A secure encryption and decryption method and system for resisting side channel attacks

By constructing multiple operator groups in the operator matrix and dynamically reconstructing the hardware circuit, the problem of cryptographic algorithm chips being susceptible to side channel attacks during the encryption and decryption process is solved, and higher security and flexibility are achieved, adapting to the security and response speed requirements in different scenarios.

CN120185795BActive Publication Date: 2025-08-12无锡沐创集成电路设计有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510655668.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-08-12
Estimated Expiration
2045-05-21

AI Technical Summary

Technical Problem

Existing cryptographic algorithm chips are susceptible to side channel attacks during the encryption and decryption process. Commonly used masking techniques and formula replacement strategies have limited security improvements and are difficult to effectively resist side channel attacks.

Method used

Each operator function in the operator matrix corresponds to multiple operator groups, different operator groups are selected to form an encryption and decryption path, and dynamic reconstruction of operator arrays is used to combine group intelligent algorithms to optimize the encryption and decryption paths to improve the complexity of side channel information.

Benefits of technology

By randomly selecting the encryption and decryption path formed by the operator group, the ability to resist side channel attacks is enhanced, the security and flexibility of the data encryption and decryption process is improved, and the security and response speed requirements are adapted to different scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185795B_ABST
    Figure CN120185795B_ABST
Patent Text Reader

Abstract

The present application discloses a secure encryption and decryption method and system for resisting side channel attacks, which relates to the field of encryption and decryption technology. The operator matrix obtained by the method and matching the algorithm architecture includes operator groups corresponding to various operator functions, and there is at least one operator function in the operator matrix corresponding to multiple operator groups with different side channel information. When data needs to be securely encrypted and decrypted, an operator group is randomly selected from the several operator groups corresponding to each operator function in the operator matrix, and secure encryption and decryption is performed using the encryption and decryption path formed by the selected operator group. Since the side channel information of different operator groups is different, the side channel information generated by the different encryption and decryption paths formed by randomly selecting different operator groups is also different. The randomness of the side channel information improves the ability to resist side channel attacks, thereby improving the security of the data encryption and decryption process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of encryption and decryption technology, and in particular to a secure encryption method and system for resisting side-channel attacks. Background Art

[0002] With the popularization and development of information technology, the importance of information security has gradually become prominent. In order to ensure the security of information data, important information data is often encrypted through cryptographic algorithm chips to form ciphertext data for storage and transmission, and the ciphertext data is decrypted and used when needed.

[0003] However, cryptographic algorithm chips generate electromagnetic radiation during the encryption and decryption process, leaking internal state information such as power consumption, time, electromagnetic waves, and error information in the form of energy consumption. This information is collectively referred to as side channel information and is related to the key. Side-channel attack (SCA) techniques can be used to attack this leaked side channel information, deciphering the key and stealing data, thus compromising the security of cryptographic algorithm chips.

[0004] A mainstream countermeasure against existing side-channel attacks in applications is masking technology. This technology partitions sensitive variables and related intermediate states into multiple independent, random, shared values, thus severing the direct dependency between sensitive variables (such as key-related information) and side information such as power consumption. However, the security improvements provided by commonly used masking techniques and formula substitution strategies are very limited, and their ability to defend against side-channel attacks remains suboptimal. Summary of the Invention

[0005] In response to the above-mentioned problems and technical requirements, this application proposes a secure encryption method and system for resisting side-channel attacks. The technical solution of this application is as follows:

[0006] A secure encryption method for resisting side channel attacks, the secure encryption method comprising:

[0007] Obtain an operator matrix that matches the algorithm architecture, where the algorithm architecture includes multiple operator functions and the operator functions are executed in a global function order; the operator matrix includes operator groups corresponding to each operator function in the algorithm architecture and data transmission paths between corresponding operator groups established in a global function order; each operator group includes several operators and data transmission paths between corresponding operators established in an operator execution order, and several operators in the same operator group are executed in an operator execution order to jointly implement a corresponding operator function; there is at least one operator function in the operator matrix corresponding to multiple operator groups, and any two operator groups corresponding to the same operator function have different operator content and / or hardware carriers used and have different side channel information, and the operator content of each operator group includes the number of operators included in the operator group, the operation logic of each operator, and the operator execution order adopted;

[0008] An operator group is randomly selected from several operator groups used to implement each operator function in the operator matrix, and the input data to be encrypted is securely encrypted using the encryption path formed by the selected operator group according to the global function order between the operator functions.

[0009] A further technical solution is that the secure encryption method securely encrypts the input data to be encrypted through multiple encryption rounds, and the secure encryption method includes:

[0010] An operator matrix matching the algorithm architecture used by each encryption round is obtained, and an operator group is selected from the operator matrix to form an encryption path for the current encryption round to securely encrypt a local data group in the data to be encrypted. There are at least two encryption rounds that use different operator matrices and / or different operator groups selected from the operator matrices to form different encryption paths.

[0011] A further technical solution is that the operator matrix is implemented based on a reconfigurable hardware circuit. Obtaining the operator matrix used in each encryption round that matches the algorithm architecture includes:

[0012] When the reconstruction requirements of the current encryption round are different from those of the previous encryption round, the reconfigurable hardware circuit is reconfigured according to the reconstruction requirements of the current encryption round to obtain the operator matrix used by the current encryption round; when the reconstruction requirements of the current encryption round are the same as those of the previous encryption round, the operator matrix of the previous encryption round is directly used as the operator matrix used by the current encryption round;

[0013] Among them, the reconstruction requirements include the operator content and hardware carriers of each operator group corresponding to each operator function in the algorithm architecture.

[0014] The further technical solution is to determine the reconstruction requirements of the current encryption wheel, including:

[0015] Using true random number generation includes bits of global reconstruction configuration code, bits form all There are corresponding hardware allocation relationships for each type of global reconfiguration configuration code. Each hardware allocation relationship indicates the circuit module in the reconfigurable hardware circuit allocated to each operator group corresponding to each operator function, and the circuit module allocated to each operator group meets the hardware resource requirements of the corresponding operator group. is an integer parameter;

[0016] The reconstruction requirements of the current encryption round are obtained by combining the hardware allocation relationship corresponding to the randomly generated global reconstruction configuration code and the operator content of each operator group.

[0017] Its further technical solution is that the algorithm architecture of the secure encryption method includes at least two operator functions belonging to the same operation function category but located at different positions in the global function order, the operator contents of the operator groups corresponding to any two operator functions belonging to the same operation function category in the operator matrix are the same or different, and the operator groups selected from the operator matrix for any two operator functions belonging to the same operation function category to form an encryption path are the same or different.

[0018] Its further technical solution is that the secure encryption method securely encrypts the input data to be encrypted through multiple encryption rounds, each encryption round is used to securely encrypt a local data group in the encrypted data, and for any integer parameter as well as , in The encryption round is selected from the operator matrix to implement the The operator group of the term operator function includes:

[0019] When When the operator function is the first operator function in the global function order, the virtual start node is initialized as the current path node Otherwise, it will be The operator matrix of the encryption round is selected to realize the The last operator in the operator group of the item operator function is initialized as the current path node , No. The operator function is The previous operator function of an operator function;

[0020] Determine the In the operator matrix used by the encryption round, the current path node Any operator in the data transmission path The data transmission path between Pheromone concentration per encryption round ,The pheromone concentration on the data transmission path between the same operators is dynamically updated along the encryption path formed by the encryption round;

[0021] Determine the The operator matrix used by the encryption round and the current path node Operators with data transmission paths The probability of selection for:

[0022]

[0023] in, It is an operator Heuristic information and , It is an operator The number of operating cycles; It is The operator matrix used by the encryption round is consistent with the current path node The set of all operators that have data transmission paths, It is The current path node in the operator matrix used by the encryption round Any operator with a data transmission path The pheromone concentration on the data transmission path between It is an operator Heuristic information and , It is an operator The number of operating cycles; is the information heuristic factor, is the expectation heuristic factor;

[0024] According to the The operator matrix used by the encryption round is consistent with the current path node The selection probability of each operator in the data transmission path is used to select an operator from them, and the selected operator is updated as the current path node Continue traversing until the selected operator is the The operator matrix used in the encryption round is the same as the The last operator of one of the operator groups corresponding to the item operator function.

