System for implementing multi-version ZUM algorithm

By designing a system that includes initial vector generation module, loading module and key generation module, multiplexing the key generation module to generate keys, the problem of high deployment cost of multi-version Zu Chongzhi algorithm is solved, and flexible and efficient algorithm implementation is achieved.

CN120217415APending Publication Date: 2025-06-27PICOCOM (HANGZHOU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510334937.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The deployment cost of implementing the multi-version Zu Chongzhi algorithm is relatively high, and it is necessary to build and deploy two independent systems to implement the ZUC-128 version and the ZUC-256 version respectively.

Method used

A system is designed, including an initial vector generation module, a loading module and a key generation module, and the corresponding initial vector generation method, loading method and key generation method are determined through the version selection signal, and the key generation module is used to generate a key.

Benefits of technology

By reusing the key generation module, the deployment cost is reduced and the flexibility and adaptability of Zu Chongzhi algorithm is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217415A_ABST
    Figure CN120217415A_ABST
Patent Text Reader

Abstract

The invention provides a system for realizing a multi-version ZUM algorithm. The system can be applied to the technical field of data encryption. The system comprises an initial vector generation module, a loading module and a key generation module, the initial vector generation module is used for determining a corresponding initial vector generation mode according to the version selection signal; generating a target initial vector based on the determined initial vector generation mode; the version selection signal is used for representing a target version needing to be realized in a plurality of preset ZUC algorithm versions; key generation modes of different preset ZUC algorithm versions are the same; the loading module is used for determining a target loading value based on a loading mode corresponding to the version selection signal according to the generated target initial vector; and the key generation module is used for generating a target key based on the key generation mode according to the determined target loading value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data encryption technology, and in particular, to a system for implementing multi-version Zu Chongzhi algorithms. Background Art

[0002] The description in this part only provides background information related to the present disclosure and does not constitute prior art. The Zu Chongzhi algorithm, i.e., the ZUC algorithm, is an encryption algorithm with multiple versions. For example, there are ZUC-128 version and ZUC-256 version. Among them, the ZUC-128 version is mainly responsible for encrypting security information under the technical framework in the 4G era, while in the future, ZUC-256 is usually responsible for encrypting security information. Currently, when implementing the Zu Chongzhi algorithm, it is usually to build and deploy two independent systems to implement the ZUC-128 version and the ZUC-256 version respectively, and the deployment cost is relatively high. Summary of the Invention

[0003] In view of the above problems, the present disclosure provides a system for implementing multi-version Zu Chongzhi algorithms, which solves the problem of relatively high deployment cost for implementing multi-version Zu Chongzhi algorithms.

[0004] According to a first aspect of the present disclosure, there is provided a system for implementing multi-version Zu Chongzhi algorithms, including: an initial vector generation module, a loading module, and a key generation module; the initial vector generation module is configured to: determine a corresponding initial vector generation method according to a version selection signal; generate a target initial vector based on the determined initial vector generation method; the version selection signal is used to represent a target version to be implemented among multiple preset Zu Chongzhi algorithm versions; between different preset Zu Chongzhi algorithm versions, the key generation method is the same; the loading module is configured to: determine a target loading value according to the generated target initial vector and based on the loading method corresponding to the version selection signal; the key generation module is configured to: generate a target key according to the determined target loading value and based on the key generation method.

[0005] A second aspect of the present disclosure provides a method for implementing the Zu Chongzhi algorithm, which is applied to a preset system, and the preset system includes: an initial vector generation module, a loading module, and a key generation module; the method includes: the initial vector generation module determines a corresponding initial vector generation method according to a version selection signal; generates a target initial vector based on the determined initial vector generation method; the version selection signal is used to represent a target version to be implemented among multiple preset Zu Chongzhi algorithm versions; between different preset Zu Chongzhi algorithm versions, the key generation method is the same; the loading module determines a target loading value according to the generated target initial vector and based on the loading method corresponding to the version selection signal; the key generation module generates a target key according to the determined target loading value and based on the key generation method.

[0006] The third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method for implementing the Zu Chongzhi algorithm.

[0007] The fourth aspect of the present disclosure further provides a computer-readable storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by a processor, the steps of the method for implementing the Zu Chongzhi algorithm are implemented.

[0008] The fifth aspect of the present disclosure further provides a computer program product, including a computer program or instruction, and when the computer program or instruction is executed by a processor, the steps of the method for implementing the Zu Chongzhi algorithm are implemented.

[0009] According to the above embodiments, it can be known that in the process of implementing different versions of the Zu Chongzhi algorithm, a key can be generated by reusing the key generation module, which can reduce the deployment cost. It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above content and other objects, features and advantages of the present disclosure will be clearer. In the drawings:

[0011] Figure 1 Schematically shows a schematic structural diagram of a system for implementing multiple versions of the Zu Chongzhi algorithm according to an embodiment of the present disclosure;

[0012] Figure 2 Schematically shows a schematic structural diagram of another system for implementing multiple versions of the Zu Chongzhi algorithm according to an embodiment of the present disclosure;

[0013] Figure 3 Schematically shows a schematic structural diagram of an integrity algorithm module according to an embodiment of the present disclosure;

[0014] Figure 4 Schematically shows a schematic structural diagram of a key stream register according to an embodiment of the present disclosure;

[0015] Figure 5 Schematically shows a schematic flowchart of a method for implementing the Zu Chongzhi algorithm according to an embodiment of the present disclosure;

[0016] Figure 6 Schematically shows a schematic structural diagram of another system for implementing multiple versions of the Zu Chongzhi algorithm according to an embodiment of the present disclosure;

[0017] Figure 7Schematically shows a schematic diagram of the principle of a ZUC reconfigurable EIA3-NIA6 integrity algorithm according to an embodiment of the present disclosure;

[0018] Figure 8 Schematically shows a schematic diagram of the principle of another ZUC reconfigurable EIA3-NIA6 integrity algorithm according to an embodiment of the present disclosure;

[0019] Figure 9 Schematically shows a block diagram of an electronic device suitable for implementing a method for implementing a Zu Chongzhi algorithm according to an embodiment of the present disclosure. Detailed implementation manners

[0020] In order to enable those skilled in the art to better understand the technical solutions in the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present disclosure. The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components. All terms (including technical and scientific terms) used herein have the meaning commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.

[0021] In the case of using expressions such as "at least one of A, B, and C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art. For example, "a system having at least one of A, B, and C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc. In the case of using expressions such as "at least one of A, B, or C, etc.", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art. For example, "a system having at least one of A, B, or C" should include, but is not limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.

[0022] To reduce the deployment cost of implementing multiple versions of the Zu Chongzhi algorithm, embodiments of the present disclosure provide a system for implementing multiple versions of the Zu Chongzhi algorithm. In this system, considering that there are some identical algorithms and architectures among different versions of the Zu Chongzhi algorithm, the deployment cost can be reduced through reuse.

[0023] The Zu Chongzhi algorithm may include the following steps: 1) generating an initial vector; 2) generating an initial loading value by loading the input key, a preset constant, and the generated initial vector through a loading algorithm; 3) generating a key based on the initial loading value. After that, the generated key can be used to encrypt the plaintext through a confidentiality algorithm; or the generated key can be used to generate an integrity tag for the plaintext through an integrity algorithm. Among them, the integrity tag can specifically be a Message Authentication Code (MAC), also known as an integrity authentication tag, which can be used to verify the integrity of the message and the authenticity of the message source. It should be noted that the input key in step 2 can be a key input from the outside, which is different from the key generated in step 3. For the convenience of distinction, the input key used in the Zu Chongzhi algorithm is called the initial key, and the key generated in the Zu Chongzhi algorithm is called the result key or target key. The target key can be in the form of a key stream. In addition, in the Zu Chongzhi algorithm, the confidentiality algorithm or the integrity algorithm can be executed according to requirements. Since the initial vector generation methods corresponding to the confidentiality algorithm and the integrity algorithm are different, the corresponding initial vector generation method can be determined according to the algorithm that needs to be executed.

[0024] Based on the above analysis, in the system provided by the embodiments of the present disclosure, for the same algorithms among different versions of the Zu Chongzhi algorithm, the same functional modules can be reused for implementation, thereby reducing the deployment cost. For example, for the same confidentiality algorithm, when implementing different versions of the Zu Chongzhi algorithm, the same confidentiality algorithm module can be reused to encrypt the plaintext based on the confidentiality algorithm.

[0025] For different algorithms among different versions of the Zu Chongzhi algorithm, they can be implemented in various ways. For example, for different integrity algorithms, they can be implemented through separate functional modules respectively, and then each functional module can be encapsulated into one integrity algorithm module. When determining the version of the Zu Chongzhi algorithm that needs to be implemented, the corresponding functional module can be called for implementation. It can also be to design the same architecture and execute different integrity algorithms through different control methods.

[0026] In this system, the deployment cost can be reduced by reusing the same functional modules. Additionally, by implementing multiple different versions of the Zu Chongzhi algorithm, the flexibility and adaptability of the implementation of the Zu Chongzhi algorithm can be improved. Specifically, this system can be applied to the chip structure. Deploying this system in the chip can also reduce the chip area overhead and deployment cost by reusing the same functional modules. This system can also be applied in software. Deploying this system in software can also reduce the development cost and deployment cost by reusing the same functional modules.

[0027] The following details a system provided by an embodiment of the present disclosure for implementing multiple versions of the Zu Chongzhi algorithm. As Figure 1 shown, Figure 1 schematically shows a structural diagram of a system for implementing multiple versions of the Zu Chongzhi algorithm according to an embodiment of the present disclosure. The system for implementing multiple versions of the Zu Chongzhi algorithm may include: an initial vector generation module, a loading module, and a key generation module.

[0028] The initial vector generation module is configured to: determine the corresponding initial vector generation method according to the version selection signal; generate a target initial vector based on the determined initial vector generation method. The version selection signal can be used to represent a target version to be implemented among multiple preset Zu Chongzhi algorithm versions. Between different preset Zu Chongzhi algorithm versions, the key generation method can be the same.

[0029] The loading module is configured to: determine a target loading value according to the generated target initial vector and based on the loading method corresponding to the version selection signal. The key generation module is configured to: generate a target key based on the determined target loading value and based on the key generation method.

[0030] In the embodiment of this system, during the process of implementing different versions of the Zu Chongzhi algorithm, the key generation module can be reused to generate keys, which can reduce the deployment cost.

[0031] Moreover, the embodiment of this system can implement multiple different versions of the Zu Chongzhi algorithm, which can improve the compatibility of the system with the Zu Chongzhi algorithm versions and enhance the flexibility and adaptability of the implementation of the Zu Chongzhi algorithm.

[0032] The embodiment of this system does not limit the specific system form. The above system can be a hardware system or a software system; it can be deployed on a chip or implemented through a program; the module form in the system can specifically be a hardware structure or a software module. The embodiment of this system can specifically be applied to the chip structure. Deploying the embodiment of this system in the chip can also reduce the chip area overhead and hardware deployment cost by reusing the same functional modules (or hardware structures). The embodiment of this system can also be applied in software to reduce the software development cost and deployment cost by reusing the same functional modules.

[0033] It can be understood that for multiple existing versions of the Zu Chongzhi algorithm or new versions of the Zu Chongzhi algorithm to be developed in the future, when the key generation method remains unchanged, the embodiments of this system can be adopted to reduce the deployment cost by reusing the key generation module.

