340A1