A data encryption method, device, medium and product based on the SM3 algorithm

By using the data encryption method of the SM3 algorithm in the chip, the multiple data sources are filled and grouped and iteratively compressed, which solves the problem of high hardware resource consumption during multi-data source calculation, and realizes high performance and low-cost data encryption, which is suitable for mobile terminals and Internet of Things devices.

CN120165842BActive Publication Date: 2025-07-22SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510638851.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-22
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

When multiple data sources are calculated simultaneously in chips, the prior art requires a large number of hash computing units, resulting in high hardware costs, large chip area and increased power consumption, limiting the application in mobile terminals and Internet of Things devices.

Method used

Using the data encryption method based on the SM3 algorithm, by receiving the data to be encrypted from several data sources, filling the grouping process is performed separately, and the data is allocated to different packet expansion units and iterative compression units for packet expansion calculation and iterative compression calculation. Multiple packet expansion units and iterative compression units are processed according to specific timing rules to realize pipelined operation.

Benefits of technology

Improve computing performance, reduce hardware resource usage, reduce chip area and cost, and enhance power consumption attack resistance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165842B_ABST
    Figure CN120165842B_ABST
Patent Text Reader

Abstract

The present application discloses a data encryption method, device, medium and product based on the SM3 algorithm, which relates to the field of chip design and includes: respectively performing padding and grouping processing on the data to be encrypted from several data sources to obtain data groups; allocating different data sources to different grouping expansion units, and based on the first preset timing rule, sequentially inputting each target data in each data group into the corresponding grouping expansion unit for grouping expansion calculation to obtain a preset number of groups of message words corresponding to each target data; based on the second preset timing rule, sequentially inputting each message word corresponding to each target data into different iterative compression units for iterative compression calculation to obtain a compression result corresponding to each target data; different iterative compression units perform iterative compression calculations for different rounds, and the output of each round of iterative compression calculation is the input of the corresponding next round of iterative compression calculation; determining the digest value of the corresponding data source based on the compression result of each target data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of chip design, and particularly to a data encryption method, device, medium and product based on the SM3 algorithm. Background Art

[0002] With the rapid development of information technology, higher challenges are posed to the performance and security of the SM3 cryptographic algorithm. In practical applications, the computing performance of the cryptographic algorithm has always been one of the key indicators. Especially in the chip application scenario, there are often situations where multiple data sources need to be calculated simultaneously.

[0003] The traditional solution is to set multiple hash function operation units in the chip, and each data source is connected to a hash function operation unit. Although this method can achieve the calculation of multiple data, it has serious defects. On the one hand, a large number of hash operation units are required, which greatly increases the hardware cost; on the other hand, when each data source performs operations, it also needs to be equipped with related modules such as a data padding unit, FIFO (First Input First Output) / RAM (Random Access Memory) storage resources, and complex control logic, resulting in a significant increase in the chip area and a significant increase in power consumption. This not only increases the production cost but also limits the application of the chip in some devices with strict requirements for power consumption and size, such as mobile terminals, Internet of Things devices, etc.

[0004] In summary, when multiple data sources perform operations simultaneously, how to ensure high performance and low hardware resource consumption is a problem to be solved at present. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a data encryption method, device, medium and product based on the SM3 algorithm, which can ensure high performance and low hardware resource consumption when multiple data sources perform operations simultaneously. The specific solutions are as follows:

[0006] In the first aspect, the present application discloses a data encryption method based on the SM3 algorithm, which is applied to a target hash function operation unit and includes:

[0007] Receiving the data to be encrypted from several data sources, and respectively performing padding and grouping processing on the data to be encrypted corresponding to each data source to obtain corresponding data groups; wherein, each data group includes a certain number of target data with the same length;

[0008] Allocate data sources of different channels to different grouping expansion units, and sequentially input each target data in each data group into the corresponding grouping expansion unit according to the first preset timing rule for grouping expansion calculation, so as to obtain a preset number of groups of message words corresponding to each target data;

[0009] Sequentially input each message word corresponding to each target data into different iterative compression units according to the second preset timing rule for iterative compression calculation, so as to obtain a compression result corresponding to each target data; wherein, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation;

[0010] Determine the digest value of the corresponding data source based on the compression result of each target data.

[0011] Optionally, different grouping expansion units correspond to different data paths based on a preset mapping relationship;

[0012] Correspondingly, allocating data sources of different channels to different grouping expansion units includes:

[0013] Allocate the data source of each data path to the corresponding grouping expansion unit based on the preset mapping relationship, set the gating clock switch of the grouping expansion unit to the on state, and set the output enable signal of the data path to a first target value for representing the enabled state.

[0014] Optionally, the data encryption method based on the SM3 algorithm of the present application further includes:

[0015] If there is no data to be encrypted in the target data path corresponding to any grouping expansion unit, configure any grouping expansion unit based on the first configuration method or the second configuration method, and set the output enable signal of the target data path to a second target value for representing the disabled state;

[0016] Wherein, the first configuration method is to set the gating clock switch of any grouping expansion unit to the off state;

[0017] The second configuration method is to set the gating clock switch of any grouping expansion unit to the on state, then generate a target random number by using a preset random number generator, and use the target random number as the data to be encrypted currently in the target data path, so as to perform the grouping expansion calculation and iterative compression calculation corresponding to the target data path, so as to obtain the digest value of the data source corresponding to the target data path.

[0018] Optionally, after determining the digest value of the corresponding data source based on the compression result of each target data, it further includes:

[0019] Determine the output enable signals of the data paths where each data source is located;

[0020] If the output enable signal is the first target value, the summary value corresponding to the output data source is output;

[0021] If the output enable signal is the second target value, output of the summary value corresponding to the data source is prohibited.

[0022] Optionally, padding and grouping processing is respectively performed on the data to be encrypted corresponding to each data source to obtain corresponding data groups, including:

[0023] Determine whether the length of the data to be encrypted corresponding to each data source is an integer multiple of the target length value;

[0024] If the length of the data to be encrypted is an integer multiple of the target length value, grouping processing is performed on the data to be encrypted based on the target length value to obtain corresponding data groups;

[0025] If the length of the data to be encrypted is not an integer multiple of the target length value, padding processing is performed on the data to be encrypted so that the length of the padded data to be encrypted is an integer multiple of the target length value, and then grouping processing is performed on the padded data to be encrypted based on the target length value to obtain corresponding data groups;

[0026] Wherein, each data group includes a certain number of target data, and the length of each target data is the target length value.

[0027] Optionally, based on the first preset timing rule, each target data in each data group is sequentially input into the corresponding grouping expansion unit for grouping expansion calculation to obtain a preset number of groups of message words corresponding to each target data, including:

[0028] For different data groups, based on the first sequence order between the data groups, the first target data of each data group is sequentially input into the corresponding grouping expansion unit within the current consecutive target number of clock cycles, and based on the first sequence order, the next target data corresponding to the first target data in each data group is sequentially input into the corresponding grouping expansion unit within the next consecutive target number of clock cycles until all target data is input; wherein, the target number is the same as the value of the expansion round of the grouping expansion unit;

[0029] For the same data group, within the corresponding grouping expansion unit, based on the second sequence order of each target data in the data group, the grouping expansion calculation of the first target data is completed within the current consecutive target number of clock cycles, and the grouping expansion calculation of the next target data is completed within the next consecutive target number of clock cycles until the grouping expansion calculation of all target data is completed to obtain a preset number of groups of message words corresponding to each target data; wherein, the preset number is the same as the value of the expansion round of the grouping expansion unit.