[0034] In the embodiments of this system, the target version can be any one of multiple preset Zu Chongzhi algorithm versions. For the convenience of description, any one of the multiple preset Zu Chongzhi algorithm versions that needs to be implemented currently is called the target version. Each time the embodiments of this system can implement one preset Zu Chongzhi algorithm version.

[0035] In an alternative embodiment, the above system may further include a confidentiality algorithm module and an integrity algorithm module. The confidentiality algorithm module and the integrity algorithm module can perform corresponding operations based on the received target key (the key generated based on the target version).

[0036] Among them, the confidentiality algorithm module can be used to: encrypt the target plaintext based on the confidentiality algorithm to obtain the target ciphertext under the target version. The integrity algorithm module can be used to: generate the target integrity tag under the target version for the target plaintext based on the integrity algorithm corresponding to the version selection signal.

[0037] Optionally, since the confidentiality algorithm module and the integrity algorithm module can correspond to different initial vector generation methods and different loading methods, the corresponding initial vector generation method and loading method can be determined according to the algorithm module that needs to be executed.

[0038] Optionally, the initial vector generation module can be used to: determine the corresponding initial vector generation method according to the version selection signal and the module selection signal; generate a target initial vector based on the determined initial vector generation method. The module selection signal can be used to indicate whether the confidentiality algorithm module needs to be executed and whether the integrity algorithm module needs to be executed. Among different preset Zu Chongzhi algorithm versions, the confidentiality algorithm can be the same. The loading module can be used to: determine the corresponding loading method according to the version selection signal and the module selection signal; determine the target loading value based on the generated target initial vector according to the determined loading method. The confidentiality algorithm module can be used to: encrypt the target plaintext based on the confidentiality algorithm to obtain the target ciphertext in the target version when it is determined according to the module selection signal that the confidentiality algorithm module needs to be executed. The integrity algorithm module can be used to: generate the target integrity tag in the target version for the target plaintext based on the integrity algorithm corresponding to the version selection signal when it is determined according to the module selection signal that the integrity algorithm module needs to be executed. In the embodiment of this system, during the process of implementing different versions of the Zu Chongzhi algorithm, the confidentiality algorithm module can be reused to encrypt the plaintext, which can reduce the deployment cost. It should be noted that the module selection signal can be used to indicate that both the confidentiality algorithm module and the integrity algorithm module need to be executed.

[0039] Since the processes of the Zu Chongzhi algorithm for each version are public, in the embodiment of this system, the specific method steps in each version of the Zu Chongzhi algorithm can refer to the public Zu Chongzhi algorithm process. Different versions of the Zu Chongzhi algorithm can correspond to different integrity algorithms. Therefore, the corresponding integrity algorithm can be further determined according to the version selection signal when the target version is determined.

[0040] Optionally, the multiple preset Zu Chongzhi algorithm versions can include: the ZUC-256 version and the ZUC-128 version. This embodiment can improve the compatibility of the system with the Zu Chongzhi algorithm versions by specifying specific Zu Chongzhi algorithm versions, and improve the flexibility and adaptability of the implementation of the Zu Chongzhi algorithm.

[0041] The following will explain each aspect in the embodiment of this system in detail.

[0042] I. Control module.

[0043] In an optional embodiment, the above system embodiment may further include a control module, which can be used to receive external input signals and control the operations of each module in the system to implement multiple versions of the Zu Chongzhi algorithm. Specifically, the control module can be used to transmit the external input signals to the required modules.

[0044] Optionally, the above system may further include a control module for transmitting signals, such as version selection signals and module selection signals. In this embodiment, by deploying the control module, the transmission of the version selection signal and the module selection signal can be controlled, improving the controllability of signal transmission.

[0045] As Figure 2 shown, Figure 2 schematically shows a structural diagram of another system for implementing the multi-version Zu Chongzhi algorithm according to an embodiment of the present disclosure. The control module can be connected to each of the other modules.

[0046] II. Initial vector generation module.

[0047] Optionally, the initial vector generation module can be used to generate an initial vector. The generated initial vector can be provided to the loading module for loading to obtain a loaded value, and thus the loaded value can be provided to the key generation module for generating a target key. The specific way to generate the initial vector can be the initial vector generation method disclosed in the Zu Chongzhi algorithm.

[0048] Different versions of the Zu Chongzhi algorithm can correspond to different initial vector generation methods. In any version of the Zu Chongzhi algorithm, the initial vector generation method used when implementing the confidentiality algorithm can be different from the initial vector generation method used when implementing the integrity algorithm. For example, for the ZUC-128 version of the Zu Chongzhi algorithm, the confidentiality algorithm used is the EEA3 algorithm, and the integrity algorithm used is the EIA3 algorithm. There are differences between the initial vector generation methods corresponding to the EEA3 algorithm and the EIA3 algorithm.

[0049] Therefore, optionally, the initial vector generation module can be used to determine the corresponding initial vector generation method according to the version selection signal and the module selection signal. Then, the target initial vector can be generated based on the determined initial vector generation method.

[0050] Optionally, the initial vector generation module can be used to receive input signals from outside the system. Specifically, it can receive signals such as a counter, a bearer layer identifier, and a transmission direction identifier for generating an initial vector. Specifically, it can be based on the control signal of the control module and generate an initial vector according to the determined initial vector generation method.

[0051] In a specific example, the initial vector generation module may include multiple sub-modules, which are respectively used to implement different initial vector generation methods. The initial vector generation module can select the corresponding sub-module according to the version selection signal and the module selection signal to execute the initial vector generation step, thereby determining the corresponding initial vector generation method and generating the target initial vector based on the determined initial vector generation method. Among them, one or more sub-modules can be selected to generate the initial vector.

[0052] Regarding the target initial vector generated by the initial vector generation module, in the embodiments of this system, the loading module needs to use the generated target initial vector. Therefore, the initial vector generation module can be used to transmit the target initial vector to the loading module. The embodiments of this system do not limit the specific way of transmitting the target initial vector to the loading module.

[0053] III. Loading module.

[0054] Optionally, the loading module can be used to determine a loading value, so that the loading value can be provided to the key generation module for generating a target key. The specific way to determine the loading value can be the loading method disclosed in the Zu Chongzhi algorithm. Different versions of the Zu Chongzhi algorithm can correspond to different loading methods. Optionally, the loading module can be used to determine the loading method corresponding to the target version according to the version selection signal.

[0055] In a specific example, the loading module can include multiple sub-modules, which are respectively used to implement different loading methods. The loading module can select the sub-module corresponding to the target version according to the version selection signal to execute the loading step, so that based on the loading method corresponding to the target version, the loading value can be determined according to the target initial vector.

[0056] Furthermore, in any version of the Zu Chongzhi algorithm, the input of the loading method used when implementing the confidentiality algorithm may be different from the input of the loading method used when implementing the integrity algorithm. For the integrity algorithm with variable integrity tag length, the input of the loading methods corresponding to different tag lengths may also be different.

[0057] Therefore, for the loading method corresponding to any preset version of the Zu Chongzhi algorithm, it can be further divided into the loading methods corresponding to the confidentiality algorithm and the integrity algorithm respectively, and the loading method corresponding to the integrity algorithm can also be further divided into the loading methods corresponding to different tag lengths respectively.

[0058] In a specific example, the loading module may include two first-level sub-modules, which are respectively used to implement: 1) the loading method corresponding to the ZUC-128 version; 2) the loading method corresponding to the ZUC-256 version. Among them, a single first-level sub-module may include two second-level sub-modules, namely the loading method corresponding to the confidentiality algorithm module and the loading method corresponding to the integrity algorithm module. In the second-level sub-module corresponding to the integrity algorithm module, there may be multiple third-level sub-modules, which are respectively used to implement the loading methods corresponding to the integrity algorithms with different integrity tag lengths. Of course, for the integrity algorithm with a fixed integrity tag length, the third-level sub-module may not be included. It can be understood that, according to the version selection signal, the module selection signal, and the tag length selection signal, the corresponding sub-module can be determined to execute the loading method. Among them, one or more sub-modules can be selected to execute the loading method.

[0059] Regarding the target loading value determined by the loading module, in the embodiment of the present system, the key generation module needs to use the determined target loading value. Therefore, the loading module can be used to transmit the target loading value to the key generation module. The embodiment of the present system does not limit the specific way of transmitting the target loading value to the key generation module.

[0060] IV. Key generation module.

[0061] Optionally, the key generation module can be used to: generate a target key based on the key generation method according to the target loading value. The key generation methods may be the same among different preset ZUC algorithm versions. Therefore, the key generation module can specifically be used to implement the key generation method in the publicly disclosed ZUC algorithm. By reusing the key generation module in the embodiment of the present system to execute the implementation processes of different versions of the ZUC algorithm, the system deployment cost can be reduced. In the ZUC algorithm, according to different requirements, the required key lengths may be different.

[0062] Optionally, the key generation module can be used to generate a key stream, and specifically can be used to generate a target key based on the key generation method according to the target loading value and the required key length. Among them, specifically, the target key length generated by the key generation module can be controlled by the control module, and the control module can determine the required key length according to multiple signals such as the version selection signal and the module selection signal, so as to control the key generation module to generate a target key with a corresponding length.

[0063] Regarding the target key generated by the key generation module, in the embodiments of this system, the confidentiality algorithm module and the integrity algorithm module need to use the generated target key to perform corresponding operations. Therefore, the key generation module can be used to transmit the target key to the algorithm modules that need to execute, specifically, according to the module selection signal, transmit the target key to the algorithm modules that need to execute. The embodiments of this system do not limit the specific manner of transmitting the target key.

[0064] In an optional embodiment, the key generation module can generate one target key at a time, or can generate multiple different target keys at a time. Among them, for the embodiments where a single algorithm module in the confidentiality algorithm module and the integrity algorithm module needs to execute, the key generation module can generate one target key at a time, that is, the target key required by the single algorithm module that needs to execute.

[0065] For the embodiments where both the confidentiality algorithm module and the integrity algorithm module need to execute, the key generation module can generate one target key at a time, and can generate different target keys 2 times successively, respectively for the confidentiality algorithm module and the integrity algorithm module to use. The key generation module can also generate two different target keys at a time, respectively for the confidentiality algorithm module and the integrity algorithm module to use.

[0066] The embodiments of this system do not limit the implementation manner of the key generation module generating multiple different target keys at a time. Optionally, multiple sub-modules can be deployed in the key generation module, and a single sub-module can be used to generate the target key, so that multiple different target keys can be generated at a time by inputting different information for different sub-modules. For example, for the key generation module in the form of software, different target keys can be directly generated using different threads or processes for different input information. The key generation module can also be in the form of a dual-core, which can include 2 key generation circuits.

[0067] Optionally, 2 sub-modules can be deployed in the key generation module, which can correspond to the confidentiality algorithm module and the integrity algorithm module respectively, that is, the key generation module can include: a first sub-module for generating the target key corresponding to the confidentiality algorithm module, and a second sub-module for generating the target key corresponding to the integrity algorithm module. Of course, binding can also not be performed.