[0025] Its further technical solution is to determine the current path node To Operator The data transmission path between Pheromone concentration per encryption round include:

[0026] when Initialize the pheromone concentration ;

[0027] when And the first The operator matrix used by the encryption round does not contain the current path node To Operator Initialize the pheromone concentration when the data transmission path between ;

[0028] when And the first The current path node exists in the operator matrix used by the encryption round To Operator When the data transmission path between The encryption path formed by the encryption round contains the current path node To Operator The data transmission path between ; When the The encryption path formed by the encryption round does not contain the current path node To Operator The data transmission path between ; is the pheromone volatility coefficient, It is the pheromone increment.

[0029] Its further technical solution is to determine the information heuristic factor and expectation heuristics include:

[0030] Use the security encryption method to repeatedly perform security encryption tests on the test data, and adjust the information heuristic factor according to the selected probability of each operator group during the security encryption test. and expectation heuristics The security encryption test is performed again until the selection probability of each operator group in the security encryption test reaches a predetermined probability threshold.

[0031] A secure decryption method for resisting side channel attacks, the secure decryption method comprising:

[0032] Obtain an operator matrix that matches the algorithm architecture, where the algorithm architecture includes multiple operator functions and the operator functions are executed in a global function order; the operator matrix includes operator groups corresponding to each operator function in the algorithm architecture and data transmission paths between corresponding operator groups established in a global function order; each operator group includes several operators and data transmission paths between corresponding operators established in an operator execution order, and several operators in the same operator group are executed in an operator execution order to jointly implement a corresponding operator function; there is at least one operator function in the operator matrix corresponding to multiple operator groups, and any two operator groups corresponding to the same operator function have different operator content and / or hardware carriers used and have different side channel information, and the operator content of each operator group includes the number of operators included in the operator group, the operation logic of each operator, and the operator execution order adopted;

[0033] An operator group is randomly selected from several operator groups used to implement each operator function in the operator matrix, and the input data to be decrypted is securely decrypted using the decryption path formed by the selected operator group according to the global function order between the operator functions.

[0034] A secure encryption and decryption system for resisting side-channel attacks, the secure encryption and decryption system comprising one or more processors and a computer-readable storage medium for storing one or more programs; when the programs in the computer-readable storage medium are executed by the processors, the steps of the secure encryption method of the first aspect and / or the steps of the secure decryption method of the second aspect are implemented.

[0035] The beneficial technical effects of this application are:

[0036] The present application discloses a secure encryption and decryption method and system for resisting side channel attacks. In the process of encrypting and decrypting data based on an encryption and decryption algorithm architecture, the present application constructs multiple operator groups with different side channel information for at least one operator function in the algorithm architecture to form an operator matrix, and then randomly selects operator groups from the operator matrix to form encryption and decryption paths to encrypt and decrypt the data. Since the side channel information of different operator groups is different, the different encryption and decryption paths formed by selecting different operator groups will generate different side channel information even when processing the same data. This random path selection and side channel information improve the ability to resist side channel attacks, thereby improving the security of the data encryption and decryption process.

[0037] Furthermore, reconfigurable hardware circuits can be used to form operator arrays through circuit reconstruction. This approach can dynamically update the operator array during the encryption and decryption process through dynamic reconstruction, thereby introducing more side channel information complexity to enhance security within a limited circuit area. Compared with traditional masking technology, it is more flexible and easier to implement on the chip.

[0038] Furthermore, true random numbers can be combined to dynamically form operator arrays. True random numbers refer to statistically completely random sequences of numbers. Their generation process is not controlled by any deterministic algorithm or initial conditions. Each number is completely independent and unpredictable, making the resulting reconstruction requirements irregular. This introduces complex random side-channel information, further enhancing the ability to resist side-channel attacks and improving security. In addition to using common FPGAs to build hardware circuit arrays, specialized reconfigurable chips can also be used. These chips feature both software and hardware programming, meeting the real-time reconstruction requirements of this application scenario.

[0039] Furthermore, when selecting the encryption and decryption path, a swarm intelligence algorithm is introduced to select the operator group. As the encryption round continues, the encryption and decryption path with the smallest delay can be found as much as possible. This improves the encryption and decryption performance while ensuring security, and has more outstanding performance in scenarios with large data volumes.

[0040] The secure encryption and decryption method provided in this application has good flexibility. It can flexibly configure the operator matrix reconstruction frequency and operator group selection frequency of each encryption round / decryption round, thereby adjusting the change frequency of the encryption and decryption paths formed by different encryption rounds / decryption rounds to balance the performance of the encryption and decryption method in terms of security and response speed. It can not only adapt to the different emphasis requirements in different scenarios, but also be adjusted to achieve better overall performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 This is a flowchart of a secure encryption method in one embodiment of the present application.

[0042] Figure 2 This is a schematic diagram of an operator matrix obtained in one embodiment of the present application.

[0043] Figure 3 This is a schematic diagram of an operator matrix obtained in another embodiment of the present application.

[0044] Figure 4 This is a schematic diagram of an operator matrix obtained in another embodiment of the present application.

[0045] Figure 5 This is a schematic diagram of the operator matrix obtained in the first encryption round in an example.

[0046] Figure 6 yes Figure 5 Schematic diagram of the operator matrix obtained in the second encryption round in the example.

[0047] Figure 7 This is a flowchart of a secure decryption method in one embodiment of the present application. DETAILED DESCRIPTION

[0048] The specific implementation of this application will be further described below with reference to the accompanying drawings.

[0049] This application discloses a secure encryption method for resisting side channel attacks. Figure 1 In the flowchart of Example 1, the security encryption method includes:

[0050] Step 110: Obtain an operator matrix that matches the algorithm architecture.

[0051] The algorithm architecture of this secure encryption method is pre-designed and can be implemented based on existing or custom algorithm architectures. Common algorithm architectures include symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms. Common symmetric encryption algorithms include AES and SM4. Common asymmetric encryption algorithms include RSA (Rivest-Shamir-Adleman), ECC (Elliptic Curve Cryptography), and SM2.

[0052] Regardless of the algorithm architecture on which the security encryption method of this application is based, the algorithm architecture always includes multiple operator functions and each operator function is executed according to a pre-set global function order. However, when different algorithm architectures are used, there will be differences in the specific operator functions included and the global function order adopted.

[0053] For example, when the secure encryption method is based on the AES algorithm architecture and has a key length of 128 bits, the entire secure encryption method consists of four parts. The first part performs key expansion through 10 main rounds to obtain round keys, and each main round includes three operator functions: "byte replacement," "cyclic shift," and "round constant XOR." The second part is used to perform byte-by-byte XOR on the round key and input data, and includes one operator function: "byte-by-byte XOR." The third part performs encryption through 9 main rounds, and each main round includes four operator functions: "byte replacement," "row shift," "column obfuscation," and "round key addition." The fourth part is used to output ciphertext and includes three operator functions: "byte replacement," "row shift," and "round key addition." Therefore, the entire secure encryption method includes 30 operator functions in the first part, one operator function in the second part, 36 operator functions in the third part, and three operator functions in the fourth part, for a total of 70 operator functions, and the global function order follows the above sequence.

[0054] For example, when the security encryption method is based on the SM2 algorithm architecture, the security encryption method includes a total of three operator functions, and in the order of global functions, they are "digital signature", "key exchange" and "public key encryption".

[0055] The operator matrix obtained to match the algorithm architecture includes the operator groups corresponding to each operator function in the algorithm architecture and the data transmission paths between the corresponding operator groups established according to the global functional order. Each operator group corresponding to each operator function has a data transmission path with each operator group corresponding to the next operator function in the global functional order. Each operator group corresponding to each operator function in the operator matrix includes several operators, each with its own operational logic, and these operators are executed according to the pre-set operator execution order to jointly implement the corresponding operator function.

[0056] Each operator function corresponds to at least one operator group, and there is at least one operator function in the operator matrix that has corresponding multiple operator groups for implementing the operator function, so that there are at least two operator groups in the operator matrix that implement the same operator function.