[0030] Optionally, the grouped expansion calculation of the target data is completed within a consecutive target number of clock cycles, including:

[0031] Within a consecutive target number of clock cycles, different rounds of grouped expansion calculations are respectively executed based on the expansion rounds and in the order of the clock cycles from front to back.

[0032] Optionally, each group of message words includes a bit message word and an extended message word; wherein, the extended message word is calculated based on the corresponding bit message word.

[0033] Optionally, the process by which the grouped expansion unit performs grouped expansion calculation on the target data to obtain the bit message word includes:

[0034] Group the target data according to the target number of bits to obtain a number of initial bit words;

[0035] Calculate based on the initial bit words and a preset recurrence expression to generate target bit words; wherein, the recurrence expression is constructed based on a permutation function, an exclusive OR operation rule, and a left shift operation rule;

[0036] Obtain the bit message word based on the initial bit words and the target bit words.

[0037] Optionally, the number of iterative compression units is the same as the number of groups of message words;

[0038] Correspondingly, based on the second preset timing rule, each message word corresponding to each target data is sequentially input into different iterative compression units for iterative compression calculation to obtain a compression result corresponding to each target data, including:

[0039] For any target data, each message word is sequentially assigned to different iterative compression units based on the sequential generation order of the message words and the sequential iteration order of the iterative compression units;

[0040] Determine the target input value of each iterative compression unit, and sequentially perform iterative compression calculation in each iterative compression unit based on the corresponding target input value and message word within a consecutive target number of clock cycles, so as to obtain a compression result corresponding to any target data after completing the last round of iterative compression calculation of any target data; wherein, the target number is the same as the number of iterative compression units.

[0041] Optionally, determining the target input value of each iterative compression unit includes:

[0042] If it is determined based on the sequential iteration order that the current iterative compression unit is the first-round iterative compression unit, obtain the target initial value and use the target initial value as the target input value of the current iterative compression unit;

[0043] If it is determined that the current iterative compression unit is a non-first-round iterative compression unit based on the sequential iteration order, obtain the output value of the previous-round iterative compression calculation, and use the output value of the previous-round iterative compression calculation as the target input value of the current iterative compression unit.

[0044] Optionally, obtaining the target initial value includes:

[0045] If any target data is the first target data in the corresponding data group, use the preset value as the target initial value;

[0046] If any target data is not the first target data in the corresponding data group, obtain the compression result corresponding to the previous target data in the same data group, and calculate the target initial value based on the compression result corresponding to the previous target data.

[0047] Optionally, determining the digest value of the corresponding data source based on the compression result of each target data includes:

[0048] Determine whether the current target data is the last target data in the corresponding data group;

[0049] If the current target data is the last target data in the corresponding data group, perform an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and use the exclusive OR operation result as the digest value of the corresponding data source;

[0050] If the current target data is not the last target data in the corresponding data group, perform an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and use the exclusive OR operation result as the target initial value of the first-round iterative compression unit corresponding to the next target data until the compression result of the last target data in the corresponding data group is obtained.

[0051] In a second aspect, the present application discloses an electronic device, including:

[0052] A memory for storing a computer program;

[0053] A processor for executing the computer program to implement the steps of the data encryption method based on the SM3 algorithm disclosed above.

[0054] In a third aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the data encryption method based on the SM3 algorithm disclosed above are implemented.

[0055] In a fourth aspect, the present application discloses a computer program product including a computer program / instructions; when the computer program / instructions are executed by a processor, the steps of the data encryption method based on the SM3 algorithm disclosed above are implemented.

[0056] It can be seen that the target hash function operation unit in the present application receives the data to be encrypted from several data sources, and performs padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups; wherein, each data group includes a certain number of target data with the same length; different data sources are allocated to different grouping expansion units, and each target data in each data group is sequentially input into the corresponding grouping expansion unit for grouping expansion calculation based on the first preset timing rule to obtain a preset number of groups of message words corresponding to each target data; each message word corresponding to each target data is sequentially input into different iterative compression units for iterative compression calculation based on the second preset timing rule to obtain a compression result corresponding to each target data; wherein, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation; the digest value of the corresponding data source is determined based on the compression result of each target data.

[0057] Beneficial effects: The target hash function operation unit in this application can receive the data to be encrypted from several data sources simultaneously, and can perform padding and grouping processing, grouped expansion calculation, and iterative compression calculation on multiple data sources respectively. First, it is necessary to perform padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups, so that each data group includes a certain number of target data with the same length. Secondly, multiple grouped expansion units are provided in the target hash function operation unit of this application, which can realize the distribution of different data sources to different grouped expansion units for processing, so as to perform grouped expansion calculation on multiple data sources simultaneously. Specifically, it is necessary to sequentially input each target data in each data group to the corresponding grouped expansion unit for grouped expansion calculation based on the first preset timing rule, so as to obtain a preset number of groups of message words corresponding to each target data. Further, multiple iterative compression units are also provided in the target hash function operation unit of this application to realize iterative compression calculation on multiple data sources simultaneously. Specifically, based on the second preset timing rule, each message word corresponding to each target data is sequentially input to different iterative compression units for iterative compression calculation. Among them, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation, so as to quickly obtain the compression result corresponding to each target data, greatly shortening the overall encryption time and improving the operation speed. Finally, the digest value of the corresponding data source is determined based on the compression result of each target data. That is to say, in this application, the data of different data sources are processed in the corresponding grouped expansion units and iterative compression units according to specific timing rules, and each unit performs its own duties and works in cooperation. Multiple grouped expansion units are responsible for expanding the target data into message words, and multiple iterative compression units then perform multiple rounds of iterative compression calculation based on the obtained message words. This pipeline processing method reduces the data waiting time, improves the utilization rate of hardware resources, and effectively improves the operation performance. Moreover, for multiple data sources in this application, only one target hash function operation unit is required, which greatly reduces the occupation of hardware resources and reduces the chip area and cost. Description of the Drawings

[0058] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0059] Figure 1 Flowchart of a data encryption method based on the SM3 algorithm disclosed in this application;

[0060] Figure 2 It is a hardware architecture diagram of the SM3 algorithm disclosed in this application;

[0061] Figure 3 It is a flowchart of a specific data encryption method based on the SM3 algorithm disclosed in this application;

[0062] Figure 4 It is a data input timing diagram disclosed in this application;

[0063] Figure 5 It is a timing diagram of the calculation of the packet expansion unit under full bandwidth conditions disclosed in this application;

[0064] Figure 6 It is a timing diagram of the calculation of the packet expansion unit under non-full bandwidth conditions disclosed in this application;

[0065] Figure 7 It is a timing diagram of the calculation of the iterative compression unit disclosed in this application;

[0066] Figure 8 It is a schematic structural diagram of a data encryption device based on the SM3 algorithm disclosed in this application;

[0067] Figure 9 It is a structural diagram of an electronic device disclosed in this application. Specific embodiments

[0068] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0069] In the case where multiple data sources need to be calculated simultaneously, the traditional solution is to set multiple hash function operation units in the chip, and each data source is connected to a hash function operation unit. Although this method can achieve the calculation of multiple data sources, it has serious defects. On the one hand, a large number of hash operation units are required, which greatly increases the hardware cost; on the other hand, when each data source performs operations, relevant modules such as data padding units, FIFO / RAM storage resources, and complex control logic also need to be equipped, resulting in a significant increase in chip area and power consumption. This not only increases the production cost but also limits the application of the chip in some devices with strict requirements for power consumption and size, such as mobile terminals and Internet of Things devices. Therefore, the embodiments of this application disclose a data encryption method, device, medium, and product based on the SM3 algorithm, which can ensure high performance and low hardware resource consumption while realizing the simultaneous operation of multiple data sources.