[0068] For ease of understanding, for embodiments that need to be executed for both the confidentiality algorithm module and the integrity algorithm module, optionally, the initial vector generation module can be used to: when it is determined according to the module selection signal that the confidentiality algorithm module and the integrity algorithm module need to be executed, determine the corresponding confidentiality algorithm initial vector generation method and the corresponding integrity algorithm initial vector generation method according to the version selection signal; generate a confidentiality target initial vector based on the determined confidentiality algorithm initial vector generation method; generate an integrity target initial vector based on the determined integrity algorithm initial vector generation method.

[0069] The loading module can be used to: when it is determined according to the module selection signal that the confidentiality algorithm module and the integrity algorithm module need to be executed, determine the corresponding confidentiality algorithm loading method and the corresponding integrity algorithm loading method according to the version selection signal; determine the confidentiality target loading value based on the determined confidentiality algorithm loading method according to the generated confidentiality target initial vector; determine the integrity target loading value based on the determined integrity algorithm loading method according to the generated integrity target initial vector.

[0070] The key generation module can be used to: generate a confidentiality target key based on the key generation method according to the determined confidentiality target loading value; generate an integrity target key based on the key generation method according to the determined integrity target loading value.

[0071] The confidentiality algorithm module can be used to: when it is determined according to the module selection signal that the confidentiality algorithm module needs to be executed, encrypt the target plaintext based on the confidentiality algorithm using the generated confidentiality target key to obtain the target ciphertext under the target version.

[0072] The integrity algorithm module can be used to: when it is determined according to the module selection signal that the integrity algorithm module needs to be executed, generate a target integrity tag under the target version for the target plaintext using the generated integrity target key based on the integrity algorithm corresponding to the version selection signal.

[0073] In this embodiment, the initial vector generation module can generate 2 initial vectors, the loading module correspondingly determines 2 loading values, and the key generation module correspondingly generates 2 target keys, so that the confidentiality algorithm module and the integrity algorithm module can respectively use the generated 2 target keys to execute the corresponding steps, which can improve the execution efficiency of the confidentiality algorithm and the integrity algorithm.

[0074] This embodiment does not limit the execution order of the steps in each module. Optionally, the initial vector generation module can be used to generate the confidentiality initial vector and the integrity initial vector in parallel; the loading module can be used to determine the confidentiality target loading value and the integrity target loading value in parallel; the key generation module can be used to generate the confidentiality target key and the integrity target key in parallel. Accordingly, the confidentiality algorithm module and the integrity algorithm module can be executed in parallel.

[0075] V. Confidentiality algorithm module.

[0076] Optionally, the confidentiality algorithm module can be used to: when it is determined that the confidentiality algorithm module needs to execute according to the module selection signal, encrypt the target plaintext based on the confidentiality algorithm to obtain the target ciphertext under the target version. Specifically, the received target key can be used, such as the confidentiality target key in the above embodiment.

[0077] This embodiment does not limit the specific "situation where it is determined that the confidentiality algorithm module needs to execute according to the module selection signal". Optionally, it can be the situation of receiving the target key sent by the key generation module, or the situation determined by being triggered by the control module, or the confidentiality algorithm module itself determines according to the module selection signal. Between different preset versions of the ZUC algorithm, the confidentiality algorithm can be the same. Therefore, the confidentiality algorithm module can specifically be used to implement the confidentiality algorithm in the publicly disclosed ZUC algorithm. By reusing the confidentiality algorithm module in this system embodiment, the implementation process of different versions of the ZUC algorithm is executed, thereby reducing the system deployment cost.

[0078] Corresponding to the confidentiality algorithm, the length of the generated target key is the same as the length of the plaintext to be encrypted. The specific confidentiality algorithm can be to perform an exclusive OR operation on the target key and the plaintext, specifically, perform an exclusive OR operation bit by bit to obtain the corresponding ciphertext, that is, the target ciphertext under the target version.

[0079] Therefore, optionally, the confidentiality algorithm module can be used to: when it is determined that the confidentiality algorithm module needs to execute according to the module selection signal, perform an exclusive OR operation on the target plaintext and the received target key based on the confidentiality algorithm to obtain the target ciphertext under the target version. This embodiment can reduce the deployment cost by reusing the confidentiality algorithm module. This system embodiment does not limit the specific way of performing the exclusive OR operation.

[0080] VI. Integrity algorithm module.

[0081] Optionally, the integrity algorithm module can be used to generate an integrity tag for the plaintext, that is, a message authentication code, which can be used to verify the integrity of the plaintext at least. Specifically, the received target key can be used, such as the integrity target key in the above embodiment.

[0082] Different versions of the Zu Chongzhi algorithm can correspond to different integrity algorithms. In some versions of the Zu Chongzhi algorithm, further settings are made for the integrity algorithm. Specifically, according to actual requirements, the length of the generated integrity tag can be flexibly set to meet the requirements for the length of the integrity tag in different business needs.

[0083] Therefore, the integrity algorithm module can further select a target tag length from multiple preset lengths according to the external tag length selection signal, and generate a target integrity tag with the length of the target tag length.

[0084] In an optional embodiment, the integrity algorithm module is used to: when it is determined that the integrity algorithm module needs to execute according to the module selection signal, determine the corresponding integrity algorithm based on the tag length selection signal and the version selection signal; generate a target integrity tag in the target version for the target plaintext based on the determined integrity algorithm; the tag length selection signal is used to determine a target tag length among multiple preset lengths; the length of the target integrity tag is the target tag length. Taking the ZUC-256 version as an example, the integrity algorithm NIA6 algorithm therein can support different integrity tag lengths. This embodiment can improve the flexibility and adaptability of the integrity tag by setting different integrity tag lengths. This embodiment does not limit the specific form of the tag length selection signal.

[0085] This embodiment does not limit the specific manner of implementing the integrity algorithm.

[0086] The following takes the two versions of ZUC-128 and ZUC-256 as examples for explanation. The integrity algorithm can be the EIA3 algorithm or the NIA6 algorithm, and the corresponding process pseudocode can refer to the public content of the Zu Chongzhi algorithm.

[0087] (1) The architecture of the integrity algorithm module.

[0088] This system embodiment does not limit the specific architecture of the integrity algorithm module.

[0089] In an optional embodiment, the integrity algorithm module may include: a key stream register, multiple selection modules, a comprehensive exclusive OR module, and a result register. The multiple selection modules may include an initial selection module and may also include a compatibility selection module. The initial selection module can be used to determine the initial value of the integrity tag. The compatibility selection module can be used to determine whether to perform an exclusive OR operation on the corresponding key content and the current integrity tag according to the plaintext bit value. Optionally, the comprehensive exclusive OR module can be used to perform an exclusive OR operation on the output of the initial selection module, the outputs of the compatibility selection modules 0 to 31, and the output of the result register. Optionally, the result register can be used to output the currently stored value to the comprehensive exclusive OR module.

[0090] In an alternative embodiment, the integrity algorithm module may include: a key stream register, one initial selection module, compatibility selection modules 0 to 31, a comprehensive exclusive-OR module, and a result register. The key stream register includes 32 * 9 bits, specifically including Z[0] to Z

[287] ; the 128-bit output of Z[0] to Z

[127] in the key stream register is connected to the initial selection module; the 128-bit output of Z[i + 128] to Z[i + 255] in the key stream register is connected to the compatibility selection module i; i = 0, 1, 2, …, 31; the outputs of the initial selection module, the outputs of the compatibility selection modules 0 to 31, and the output of the result register are connected to the comprehensive exclusive-OR module; the output of the comprehensive exclusive-OR module is connected to the result register.

[0091] In this embodiment, by setting a specific architecture, multiple different integrity algorithms can be made compatible, enabling multiple different integrity algorithms to be implemented based on the same architecture, thereby reducing the deployment cost.

[0092] For ease of understanding, as Figure 3 shown, Figure 3 schematically shows a schematic diagram of the architecture of an integrity algorithm module according to an embodiment of the present disclosure. Figure 3 The integrity algorithm module in [reference] includes a key stream register, one initial selection module, compatibility selection modules 0 to 31, a comprehensive exclusive-OR module, and a result register.

[0093] For ease of understanding, as Figure 4 shown, Figure 4 schematically shows a schematic diagram of the architecture of the key stream register according to an embodiment of the present disclosure.

[0094] Figure 4 The key stream register in [reference] may include a total of 288 bits from Z[0] to Z

[287] . Figure 4 [Reference] shows that some bit outputs in the key stream register are connected to the initial selection module and the compatibility selection module. Figure 4 The compatibility selection modules in [reference] are only for illustrative purposes, and the connection situations of other compatibility selection modules can be determined by simple reasoning.

[0095] (2) Implementation of the integrity algorithm under the ZUC-128 version.

[0096] For the EIA3 algorithm: Considering the length of the plaintext information, the length of the plaintext can be set to an integer multiple of 32 bits. Correspondingly, for a plaintext message of 32 * p bits in length, it can be represented as m[0] to m[32 * p - 1]. The length of the correspondingly generated integrity tag is 32 bits. p ≥ 1. The corresponding process pseudocode is as follows.

[0097] 1) Run the ZUC-128 stream cipher to generate a key stream of length p + 2 bytes. The binary sequence of this key stream can be represented as k[0]~k[32*(p + 2)-1], where k[0] is the most significant bit of the first key stream word and k

[31] is the least significant bit of the first key stream word.

[0098] 2) Initialize Tag = 0

[0099] 3) for i = 0 to 32*p - 1 do {Let W[i] = (k[i],…,k[i + 31]); If m[i] is 1, then Tag = Tag ⊕ W[i]; i = i + 1}

[0100] 4) W[32*p] = (k[32*p],…,k[32*(p + 1)-1]); Tag = Tag ⊕ W[32*p]

[0101] 5) W[32*(p + 1)] = (k[32*(p + 1)],…,k[32*(p + 2)-1]); Tag = Tag ⊕ W[32*(p + 1)]

[0102] 6) Return Tag. Here, = is the assignment operation and ⊕ is the bitwise exclusive OR operation.

[0103] Optionally, the integrity algorithm module is used to: when it is determined according to the module selection signal that the integrity algorithm module needs to execute, perform the following operations:

[0104] (1) When the target version is the ZUC-128 version and the length of the target plaintext is 32*p bits, the length of the target key is 32*(p + 2) bits, p ≥ 1; the target key is specifically k[0]~k[32*(p + 2)-1]; the target plaintext is specifically m[0]~m[32*p - 1]; the initial value stored in the result register is 0;

[0105] (2) Loop and execute the following steps until the end of the p-th loop: Input k[32*(j - 1)] to k[32*(j + 4) - 1] in the target key into Z

[128] to Z

[287] of the key stream register, where j is the current loop count; Based on the tag length selection signal and the version selection signal, control the initial selection module to output 0 to the comprehensive XOR module; Based on the tag length selection signal and the version selection signal, when the plaintext m[32*(j - 1) + i] has a value of 1, control the compatibility selection module i to output the 32-bit bit value in Z[i + 128] to Z[i + 159] to the comprehensive XOR module; Based on the tag length selection signal and the version selection signal, when the plaintext m[32*(j - 1) + i] has a value of 0, control the compatibility selection module i to output 0 to the comprehensive XOR module; i = 0, 1, 2, …, 31; Control the result register to output the currently stored value to the comprehensive XOR module; Control the comprehensive XOR module to perform an XOR operation on the outputs of the initial selection module, compatibility selection modules 0 to 31, and the result register, and output the result of the XOR operation to the result register for storage;

[0106] (3) When the p-th loop execution ends, input k[32*p] to k[32*(p + 2) - 1] in the target key into Z

[128] to Z

[191] of the key stream register; Based on the tag length selection signal and the version selection signal, control the compatibility selection module 0 to output the 32-bit bit value in Z

[128] to Z

[159] to the comprehensive XOR module, and control the compatibility selection module 31 to output the 32-bit bit value in Z

[160] to Z

[191] to the comprehensive XOR module; Based on the tag length selection signal and the version selection signal, control the initial selection module and compatibility selection modules 1 to 30 to output 0 to the comprehensive XOR module; Control the result register to output the currently stored value to the comprehensive XOR module; Control the comprehensive XOR module to perform an XOR operation on the outputs of the initial selection module, compatibility selection modules 0 to 31, and the result register, and output the result of the XOR operation to the result register to obtain the target integrity tag under the target version.