[0057] Each operator group has its own operator content, which includes the number of operators included in the operator group, the operational logic of each operator, and the order in which the operators are executed. When the operator content of two operator groups is different, the operation processes performed by the two operator groups are different, resulting in different side channel information. In addition, the operator matrix is implemented based on hardware circuits, and each corresponding operator group is also implemented by a circuit module in the hardware circuit. Therefore, each operator group has its own hardware carrier. The hardware carrier of each operator group is also the circuit module in the hardware circuit used to implement the operator group. The hardware circuit here specifically refers to all or part of the circuit modules in a chip. The circuit modules in the hardware circuit are used to implement the data transmission paths between each operator in the operator matrix and different operators, including data transmission paths between different operators in the same operator group and data transmission paths between operators in different operator groups. It should be noted that each circuit module represents a local circuit structure in a group of hardware circuits, but the specifications of each circuit module can be customized. For the convenience of description in this application, a circuit module is defined as the local circuit structure used to implement each operator in an operator group. Due to the differences in hardware carriers, even if the operator contents of two operator groups are the same, the side channel information generated by the two operator groups performing the same operation process based on different hardware carriers is different.

[0058] Therefore, any two operator groups corresponding to the same operator function in the operator matrix have different operator content and / or different hardware carriers. In other words, any two operator groups corresponding to the same operator function in the operator matrix have different side channel information. The above side channel information includes at least one of operation time, electromagnetic, power consumption, temperature, and voltage.

[0059] For example, in one instance, when the secure encryption method is based on the SM2 algorithm architecture, two operator groups with different operator contents are constructed for the operator function "digital signature":

[0060] The first operator group z0 constructed for the operator function "digital signature" includes 5 operators and the order of operator execution is as follows:

[0061] (a) Operator z0-0, the operation logic is: calculate modular multiplication

[0062] (b) Operator z0-1, the operation logic is: Calculate modular subtraction

[0063] (c) Operator z0-2, the operation logic is: Calculate the modular addition

[0064] (d) Operator z0-3, the operation logic is: calculate the modular inverse

[0065] (e) Operator z0-4, the operation logic is: calculate modular multiplication

[0066] The second operator group z1 constructed for the operator function "digital signature" includes 5 operators and the order of operator execution is as follows:

[0067] (a) Operator z1-0, the operation logic is: Calculate modular addition

[0068] (b) Operator z1-1, the operation logic is: Calculate modular addition

[0069] (c) Operator z1-2, the operation logic is: Calculate the modular inverse

[0070] (d) Operator z1-3, the operation logic is: calculate modular multiplication

[0071] (e) Operator z1-4, the operation logic is: Calculate modular subtraction

[0072] The first operator group z0 is The calculation formula for the input The signature is calculated , and the second operator group z1 is The calculation formula for the input The signature is calculated . Represents the private key, represents the order of the elliptic curve basis point, It can be seen that the first operator group z0 and the second operator group z1 are based on the same parameters 、 、 For input Calculate the same signature , so the same operator function is implemented, but the operators contained in the first operator group z0 and the second operator group z1 are different, as well as the operator execution order adopted. Therefore, there is a difference in the operator content of the first operator group z0 and the second operator group z1, and the side channel information generated is different.

[0073] In one embodiment, each operator function in the algorithm architecture corresponds to multiple operator groups. Alternatively, some operator functions in the algorithm architecture correspond to multiple operator groups, while other operator functions correspond to only one operator group. A typical application is that important operator functions in the algorithm architecture correspond to multiple operator groups, while other less important operator functions correspond to only one operator group.

[0074] In another embodiment, the numbers of operator groups corresponding to any two operator functions in the algorithm architecture are equal or unequal.

[0075] For example, in one example, the algorithm architecture includes four operator functions in the order of global functions, which are recorded as operator function A, operator function B, operator function C, and operator function D:

[0076] An operator matrix is obtained as Figure 2 As shown, operator function A corresponds to one operator group a1 and is implemented using hardware carrier 201. Operator function B corresponds to three operator groups, namely operator group b1, operator group b2, and operator group b3, and is implemented using hardware carriers 202, 203, and 204, respectively. Operator function C corresponds to three operator groups, namely operator group c1, operator group c2, and operator group c3, and is implemented using hardware carriers 205, 206, and 207, respectively. Operator function D corresponds to two operator groups, namely operator group d1 and operator group d2, and is implemented using hardware carriers 208 and 209, respectively. In this example, operator functions B, C, and D each correspond to multiple operator groups, while operator function A corresponds to only one operator group. Operator functions B and C correspond to the same number of operator groups, while the other operator functions correspond to different numbers of operator groups.

[0077] Another operator matrix obtained is Figure 3As shown, operator function A corresponds to three operator groups, namely operator a1, operator a2, and operator a3, and are implemented using hardware carriers 401, 402, and 403, respectively. Operator function B corresponds to three operator groups, namely operator b1, operator b2, and operator b3, and are implemented using hardware carriers 404, 405, and 406, respectively. Operator function C corresponds to three operator groups, namely operator c1, operator c2, and operator c3, and are implemented using hardware carriers 407, 408, and 409, respectively. Operator function D corresponds to three operator groups, namely operator d1, operator d2, and operator d3, and are implemented using hardware carriers 410, 411, and 412, respectively. In this example, each of the four operator functions corresponds to multiple operator groups, and the number of these groups is equal.

[0078] Figure 2 and Figure 3 The example actually also includes the data transmission path between the operator groups. It can be understood by those skilled in the art that, for example Figure 2 The data transmission paths include the data transmission paths between operator group a1 and operator groups b1, b2, and b3, the data transmission paths between operator group b1 and operator groups c1, c2, and c3, and the data transmission paths between operator group b2 and operator groups c1, c2, and c3. The other paths are not described in detail and are not shown in the figure. Figure 2 and Figure 3 In the example, each operator group may include several operators, which will not be expanded here, and only the operator group as a whole will be explained.

[0079] Step 120 , randomly selecting an operator group from a plurality of operator groups for implementing each operator function in the operator matrix, and securely encrypting the input data to be encrypted using an encryption path formed by the selected operator group in accordance with the global function order between the operator functions.

[0080] For any operator function, if the operator matrix includes only one operator group corresponding to that operator function, the operator group corresponding to that operator function is directly selected and added to the encryption path. If the operator matrix includes multiple operator groups corresponding to that operator function, one operator group is randomly selected from the multiple operator groups corresponding to that operator function. The probability of each operator group being selected for the same operator function is within the range of (0%, 100%). Therefore, the resulting encryption path is random. Different operator groups corresponding to the same operator function have different side channel information, so the side channel information of the resulting encryption path is also random, improving the ability to resist side channel attacks.

[0081] For example, based on Figure 2For the operator matrix, operator function A corresponds to only one operator group a1, then operator group a1 is directly selected. For operator function B, select one from the corresponding operator group b1, operator group b2, and operator group b3. For operator function C, select one from the corresponding operator group c1, operator group c2, and operator group c3. For operator function D, select one from the corresponding operator group d1 and operator group d2. For example, in one case, operator group a1, operator group b1, operator group c2, and operator group d1 are selected to form an encryption path, and in another case, operator group a1, operator group b1, operator group c3, and operator group d2 are selected to form an encryption path. Based on Figure 2 There are 18 different combinations of operator matrices, forming 18 encryption paths with different side channel information. When used, an encryption path will be randomly selected to generate random side channel information. Compared with the traditional method of fixedly designing a unique encryption path, this random path selection and side channel information improves the ability to resist side channel attacks. Similarly, Figure 3 In the example of , there are 81 different combination selection methods to form 81 encryption paths with different side channel information, compared to Figure 2 It has stronger ability to resist side channel attacks.

[0082] From this, it can be seen that by constructing multiple operator groups of at least one operator function in the algorithm architecture in the operator matrix, the unique encryption path can be expanded into multiple encryption paths. Since the operator groups included in different encryption paths are different, the difference in side channel information between different operator groups will lead to differences in the side channel information generated by the same data operations under different encryption paths. Random selection of encryption will generate random side channel information. This random difference in side channel information brings greater side channel information complexity, making side channel attacks difficult to succeed, which is conducive to improving the security of the secure encryption method.