[0070] See Figure 1 and Figure 2 As shown, an embodiment of the present application discloses a data encryption method based on the SM3 algorithm, which is applied to a target hash function operation unit. The method includes:

[0071] Step S11: Receive the data to be encrypted from several data sources, and perform padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups; wherein, each data group includes a certain number of target data with the same length.

[0072] In this embodiment, the target hash function operation unit can simultaneously receive the data to be encrypted from several data sources, and can perform padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups, so that each data group includes a certain number of target data with the same length.

[0073] In the specific implementation, performing padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups includes: determining whether the length of the data to be encrypted corresponding to each data source is an integer multiple of the target length value; if the length of the data to be encrypted is an integer multiple of the target length value, then perform grouping processing on the data to be encrypted based on the target length value to obtain corresponding data groups; if the length of the data to be encrypted is not an integer multiple of the target length value, then perform padding processing on the data to be encrypted so that the length of the padded data to be encrypted is an integer multiple of the target length value, and then perform grouping processing on the padded data to be encrypted based on the target length value to obtain corresponding data groups; wherein, each data group includes a certain number of target data, and the length of each target data is the target length value.

[0074] Such as Figure 2As shown in the hardware architecture diagram, after obtaining the data to be encrypted, message padding and grouping processing need to be performed first. Specifically, it is necessary to first determine whether the length of the data to be encrypted corresponding to each data source is an integer multiple of the target length value, where the target length value is specifically 512 bits. In a specific implementation, if the length of the data to be encrypted is an integer multiple of 512 bits, it means that the message padding processing of the data to be encrypted has been completed externally. At this time, the data to be encrypted can be grouped based on 512 bits to obtain corresponding data groups, that is, the data to be encrypted needs to be divided into multiple target data with a length of 512 bits. In another specific implementation, if the length of the data to be encrypted is not an integer multiple of 512 bits, it is necessary to first perform padding processing on the data to be encrypted so that the length of the padded data to be encrypted is an integer multiple of 512 bits. The specific padding process is to first add the bit '1' to the end of the data to be encrypted, then add a certain number of '0's, and finally add 64 bits of data length so that the total is an integer multiple of 512 bits. It should be noted that generally, padding is performed according to the minimum amount of data to be padded. For example, if the length of the data to be encrypted is 800, then 224 bits need to be padded to reach 1024 bits. Finally, the padded data to be encrypted is divided into multiple target data with a length of 512 bits, and data groups are constructed based on these target data.

[0075] Step S12: Allocate data sources of different paths to different grouping expansion units, and sequentially input each target data in each data group into the corresponding grouping expansion unit according to the first preset timing rule for grouping expansion calculation, so as to obtain a preset number of groups of message words corresponding to each target data.

[0076] In this embodiment, multiple grouping expansion units are provided in the target hash function operation unit, which can allocate data sources of different paths to different grouping expansion units for processing, so as to perform grouping expansion calculation on multiple data sources simultaneously. Specifically, it is necessary to sequentially input each target data in each data group into the corresponding grouping expansion unit according to the first preset timing rule for grouping expansion calculation, so as to obtain a preset number of groups of message words corresponding to each target data.

[0077] In a specific implementation, different grouping expansion units correspond to different data paths based on a preset mapping relationship; correspondingly, allocating data sources of different paths to different grouping expansion units includes: allocating the data source of each data path to the corresponding grouping expansion unit based on the preset mapping relationship, setting the gating clock switch of the grouping expansion unit to the on state, and setting the output enable signal of the data path to a first target value for characterizing the enable state.

[0078] That is, the present application can pre - establish the mapping relationship between each packet expansion unit and each data path, so that each packet expansion unit corresponds to a data source. Then, when the data to be encrypted sent by the data source of a certain data path is received, the data group obtained after the extended packet processing is input to the corresponding packet expansion unit for packet expansion calculation based on the mapping relationship, and the gating clock switch of the packet expansion unit is set to the on state. Specifically, the enable signal gate_ex_n corresponding to the gating clock switch is set to 1, and the output enable signal of the data path is set to the first target value representing the enabled state. Specifically, the output enable signal digest_en_n is set to 1. In addition, when there is no real data input from the data source corresponding to a certain packet expansion unit, it means that the corresponding packet expansion unit is in the idle and bypass state at this time. Among them, the clock gating technology is a technology used to reduce power consumption in digital integrated circuit design. It reduces the dynamic power consumption by turning off the clock in the parts that do not require the clock signal, achieving the effect of reducing power consumption. In actual use, by controlling the enable signal gate_ex_n corresponding to the gating clock switch, the clock of the subsequent module can be turned on or off to reduce power consumption.

[0079] In addition, in addition to pre - establishing the mapping relationship, each packet expansion unit can also be numbered in ascending order in advance. Then, when receiving the data to be encrypted from several data sources, the packet expansion units can be allocated in the order of arrival of each data source. For example, first allocate the packet expansion unit numbered 1, then allocate the packet expansion unit numbered 2, and so on. In addition, considering the case of non - full bandwidth, that is, when the number of data sources is less than the number of packet expansion units, the packet expansion units can be randomly allocated in the order of arrival of each data source to avoid always using the packet expansion units corresponding to small serial numbers for calculation, thereby achieving load balancing.

[0080] Furthermore, the above - mentioned method further includes: if there is no data to be encrypted in the target data path corresponding to any packet expansion unit, configure any packet expansion unit based on the first configuration method or the second configuration method, and set the output enable signal of the target data path to the second target value representing the disabled state; where the first configuration method is to set the gating clock switch of any packet expansion unit to the off state; the second configuration method is to set the gating clock switch of any packet expansion unit to the on state, then use a preset random number generator to generate a target random number, and use the target random number as the data to be encrypted currently in the target data path, so as to perform the packet expansion calculation and iterative compression calculation corresponding to the target data path to obtain the digest value of the data source corresponding to the target data path.

[0081] That is, for the target data path without real data input, there are mainly two configuration methods, and the corresponding grouping expansion unit can be configured according to the usage requirements. However, no matter which configuration method is used, the output enable signal digest_en_n of the target data path needs to be set to the second target value 0 for characterizing the enable state.

[0082] The first configuration method is to directly turn off the gating clock switch of the grouping expansion unit of the target data path, that is, set the enable signal gate_ex_n corresponding to the gating clock switch to 0. Since there is no real data input to this grouping expansion unit, it does not participate in any calculations, that is, it is in a standby state. In this configuration method, the power consumption of the algorithm core can be reduced.