[0107] This embodiment can perform specific operations through the integrity algorithm module. Implementing the integrity algorithm under the ZUC-128 version based on the above architecture can reduce the deployment cost.

[0108] The above operations (1)-(3) performed by the integrity algorithm module are explained below.

[0109] The above operation (1): Corresponds to steps 1 and 2 in the above process pseudocode. The initial value 0 stored in the result register, which is the operation of initializing Tag to 0. Specifically, the value stored in the result register can be initialized to 0.

[0110] The above operation (2): corresponds to step 3 in the above process pseudocode. In each loop of operation (2), 32 operations can be executed through the compatibility selection module 0 to 31, so that 32 loop operations in step 3 of the process pseudocode can be executed.

[0111] For the convenience of explanation, the specific loop in operation (2) is explained below.

[0112] In the first loop, k[0] to k[32*5 - 1] in the target key can be input into Z

[128] to Z

[287] in the key stream register.

[0113] Correspondingly, the input of compatibility selection module 0 is the 128-bit bit value in Z

[128] to Z

[255] , and the current input is k[0] to k[32*4 - 1]. Combining W[i] = (k[i], …, k[i + 31]) in the above process pseudocode, that is, W[0] is the 32-bit bit value in k[0] to k

[31] . Therefore, when the compatibility selection module 0 determines that the current target version is the ZUC-128 version based on the tag length selection signal and the version selection signal, it can take the first 32-bit bit values in the current input Z

[128] to Z

[255] , that is, the 32-bit bit values in Z

[128] to Z

[159] , which are the 32-bit bit values in k[0] to k

[31] (equivalent to W[0]). Then, in combination with the bit value of the corresponding bit m[0] of the plaintext, it can be determined whether to output 0 (which does not affect the subsequent XOR operation) or the 32-bit bit value in k[0] to k

[31] (in combination with the subsequent comprehensive XOR module, it can be equivalent to if m[0] is 1, then Tag = Tag ⊕ W[0]).

[0114] Similarly, when the compatibility selection module 1 determines that the current target version is the ZUC-128 version based on the tag length selection signal and the version selection signal, it can take the first 32-bit bit values in the current input Z

[129] to Z

[256] , that is, the 32-bit bit values in Z

[129] to Z

[160] , which are the 32-bit bit values in k[1] to k

[32] (equivalent to W[1]). Then, in combination with the bit value of the corresponding bit m[1] of the plaintext, it can be determined whether to output 0 (which does not affect the subsequent XOR operation) or the 32-bit bit value in k[1] to k

[32] (in combination with the subsequent comprehensive XOR module, it can be equivalent to if m[1] is 1, then Tag = Tag ⊕ W[1]).

[0115] And so on. When the compatibility selection module 31 determines that the current target version is the ZUC-128 version based on the tag length selection signal and the version selection signal, it can take the bit values of the first 32 bits Z

[159] ~Z

[190] from the current input Z

[159] ~Z

[286] , that is, the 32-bit bit values in k

[31] ~k

[62] (equivalent to W

[31] ). Then, in combination with the bit value of the corresponding bit m

[31] of the plaintext, it can be determined whether to output 0 (which does not affect the subsequent XOR operation) or the 32-bit bit values in k

[31] ~k

[62] (in combination with the subsequent comprehensive XOR module, it can be equivalent to if m

[31] is 1, then Tag = Tag⊕W

[31] ).

[0116] After that, through the comprehensive XOR module, the initial value 0 output from the result register (equivalent to the initial value 0 of Tag), the 0 output from the initial selection module (which does not affect the XOR operation of the comprehensive XOR module), and the outputs of the compatibility selection modules 0~31 can be comprehensively XORed, and the XOR operation result can be stored in the result register.

[0117] The comprehensive XOR module can be used to perform XOR operations on the output of the initial selection module, the outputs of the compatibility selection modules 0~31, and the output of the result register.

[0118] Therefore, in the first loop of the above operation (2), the loop from i = 0 to i = 31 in step 3 of the process pseudocode can be executed, which is equivalent to executing 32 loops in step 3 of the above process pseudocode.

[0119] Similarly, in the second loop, k

[32] ~k[32*6 - 1] in the target key can be input into Z

[128] ~Z

[287] of the key stream register. The steps in the loop can refer to the above explanation. After that, through the comprehensive XOR module, the XOR operation result of the first loop stored in the result register, the 0 output from the initial selection module (which does not affect the XOR operation of the comprehensive XOR module), and the outputs of the compatibility selection modules 0~31 can be comprehensively XORed, and the XOR operation result can be stored in the result register.

[0120] Subsequent loops can continue to be executed with reference to the previous text.

[0121] Similarly, in the p-th loop (the last loop), the k[32*(p - 1)] to k[32*(p + 4)-1] in the target key can be input into Z

[128] to Z

[287] of the key stream register. Correspondingly, the input of the compatibility selection module 0 is the 128-bit value among Z

[128] to Z

[255] , and the current input is k[32*(p - 1)] to k[32*(p + 4)-1]. It should be noted that the length of the target key is 32*(p + 2) bits. For the bits exceeding the length of the target key, they can be directly set to 0 for supplementation. For example, the values of k[32*(p + 2)] to k[32*(p + 4)-1] in the above target key can all be set to 0.

[0122] The steps in the loop can be referred to the above explanation. In the p-th loop, the compatibility selection module 31 performs related operations on the last plaintext bit m[32*p - 1], that is, it completes the last loop of step 3 in the above process pseudocode, and completes the related operations based on all plaintext bit values.

[0123] It can be understood that through the loop in the above operation (2), step 3 in the above process pseudocode can be implemented.

[0124] The above operation (3): corresponds to steps 4 to 6 in the above process pseudocode.

[0125] When the p-th loop execution ends, the k[32*p] to k[32*(p + 2)-1] in the target key can be input into Z

[128] to Z

[191] of the key stream register; based on the tag length selection signal and the version selection signal, control the compatibility selection module 0 to output the 32-bit value among Z

[128] to Z

[159] to the comprehensive exclusive OR module, and control the compatibility selection module 31 to output the 32-bit value among Z

[160] to Z

[191] to the comprehensive exclusive OR module.

[0126] Among them, W[32*p] = (k[32*p],…,k[32*(p + 1)-1]). Select the 32-bit value among Z

[128] to Z

[159] from the compatibility selection module 0 (the current input bit values of Z

[128] to Z

[255] ), that is, k[32*p] to k[32*(p + 1)-1], which is equivalent to W[32*p], and can be directly output to the comprehensive exclusive OR module to participate in the subsequent exclusive OR operation, so that it can be equivalent to step 4 in the above process pseudocode.

[0127] W[32*(p + 1)] = (k[32*(p + 1)], …, k[32*(p + 2) - 1]), which is the 32-bit bit values from Z

[160] to Z

[191] among the (current input bit values of Z

[159] to Z

[286] ) in the compatibility selection module 31, that is, k[32*(p + 1)] to k[32*(p + 2) - 1], equivalent to W[32*(p + 1)], can be directly output to the comprehensive XOR module to participate in the subsequent XOR operation, thus being equivalent to step 5 in the above process pseudocode.

[0128] Based on the tag length selection signal and the version selection signal, control the initial selection module and compatibility selection modules 1 to 30 to output 0 to the comprehensive XOR module (without affecting the subsequent XOR operation); control the result register to output the currently stored value to the comprehensive XOR module (the result of the XOR operation in the p-th loop); control the comprehensive XOR module to perform an XOR operation on the outputs of the initial selection module, compatibility selection modules 0 to 31, and the result register, and output the result of the XOR operation to the result register to obtain the target integrity tag in the ZUC-128 version, thus being equivalent to step 6 in the above process pseudocode.

[0129] Therefore, the above operation (3) can implement steps 4 to 6 in the above process pseudocode.

[0130] In the above embodiments, the integrity algorithm can be implemented by controlling the architecture in the above integrity algorithm module. It can be understood that for the integrity algorithm of the above ZUC-128 version, it can also be implemented by other control operations on the architecture in the above integrity algorithm module. The embodiments of this system are not limited to the above implementation method.

[0131] Specifically, the embodiments of this system do not limit the above control method. Optionally, for the above operation (3), the compatibility selection module 31 can be replaced with other compatibility selection modules (excluding compatibility selection module 0), as long as the input of the other compatibility selection modules used includes the 32-bit bit values from Z

[160] to Z

[191] .

[0132] Therefore, as long as the integrity algorithm can be implemented based on the above architecture, the embodiments of this system do not limit the specific control method, thereby reducing the deployment cost.

[0133] The embodiments of this system do not limit the specific way of controlling each module in the integrity algorithm module. Optionally, it can be controlled by control signals, specifically by the tag length selection signal and the version selection signal.

[0134] In an alternative embodiment, for each module in the integrity algorithm module, different control signals in different cases can be used for control. Specifically, the control signals in the corresponding cases can be selected through the tag length selection signal and the version selection signal in combination with a multiplexer.

[0135] Taking the compatibility selection module 0 as an example, based on the tag length selection signal and the version selection signal, the control signal in the case of the ZUC-128 version can be selected through a multiplexer, so that each operation in the above embodiment can be executed based on the control signal. This embodiment does not limit the control signal. Specifically, the control signal can be used to provide the plaintext bit value of the corresponding bit position, and can also be used to determine the bit width required to be output by the compatibility selection module 0, etc. This embodiment does not limit the deployment position of the multiplexer. Specifically, the multiplexer can be deployed in the compatibility selection module 0.

[0136] This system embodiment does not limit the specific implementation manner of the above loop operation. Optionally, the above loop operation can be controlled by a timing signal. Specifically, the loop operation can be executed once per clock cycle. Correspondingly, for the above key stream register, at the beginning of each clock cycle, the currently stored target key can be shifted left by 32 bits.

[0137] The above embodiment of the integrity algorithm is explained for the case where the plaintext bit length is an integer multiple of 32. Optionally, for the case where the plaintext bit length is not an integer multiple of 32, the plaintext bit length can be extended to an integer multiple of 32 by padding with 0s, so that the above embodiment can be executed.

[0138] (3) Under the ZUC-256 version, the integrity tag length is 32 bits, and the implementation of the corresponding integrity algorithm.

[0139] For the NIA6 algorithm: Considering the length of the plaintext information, the length of the plaintext can be set to an integer multiple of 32 bits. Correspondingly, for a plaintext message with a length of 32*p bits, it can be represented as m[0]~m[32*p - 1]. The generated integrity tag length is 32 bits. p≥1. The relevant process pseudocode is as follows.