[0083] Example 2: In this example, the hardware circuit used to implement the operator matrix adopts a fixed circuit structure, for example, the hardware circuit adopts all or part of the circuit modules in an ASIC chip. In this example, after the operator matrix matching the algorithm architecture is constructed, the number of operator groups constructed for each operator function in the operator matrix, the operator content of each operator group, and the hardware carrier used remain unchanged, that is, the operator matrix remains fixed. For example, Figure 2 In the example, circuit modules 201 to 209 in the hardware circuit with a fixed circuit structure are used as the hardware circuits of each operator group and constructed as follows Figure 2 The operator matrix in this way is highly specialized and has low flexibility.

[0084] In embodiment 3, the hardware circuit used to implement the operator matrix in this embodiment adopts a reconfigurable hardware circuit. A reconfigurable hardware circuit is any hardware circuit that supports circuit reconfiguration. In one embodiment, the reconfigurable hardware circuit used is all or part of the circuit modules in a dedicated reconfigurable chip, and the reconfiguration characteristics are better. Or in another embodiment, the reconfigurable hardware circuit used is all or part of the circuit modules in an FPGA chip, and the reconfiguration characteristics are slightly worse than those of a dedicated reconfigurable chip, but easier to obtain. In this example, after the reconfigurable hardware circuit is reconfigured to obtain the operator matrix, the operator matrix can be dynamically adjusted by reconfiguring it again, and the operator matrix has greater flexibility.

[0085] In Example 4, the algorithm architecture contains multiple operator functions that may have duplicate functions, that is, there are two operator functions that belong to the same operation function category but are located in different positions in the global function order. A more typical case is that the algorithm architecture adopts a round-robin architecture. For example, the AES algorithm architecture is a typical round-robin architecture. This algorithm architecture includes at least one loop group, each loop group includes multiple iterations that are executed continuously, and each iteration contains multiple operator functions executed in a local function order. Any two iterations in the same loop group contain the same operator function category and the same local function order. In this case, each iteration contains operator functions of the same operation function category, and there will be multiple operator functions with the same operation function category in the operator matrix. For example, the AES algorithm architecture includes two loop groups: a loop group in the first part and a loop group in the third part. The loop group in the first part includes 10 consecutive iterations. Each iteration contains three operator functions: "byte replacement," "circular shift," and "round constant XOR," which are executed in sequence according to the local function order. The operator function "circular shift" in the 10 iterations belongs to the same operation function category, and the same applies to the others. The loop group in the third part includes 9 consecutive iterations. Each iteration contains four operator functions: "byte replacement," "row shift," "column obfuscation," and "round key addition," which are executed in sequence according to the local function order. The operator function "byte replacement" in the 9 iterations belongs to the same operation function category, and the same applies to the others. From the above introduction, it can be seen that there are multiple operator functions belonging to the same operation function category in the same loop group. In addition, there may be cases where multiple operator functions belonging to the same operation function category are not in the same loop group. For example, in the AES algorithm architecture, as introduced above, a loop group in the first part, a loop group in the third part, and the fourth part all contain the operator function "byte replacement" belonging to the same operation function category, but these operator functions "byte replacement" are located at different execution positions in the global function order.

[0086] Regardless of whether they appear in rounds, any two operator functions belonging to the same operator function category in the operator matrix may have the same or different operator groups. For example, in the operator matrix, the operator function "byte replace" in the first major round corresponds to operator group w0 and operator group w1. The operator function "byte replace" in the second major round also corresponds to operator group w0 and operator group w1, but the operator function "byte replace" in the third major round also corresponds to operator group w2.

[0087] When selecting an operator group from the operator matrix to form an encryption path for each operator function, the operator groups selected from the operator matrix to form the encryption path for any two operator functions belonging to the same operation function category may be the same or different. For example, based on the above example, operator group w0 is selected for the "byte replacement" operator function in the first main round, and operator group w1 is selected for the "byte replacement" operator function in the second main round. Although the operator contents of the operator groups corresponding to the two operator functions are the same, the actual selected operator groups are different.

[0088] In Example 5, when securely encrypting input data to be encrypted according to the secure encryption method of the present application, if the data to be encrypted is large, it is often impossible to complete the secure encryption in one go. Instead, the data to be encrypted must be divided into multiple local data components and performed in multiple encryption rounds. In each encryption round, the operator matrix used by the current encryption round that matches the algorithm architecture is obtained, and then an operator group is selected from it to form the encryption path for the current encryption round to securely encrypt a local data group. The next encryption round is then entered until all the data to be encrypted is securely encrypted through multiple encryption rounds. For example, if the input data to be encrypted is 1 kB, it is divided into 64 local data components and completed in 64 encryption rounds, with each encryption round securely encrypting 16 bytes of data in one of the local data groups. Each encryption round can be securely encrypted according to the methods of Examples 1-4 above.

[0089] Each encryption round needs to determine the operator matrix used by the current encryption round, and also needs to select an operator group corresponding to each operator function from the operator matrix to form an encryption path. Different operator matrices and different operator groups will affect the encryption path. For any encryption round:

[0090] When the operator matrix of the current encryption round is different from the operator matrix of the previous encryption round, since the operator matrix has changed, it is usually necessary to reselect the operator group corresponding to each operator function.

[0091] When the operator matrix of the current encryption round is the same as that of the previous encryption round, one approach is to randomly select the operator group corresponding to each operator function in the current encryption round. Although based on the same operator matrix, the randomness of the selection often results in the encryption path formed by the current encryption round being different from the encryption path formed by the previous encryption round. Alternatively, the current encryption round directly uses the operator group corresponding to each operator function selected in the previous encryption round, without re-performing the random operator group selection step. In this case, the encryption path formed by the current encryption round is the same as the encryption path formed by the previous encryption round.

[0092] For example, both encryption wheels use Figure 3 When the operator matrix is , the first encryption round selects operator group a1, operator group b1, operator group c1, and operator group d1 to form an encryption path. The second encryption round can remain unchanged and directly select operator group a1, operator group b1, operator group c1, and operator group d1 to form the same encryption path. Alternatively, the second encryption round can randomly select operator group a3, operator group b2, operator group c2, and operator group d2 to form another encryption path.

[0093] From the above introduction, it can be seen that when any two encryption rounds use different operator matrices or use the same operator matrix but select different operator groups, different encryption paths will be formed.

[0094] One approach is to use the same operator matrix in each encryption round and use the same operator group for each operator function selected from the operator matrix, thereby forming the same encryption path in each encryption round to securely encrypt different local data groups.

[0095] Another approach is to have at least two encryption rounds use different operator matrices and / or different operator groups selected from the operator matrices to form different encryption paths. This approach changes the encryption path at least once during the secure encryption of the encrypted data, further increasing the complexity of the side channel information generated during the secure encryption of the encrypted data, thereby further improving the ability to resist side-channel attacks and enhancing security. In practical applications, the encryption path can be changed in each encryption round, but this may result in a decrease in response speed. Therefore, considering the balance between security and response speed, the encryption path change can be performed every several encryption rounds.

[0096] For example, suppose the operator matrix used in the first encryption round is Figure 3 As shown, the operator group a1, operator group b1, operator group c1, and operator group d1 are selected to form the encryption path of the first encryption round. In an example, the operator matrix used in the second encryption round is also as follows Figure 3As shown, the encryption path formed by the operator group a1, operator group b1, operator group c1, and operator group d1 selected in the first encryption round is directly used as the encryption path of the second encryption round. Or in another example, the operator matrix used in the second encryption round is also as follows Figure 3 The encryption path of the second encryption round is formed by randomly selecting operator groups a3, b2, c1, and d1. Alternatively, in another example, the encryption path of the second encryption round can be reconstructed as follows: Figure 4 The operator matrix shown is used, and the operator group a3, operator b2, operator c1, and operator d3 are reselected to form the encryption path of the second encryption round.