[0083] The second configuration method is to still turn on the gating clock switch of the grouping expansion unit of the target data path, that is, set the enable signal gate_ex_n corresponding to the gating clock switch to 1 to keep it working, and then use Figure 2 the random number generator shown in to generate the target random number, and use this target random number as the data to be encrypted currently by the target data path, so as to perform the subsequent grouping expansion calculation and iterative compression calculation corresponding to the target data path to obtain the digest value of the data source corresponding to the target data path. This configuration method ensures that regardless of any input situation, the power consumption of the entire algorithm tends to be averaged (stable), enhances the anti-power consumption attack ability, makes it impossible to decipher key information through power consumption analysis methods, and improves the security of the algorithm. That is, in this application, by inputting random numbers for pseudo-calculation in the idle data path, the overall power consumption curve tends to be stable, making it impossible for the attacker to distinguish which path is calculating real data and which path is calculating random numbers, so as to resist DPA (Differential Power Analysis) attacks. Among them, in addition to using a random number generator to generate the target random number, it can also be that the software generates the target random number through an algorithm, and this embodiment does not limit this.

[0084] Step S13: Based on the second preset timing rule, sequentially input each message word corresponding to each target data to different iterative compression units for iterative compression calculation to obtain the compression result corresponding to each target data; wherein, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation.

[0085] In this embodiment, the target hash function operation unit is further provided with a plurality of iterative compression units to simultaneously perform iterative compression calculations on multiple data sources. Specifically, according to the second preset timing rule, each message word corresponding to each target data is sequentially input into different iterative compression units for iterative compression calculations. Among them, different iterative compression units are used to perform iterative compression calculations in different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation. Therefore, the compression results corresponding to each target data can be quickly obtained, greatly shortening the overall encryption time and improving the operation speed.

[0086] Step S14: Determine the digest value of the corresponding data source based on the compression result of each target data.

[0087] In this embodiment, finally, the digest value of the corresponding data source is determined based on the compression result of each target data. That is to say, in this application, the data of different data sources are respectively processed in the corresponding grouping expansion unit and iterative compression unit according to a specific timing rule. Each unit performs its own duties and works in cooperation. Multiple grouping expansion units are responsible for expanding the target data into message words, and multiple iterative compression units then perform multiple rounds of iterative compression calculations based on the obtained message words. This pipeline processing method reduces the data waiting time, improves the utilization rate of hardware resources, and effectively improves the operation performance. Moreover, for multiple data sources in this application, only one target hash function operation unit is required, greatly reducing the occupation of hardware resources and reducing the chip area and cost.

[0088] Further, after determining the digest value of the corresponding data source based on the compression result of each target data, it further includes: determining the output enable signal of the data path where each data source is located; if the output enable signal is the first target value, output the digest value corresponding to the data source; if the output enable signal is the second target value, prohibit outputting the digest value corresponding to the data source. That is to say, after obtaining the digest value corresponding to each data source, it is necessary to determine whether to output the digest value according to the value of the output enable signal digest_en_n of the data path where it is located. When the output enable signal digest_en_n is the first target value 1, it means that the digest value is calculated based on the input of the real data source, so the digest value corresponding to the data source is output; when the output enable signal digest_en_n is the second target value 0, it means that the digest value is not calculated based on the input of the real data source. As can be seen from the foregoing content, it is calculated based on the target random number, and its purpose is to be used for power consumption perturbation to avoid DPA attacks, so the output of the digest value corresponding to the data source is prohibited.

[0089] It can be seen that the target hash function operation unit in the present application can simultaneously receive the data to be encrypted from several data sources, and can simultaneously perform padding and grouping processing, grouped expansion calculation, and iterative compression calculation on multiple paths of data respectively. First, it is necessary to perform padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups, so that each data group includes a certain number of target data with the same length. Secondly, multiple grouped expansion units are provided in the target hash function operation unit of the present application, which can realize the distribution of different data sources to different grouped expansion units for processing, so as to simultaneously perform grouped expansion calculation on multiple data sources. Specifically, it is necessary to sequentially input each target data in each data group to the corresponding grouped expansion unit based on the first preset timing rule for grouped expansion calculation, so as to obtain a preset number of groups of message words corresponding to each target data. Further, multiple iterative compression units are also provided in the target hash function operation unit of the present application to realize simultaneous iterative compression calculation on multiple data sources. Specifically, based on the second preset timing rule, each message word corresponding to each target data is sequentially input to different iterative compression units for iterative compression calculation, where different iterative compression units are used to perform iterative compression calculation in different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation, so as to quickly obtain the compression result corresponding to each target data, greatly shortening the overall encryption time and improving the operation speed. Finally, the digest value of the corresponding data source is determined based on the compression result of each target data. That is, in the present application, the data of different data sources are respectively processed in the corresponding grouped expansion unit and iterative compression unit according to a specific timing rule, and each unit performs its own duties and works in cooperation. Multiple grouped expansion units are responsible for expanding the target data into message words, and multiple iterative compression units then perform multiple rounds of iterative compression calculation based on the obtained message words. This pipelined processing method reduces the data waiting time, improves the utilization rate of hardware resources, and effectively improves the operation performance. Moreover, for multiple data sources in the present application, only one target hash function operation unit is required, which greatly reduces the occupation of hardware resources and reduces the chip area and cost.

[0090] See Figure 3 As shown, the embodiment of the present application discloses a specific data encryption method based on the SM3 algorithm. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution. Specifically, it includes:

[0091] Step S21: Receive the data to be encrypted from several data sources, and perform padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups; wherein, each data group includes a certain number of target data with the same length.

[0092] Step S22: Assign data sources of different paths to different grouped expansion units. Then, for different data groups, based on the first order among the data groups, input the first target data of each data group into the corresponding grouped expansion unit in sequence within the current consecutive target number of clock cycles, and based on the first order, input the next target data corresponding to the first target data in each data group into the corresponding grouped expansion unit in sequence within the next consecutive target number of clock cycles until all the target data is input; where the target number is the same as the value of the expansion round of the grouped expansion unit.

[0093] In this embodiment, when inputting each target data in each data group into the corresponding grouped expansion unit in sequence for grouped expansion calculation based on the first preset timing rule, first, for different data groups, it is necessary to input the first target data of each data group into the corresponding grouped expansion unit in sequence within the current consecutive target number of clock cycles based on the first order among the data groups. It should be noted that the first order here may refer to the arrival order of each data source. The number of data paths in this application is specifically 64, and the number of corresponding grouped expansion units is also 64. Then, the data sources can be sequentially denoted as data source 1, data source 2,..., data source 64 according to the arrival order, and the grouped expansion units corresponding to each data source are sequentially denoted as grouped expansion unit 1, grouped expansion unit 2,..., grouped expansion unit 64. In addition, it should be noted that the above-mentioned target number is also 64, which means that the expansion round of the grouped expansion unit is also 64.

[0094] Then, at the highest performance (i.e., full bandwidth), 64 data sources are simultaneously calculated at this time, that is, the first target data of these 64 data groups are input into the corresponding grouped expansion unit in sequence within the current consecutive 64 clock cycles, and then the second target data in each data group are input into the corresponding grouped expansion unit in sequence within the next consecutive 64 clock cycles until all the target data is input. Specifically, as Figure 4 shown, in the first clock cycle T1, the first target data of data source 1 is input into grouped expansion unit 1. In the second clock cycle T2, the first data of data source 2 is input into grouped expansion unit 2, and so on. In the 65th clock cycle T65, the second data of data source 1 is input into grouped expansion unit 1. In the 66th clock cycle T66, the second data of data source 2 is input into grouped expansion unit 2, and so on. It can be known from the foregoing content that the gating clock switch gate_ex_n of each grouped expansion unit needs to be 1, that is, all are kept in the open state; the data output enable signal digest_en_n of each path is also 1.