[0140] 1) Run the ZUC-256 stream cipher to generate a key stream with a length of p + 2 bytes. The binary sequence of this key stream can be represented as k[0]~k[32·(p + 2)−1], where k[0] is the highest bit of the first key stream word, and k

[31] is the lowest bit of the first key stream word.

[0141] 2) Initialize Tag = (k[0],…,k

[31] )

[0142] 3) For i = 0 to 32*p - 1 do {Let W[i] = (k[i + 32], ···, k[i + 63]); If m[i] is 1, then Tag = Tag ⊕ W[i]; i = i + 1}

[0143] 4) W[32*p] = (k[32*(p + 1)], ···, k[32*(p + 2) - 1]); Tag = Tag ⊕ W[32*p]

[0144] 5) Return Tag. Where, = is the assignment operation, and ⊕ is the bitwise exclusive OR operation.

[0145] It can be understood that p, i, etc. that appear in the embodiments of the present disclosure can represent different meanings and different numerical values in different algorithm pseudocodes and embodiments. The specific meaning can be referred to the corresponding embodiment.

[0146] Optionally, the integrity algorithm module is used for: when it is determined that the integrity algorithm module needs to execute according to the module selection signal, perform the following operations:

[0147] (1) When the target version is the ZUC - 256 version, the target tag length is 32 bits, and the length of the target plaintext is 32*p bits, the length of the target key is 32*(p + 2) bits, p ≥ 1; the target key is specifically k[0] ~ k[32*(p + 2) - 1]; the target plaintext is specifically m[0] ~ m[32*p - 1]; the initial value stored in the result register is 0;

[0148] (2) Input k[0] ~ k[32*6 - 1] in the target key into Z

[96] ~ Z

[287] of the key stream register; Based on the tag length selection signal and the version selection signal, control the initial selection module to output 32 - bit values in Z

[96] ~ Z

[127] to the comprehensive exclusive OR module; Based on the tag length selection signal and the version selection signal, when the plaintext m[i] takes the value of 1, control the compatible selection module i to output 32 - bit values in Z[i + 128] ~ Z[i + 159] to the comprehensive exclusive OR module; Based on the tag length selection signal and the version selection signal, when the plaintext m[i] takes the value of 0, control the compatible selection module i to output 0 to the comprehensive exclusive OR module; Control the result register to output the currently stored value to the comprehensive exclusive OR module; Control the comprehensive exclusive OR module to perform an exclusive OR operation on the outputs of the initial selection module, the compatible selection modules 0 ~ 31, and the result register, and output the result of the exclusive OR operation to the result register for storage;

[0149] (3) When p ≥ 2, loop and execute the following steps until the end of the (p - 1)-th loop: Input k[32*(j + 1)] to k[32*(j + 6) - 1] in the target key into Z

[128] to Z

[287] in the key stream register, where j is the current loop count; Based on the tag length selection signal and the version selection signal, control the initial selection module to output 0 to the comprehensive XOR module; Based on the tag length selection signal and the version selection signal, when the plaintext m[32*j + i] has a value of 1, control the compatibility selection module i to output the 32-bit bit value in Z[i + 128] to Z[i + 159] to the comprehensive XOR module; Based on the tag length selection signal and the version selection signal, when the plaintext m[32*j + i] has a value of 0, control the compatibility selection module i to output 0 to the comprehensive XOR module; i = 0, 1, 2, …, 31; Control the result register to output the currently stored value to the comprehensive XOR module; Control the comprehensive XOR module to perform an XOR operation on the outputs of the initial selection module, compatibility selection modules 0 to 31, and the result register, and output the result of the XOR operation to the result register for storage;

[0150] (4) When the (p - 1)-th loop execution ends, input k[32*(p + 1)] to k[32*(p + 2) - 1] in the target key into Z

[128] to Z

[159] in the key stream register; Based on the tag length selection signal and the version selection signal, control the compatibility selection module 0 to output the 32-bit bit value in Z

[128] to Z

[159] to the comprehensive XOR module; Based on the tag length selection signal and the version selection signal, control the initial selection module and compatibility selection modules 1 to 31 to output 0 to the comprehensive XOR module; Control the result register to output the currently stored value to the comprehensive XOR module; Control the comprehensive XOR module to perform an XOR operation on the outputs of the initial selection module, compatibility selection modules 0 to 31, and the result register, and output the result of the XOR operation to the result register to obtain the target integrity tag under the target version.

[0151] This embodiment can execute specific operations through the integrity algorithm module. Based on the above architecture, an integrity algorithm corresponding to an integrity tag length of 32 bits in the ZUC-256 version can be implemented, which can reduce the deployment cost.

[0152] The following will explain the above operations (1)-(4) performed by the integrity algorithm module respectively.

[0153] The above operation (1): corresponds to step 1 in the above process pseudocode. The initial value 0 stored in the result register may not affect the XOR operation in the comprehensive XOR module. The above operation (2): corresponds to the first 32 loops in steps 2 and 3 of the above process pseudocode. Among them, since k[0] to k[32*6 - 1] in the target key are input into Z

[96] to Z

[287] in the key stream register, and the input of the initial selection module is Z[0] to Z

[127] , it can be determined that the 32-bit bit values in Z

[96] to Z

[127] output by the initial selection module are exactly k[0] to k

[31] , that is, the Tag initialized in step 2 of the above process pseudocode. Thus, step 2 in the above process pseudocode can be implemented. Further, through compatibility selection modules 0 to 31, the outputs of W[0] to W

[31] can be respectively performed according to the corresponding plaintext bit values. For specific explanations, please refer to the previous embodiments.

[0154] When p is 1, the subsequent steps may not be executed, and the result of the XOR operation in the current comprehensive XOR module can be directly determined as the target integrity tag in the target version.

[0155] The above operation (3): can correspond to the subsequent loops in step 3 of the above process pseudocode. Each loop in operation (3) can execute 32 operations through compatibility selection modules 0 to 31, which is equivalent to executing 32 loop operations in step 3 of the above process pseudocode. For specific explanations, please refer to the previous embodiments. It can be understood that through the above operation (2) and the above operation (3), step 3 in the above process pseudocode can be implemented.

[0156] The above operation (4): can correspond to steps 4 and 5 in the above process pseudocode. When the (p - 1)-th loop execution ends, the k[32*(p + 1)] to k[32*(p + 2)-1] in the target key can be input into Z

[128] to Z

[159] of the key stream register; based on the tag length selection signal and the version selection signal, control the compatibility selection module 0 to output 32-bit bit values in Z

[128] to Z

[159] to the comprehensive exclusive-OR module. Step 4 in the above process pseudocode is W[32*p] = (k[32*(p + 1)],···,k[32*(p + 2)-1]); Tag = Tag⊕W[32*p]. It can be seen that the 32-bit bit values in Z

[128] to Z

[159] output by the compatibility selection module 0, which are k[32*(p + 1)] to k[32*(p + 2)-1] in the target key, are equivalent to W[32*p]. Based on the tag length selection signal and the version selection signal, control the initial selection module and the compatibility selection modules 1 to 31 to output 0 to the comprehensive exclusive-OR module, which has no impact on subsequent exclusive-OR operations. Control the result register to output the currently stored value to the comprehensive exclusive-OR module, so that the exclusive-OR operation result obtained in the above operation (3) can be output. Control the comprehensive exclusive-OR module to perform exclusive-OR operations on the outputs of the initial selection module, the compatibility selection modules 0 to 31, and the result register, so as to achieve Tag = Tag⊕W[32*p]. Output the result of the exclusive-OR operation to the result register to obtain the target integrity tag in the target version, which is equivalent to returning Tag. Therefore, the above operation (4) can implement steps 4 and 5 in the above process pseudocode.

[0157] In the above embodiment, the integrity algorithm can be implemented by controlling the architecture in the above integrity algorithm module. It can be understood that for the integrity algorithm corresponding to the integrity tag length of 32 bits in the above ZUC-256 version, it can also be implemented by other control operations on the architecture in the above integrity algorithm module. The system embodiment of the present invention is not limited to the above implementation manner.

[0158] Specifically, the system embodiment of the present invention does not limit the above control manner. Optionally, for the above operation (3), k[0] to k

[31] in the target key can be input into the result register as the initial value, which is equivalent to "initializing Tag = (k[0],…,k

[31] )" to replace the initial selection module. The initial selection module can delete or output 0 to the comprehensive exclusive-OR module, while the result register can output the currently stored initial value to the comprehensive exclusive-OR module. Therefore, as long as the integrity algorithm can be implemented based on the above architecture, the system embodiment of the present invention does not limit the specific control manner, thereby reducing the deployment cost.

[0159] (4) Under the ZUC-256 version, the integrity tag length is 64 bits, and the implementation of the corresponding integrity algorithm.

[0160] The specific pseudo-code process can refer to the public content of the Zu Chongzhi algorithm. Optionally, the integrity algorithm module can be used to perform the following operations when it is determined that the integrity algorithm module needs to execute according to the module selection signal:

[0161] (1) When the target version is the ZUC-256 version, the target tag length is 64 bits, and the length of the target plaintext is 32*p bits, the length of the target key is 32*(p + 4) bits, where p ≥ 1; the target key is specifically k[0] ~ k[32*(p + 4) - 1]; the target plaintext is specifically m[0] ~ m[32*p - 1]; the initial value stored in the result register is 0;

[0162] (2) Input k[0] ~ k[32*7 - 1] in the target key into Z

[64] ~Z

[287] of the key stream register; based on the tag length selection signal and the version selection signal, control the initial selection module to output 64-bit bit values in Z

[64] ~Z

[127] to the comprehensive exclusive-OR module; based on the tag length selection signal and the version selection signal, when the plaintext m[i] takes the value of 1, control the compatible selection module i to output 64-bit bit values in Z[i + 128]~Z[i + 191] to the comprehensive exclusive-OR module; based on the tag length selection signal and the version selection signal, when the plaintext m[i] takes the value of 0, control the compatible selection module i to output 0 to the comprehensive exclusive-OR module; control the result register to output the currently stored value to the comprehensive exclusive-OR module; control the comprehensive exclusive-OR module to perform an exclusive-OR operation on the outputs of the initial selection module, the compatible selection modules 0~31, and the result register, and output the result of the exclusive-OR operation to the result register for storage;

[0163] (3) When p ≥ 2, loop and execute the following steps until the end of the (p - 1)-th loop: Input k[32*(j + 2)]~k[32*(j + 7) - 1] in the target key into Z

[128] ~Z

[287] of the key stream register, where j is the current loop count; Based on the tag length selection signal and the version selection signal, control the initial selection module to output 0 to the comprehensive exclusive-or module; Based on the tag length selection signal and the version selection signal, when the plaintext m[32*j + i] takes the value of 1, control the compatible selection module i to output the 64-bit bit value in Z[i + 128]~Z[i + 191] to the comprehensive exclusive-or module; Based on the tag length selection signal and the version selection signal, when the plaintext m[32*j + i] takes the value of 0, control the compatible selection module i to output 0 to the comprehensive exclusive-or module; i = 0, 1, 2, …, 31; Control the result register to output the currently stored value to the comprehensive exclusive-or module; Control the comprehensive exclusive-or module to perform an exclusive-or operation on the outputs of the initial selection module, the compatible selection modules 0~31, and the result register, and output the result of the exclusive-or operation to the result register for storage;

[0164] (4) When the (p - 1)-th loop execution ends, input k[32*(p + 2)]~k[32*(p + 4) - 1] in the target key into Z

[128] ~Z

[191] of the key stream register; Based on the tag length selection signal and the version selection signal, control the compatible selection module 0 to output the 64-bit bit value in Z

[128] ~Z

[191] to the comprehensive exclusive-or module; Based on the tag length selection signal and the version selection signal, control the initial selection module and the compatible selection modules 1~31 to output 0 to the comprehensive exclusive-or module; Control the result register to output the currently stored value to the comprehensive exclusive-or module; Control the comprehensive exclusive-or module to perform an exclusive-or operation on the outputs of the initial selection module, the compatible selection modules 0~31, and the result register, and output the result of the exclusive-or operation to the result register to obtain the target integrity tag under the target version.