[0097] In actual implementation, it can be designed to fixedly adopt a certain path change strategy to change the encryption path of different encryption rounds, or dynamically adjust the path change strategy according to user configuration. In this way, users can adjust the path change strategy according to actual needs. When higher security requirements are required, the frequency of path change can be increased. When higher performance requirements are required, the frequency of path change can be appropriately reduced, which is more flexible.

[0098] On this basis, if the method of the above-mentioned embodiment 2 is adopted to implement the operator matrix using a hardware circuit with a fixed circuit structure, then by pre-constructing multiple groups of different operator matrices, different operator matrices can be switched in different encryption rounds. However, each operator matrix needs to occupy a corresponding hardware circuit, and the superposition of the hardware circuits occupied by multiple operator matrices will produce a larger circuit area.

[0099] Therefore, a more common approach is to use the method of Example 3 above to implement the operator matrix used in each encryption round using a reconfigurable hardware circuit. By reconfiguring the reconfigurable hardware circuit, different operator matrices can be implemented. This approach allows the reconfigurable hardware circuit to switch between operator matrices, thereby introducing greater complexity while maintaining a small circuit area. It should be noted that when the reconfigurable hardware circuit is implemented using an FPGA, it is difficult to achieve real-time reconfiguration on the FPGA, making it difficult to support changes to the operator matrix for each encryption round. Therefore, when the operator matrix needs to be changed for each encryption round, a dedicated reconfigurable chip is required to construct the operator matrix.

[0100] In the sixth embodiment, in the fifth embodiment, when a reconfigurable hardware circuit is used to implement the operator matrix used in each encryption round, a method for obtaining the operator matrix used in each encryption round that matches the algorithm architecture includes:

[0101] First, determine whether the reconstruction requirements of the current encryption round are the same as those of the previous encryption round. The reconstruction requirements of each encryption round include the operator content and hardware support of each operator group corresponding to each operator function in the algorithm architecture. The algorithm architecture used by each encryption round is the same, but the reconstruction requirements can be the same or different. If there is at least one difference in the operator content and hardware support used by each operator group corresponding to each operator function, the two reconstruction requirements are different.

[0102] If the reconstruction requirements of the current encryption round are the same as those of the previous encryption round, the operator matrix of the previous encryption round is directly used as the operator matrix for the current encryption round, and the circuit reconstruction operation is not performed again. If the reconstruction requirements of the current encryption round are different from those of the previous encryption round, the reconfigurable hardware circuit is reconfigured according to the reconstruction requirements of the current encryption round to obtain the operator matrix for the current encryption round.

[0103] For example, in one embodiment, the algorithm architecture includes algorithm functions A, B, C, and D that are executed in sequence according to the global function order. The reconstruction requirements of an encryption round include: the operator content of the operator groups a1, a2, and a3 corresponding to the operator function A and the hardware carriers 401, 402, and 403 used in sequence; the operator content of the operator groups b1, b2, and b3 corresponding to the operator function B and the hardware carriers 404, 405, and 406 used in sequence; the operator content of the operator groups c1, c2, and c3 corresponding to the operator function C and the hardware carriers 407, 408, and 409 used in sequence; the operator content of the operator groups d1, d2, and d3 corresponding to the operator function D and the hardware carriers 410, 411, and 412 used in sequence. The operator matrix used by the encryption round is obtained by reconstructing the reconfigurable hardware circuit according to the reconstruction requirements. Figure 3 shown.

[0104] The reconstruction requirements of another encryption round include: the operator contents of the operator groups a1, a2, and a3 corresponding to the operator function A and the hardware carriers 401, 402, and 403 used in sequence; the operator contents of the operator groups b1, b2, and b3 corresponding to the operator function B and the hardware carriers 404, 405, and 406 used in sequence; the operator contents of the operator groups c1, c2, and c3 corresponding to the operator function C and the hardware carriers 408, 407, and 409 used in sequence; the operator contents of the operator groups d1, d2, and d3 corresponding to the operator function D and the hardware carriers 412, 410, and 411 used in sequence. The operator matrix used in the encryption round is obtained by reconstructing the reconfigurable hardware circuit according to the reconstruction requirements. Figure 4 shown.

[0105] Even though the operator contents of each operator group in the two encryption rounds are the same, the hardware carriers used by the operator groups are different. Therefore, the reconstruction requirements of the two encryption rounds are obviously different, and the reconstructed operator matrices are also different.

[0106] In Example 7, in Example 6 above, it is necessary to determine the reconstruction requirement for each encryption round. One scenario is to pre-determine the reconstruction requirement for each encryption round. However, to further improve the randomness of the side channel information, this embodiment uses the random numbers generated by the true random number module to randomly form the reconstruction requirement for each encryption round.

[0107] However, when randomly forming the reconstruction requirements of each encryption round, considering that too high randomness will also affect the response speed, not every information in the reconstruction requirements is generated completely randomly. Instead, the operator contents of each operator group corresponding to each operator function are predetermined. In this way, the number of operator groups and operator contents corresponding to each operator function can be predetermined.

[0108] However, the hardware carrier used by each operator group is randomly assigned and determined, including: using true random number generation including bits of global reconstruction configuration code, bits form all Each global reconfiguration configuration code has its own corresponding hardware allocation relationship. Each hardware allocation relationship indicates the circuit module in the reconfigurable hardware circuit allocated to each operator group corresponding to each operator function, and the circuit module allocated to each operator group meets the hardware resource requirements of the corresponding operator group. is an integer parameter.

[0109] Then, the reconstruction requirements of the current encryption round are obtained by combining the hardware allocation relationship corresponding to the randomly generated global reconstruction configuration code and the operator content of each operator group.

[0110] For example, in one instance, the operator contents of the three operator groups a1, a2, and a3 corresponding to the operator function A, the operator contents of the three operator groups b1, b2, and b3 corresponding to the operator function B, the operator contents of the three operator groups c1, c2, and c3 corresponding to the operator function C, and the operator contents of the three operator groups d1, d2, and d3 corresponding to the operator function D are predetermined.

[0111] Then, a global reconstruction configuration code is generated using true random numbers. The hardware allocation relationship corresponding to a randomly generated global reconstruction configuration code is as follows: Figure 3 The hardware allocation relationship corresponding to another randomly generated global reconstruction configuration code is shown as follows Figure 4 .

[0112] Since the global reconstruction configuration code is generated using true random numbers, the randomness of the hardware allocation relationship is guaranteed. In this way, random reconstruction requirements can be formed even when the operator content remains unchanged, thereby constructing a random operator matrix, further improving the randomness of the generated side channel information to resist side channel attacks.

[0113] The correspondence between different global reconfiguration configuration codes and hardware allocation relationships is pre-configured. In one case, first determine the use of all the reconfigurable hardware circuits. The circuit module realizes all All hardware allocation relationships when there are operator groups, according to the permutation and combination principle, there are Different hardware allocation relationships, is the factorial symbol, Then determine the number of bits of the global reconstruction configuration code to meet To ensure that each hardware allocation relationship corresponds to at least one global reconstruction configuration code, and then pre-configure A global reconfiguration code and The corresponding relationship of hardware allocation relationship. However, this implementation method is relatively complex, for example, Figure 3 and Figure 4 In this example, taking the implementation of 12 operator groups across all 12 circuit modules in a reconfigurable hardware circuit as an example, there are 12! = 47,900,1600 possible reconfigurations. The global reconfiguration configuration code used has 29 bits, resulting in a high level of complexity. Furthermore, actual reconfigurable hardware circuits contain more circuit modules and operator groups, resulting in even higher complexity. This approach can affect speed and overall performance.

[0114] Therefore, considering the feasibility of practical applications, it is generally recommended to select a more appropriate number of bits for the global reconstruction configuration code, such as , then randomly selects 256 corresponding hardware allocation relationships to 256 global reconstruction configuration codes formed by 8 bits. This method is equivalent to first randomly selecting a limited number of hardware allocation relationships and then randomly selecting one hardware allocation relationship from the limited number of hardware allocation relationships. It also effectively ensures the randomness of the generated reconstruction requirements and keeps the computational complexity within an acceptable range.