[0095] Step S23: For the same data group, within the corresponding grouping expansion unit, based on the second sequence order of each target data in the data group, complete the grouping expansion calculation of the first target data within the current consecutive target number of clock cycles, and complete the grouping expansion calculation of the next target data within the next consecutive target number of clock cycles until all target data's grouping expansion calculations are completed, so as to obtain a preset number of groups of message words corresponding to each target data; where the preset number is the same as the value of the expansion round of the grouping expansion unit.

[0096] In this embodiment, for the same data group, it is necessary to complete 64 rounds of grouping expansion calculations for each target data within the corresponding grouping expansion unit to obtain 64 groups of corresponding message words. Specifically, after padding and grouping the data to be encrypted to obtain a data group, each target data in the data group will be numbered in the sorting order of the data to be encrypted, so as to perform 64 rounds of grouping expansion calculations on each target data in ascending order of the numbers (i.e., the subsequent second sequence order). Therefore, first complete the 64 rounds of grouping expansion calculations of the first target data within the current consecutive 64 clock cycles, and complete the 64-grouping expansion calculations of the second target data within the next consecutive 64 clock cycles until all target data's grouping expansion calculations are completed, so as to obtain 64 groups of message words corresponding to each target data.

[0097] Among them, completing the grouping expansion calculation of the target data within the consecutive target number of clock cycles includes: within the consecutive target number of clock cycles, based on the expansion round and in the order of the clock cycles from front to back, perform grouping expansion calculations of different rounds respectively. That is, within the consecutive 64 clock cycles, first perform the 0th round of grouping expansion calculation of the target data in the 1st clock cycle, then perform the 1st round of grouping expansion of the target data in the 2nd clock cycle, and so on, until the 63rd round of grouping expansion calculation of the target data is performed in the 64th clock cycle.

[0098] It can be understood that in the traditional solution, each hash function operation unit has only one grouping expansion calculation unit, which realizes expanding the input data that meets the grouping length into 64 groups of message words for the subsequent 64-round iterative compression process. It should be noted that in the SM3 algorithm used in this application, the hash function operation unit specifically refers to the SM3 algorithm core, and the SM3 algorithm core refers to the hash function operation unit that specifically implements the SM3 hash algorithm.

[0099] In the embodiments of the present application, the SM3 algorithm core has 64 independent block expansion units, which can perform calculations on up to 64 data paths simultaneously. After the data paths are allocated, each block expansion unit corresponds to one data source path, and before the calculation of the current data source path is completed, it will not switch to other data sources. The timing of the block expansion unit calculation is as Figure 5 shown, where the serial numbers of "block expansion x-y-z" in the figure are respectively:

[0100] x: The serial number of the block expansion unit, representing which one of the 64 block expansion units is used;

[0101] y: The data serial number, representing which target among the targets of this data source path;

[0102] z: The round of block expansion calculation for the target data (0-63).

[0103] Then, in the case of 64-way full-bandwidth calculation, as Figure 5 shown:

[0104] The 1st clock cycle T1: Perform the 0th round of block expansion calculation on the 1st data of the 1st data source path in block expansion unit 1;

[0105] The 2nd clock cycle T2: Perform the 1st round of block expansion calculation on the 1st data of the 1st data source path in block expansion unit 1; perform the 0th round of block expansion calculation on the 1st data of the 2nd data source path in block expansion unit 2;

[0106] The 3rd clock cycle T3: Perform the 2nd round of block expansion calculation on the 1st data of the 1st data source path in block expansion unit 1; perform the 1st round of block expansion calculation on the 1st data of the 2nd data source path in block expansion unit 2; perform the 0th round of block expansion calculation on the 1st data of the 3rd data source path in block expansion unit 3;

[0107] And so on;

[0108] The 64th clock cycle T64: Perform the 63rd round of block expansion calculation on the 1st data of the 1st data source path in block expansion unit 1; perform the 62nd round of block expansion calculation on the 1st data of the 2nd data source path in block expansion unit 2; perform the 61st round of block expansion calculation on the 1st data of the 3rd data source path in block expansion unit 3,..., perform the 0th round of block expansion calculation on the 1st data of the 64th data source path in block expansion unit 64.

[0109] After 64 clock cycles, the first data of the first data source has completed 64 rounds of block expansion calculation. Therefore, in the 65th clock cycle T65, the second data of the first data source is input into block expansion unit 1 to perform its 0th round of block expansion calculation, specifically as Figure 5 shown.

[0110] When not performing 64-channel full-bandwidth calculation, as Figure 6 shown. For example, assuming that there is no data input from data source 2, there are two processing methods according to the previous-stage data distribution and gated clock control at this time:

[0111] 1. Turn off the gated clock switch of block expansion unit 2 corresponding to data source 2. At this time, the clock of block expansion unit 2 is turned off, achieving power consumption reduction;

[0112] 2. Still turn on the gated clock switch of block expansion unit 2 corresponding to data source 2 to perform block expansion calculation. However, the input data is a random input at this time. The data is calculated normally, but the final digest value is not output, only achieving power consumption perturbation and enhancing the anti-power consumption attack performance of the algorithm.

[0113] Furthermore, each group of message words includes a bit message word and an extended message word; among them, the extended message word is calculated based on the corresponding bit message word. It can be understood that the purpose of block expansion is to generate 64 groups of message words from the input 512-bit target data. Each group of message words includes a bit message word W j and an extended message word W j ’. The extended message word W j ’ is specifically calculated based on the corresponding bit message word W j , where j is an integer between 0 and 63.

[0114] In the specific implementation manner, the process of the block expansion unit performing block expansion calculation on the target data to obtain the bit message word includes: grouping the target data according to the target number of bits to obtain a number of initial bit words; calculating based on the initial bit words and a preset recurrence expression to generate the target bit words; where the recurrence expression is constructed based on a permutation function, an exclusive OR operation rule, and a left shift operation rule; obtaining the bit message word based on the initial bit words and the target bit words.

[0115] It can be understood that in this embodiment, the target data will be grouped according to the target number of bits first to obtain a number of initial bit words. Among them, the target number of bits is specifically 32 bits, thereby generating 16 initial bit words, which are respectively denoted as W0-W 15 . Among them, the 512-bit data is divided into 16 groups according to 32 bits to obtain W0 to W 15Process: Data[511:480]=W0, Data[479:448]=W1, Data[447:416]=W2, …, Data[63:32]=W 14 , Data[31:0]=W 15 . After obtaining the initial bit words W0 - W 15 , the preset recurrence expression can be used for calculation to generate the target bit word W 16 -W 63 , thereby obtaining all the bit message words W0 - W 63 .

[0116] Among them, the recurrence expression is specifically as follows:

[0117] ;

[0118] Process of calculating the extended message word based on the bit message word:

[0119] ;

[0120] Among them, P1 represents the permutation function, ;

[0121] is the exclusive - or operation, ≪ represents the circular left - shift by k bits operation, and X is a word (32 - bit data).