[0165] This embodiment can execute specific operations through the integrity algorithm module. Based on the above architecture, an integrity algorithm corresponding to an integrity tag length of 64 bits in the ZUC-256 version can be implemented, which can reduce the deployment cost. The explanation of this embodiment can refer to other embodiments.

[0166] (5) For the integrity tag length of 128 bits in the ZUC-256 version and the implementation of the corresponding integrity algorithm.

[0167] The specific pseudo-code process can refer to the public content of the ZUC algorithm. Optionally, the integrity algorithm module can be used to: when it is determined according to the module selection signal that the integrity algorithm module needs to execute, perform the following operations:

[0168] (1) When the target version is the ZUC-256 version, the target tag length is 128 bits, and the length of the target plaintext is 32*p bits, the length of the target key is 32*(p + 8) bits, where p≥1; the target key is specifically k[0]~k[32*(p + 8)-1]; the target plaintext is specifically m[0]~m[32*p-1]; the initial value stored in the result register is 0;

[0169] (2) Input k[0]~k[32*9-1] in the target key into Z[0]~Z

[287] of the key stream register; based on the tag length selection signal and the version selection signal, control the initial selection module to output 128-bit values in Z[0]~Z

[127] to the comprehensive exclusive OR module; based on the tag length selection signal and the version selection signal, when the plaintext m[i] takes the value of 1, control the compatible selection module i to output 128-bit values in Z[i + 128]~Z[i + 255] to the comprehensive exclusive OR module; based on the tag length selection signal and the version selection signal, when the plaintext m[i] takes the value of 0, control the compatible selection module i to output 0 to the comprehensive exclusive OR module; control the result register to output the currently stored value to the comprehensive exclusive OR module; control the comprehensive exclusive OR module to perform an exclusive OR operation on the outputs of the initial selection module, the compatible selection modules 0~31, and the result register, and output the result of the exclusive OR operation to the result register for storage;

[0170] (3) When p≥2, loop and execute the following steps until the end of the (p - 1)th loop execution: input k[32*(j + 4)]~k[32*(j + 9)-1] in the target key into Z

[128] ~Z

[287] of the key stream register, where j is the current loop count; based on the tag length selection signal and the version selection signal, control the initial selection module to output 0 to the comprehensive exclusive OR module; based on the tag length selection signal and the version selection signal, when the plaintext m[32*j + i] takes the value of 1, control the compatible selection module i to output 128-bit values in Z[i + 128]~Z[i + 255] to the comprehensive exclusive OR module; based on the tag length selection signal and the version selection signal, when the plaintext m[32*j + i] takes the value of 0, control the compatible selection module i to output 0 to the comprehensive exclusive OR module; i = 0, 1, 2, …, 31; control the result register to output the currently stored value to the comprehensive exclusive OR module; control the comprehensive exclusive OR module to perform an exclusive OR operation on the outputs of the initial selection module, the compatible selection modules 0~31, and the result register, and output the result of the exclusive OR operation to the result register for storage;

[0171] (4) When the (p - 1)-th loop execution ends, input k[32*(p + 4)] to k[32*(p + 8)-1] in the target key into Z

[128] to Z

[255] of the key stream register; based on the tag length selection signal and the version selection signal, control the compatibility selection module 0 to output 128-bit bit values in Z

[128] to Z

[255] to the comprehensive exclusive-OR module; based on the tag length selection signal and the version selection signal, control the initial selection module and the compatibility selection modules 1 to 31 to output 0 to the comprehensive exclusive-OR module; control the result register to output the currently stored value to the comprehensive exclusive-OR module; control the comprehensive exclusive-OR module to perform an exclusive-OR operation on the outputs of the initial selection module, the compatibility selection modules 0 to 31, and the result register, and output the result of the exclusive-OR operation to the result register to obtain the target integrity tag under the target version.

[0172] In this embodiment, specific operations can be performed through the integrity algorithm module. Based on the above architecture, the integrity algorithm corresponding to an integrity tag length of 128 bits under the ZUC-256 version can be implemented, which can reduce the deployment cost. For the explanation of this embodiment, reference can be made to other embodiments.

[0173] Through the above 4 specific embodiments, based on the same architecture, the integrity algorithms under the ZUC-128 version and the ZUC-256 version can be implemented, reducing the deployment cost of the integrity algorithm module and improving the flexibility and adaptability of the integrity algorithm module.

[0174] (VI) Other architectures and implementation methods.

[0175] In addition to the above architectures and implementation methods, the embodiments of the present disclosure also provide other optional architectures and implementation methods.

[0176] Optionally, the integrity algorithm module may include multiple sub-modules, which are respectively used to implement different integrity algorithms. Then, based on the tag length selection signal and the version selection signal, the corresponding sub-module can be determined to perform the corresponding operation.

[0177] Optionally, the initial selection module in the above embodiment can also be deleted. The integrity algorithm module may include: a key stream register, compatibility selection modules 0 to 31, a comprehensive exclusive-OR module, and a result register. The key stream register includes 32 * 5 bit positions, specifically including Z[0] to Z

[159] ; the 128-bit bit values output from Z[i] to Z[i + 127] in the key stream register are connected to the compatibility selection module i; i = 0, 1, 2,..., 31; other architectures are similar to the above integrity algorithm module.

[0178] Accordingly, specific control operations can be referred to other embodiments. Among them, since the initial selection module is deleted, accordingly, the number of bits in the key stream register can be reduced to 32 * 5. For the ZUC-128 version algorithm, the related operations of the initial selection module can be deleted. For the ZUC-256 version algorithm, the initial Tag value originally output in step (2) in the initial selection module can be initialized into the result register, and through the result register, the initial Tag value is output to the comprehensive exclusive OR module in step (2).

[0179] The following explains the architecture and control method of another integrity algorithm module.

[0180] In an alternative embodiment, the integrity algorithm module may include: a key stream register, 1 initial selection module, compatibility selection modules 0 to 32, a comprehensive exclusive OR module, and a result register. The key stream register includes 32 * 9 bits, specifically including Z[0] to Z

[287] ; the 128-bit value output of Z[0] to Z

[127] in the key stream register is connected to the initial selection module; the 128-bit value output of Z[i + 128] to Z[i + 255] in the key stream register is connected to the compatibility selection module i; i = 0, 1, 2,..., 32; the output of the initial selection module, the outputs of the compatibility selection modules 0 to 32, and the output of the result register are connected to the comprehensive exclusive OR module; the output of the comprehensive exclusive OR module is connected to the result register.

[0181] The following first explains each part in the integrity algorithm module separately.

[0182] The explanation of the key stream register in this embodiment can be referred to the above embodiment. The initial selection module in this embodiment can be used to determine the output bit value according to the version selection signal and the tag length selection signal, that is, the initial value of the integrity tag in the integrity algorithm. Specifically, it can refer to the explanation in the above embodiment.

[0183] The compatibility selection module in this embodiment can be used to determine the output bit value according to the version selection signal and the tag length selection signal, and specifically, the plaintext bit value can be not considered. The plaintext bit value is input into the comprehensive exclusive OR module for selection, and the compatibility selection module can input the key content of the corresponding number of bits into the comprehensive exclusive OR module.

[0184] Optionally, for the ZUC-128 version, the compatible selection module i can be controlled to output the 32-bit bit value in Z[i+128]~Z[i+159] to the comprehensive exclusive-OR module; for the ZUC-256 version and the tag length is 32 bits, the compatible selection module i can be controlled to output the 32-bit bit value in Z[i+128]~Z[i+159] to the comprehensive exclusive-OR module; for the ZUC-256 version and the tag length is 64 bits, the compatible selection module i can be controlled to output the 64-bit bit value in Z[i+128]~Z[i+191] to the comprehensive exclusive-OR module; for the ZUC-256 version and the tag length is 128 bits, the compatible selection module i can be controlled to output the 128-bit bit value in Z[i+128]~Z[i+255] to the comprehensive exclusive-OR module. For the specific update situation of the key stream register with the loop, reference can be made to the above embodiments.

[0185] The comprehensive exclusive-OR module in this embodiment can be used to perform a comprehensive exclusive-OR operation on the outputs of the initial selection module, the compatible selection modules 0~32, and the result register, combined with the plaintext bit value, to implement the integrity algorithm. This embodiment does not limit the specific comprehensive exclusive-OR operation.

[0186] Optionally, the comprehensive exclusive-OR module can be used to perform the following operations: Based on whether it is the first loop currently, select and output the output of the initial selection module and the output of the result register. Specifically, if it is the first loop currently, the initial value output by the initial selection module is determined as the temporary result [0] for output; if it is not the first loop currently, the output of the result register is determined as the temporary result [0] for output.

[0187] After that, based on the first plaintext bit value n[0] in the input 32-bit plaintext bit values n[0]~n

[31] , select and output the temporary result [0], and the exclusive-OR result between the temporary result [0] and the output of the compatible selection module 0. Specifically, if n[0] is 1, the exclusive-OR result between the temporary result [0] and the output of the compatible selection module 0 is determined as the temporary result [1] for output; if n[0] is 0, the temporary result [0] is determined as the temporary result [1] for output.

[0188] And so on, based on n[i] in the input 32-bit plaintext bit values n[0]~n

[31] , select and output the temporary result [i], and the exclusive-OR result between the temporary result [i] and the output of the compatible selection module i. Specifically, if n[i] is 1, the exclusive-OR result between the temporary result [i] and the output of the compatible selection module i is determined as the temporary result [i+1] for output; if n[i] is 0, the temporary result [i] is determined as the temporary result [i+1] for output.

[0189] Finally, a temporary result

[32] can be obtained, which is the XOR operation result after 32-bit plaintext selection. It can be understood that the update situation of the 32-bit plaintext with the loop can be referred to the above embodiments.

[0190] After that, based on whether it is the last loop currently, a selection output can be made for the temporary result

[32] and the first preset result. If it is not the last loop currently, the temporary result

[32] can be determined as the result to be cached for output; if it is the last loop currently, the first preset result can be determined as the result to be cached for output.

[0191] Among them, the first preset result corresponds to the steps executed after the loop ends in the integrity algorithm pseudocode (corresponding to step 4 of the above EIA3 algorithm pseudocode and step 4 of the above NIA6 algorithm pseudocode). Thus, in the last loop, this step in the pseudocode can be executed and the current integrity tag can be output. And for the case where the plaintext bit length is an integer multiple of 32, the first preset result can be the XOR result between the temporary result

[32] and the output of the compatibility selection module

[32] . For the case where the plaintext bit length is not an integer multiple of 32, the first preset result can be the XOR result between the temporary result [y] determined for the remainder y of the plaintext bit position with respect to 32 and the output of the compatibility selection module [y].