[0115] Example 8, as described in Example 5 above, when all data to be encrypted are securely encrypted through multiple encryption rounds, when an encryption round needs to randomly select an operator group from the operator matrix to form an encryption path, the operator group can be selected completely independently and randomly. Although this completely random selection method can ensure the randomness of the encryption path, for a secure encryption method, security is one aspect of performance, and on the other hand, the delay of the encryption path should be minimized as much as possible. Therefore, in order to improve the overall performance, another approach is to consider the operator group selected in the encryption path formed by the previous encryption round and select the operator group of the current encryption round based on the ant colony algorithm to form the encryption path. In actual implementation, the relationship between different operator groups is not as described above. Figure 3 and Figure 4 As shown in the figure, they are completely independent. In actual application, in order to improve the operator reuse rate, different operator groups corresponding to the same operator function may share operators, which makes the logical relationship between operator groups more complicated. For example, in an example, Figure 3 Each operator group in the operator matrix is further expanded as follows Figure 5 As shown, Figure 5 In , operator group a1 includes operators a1-0 and a1-1 which are executed in sequence according to the operator execution order. Other representations are similar and will not be described in detail. Figure 5 In the example, operator group b1 includes operators b2-0, b2-1, b1-0, b1-1, and b1-2, which are executed in the order of operator execution. Operator group b2 includes operators b2-0, b2-1, b2-2, b2-3, and b2-4, which are executed in the order of operator execution. Operator group b3 includes operators b2-0, b2-1, b2-2, b3-0, and b3-1, which are executed in the order of operator execution. It can be seen that operator groups b1, b2, and b3 share operators b2-0 and b2-1, and operator groups b2 and b3 also share operator b2-2. The sharing relationship between different operator groups in the actual operator matrix may be more complex than Figure 5 The structure is more complex, and it is difficult to directly select each operator group as a whole. Therefore, in this embodiment, the selected operator group is determined by traversing each operator in turn.

[0116] For any integer argument as well as , in The encryption round is selected from the operator matrix to implement the The operator group of the term operator function includes:

[0117] (1) First initialize the current path node , there are two cases: when When the operator function is the first operator function in the global function order, the virtual start node is initialized as the current path node Otherwise, The operator matrix of the encryption round is selected to realize the The last operator in the operator group of the item operator function is initialized as the current path node , No. The operator function is The previous operator function of an operator function.

[0118] (2) Determine the The operator matrix used by the encryption round is the same as the current path node Any operator with a data transmission path Number of operating cycles , and according to the number of operating cycles Determine the operator Heuristic information .

[0119] Determine the heuristic information obtained and the number of operating cycles In one embodiment, the current path node Any operator with a data transmission path Heuristic information .

[0120] (3) Determine the The operator matrix used by the encryption round is the same as the current path node Any operator with a data transmission path and the current path node On the data transmission path between Pheromone concentration per encryption round .

[0121] (4) Combining operators Heuristic information and its relationship with the current path node On the data transmission path between Pheromone concentration per encryption round , calculation operator In the The probability of selection in the encryption round for:

[0122]

[0123] in, It is The operator matrix used by the encryption round is consistent with the current path node The set of all operators that have a data transmission path. Is the current path node And the existence of any operator in the data transmission path The data transmission path between The pheromone concentration in the iteration round, Is the node with the current path Operators with data transmission paths Heuristic information and , It is an operator The number of running cycles. is the information heuristic factor, It is the expectation heuristic factor.

[0124] (5) According to The operator matrix used by the encryption round is consistent with the current path node An operator is selected from each operator group in the data transmission path according to its respective selection probability.

[0125] (6) Update the selected operator to the current path node Continue to traverse and determine the next operator according to the method of steps (2) to (5) until the currently selected operator is the The operator matrix used in the encryption round is the same as the When the last operator of one of the operator groups corresponding to the operator function is selected, the One of the operator groups corresponding to the operator function is added to the encryption path. Then, the next operator function is executed again according to steps (1) to (6).

[0126] It should be noted that the above process can be further simplified in the actual execution process. After the above step (1), the node with the current path is first determined. The number of operators in the data transmission path, when there is only one operator and the current path node When there is a data transmission path, the selection probability of the operator calculated according to the above method is always 1, so the node with the current path can be directly selected. There is an operator in the data transmission path, and jump to step (6) to continue traversing the next operator, so that the selection probability calculation process of steps (2) to (5) can be skipped to simplify the calculation process. When there is a data transmission path, the selection probability is calculated through the above steps (2) to (5), and then an operator is selected from it, and then jump to step (6) to continue traversing the next operator.

[0127] In the above process, the pheromone concentration on the data transmission path between the same operators in the operator matrix is dynamically updated along with the encryption path formed by the encryption round. AND operator On the data transmission path between Pheromone concentration per encryption round include:

[0128] when Initialize the pheromone concentration , that is, the pheromone concentration of the data transmission path between different operators in the operator matrix used in the first encryption round is the initial setting value.

[0129] when And the first The operator matrix used by the encryption round does not contain the current path node To Operator Initialize the pheromone concentration when the data transmission path between As mentioned above, the operator matrix used in different encryption rounds will change, which will lead to the emergence of new data transmission paths between operators. There are also cases where data transmission paths between operators disappear. The disappeared data transmission paths are no longer considered, and the newly appeared data transmission paths will also reinitialize the pheromone concentration.

[0130] when And the first The current path node exists in the operator matrix used by the encryption round To Operator When the data transmission path between The encryption path formed by the encryption round contains the current path node To Operator The data transmission path between When the The encryption path formed by the encryption round does not contain the current path node To Operator The data transmission path between . is the pheromone volatility coefficient, The pheromone increment can be preset.

[0131] For example, in one example, the operator matrix of the first encryption round is Figure 5 As shown, the data transmission path between different operators in the operator matrix is as follows Figure 5 As shown by the solid arrows, the pheromone concentrations on each data transmission path are first initialized.

[0132] In the first encryption round, the virtual starting node O is initialized as the current path node , and then calculate the nodes on the current path (i.e. virtual starting node O) has a data transmission path for operators a1-0, a2-0, and a3-0. For operator a1-0, the heuristic information of operator a1-0 is calculated based on the inverse of the number of its operating cycles, combined with the pheromone concentration in the first encryption round on the data transmission path between the virtual starting node O and operator a1-0. Calculate the selection probability of operator a1-0. Similarly, calculate the selection probability of operators a2-0 and a3-0. Then, according to the selection probabilities of operators a1-0, a2-0, and a3-0, select one from them, for example, select operator a1-0. Then update operator a1-0 to the current path node. , at this time, judge the current path node If the only operator a1-1 (i.e., operator a1-0) with a data transmission path exists, operator a1-1 is directly selected. At this point, it is determined that the selected operator a1-1 is the last operator in operator group a1 corresponding to operator function A. Therefore, the operator group corresponding to operator function A has been selected, namely, operator group a1 to which operators a1-0 and a1-1, which were selected in that order, belong.

[0133] Then initialize the last operator in operator group a1 selected for operator function A, that is, operator a1-1, as the current path node , at this time, judge the current path node (i.e. operator a1-1) If the only operator b2-0 that has a data transmission path is operator b2-0, then operator b2-0 is directly selected. Operator b2-0 is then initialized as the current path node. , judge the node with the current path (i.e. operator b2-0) If the only operator b2-1 in the data transmission path is selected, operator b2-1 is directly selected. Operator b2-1 is then initialized as the current path node. , respectively calculated with the current path node (i.e., operator b2-1) The selection probability of operators b1-0 and b2-2 in the data transmission path is calculated in the same way as a1-0 above and will not be repeated here. Then, one of the operators b1-0 and b2-2 is selected according to their respective selection probabilities, for example, operator b2-2 is selected. Operator b2-2 is then initialized as the current path node. , respectively calculated with the current path node (i.e. operator b2-2) There are selection probabilities of operators b2-3 and b3-0 in the data transmission path, and one is selected from them according to the respective selection probabilities of operators b2-3 and b3-0, for example, operator b2-3 is selected. Then operator b2-3 is initialized as the current path node , judge the node with the current path If the only operator with a data transmission path (i.e., operator b2-3) is b2-4, then operator b2-4 is directly selected. At this point, the selected operator b2-4 is already the last operator in one of the operator groups b2 corresponding to operator function B. Therefore, the operator group corresponding to operator function B has been selected, namely, operator group b2, to which operators b2-0, b2-1, b2-2, b2-3, and b2-4 are assigned in that order.