[0122] Step S24: For any target data, allocate each message word to different iterative compression units in sequence based on the sequential generation order of the message words and the sequential iteration order of the iterative compression units; among them, the number of iterative compression units is the same as the number of groups of message words, and different iterative compression units are used to perform iterative compression calculations for different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next - round iterative compression calculation.

[0123] In this embodiment, 64 iterative compression calculation units are used to implement the calculation of 64 data sources simultaneously. Therefore, for the 64 groups of message words generated for each target data, it is necessary to allocate each message word to 64 groups of iterative compression units in sequence based on the sequential generation order of the message words and the sequential iteration order of the iterative compression units, so that each group of message words participates in the corresponding iterative compression calculation. Specifically, the first - generated group of message words W1 and W1’ participate in the first - round iterative compression calculation, the second - generated group of message words W2 and W2’ participate in the second - round iterative compression calculation, and so on.

[0124] And it should be noted that the output value of each round of iterative compression calculation is the input value of the corresponding next - round iterative compression calculation. Among them, when 0 < n < 64, there is:

[0125] Cf_in_v_n = cf_out_v_n - 1;

[0126] Cf_in_v_n is the input value for the n-th round of iterative compression calculation;

[0127] Cf_out_n - 1 is the output value for the (n - 1)-th round of iterative compression calculation;

[0128] When n = 0, that is, in the first round of calculation, Cf_in_v_0 is the preset initial value or the intermediate value after 64 rounds of iterative compression calculation of the previous target data from the same data source.

[0129] Step S25: Determine the target input value of each iterative compression unit, and perform iterative compression calculation in each iterative compression unit in sequence within a continuous target number of clock cycles based on the corresponding target input value and message word, so as to obtain the compression result corresponding to any target data after completing the last round of iterative compression calculation of any target data; wherein, the target number is the same as the number of iterative compression units.

[0130] In this embodiment, the number of iterative compression units is also 64. Each group of message words has been allocated to each iterative compression unit through the foregoing content. When performing iterative compression calculation, in addition to using the message words, input parameters are also required. Therefore, this application needs to determine the target input value of each iterative compression unit, so as to perform iterative compression calculation in 64 iterative compression units in sequence within 64 consecutive clock cycles based on the corresponding target input value and message word, and obtain the compression result corresponding to the target data after completing the last round of iterative compression calculation of the target data.

[0131] In the specific implementation manner, determining the target input value of each iterative compression unit includes: if it is determined that the current iterative compression unit is the first-round iterative compression unit based on the sequential iteration order, obtain the target initial value and use the target initial value as the target input value of the current iterative compression unit; if it is determined that the current iterative compression unit is a non-first-round iterative compression unit based on the sequential iteration order, obtain the output value of the previous round of iterative compression calculation and use the output value of the previous round of iterative compression calculation as the target input value of the current iterative compression unit. That is, 64 iterative compression units sequentially perform the 0 - 63 rounds of iterative compression calculation. If the current iterative compression unit is the first-round iterative compression unit, obtain the target initial value and use the target initial value as the target input value of the current iterative compression unit. If the current iterative compression unit is a non-first-round iterative compression unit, use the output value of the previous round of iterative compression calculation as the target input value of the current iterative compression unit.

[0132] Among them, obtaining the target initial value includes: if any target data is the first target data in the data group where it is located, using the preset value as the target initial value; if any target data is not the first target data in the data group where it is located, obtaining the compression result corresponding to the previous target data in the same data group, and calculating the target initial value based on the compression result corresponding to the previous target data.

[0133] That is, each target data in the same data group needs to perform 64 rounds of iterative compression calculation to obtain the corresponding compression result. If the target data is the first target data in the data group where it is located, using the preset value as the target initial value; if the target data is not the first target data in the data group where it is located, it is necessary to further obtain the compression result corresponding to the previous target data in the same data group, and calculate the target initial value based on the compression result corresponding to the previous target data.

[0134] Step S26: Determine the digest value of the corresponding data source based on the compression result of each target data.

[0135] In this embodiment, the above-mentioned determining the digest value of the corresponding data source based on the compression result of each target data includes: determining whether the current target data is the last target data in the data group where it is located; if the current target data is the last target data in the data group where it is located, performing an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and using the exclusive OR operation result as the digest value of the corresponding data source; if the current target data is not the last target data in the data group where it is located, performing an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and using the exclusive OR operation result as the target initial value of the first-round iterative compression unit corresponding to the next target data until the compression result of the last target data in the data group is obtained.

[0136] That is, after obtaining the compression result of the current target data, it is necessary to determine whether the current target data is the last target data in the data group where it is located. If so, perform an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and use the exclusive OR operation result as the digest value of the corresponding data source. It should be noted that if there is only one target data in the data group, perform an exclusive OR operation on the compression result of the current target data and the target initial value. In addition, if the current target data is not the last target data in the data group where it is located, perform an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and use the exclusive OR operation result as the target initial value of the first-round iterative compression unit corresponding to the next target data until the compression result of the last target data in the data group is obtained.

[0137] It can be understood that in the traditional solution, each SM3 algorithm core has only one iterative compression unit, and in use, the time-division multiplexing method is used to sequentially complete the iterative compression calculations for 64 rounds. In this application, 64 iterative compression units are used to simultaneously calculate 64 data sources.

[0138] During the 64-channel full-bandwidth calculation, in each clock cycle, there is data for calculation in all 64 data sources. As Figure 7 shown, the serial numbers of "data source x-y-z" in the figure are respectively:

[0139] x: Serial number of the data source;

[0140] y: Serial number of the data, representing the nth target data in this data source;

[0141] z: Round number (0 - 63) for the target data to perform iterative compression;

[0142] The 1st clock cycle T1: Perform the 0th round iterative compression calculation for the 1st data of the 1st data source in iterative compression unit 1;

[0143] The 2nd clock cycle T2: Perform the 1st round iterative compression calculation for the 1st data of the 1st data source in iterative compression unit 2; perform the 0th round iterative compression calculation for the 1st data of the 2nd data source in iterative compression unit 1;

[0144] The 3rd clock cycle T3: Perform the 2nd round iterative compression calculation for the 1st data of the 1st data source in iterative compression unit 3; perform the 1st round iterative compression calculation for the 1st data of the 2nd data source in iterative compression unit 2; perform the 0th round iterative compression calculation for the 1st data of the 3rd data source in iterative compression unit 1;

[0145] And so on;

[0146] The 64th clock cycle T64: Perform the 63rd round iterative compression calculation for the 1st data of the 1st data source in iterative compression unit 64; perform the 62nd round iterative compression calculation for the 1st data of the 2nd data source in iterative compression unit 63; perform the 61st round iterative compression calculation for the 1st data of the 3rd data source in iterative compression unit 62;...; perform the 0th round iterative compression calculation for the 1st data of the 64th data source in iterative compression unit 1;

[0147] The 65th clock cycle T65: Perform the 63rd round iterative compression calculation for the 1st data of the 2nd data source in iterative compression unit 64; perform the 62nd round iterative compression calculation for the 1st data of the 3rd data source in iterative compression unit 63;...; perform the 0th round iterative compression calculation for the 2nd data of the 1st data source in iterative compression unit 1;

[0148] And so on.