[0192] Furthermore, for the ZUC-128 version, 2 steps need to be executed after the loop ends in the integrity algorithm pseudocode (corresponding to step 4 and 5 of the above EIA3 algorithm pseudocode). Therefore, based on whether the loop ends currently (for example, the next clock cycle after the last loop ends), a selection output can be made for the result to be cached and the second preset result. If the loop has not ended (for example, it is still the last loop currently), the result to be cached can be stored in the result register; if the loop has ended, the second preset result can be stored in the result register.

[0193] The second preset result can correspond to the last 1 step in the integrity algorithm pseudocode for the ZUC-128 version (corresponding to step 5 of the above EIA3 algorithm pseudocode), and the second preset result can be the XOR result between the output of the result register and the corresponding key content. For the case where no step is executed in the ZUC-256 version, the second preset result can still be the output of the result register.

[0194] It can be understood that during the first loop to the penultimate loop, the temporary result

[32] is stored in the result register. During the last loop, the first preset result is stored in the result register. In the case of the end of the loop, the second preset result is stored in the result register as the final integrity tag.

[0195] Certainly, the steps executed by each module in the above embodiments are for illustrative purposes, and the embodiments of the present system do not limit the specific manner of implementing the integrity algorithm by the above integrity algorithm module architecture.

[0196] For example, the selective output for the second preset result may not be set. During the last loop, the first preset result is stored in the result register. After that, if no other steps need to be executed, such as the ZUC-256 version, the first preset result can be directly determined as the final integrity tag. If other steps still need to be executed, such as the ZUC-128 version, corresponding steps can be additionally executed for the first preset result, and there is no need to pass through the selective output.

[0197] Corresponding to the above system embodiment, an embodiment of a method is further provided in the present disclosure.

[0198] As Figure 5 shown, Figure 5 A schematic flow diagram of a method for implementing the Zu Chongzhi algorithm according to an embodiment of the present disclosure is schematically shown.

[0199] This method embodiment can be applied to a preset system, and the preset system may include: an initial vector generation module, a loading module, a key generation module, a confidentiality algorithm module, and an integrity algorithm module.

[0200] The method flow may include the following steps: S101: The initial vector generation module determines the corresponding initial vector generation method according to the version selection signal; and generates a target initial vector based on the determined initial vector generation method. S102: The loading module determines a target loading value according to the generated target initial vector and based on the loading method corresponding to the version selection signal. S103: The key generation module generates a target key according to the determined target loading value and based on the key generation method.

[0201] The version selection signal can be used to represent a target version to be implemented among multiple preset Zu Chongzhi algorithm versions. The key generation methods may be the same among different preset Zu Chongzhi algorithm versions. For a specific explanation of this method embodiment, reference can be made to the explanations in other embodiments.

[0202] An embodiment of a specific application is further provided in the present disclosure. Among them, the ZUC-128 version and the ZUC-256 version are taken as examples.

[0203] In the existing implementation of the Zu Chongzhi algorithm, the implementations of ZUC-128 and ZUC-256 are separate and independent, which will directly lead to an increase in chip area and, to a certain extent, increase the power consumption of the chip, bringing greater tape-out costs and testing costs to chip design companies. In this embodiment, the reconfigurable implementation of ZUC-128 and ZUC-256 can reduce the chip area resource overhead and also reduce the power consumption resource overhead to a certain extent, thus helping chip design companies reduce tape-out costs and testing costs, helping communication operating companies save energy, and also meeting the requirements of "dynamic, configurable, and flexible" for future communication systems. Its flexibility meets the requirements for security encryption in various technical frameworks.

[0204] ZUC-256 is an upgraded version of ZUC-128. Except for the changes in the key length and the length of the initial vector, ZUC-256 also adopts a new design scheme in the initial stage and the message authentication code generation stage. However, compared with ZUC-128, its structural framework has hardly changed. Therefore, at the hardware level, many things can be reused. Such as: Linear Feedback Shift Register (LFSR), mod(2^31-1) adder, bit recombination layer, 32bit adder, S-box, shifter, etc.

[0205] The overall block diagram of the reconfigurable design of ZUC-128 and ZUC-256 in this embodiment is as Figure 6 shown, Figure 6 which schematically shows the structural diagram of another system for implementing multi-version Zu Chongzhi algorithm according to an embodiment of the present disclosure.

[0206] As Figure 6 shown, the system may include an IV generator (corresponding to the above-mentioned initial vector generation module), a ZUC reconfigurable circuit controller (corresponding to the above-mentioned control module), an initial loader module (corresponding to the above-mentioned loading module), a ZUC reconfigurable circuit (corresponding to the above-mentioned key generation module), a ZUC reconfigurable EEA3-NEA6 confidentiality algorithm module (corresponding to the above-mentioned confidentiality algorithm module), a ZUC reconfigurable EIA3-NIA6 integrity algorithm module (corresponding to the above-mentioned integrity algorithm module), and a serial-to-parallel module.

[0207] (1) The IV generator receives COUNT-128 (counter), BEARER-5 (bearer layer identifier), and DIRECTION (transmission direction) from outside the system, and generates an initial vector IV-128 in a certain manner according to the control signal from the ZUC reconfigurable controller (the IV generation method is described below), and transmits this signal to the ZUC reconfigurable circuit controller.

[0208] In this embodiment, "║" represents a splicing operation or a connection operation, "=" represents an assignment, "⊕" represents bitwise exclusive OR between integers, " " represents modulo 2 32 addition, "<<<" represents a circular left shift, and the number following it is the number of bits shifted to the left. ">>" represents a right shift, and the number following it is the number of bits shifted to the right. "(, ,…, ,) →(, ,…, ,)" represents a parallel assignment. For the initial vector IV generation methods of EEA3, EIA3, NEA6, and NIA6, reference can be made to the publicly disclosed Zu Chongzhi algorithm.

[0209] (2) In addition to the IV from the IV generator, the ZUC reconfigurable circuit controller also receives the key KEY-256, encryption mode selection signal, MAC tag length selection signal-2, and the length signal LENGTH-32 of the plaintext to be encrypted sent by an external system, and transmits this information to the initial loader, ZUC reconfigurable circuit module, confidentiality algorithm module, integrity algorithm module, and serial-to-parallel module. Among them, the ZUC reconfigurable circuit controller transmits the encryption mode selection signal to the initial loader module, confidentiality algorithm module, and integrity algorithm module to unify the data path for a specific encryption mode; transmits control signals to the ZUC reconfigurable circuit and serial-to-parallel module to control the generation and end of the key stream and the start and end of the plaintext transmission; and transmits the key KEY and the initial vector IV to the initial loader module. The ZUC-128 loader and ZUC-256 loader in this module will combine the key KEY, the initial vector IV, and the constant d inside them in a certain way (the loading method is described below) to generate six groups of initial loading values, and each group of initial values consists of a sequence of 16 31-bit binary numbers. Each 31-bit binary sequence corresponding to the ZUC-256 loader is represented by the symbol SAi (i can take values 0, 1, 2, ……14, 15), and each SAi is 31 bits wide. Each 31-bit binary sequence corresponding to the ZUC-128 loader is represented by the symbol SBi (i can take values 0, 1, 2, ……14, 15), and each SBi is 31 bits wide. Among them, for different algorithm versions, two groups of initial loading values can be generated respectively for the confidentiality algorithm and the integrity algorithm. For the specific loading methods of the ZUC-256 initial loader and the ZUC-128 initial loader, reference can be made to the publicly disclosed content of the Zu Chongzhi algorithm.

[0210] After the initial loader finishes loading, the encryption algorithm selects a signal for selection and output, and outputs one of SA-496 or SB-496 to the register unit of the LFSR in the ZUC reconfigurable circuit. There are 16 registers Si (i can take 0, 1, 2, …… 14, 15) in the LFSR register bank. The connection relationship between SA-496 or SB-496 and the LFSR register is: SAi / SBi is connected to the register Si. The ZUC encryption workflow is roughly divided into three stages: the initial data loading stage, the LFSR initialization stage, and the key generation stage. For details, please refer to the public content of the ZUC algorithm. Since ZUC-256 is an upgraded version of ZUC-128, the process frameworks of ZUC-128 and ZUC-256 are almost the same in the LFSR initialization stage and the key generation stage. Therefore, almost all the circuits involved in these two stages can be reused, that is, the LFSR layer, the BR layer, and the FSM layer of the ZUC stream cipher generation circuit are reused. Because the confidentiality algorithm and the integrity algorithm of ZUC-256 require different initial loading values, in order to improve the encryption rate, two ZUC stream cipher reconfigurable cores (Core1 and Core2) can be deployed in this embodiment to parallelly construct two different keys.

[0211] (4)After the key is generated, the generated key stream, the plaintext, and the encryption selection signal can be input into the confidentiality algorithm module and the integrity algorithm module together. For the confidentiality algorithm, the confidentiality algorithm EEA3 of ZUC-128 has been determined. This algorithm actually performs an exclusive OR operation on the key stream generated by the ZUC reconfigurable circuit and the plaintext, and the result is the ciphertext.

[0212] The bit width of the key stream can be 32bit. Therefore, the input plaintext can be serialized into parallel data, and the plaintext input into the ZUC reconfigurable EEA3-NEA6 confidentiality algorithm module becomes 32bit wide, so as to improve the encryption rate. The serial data to 32bit parallel data can be implemented by any bit width compliant serial-to-parallel circuit.

[0213] (5)For the integrity algorithm, the integrity algorithm of ZUC-256 is NIA6, and the integrity algorithm of ZUC-128 is EIA3. The EIA3 algorithm only supports the generation of MAC-TAG with a width of 32bit, while NIA6 supports the generation of MAC-TAG with three lengths of 32bit, 64bit, and 128bit. The pseudo-codes of the EIA3 and NIA6 processes can be found in the public content of the ZUC algorithm.

[0214] Both the NIA6 and EIA3 algorithms utilize the hashing principle, but their specific implementation processes are different. Additionally, NIA6 supports multiple tag bit widths, so the reconfigurable design of EIA3 and NIA6 cannot be simply achieved. This embodiment proposes a reconfigurable method that supports multiple tag lengths of NIA6 and is compatible with EIA3. As Figure 7 shown, Figure 7 schematically shows a schematic diagram of the principle of a ZUC reconfigurable EIA3-NIA6 integrity algorithm according to an embodiment of the present disclosure. For ease of description, Figure 7 Wi, etc. in are represented in the form of W[i], Figure 7 and Mi in is represented as M[i].