[0134] Then initialize the last operator in operator group b2 selected for operator function B, i.e. operator b2-4, as the current path node , respectively calculated with the current path node (i.e. operator b2-4) has the selection probability of operators c1-0, c2-0, and c3-0 in the data transmission path, and selects one according to the operator selection probability, for example, operator c2-0. Then operator c2-0 is updated to the current path node , judge the node with the current path If the only operator with a data transmission path (i.e., operator c2-0) is operator c2-1, operator c2-1 is directly selected. At this point, it is determined that the selected operator c2-1 is the last operator in operator group c2 corresponding to operator function C. Therefore, the operator group corresponding to operator function C has been selected, namely, operator group c2, to which operators c2-0 and c2-1, which were selected in that order, belong.

[0135] Then initialize the last operator in operator group c2 selected for operator function C, i.e. operator c2-1, as the current path node , respectively calculated with the current path node (i.e. operator c2-1) has the selection probability of operators d1-0, d2-0, and d3-0 in the data transmission path, and selects one according to the operator selection probability, for example, select operator d3-0. Then update operator d3-0 to the current path node , judge the node with the current path (i.e. operator d3-0) If the only operator with a data transmission path is operator d3-1, then operator d3-1 is directly selected. Then operator d3-0 is updated to the current path node. , judge the node with the current path If the only operator with a data transmission path (i.e., operator d3-1) is operator d3-2, then operator d3-2 is directly selected. At this point, it is determined that the selected operator d3-2 is the last operator in operator group d3 corresponding to operator function D. Therefore, the operator group corresponding to operator function D has been selected, namely, operator group d3, to which operators d3-0, d3-1, and d3-2 belong in that order.

[0136] Therefore, the first encryption round selects operator group a1, operator group b2, operator group c2 and operator group d3 in sequence to form the encryption path of the first encryption round.

[0137] Assume that the second encryption round reconstructs the operator matrix, and the reconstructed operator matrix is as follows Figure 6 As shown, compared to Figure 5 , Figure 6 The operator matrix of is added with operator group b4 corresponding to operator function B. Since the encryption path formed by the first encryption round includes operator group a1, operator group b2, operator group c2 and operator group d3, the data transmission path between the virtual starting node O and operator a1-0 is updated to obtain the pheromone concentration of the second encryption round. , assuming that all pheromone increments take fixed values The data transmission paths between operators a1-0, a1-1, b2-0, b2-1, b2-2, b2-3, b2-4, c2-0, c2-1, d3-0, d3-1, and d3-2 in the encryption path of the first encryption round are updated in the same way.

[0138] In the operator matrix used in the second encryption round, the data transmission paths between operators a1-1, a2-1, and a3-2 and operator b4-0, as well as the data transmission paths between operators b4-0 and b4-1, b4-1 and b4-2, and b4-2 and operators c1-0, c2-0, and c3-0 are not included in the operator matrix of the first encryption round. Therefore, the pheromone concentrations of these data transmission paths need to be initialized in the second encryption round.

[0139] In addition to the above two types of data transmission paths, the remaining data transmission paths are included in the operator matrix of the first encryption round but are not included in the encryption path formed by the first encryption round. For example, the pheromone concentration in the second encryption round on the data transmission path between the virtual starting node O and the operator a2-0 is , is the pheromone concentration in the first encryption round on the data transmission path between the virtual starting node O and operator a2-0. Other data transmission paths of the same type are updated in the same way.

[0140] After updating the pheromone concentration of the data transmission path between operators in the operator matrix of the second encryption round, the selection probability of each operator is calculated according to the above mechanism and selected in the same way.

[0141] The above selection logic adopted in this embodiment has the following advantages: when the number of operators in the operator matrix increases and the structure becomes more complex, the number of path selections increases accordingly, and the performance planning method of directly using the operator group as a whole is more complex. Therefore, this embodiment selects operators in sequence as the smallest unit. When selecting each operator, theoretically, the shorter the number of operating cycles of the operator, the more conducive it is to reducing the delay of the encryption path. However, if the inverse of the number of operating cycles is directly used as the selection probability of the operator, then when the number of operating cycles of the operators varies greatly, the difference in the selection probability of the operator will be very large, for example Figure 5 In the example, if the number of operating cycles of operator a1-0 is much smaller than the number of operating cycles of operator a3-0, then this approach will result in operator a3-0 being almost never selected, and subsequently operator group a3 being almost never selected, causing the method to lose its anti-attack capability. In reality, there will also be situations where the number of operating cycles of operator a1-0 is smaller than the number of operating cycles of operator a3-0, but the overall performance of operator group a3 is better than that of operator group a1. Therefore, the approach of selecting based solely on the number of operating cycles of operators cannot achieve a better selection effect. For this reason, this embodiment utilizes the idea of the ant colony algorithm to ensure that the probability of each operator group being selected is balanced and changes randomly, and as the encryption round proceeds, the overall encryption path formed moves towards a direction with better performance.

[0142] In the above method, Characterizes the degree of influence of pheromone concentration on the data transmission path on the selection of operator groups in the current encryption round, The larger the value, the stronger the pheromone concentration, that is, the operator selection result in the previous encryption round has a greater impact on the operator selection process in the current encryption round. Characterizes the degree of influence of the number of operating cycles of the operator on the selection of the operator group, The larger the value of is, the more the operator selection process in the current encryption round is affected by the number of operator cycles. It can be seen that the values of these two parameters have a great influence on the formation of the encryption path, so they need to be adjusted reasonably. and The value of can control the convergence speed and ensure the probability of the operator being selected, so it is also necessary to predetermine the information heuristic factor and expectation heuristics include:

[0143] The security encryption method is used to perform repeated security encryption tests on the test data according to the above process, and the information heuristic factor is adjusted according to the selected probability of each operator group in the security encryption test process. and expectation heuristics The security encryption test is then rerun until the probability of each operator group being selected in the security encryption test reaches the predetermined probability threshold. This ensures that the probability of each operator group being selected is balanced and randomly varied, and overall performance gradually converges to optimal performance, with better acceleration for larger amounts of data to be encrypted.

[0144] This application also discloses a secure decryption method for resisting side channel attacks, please refer to Figure 7 In the flowchart of Example 9, the secure decryption method includes:

[0145] Step 910: Obtain an operator matrix that matches the algorithm architecture. The algorithm architecture includes multiple operator functions and the operator functions are executed according to the global function order.

[0146] The operator matrix includes operator groups corresponding to each operator function in the algorithm architecture and data transmission paths between corresponding operator groups established according to the global function order; each operator group includes several operators and data transmission paths between corresponding operators established according to the operator execution order, and several operators in the same operator group are executed according to the operator execution order to jointly realize a corresponding operator function; there is at least one operator function corresponding to multiple operator groups in the operator matrix, and any two operator groups corresponding to the same operator function have different operator content and / or hardware carriers used and have different side channel information. The operator content of each operator group includes the number of operators contained in the operator group, the operation logic of each operator and the operator execution order adopted.

[0147] Step 920: randomly select an operator group from a number of operator groups used to implement each operator function in the operator matrix, and securely decrypt the input data to be decrypted using the decryption path formed by the selected operator group according to the global function order between the operator functions.

[0148] It is understood by those skilled in the art that the data processing processes implemented by the secure decryption method and the secure encryption method are symmetrical, except that the algorithm architecture adopted by the secure decryption method is different from that of the secure encryption method. For example, in the secure encryption method using the AES algorithm architecture, the four operator functions included in the nine main rounds are "byte replacement", "row shift", "column confusion", and "round key addition", while in the secure decryption method using the AES algorithm architecture, the four operator functions included in the nine main rounds are "reverse byte replacement", "reverse row shift", "reverse column confusion", and "reverse round key addition". After determining the algorithm architecture adopted by the secure decryption method, the method of obtaining the operator matrix and selecting the operator group to form the decryption path is similar to the methods of the various embodiments of the above-mentioned secure encryption method, and will not be repeated one by one through specific embodiments.