[0149] Moreover, starting from the T64 cycle, the update of Cf_in_v_0 or the output of the digest value is performed at the beginning of each clock cycle. Specifically, when outputting the last-round iterative compression result, it is determined whether the current target data of the current data source is the last data to be calculated. If so, the digest value degiest = cf_out_v_63 ^ pre_cf_out_v_63 is output, that is, the exclusive OR operation is performed on the compression result of the current target data after 64 rounds of iterative compression and the compression result of the previous target data of the same data source after 64 rounds of iterative compression.

[0150] If it is not the last data, at this time next_cf_in_v_0 = cf_out_v_63 ^ pre_cf_out_v_63, that is, the exclusive OR operation is performed on the compression result of the current target data after 64 rounds of iterative compression and the compression result of the previous data of the same data source after 64 rounds of iterative compression, and the exclusive OR calculation result (i.e., Figure 2 the intermediate parameter in) is assigned again to the input value of the next target data of the same data source for the 0th round of iterative compression calculation.

[0151] In addition, it should also be noted that the clock cycles T1 to T64 used in the compression iteration unit can be the same as the clock cycles T1 to 64 corresponding to the aforementioned grouping expansion unit. That is, for the same target data, the corresponding grouping expansion calculation can be performed in the first part of a single clock cycle, and the corresponding iterative compression calculation can be performed in the second part of a single clock cycle. In addition, considering that the calculation of the iterative compression unit needs to be based on the message words output by the grouping diffusion unit, the two processes can also be separated by one clock cycle.

[0152] Among them, for the more specific processing procedures of the above steps S21 and S26, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.

[0153] It can be seen that the SM3 algorithm core in this application has 64 independent grouping expansion units and 64 iterative compression calculation units, which can simultaneously perform filling group processing, grouping expansion calculation, and iterative compression calculation on 64 data sources. That is, this application realizes that an algorithm operation core unit calculates multiple data simultaneously, improves performance, and reduces the chip area.

[0154] See Figure 8 As shown, the embodiment of this application discloses a data encryption device based on the SM3 algorithm, which is applied to a target hash function operation unit. The device includes:

[0155] The filling and grouping module 11 is configured to receive the data to be encrypted from several data sources, and perform filling and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups; wherein, each data group includes a plurality of target data with the same length.

[0156] The grouping and extension calculation module 12 is configured to allocate different data sources to different grouping and extension units, and sequentially input each target data in each data group to the corresponding grouping and extension unit according to the first preset timing rule for grouping and extension calculation, so as to obtain a preset number of groups of message words corresponding to each target data.

[0157] The iterative compression calculation module 13 is configured to sequentially input each message word corresponding to each target data to different iterative compression units according to the second preset timing rule for iterative compression calculation, so as to obtain a compression result corresponding to each target data; wherein, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation.

[0158] The digest value determination module 14 is configured to determine the digest value of the corresponding data source based on the compression result of each target data.

[0159] It can be seen that the target hash function operation unit in the present application can simultaneously receive the data to be encrypted from several data sources, and can perform padding and grouping processing, grouped expansion calculation, and iterative compression calculation on multiple data respectively. First, it is necessary to perform padding and grouping processing on the data to be encrypted corresponding to each data source respectively to obtain corresponding data groups, so that each data group includes a certain number of target data with the same length. Secondly, multiple grouped expansion units are provided in the target hash function operation unit of the present application, which can realize the allocation of different data sources to different grouped expansion units for processing, so as to perform grouped expansion calculation on multiple data sources simultaneously. Specifically, it is necessary to sequentially input each target data in each data group to the corresponding grouped expansion unit for grouped expansion calculation based on the first preset timing rule, so as to obtain a preset number of groups of message words corresponding to each target data. Further, multiple iterative compression units are also provided in the target hash function operation unit of the present application to realize iterative compression calculation on multiple data sources simultaneously. Specifically, based on the second preset timing rule, each message word corresponding to each target data is sequentially input to different iterative compression units for iterative compression calculation. Among them, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation, so as to quickly obtain the compression result corresponding to each target data, greatly shortening the overall encryption time and improving the operation speed. Finally, the digest value of the corresponding data source is determined based on the compression result of each target data. That is to say, in the present application, the data of different data sources are processed in the corresponding grouped expansion units and iterative compression units according to specific timing rules, and each unit performs its own duties and works in cooperation. Multiple grouped expansion units are responsible for expanding the target data into message words, and multiple iterative compression units then perform multiple rounds of iterative compression calculations based on the obtained message words. This pipeline processing method reduces the data waiting time, improves the utilization rate of hardware resources, and effectively improves the operation performance. Moreover, for multiple data sources, the present application only needs to use one target hash function operation unit, which greatly reduces the occupation of hardware resources and reduces the chip area and cost.

[0160] Since the embodiments of the device part correspond to the above embodiments, the embodiments of the device part are described with reference to the embodiments of the above method part and will not be elaborated here.

[0161] Figure 9A schematic structural diagram of an electronic device provided by an embodiment of the present application. Specifically, it may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the data encryption method based on the SM3 algorithm executed by the electronic device disclosed in any of the foregoing embodiments.

[0162] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and specific limitations are not imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and the specific interface type can be selected according to specific application needs, and no specific limitations are made here.

[0163] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may further include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.

[0164] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon include an operating system 221, a computer program 222, data 223, etc., and the storage method may be temporary storage or permanent storage.

[0165] Among them, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, so as to implement the operation and processing of the massive data 223 in the memory 22 by the processor 21. It can be Windows, Unix, Linux, etc. In addition to the computer program that can be used to complete the data encryption method based on the SM3 algorithm executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks. In addition to the data that can include the data transmitted by the external device received by the electronic device, the data 223 may also include the data collected by its own input / output interface 25, etc.

[0166] Further, the embodiment of the present application also discloses a computer-readable storage medium. When the computer program stored in the storage medium is loaded and executed by the processor, the steps of the data encryption method based on the SM3 algorithm disclosed in any of the foregoing embodiments are implemented.

[0167] The embodiment of the present invention also discloses a computer program product, including a computer program / instructions. When the computer program / instructions are executed by the processor, the steps of the data encryption method based on the SM3 algorithm disclosed in any of the foregoing embodiments are implemented.

[0168] In this specification, the various embodiments are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.

[0169] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0170] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be implemented directly by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, compact disc read-only memory (CD-ROM), or any other form of storage medium well-known in the technical field.

[0171] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.

[0172] The above has introduced in detail a data encryption method, device, medium and product based on the SM3 algorithm provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A data encryption method based on the SM3 algorithm, characterized in that Applied to a target hash function operation unit, including: Receiving the data to be encrypted from several data sources, and respectively performing padding and grouping processing on the data to be encrypted corresponding to each data source to obtain corresponding data groups; wherein, each of the data groups includes a certain number of target data with the same length. Allocating different data sources to different grouping expansion units, and sequentially inputting each of the target data in each of the data groups into the corresponding grouping expansion unit for grouping expansion calculation based on a first preset timing rule to obtain a preset number of groups of message words corresponding to each of the target data. Sequentially inputting each of the message words corresponding to each of the target data into different iterative compression units for iterative compression calculation based on a second preset timing rule to obtain a compression result corresponding to each of the target data; wherein, different iterative compression units are used to perform iterative compression calculations of different rounds, and the output value of each round of iterative compression calculation is the input value of the corresponding next round of iterative compression calculation. Determining the digest value of the corresponding data source based on the compression result of each of the target data.