[0215] In this embodiment, a LFSR with a total length of 288 bits is set in the ZUC reconfigurable EIA3-NIA6 integrity algorithm module to be compatible with the generation of MAC-TAGs of lengths ZUC-256 32-bit, ZUC-256 64-bit, ZUC-256 128-bit, and ZUC-128 32-bit. It is composed of 9 registers each 32 bits long. This LFSR is shifted left by 31 bits each time, new data enters the register unit [255:287], and old data leaves from the register unit [0:31]. Taps are taken out at registers [0:127]; [128:255], [129:256], [130:257], ……, [159:286], etc., and are named T; W

[128] , W

[129] , W

[130] , ……, W

[159] respectively. These taps are connected to the corresponding selectors below. After being selected by the selection signal Sel and M[i + k] (k takes 0, 1, 2, …, 31, the same hereinafter), an exclusive OR operation is performed on the output of the selector, and the resulting value is saved in a 128-bit register REG (the value of the register was 0 before this). The saved value is fed back and input to the exclusive OR unit to perform an exclusive OR operation together with the inputs of numerous selectors. Among them, Sel is selected jointly by the encryption mode selection signal and the MAC tag length selection signal from the three tag length control signals of ZUC-256 and 0. M[i + k] is selected jointly by the encryption mode selection signal and the MAC tag length selection signal from four control signals containing the plaintext information m[i + k]. The following gives examples of the generation processes of 2 MAC tags.

[0216] 1) For the generation of a ZUC-256 128-bit length tag: The LFSR is first clocked 9 times to fill the register with the key stream. Then, the Sel signal selects T as the output, and M[i + k] selects the corresponding W

[128] to W

[159] as the output. These outputs are XORed with the feedback output of the REG register, and the result is saved in REG. In this clock cycle, 32 W[i] selected by the plaintext are calculated, which is equivalent to executing the loop operation in the process pseudocode 32 times. This method greatly improves the speed of MAC tag generation. At the 10th clock cycle, the loop operation will be executed 32 times again, and so on. Suppose at the nth clock cycle, the plaintext runs out. W[n] will be selected by M[i] from W

[128] and XORed with the feedback input of the REG register alone to obtain a 128-bit MAC-TAG. For the cases of other tag lengths of ZUC-256, the initial clock cycle can be determined to be 7 or 6 clock cycles to facilitate determining the initial value of the tag, and then the subsequent steps are executed. For a 128-bit width, other tag lengths can be filled by padding with 0s.

[0217] 2) For the generation of a ZUC-128 32-bit length tag: The LFSR is first clocked 5 times. Then, the Sel signal selects 0 as the output, and M[i + k] selects the corresponding W

[128] to W

[159] as the output (in the 128-bit output of each W, [0:31] has data and [96:127] is 0). These outputs are XORed with the feedback output of the REG register, and the result is saved in REG. In this clock cycle, 32 W[i] selected by the plaintext are calculated, which is equivalent to executing the loop operation in the process pseudocode 32 times. At the 6th clock cycle, the loop operation will be executed 32 times again, and so on. Suppose at the nth clock cycle, the plaintext runs out. W[n] will be selected by M[i] from W

[128] , and W[32*(L - 1)] will be selected by M[i + 31] from W

[159] . W128 and W159 are XORed with the feedback input of the REG register to obtain a 32-bit MAC-TAG. For specific explanations, reference can be made to other embodiments.

[0218] In addition, as Figure 8 shown, Figure 8 schematically shows a schematic diagram of the principle of another ZUC reconfigurable EIA3-NIA6 integrity algorithm according to an embodiment of the present disclosure. For specific details, reference can be made to the relevant explanations of the temporarily stored results, the first preset result, the second preset result, etc. in the foregoing embodiments. In summary, this embodiment can utilize the idea of circuit multiplexing to achieve the reconfigurable design of EIA3 and NIA6, and while generating four different MAC tags, it can greatly reduce the overhead of chip area resources.

[0219] The beneficial effects of this embodiment at least include: 1) The reconfigurable implementation of the ZUC-256 and ZUC-128 stream cipher generation circuits can reduce the chip area resource overhead by nearly half while realizing the two key stream generation functions, and also reduce the chip power consumption overhead to a certain extent. 2) The reconfigurable implementation of the EEA3 and NEA6 confidentiality algorithm circuits can reduce the chip area resource overhead by nearly half while realizing the two encryption functions, and also reduce the chip power consumption overhead to a certain extent. 3) The reconfigurable implementation of the EIA3 and NIA6 integrity algorithm circuits can reduce the chip area resource overhead while realizing the two authentication functions. 4) The NIA6 integrity algorithm circuit has configurability and can flexibly generate three MAC authentication tags of different lengths to meet the authentication functions in different scenarios.

[0220] Figure 9 Schematically shows a block diagram of an electronic device suitable for implementing a method for implementing the Zu Chongzhi algorithm according to an embodiment of the present disclosure. As Figure 9 shown, the electronic device 900 according to an embodiment of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 902 or a program loaded from a storage section 908 into a random access memory (RAM) 903. The processor 901 can include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 can also include on-board memory for caching purposes. The processor 901 can include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0221] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other through a bus 904. The processor 901 performs various operations of the method flow according to an embodiment of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the program can also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 can also perform various operations of the method flow according to an embodiment of the present disclosure by executing the programs stored in the one or more memories.

[0222] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the input / output (I / O) interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. The drive 910 is also connected to the input / output (I / O) interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read from it can be installed into the storage portion 908 as needed.

[0223] The present disclosure also provides a computer-readable storage medium, which may be included in the device described in the above embodiments; or may exist separately without being assembled into the device. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, a method for implementing the Zu Chongzhi algorithm provided by the embodiments of the present disclosure or any of the above method embodiments is realized.

[0224] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or combined with an instruction execution system, device, or component. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903.

[0225] An embodiment of the present disclosure also includes a computer program product, which includes a computer program that contains program code for executing the method shown in the flowchart. When the computer program product runs on a computer system, the program code is used to cause the computer system to implement a method for implementing the Zu Chongzhi algorithm provided by the embodiments of the present disclosure or any of the above method embodiments.

[0226] When the computer program is executed by the processor 901, the above functions defined in the device of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described devices and the like can be implemented by computer program modules.

[0227] In one embodiment, the computer program can rely on tangible storage media such as optical storage devices and magnetic storage devices. In another embodiment, the computer program can also be transmitted and distributed in the form of a signal on a network medium, and be downloaded and installed through the communication part 909, and / or be installed from the removable medium 911. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.

[0228] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 909, and / or be installed from the removable medium 911. When the computer program is executed by the processor 901, the above functions defined in the system of the embodiments of the present disclosure are executed. According to an embodiment of the present disclosure, the above-described devices and the like can be implemented by computer program modules.

[0229] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedures and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include but are not limited to, such as Java, C++, python, the "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0230] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two blocks connected in sequence may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0231] Those skilled in the art will appreciate that the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features described in the various embodiments of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.

[0232] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.

Claims

1. A system for implementing multiple versions of Zu Chongzhi's algorithm, characterized in that: The system includes: an initial vector generation module, a loading module, and a key generation module; The initial vector generation module is used to: determine the corresponding initial vector generation method according to the version selection signal; generate a target initial vector based on the determined initial vector generation method; The version selection signal is used to represent a target version that needs to be implemented among multiple preset Zu Chongzhi algorithm versions; the key generation method is the same between different preset Zu Chongzhi algorithm versions; The loading module is used to: determine the target loading value according to the generated target initial vector and based on the loading mode corresponding to the version selection signal; The key generation module is used to generate a target key based on the key generation method according to the determined target loading value.

2. The system according to claim 1, characterized in that The system also includes a confidentiality algorithm module and an integrity algorithm module; The initial vector generation module is used to: determine the corresponding initial vector generation method according to the version selection signal and the module selection signal; and generate a target initial vector based on the determined initial vector generation method; The module selection signal is used to indicate whether the confidentiality algorithm module needs to be executed, and whether the integrity algorithm module needs to be executed; the confidentiality algorithms are the same between different preset Zu Chongzhi algorithm versions; The loading module is used to: determine the corresponding loading mode according to the version selection signal and the module selection signal; determine the target loading value according to the generated target initial vector and based on the determined loading mode; The confidentiality algorithm module is used to: when it is determined according to the module selection signal that the confidentiality algorithm module needs to be executed, encrypt the target plaintext based on the confidentiality algorithm to obtain the target ciphertext under the target version; The integrity algorithm module is used to: when it is determined according to the module selection signal that the integrity algorithm module needs to be executed, generate a target integrity label under the target version for the target plaintext based on the integrity algorithm corresponding to the version selection signal.

3. The system according to claim 2, characterized in that The initial vector generation module is used to: determine the corresponding confidentiality algorithm initial vector generation method and the corresponding integrity algorithm initial vector generation method according to the version selection signal when it is determined according to the module selection signal that the confidentiality algorithm module and the integrity algorithm module need to be executed; generate a confidentiality target initial vector based on the determined confidentiality algorithm initial vector generation method; and generate an integrity target initial vector based on the determined integrity algorithm initial vector generation method; The loading module is used to: determine the corresponding confidentiality algorithm loading mode and the corresponding integrity algorithm loading mode according to the version selection signal when it is determined according to the module selection signal that the confidentiality algorithm module and the integrity algorithm module need to be executed; determine the confidentiality target loading value according to the generated confidentiality target initialization vector and the determined confidentiality algorithm loading mode; determine the integrity target loading value according to the generated integrity target initialization vector and the determined integrity algorithm loading mode; The key generation module is used to: generate a confidentiality target key based on the key generation method according to the determined confidentiality target loading value; generate an integrity target key based on the key generation method according to the determined integrity target loading value; The confidentiality algorithm module is used to: when it is determined according to the module selection signal that the confidentiality algorithm module needs to be executed, based on the confidentiality algorithm, use the generated confidentiality target key to encrypt the target plaintext to obtain the target ciphertext under the target version; The integrity algorithm module is used to: when it is determined according to the module selection signal that the integrity algorithm module needs to be executed, based on the integrity algorithm corresponding to the version selection signal, use the generated integrity target key to generate a target integrity label under the target version for the target plaintext.

4. The system according to claim 2, characterized in that The confidentiality algorithm module is used to: when it is determined according to the module selection signal that the confidentiality algorithm module needs to be executed, based on the confidentiality algorithm, perform an XOR operation on the target plaintext and the received target key to obtain the target ciphertext under the target version.

5. The system according to claim 2, characterized in that The integrity algorithm module is used to: determine the corresponding integrity algorithm based on the label length selection signal and the version selection signal when it is determined according to the module selection signal that the integrity algorithm module needs to be executed; and generate a target integrity label under the target version for the target plaintext based on the determined integrity algorithm; The label length selection signal is used to determine a target label length among a plurality of preset lengths; the length of the target integrity label is the target label length.

6. The system according to claim 1, characterized in that The multiple preset Zu Chongzhi algorithm versions include: ZUC-256 version and ZUC-128 version.

7. A method for implementing Zu Chongzhi's algorithm, characterized in that: Applied to a preset system, the preset system includes: an initial vector generation module, a loading module, and a key generation module; the method includes: The initial vector generation module determines a corresponding initial vector generation method according to the version selection signal; generates a target initial vector based on the determined initial vector generation method; The version selection signal is used to represent a target version that needs to be implemented among multiple preset Zu Chongzhi algorithm versions; the key generation method is the same between different preset Zu Chongzhi algorithm versions; The loading module determines the target loading value according to the generated target initialization vector and based on the loading mode corresponding to the version selection signal; The key generation module generates a target key according to the determined target loading value and based on the key generation method.

8. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to claim 7.

9. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instructions are executed by a processor, the steps of the method according to claim 7 are implemented.

10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instructions are executed by a processor, the steps of the method according to claim 7 are implemented.