[0149] The present application also discloses a secure encryption and decryption system for resisting side-channel attacks, the secure encryption and decryption system comprising one or more processors and a computer-readable storage medium for storing one or more programs. When the programs in the computer-readable storage medium are executed by the processor, the steps of the secure encryption method and / or the steps of the secure decryption method in each embodiment of the present application are implemented.

[0150] The above description is only a preferred embodiment of the present application, and the present application is not limited to the above embodiments. It is understood that other improvements and variations directly derived or imagined by those skilled in the art without departing from the spirit and concept of the present application should be considered to be included in the scope of protection of the present application.

Claims

1. A secure encryption method for resisting side channel attacks, characterized in that: The secure encryption method securely encrypts input data to be encrypted using multiple encryption rounds, and the secure encryption method includes: Obtain an operator matrix matching the algorithm architecture used in each encryption round, where the algorithm architecture includes multiple operator functions and the operator functions are executed in a global function order; the operator matrix includes operator groups corresponding to each operator function in the algorithm architecture and data transmission paths between corresponding operator groups established in a global function order; each operator group includes several operators and data transmission paths between corresponding operators established in an operator execution order, and several operators in the same operator group are executed in an operator execution order to jointly implement a corresponding operator function; there is at least one operator function in the operator matrix corresponding to multiple operator groups, and any two operator groups corresponding to the same operator function have different operator content and / or hardware carriers used and have different side channel information, and the operator content of each operator group includes the number of operators included in the operator group, the operation logic of each operator, and the operator execution order adopted; An operator group is randomly selected from several operator groups used to implement each operator function in the operator matrix of the current encryption round, and the selected operator group is used to form an encryption path of the current encryption round according to the global functional order between the operator functions to securely encrypt a local data group in the input data to be encrypted; there are at least two encryption rounds that use different operator matrices and / or different operator groups selected from the operator matrices to form different encryption paths.

2. The security encryption method according to claim 1, characterized in that: The operator matrix is implemented based on a reconfigurable hardware circuit. Obtaining the operator matrix used in each encryption round that matches the algorithm architecture includes: When the reconstruction requirements of the current encryption round are different from those of the previous encryption round, the reconfigurable hardware circuit is reconfigured according to the reconstruction requirements of the current encryption round to obtain the operator matrix used by the current encryption round; when the reconstruction requirements of the current encryption round are the same as those of the previous encryption round, the operator matrix of the previous encryption round is directly used as the operator matrix used by the current encryption round; The reconstruction requirements include the operator contents and hardware carriers of each operator group corresponding to each operator function in the algorithm architecture.

3. The security encryption method according to claim 2, characterized in that: Determine the reconstruction requirements of the current encryption wheel including: Using true random number generation includes bits of global reconstruction configuration code, bits form all There are corresponding hardware allocation relationships for each type of global reconfiguration configuration code. Each hardware allocation relationship indicates the circuit module in the reconfigurable hardware circuit allocated to each operator group corresponding to each operator function, and the circuit module allocated to each operator group meets the hardware resource requirements of the corresponding operator group. is an integer parameter; The reconstruction requirements of the current encryption round are obtained by combining the hardware allocation relationship corresponding to the randomly generated global reconstruction configuration code and the operator content of each operator group.

4. The security encryption method according to claim 1, wherein: The algorithm architecture of the secure encryption method includes at least two operator functions belonging to the same operation function category but located at different positions in the global function order, the operator contents of the operator groups corresponding to any two operator functions belonging to the same operation function category in the operator matrix are the same or different, and the operator groups selected from the operator matrix for any two operator functions belonging to the same operation function category to form an encryption path are the same or different.

5. The security encryption method according to claim 1, wherein: For any integer argument as well as , in The encryption round is selected from the operator matrix to implement the The operator group of the term operator function includes: When When the operator function is the first operator function in the global function order, the virtual start node is initialized as the current path node Otherwise, it will be The operator matrix of the encryption round is selected to realize the The last operator in the operator group of the item operator function is initialized as the current path node , No. The operator function is The previous operator function of an operator function; Determine the In the operator matrix used by the encryption round, the current path node Any operator in the data transmission path The data transmission path between Pheromone concentration per encryption round ,The pheromone concentration on the data transmission path between the same operators is dynamically updated along the encryption path formed by the encryption round; Determine the The operator matrix used by the encryption round and the current path node Operators with data transmission paths The probability of selection for: in, It is an operator Heuristic information and , It is an operator The number of operating cycles; It is The operator matrix used by the encryption round is consistent with the current path node The set of all operators that have data transmission paths, It is The current path node in the operator matrix used by the encryption round Any operator with a data transmission path The pheromone concentration on the data transmission path between It is an operator Heuristic information and , It is an operator The number of operating cycles; is the information heuristic factor, is the expectation heuristic factor; According to the The operator matrix used by the encryption round is consistent with the current path node The selection probability of each operator in the data transmission path is used to select an operator from them, and the selected operator is updated as the current path node Continue traversing until the selected operator is the The operator matrix used in the encryption round is the same as the The last operator of one of the operator groups corresponding to the item operator function.

6. The security encryption method according to claim 5, characterized in that: Determine the current path node To Operator The data transmission path between Pheromone concentration per encryption round include: when Initialize the pheromone concentration ; when And the first The operator matrix used by the encryption round does not contain the current path node To Operator Initialize the pheromone concentration when the data transmission path between ; when And the first The current path node exists in the operator matrix used by the encryption round To Operator When the data transmission path between The encryption path formed by the encryption round contains the current path node To Operator The data transmission path between ; When the The encryption path formed by the encryption round does not contain the current path node To Operator The data transmission path between ; is the pheromone volatility coefficient, It is the pheromone increment.

7. The security encryption method according to claim 5, characterized in that: Determine the information heuristic factor and expectation heuristics include: The security encryption method is used to repeatedly perform security encryption tests on the test data, and the information heuristic factor is adjusted according to the selected probability of each operator group during the security encryption test. and expectation heuristics The security encryption test is performed again until the selection probability of each operator group in the security encryption test reaches a predetermined probability threshold.

8. A secure decryption method for resisting side channel attacks, characterized in that: The secure decryption method securely decrypts input data to be encrypted through multiple decryption rounds, and the secure decryption method includes: Obtain an operator matrix that matches the algorithm architecture used in each decryption round, where the algorithm architecture includes multiple operator functions and the operator functions are executed in a global function order; the operator matrix includes operator groups corresponding to each operator function in the algorithm architecture and data transmission paths between corresponding operator groups established in a global function order; each operator group includes several operators and data transmission paths between corresponding operators established in an operator execution order, and several operators in the same operator group are executed in an operator execution order to jointly implement a corresponding operator function; there is at least one operator function in the operator matrix that corresponds to multiple operator groups, and any two operator groups corresponding to the same operator function have different operator content and / or hardware carriers used and have different side channel information, and the operator content of each operator group includes the number of operators included in the operator group, the operation logic of each operator, and the operator execution order adopted; An operator group is randomly selected from several operator groups used to implement each operator function in the operator matrix of the current decryption round, and the selected operator group is used to form a decryption path of the current decryption round according to the global functional order between the operator functions to securely decrypt a local data group in the input data to be decrypted; there are at least two decryption rounds using different operator matrices and / or different operator groups selected from the operator matrices to form different decryption paths.

9. A secure encryption and decryption system for resisting side channel attacks, characterized in that: The security encryption and decryption system includes one or more processors and a computer-readable storage medium for storing one or more programs; when the program in the computer-readable storage medium is executed by the processor, the steps of the security encryption method as described in any one of claims 1 to 7 are implemented, and / or the steps of the security decryption method as described in claim 8 are implemented.

Citation Information

Patent Citations

  • Implementation method and system of SKINNY-128 encryption algorithm based on coarse-grained reconfigurable computing unit

    CN110059493A

  • Improved AES (Advanced Encryption Standard) encryption method and system with side channel attack resistance attribute

    CN119995837A