2. The data encryption method based on the SM3 algorithm according to claim 1, wherein Different grouping expansion units correspond to different data paths based on a preset mapping relationship. Correspondingly, the allocating different data sources to different grouping expansion units includes: Allocating the data source of each of the data paths to the corresponding grouping expansion unit based on the preset mapping relationship, setting the gated clock switch of the grouping expansion unit to the on state, and setting the output enable signal of the data path to a first target value for representing the enabled state.

3. The data encryption method based on the SM3 algorithm according to claim 2, wherein Further including: If there is no data to be encrypted in the target data path corresponding to any grouping expansion unit, configuring the any grouping expansion unit based on a first configuration method or a second configuration method, and setting the output enable signal of the target data path to a second target value for representing the disabled state. Wherein, the first configuration method is to set the gated clock switch of the any grouping expansion unit to the off state. The second configuration method is to set the gated clock switch of the any grouping expansion unit to the on state, then generating a target random number by using a preset random number generator, and using the target random number as the data to be encrypted currently in the target data path, so as to perform the grouping expansion calculation and iterative compression calculation corresponding to the target data path to obtain the digest value of the data source corresponding to the target data path.

4. The data encryption method based on the SM3 algorithm according to claim 3, wherein, After determining the digest value of the corresponding data source based on the compression result of each of the target data, further including: Determining the output enable signals of the data paths where each of the data sources is located. If the output enable signal is the first target value, outputting the digest value corresponding to the data source. If the output enable signal is the second target value, prohibiting the output of the digest value corresponding to the data source.

5. The data encryption method based on the SM3 algorithm according to claim 1, characterized in that, The respectively performing padding and grouping processing on the data to be encrypted corresponding to each data source to obtain corresponding data groups includes: Judging whether the length of the data to be encrypted corresponding to each data source is an integer multiple of the target length value. If the length of the data to be encrypted is an integer multiple of the target length value, the data to be encrypted is grouped based on the target length value to obtain corresponding data groups; If the length of the data to be encrypted is not an integer multiple of the target length value, padding processing is performed on the data to be encrypted so that the length of the padded data to be encrypted is an integer multiple of the target length value, and then the padded data to be encrypted is grouped based on the target length value to obtain corresponding data groups; Wherein, each of the data groups includes a certain number of target data, and the length of each of the target data is the target length value.

6. The data encryption method based on the SM3 algorithm according to claim 1, wherein, The step of sequentially inputting each of the target data in each of the data groups into a corresponding grouping expansion unit according to a first preset timing rule for grouping expansion calculation to obtain a preset number of groups of message words corresponding to each of the target data includes: For different data groups, based on the first order between the data groups, the first target data of each of the data groups are sequentially input into the corresponding grouping expansion unit within the current consecutive target number of clock cycles, and based on the first order, the next target data corresponding to the first target data in each of the data groups are sequentially input into the corresponding grouping expansion unit within the next consecutive target number of clock cycles until all the target data are input; wherein, the target number is the same as the value of the expansion round of the grouping expansion unit; For the same data group, within the corresponding grouping expansion unit, based on the second order of each of the target data in the data group, the grouping expansion calculation of the first target data is completed within the current consecutive target number of clock cycles, and the grouping expansion calculation of the next target data is completed within the next consecutive target number of clock cycles until the grouping expansion calculation of all the target data is completed to obtain a preset number of groups of message words corresponding to each of the target data; wherein, the preset number is the same as the value of the expansion round of the grouping expansion unit.

7. The data encryption method based on the SM3 algorithm according to claim 6, characterized in that Completing the grouping expansion calculation of the target data within a consecutive target number of clock cycles includes: Within a consecutive target number of clock cycles, based on the expansion round and in the order of the clock cycles from front to back, grouping expansion calculations of different rounds are respectively performed.

8. The data encryption method based on the SM3 algorithm according to claim 6, characterized in that, Each group of the message words includes a bit message word and an extended message word; wherein, the extended message word is calculated based on the corresponding bit message word.

9. The data encryption method based on the SM3 algorithm according to claim 8, wherein The process by which the grouping expansion unit performs grouping expansion calculation on the target data to obtain the bit message word includes: Grouping the target data according to the target number of bits to obtain a number of initial bit words; Calculating based on the initial bit words and a preset recurrence expression to generate target bit words; wherein, the recurrence expression is constructed based on a substitution function, an exclusive OR operation rule, and a left shift operation rule; Obtaining the bit message word based on the initial bit words and the target bit words.

10. The data encryption method based on the SM3 algorithm according to claim 1, characterized in that, The number of the iterative compression units is the same as the number of groups of the message words; Correspondingly, the step of sequentially inputting each of the message words corresponding to each target data into different iterative compression units according to the second preset timing rule for iterative compression calculation to obtain a compression result corresponding to each target data includes: For any target data, sequentially allocate each of the message words to different iterative compression units based on the sequential generation order of the message words and the sequential iterative order of the iterative compression units; Determine the target input value of each iterative compression unit, and perform iterative compression calculation based on the corresponding target input value and the message word in each iterative compression unit in sequence within a continuous target number of clock cycles, so as to obtain a compression result corresponding to the any target data after completing the last round of iterative compression calculation of the any target data; wherein, the target number is the same as the number of iterative compression units.

11. The data encryption method based on the SM3 algorithm according to claim 10, wherein The step of determining the target input value of each iterative compression unit includes: If it is determined that the current iterative compression unit is the first-round iterative compression unit based on the sequential iterative order, obtain the target initial value and use the target initial value as the target input value of the current iterative compression unit; If it is determined that the current iterative compression unit is a non-first-round iterative compression unit based on the sequential iterative order, obtain the output value of the previous round of iterative compression calculation and use the output value of the previous round of iterative compression calculation as the target input value of the current iterative compression unit.

12. The data encryption method based on the SM3 algorithm according to claim 11, wherein, The step of obtaining the target initial value includes: If the any target data is the first target data in the data group, use the preset value as the target initial value; If the any target data is not the first target data in the data group, obtain the compression result corresponding to the previous target data in the same data group, and calculate the target initial value based on the compression result corresponding to the previous target data.

13. The data encryption method based on the SM3 algorithm according to claim 12, characterized in that The step of determining the digest value of the corresponding data source based on the compression result of each target data includes: Judge whether the current target data is the last target data in the data group; If the current target data is the last target data in the data group, perform an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and use the exclusive OR operation result as the digest value of the corresponding data source; If the current target data is not the last target data in the data group, perform an exclusive OR operation on the compression result of the current target data and the compression result of the previous target data, and use the exclusive OR operation result as the target initial value of the first-round iterative compression unit corresponding to the next target data until the compression result of the last target data in the data group is obtained.

14. An electronic device, characterized in that, Including: A memory for storing a computer program; A processor for executing the computer program to implement the steps of the data encryption method based on the SM3 algorithm according to any one of claims 1 to 13.

15. A computer-readable storage medium, characterized in that, For storing a computer program; wherein, the computer program, when executed by the processor, implements the steps of the data encryption method based on the SM3 algorithm according to any one of claims 1 to 13.

16. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the data encryption method based on the SM3 algorithm described in any one of claims 1 to 13 are implemented.

Citation Information

Patent Citations

  • SM3 algorithm FPGA implementation method and system based on production line

    CN111913749A

  • Apparatus and method for providing a cipheraccelerator using a hash function

    KR1020030083292A