Authentication encryption method, verification decryption method, system and device based on block cipher

Through the authentication and encryption method based on packet cipher, the codebook mode and PMAC mode are used to solve the problem of insecurity of classic authentication and encryption schemes under the quantum computing model, and high security and high efficiency encrypted communication are achieved.

CN120223293AActive Publication Date: 2025-06-27NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP

Patent Information

Application Number
CN202510676937.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-06-27
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

The existing classic authentication encryption schemes are not secure under quantum computing models, cannot effectively resist quantum forgery attacks or quantum distinction attacks, and the high efficiency requirements are difficult to meet.

Method used

The authentication encryption method based on packet cipher is adopted, plain text is encrypted through the codebook mode and authentication tags are generated using the PMAC mode to ensure the security and parallelism under the quantum computing model.

Benefits of technology

High security and high efficiency encrypted communication under the quantum computing model are realized, and data confidentiality, integrity and authentication are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223293A_ABST
    Figure CN120223293A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication encryption method, verification decryption method, system and device based on block cipher, and the authentication encryption method comprises the steps: determining a block cipher and a secret key which are used by a bottom layer, selecting an initial vector which is not used in encryption under the current secret key, taking the triad of the initial vector, the associated data and the plaintext as the input of an authentication encryption algorithm; the encryption part encrypts the masked plaintext by using a codebook mode to obtain a ciphertext; the authentication part processes the masked associated data by using a PMAC mode to obtain an authentication intermediate value, performs exclusive or on plaintext groups and encrypts the plaintext groups by using a block cipher, and performs exclusive or on the authentication intermediate value and a result encrypted by using the block cipher to generate an authentication label; and sending the initial vector, the associated data, the ciphertext and the authentication tag as a ciphertext message to a receiving end or storing the ciphertext message for decryption. According to the method, the confidentiality and integrity of data can be protected under quantum computing, and the computing efficiency can be improved through parallel computing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and particularly to an authenticated encryption method, a verification and decryption method, a system and a device based on block cipher. Background Art

[0002] Facing the security protection requirements such as data confidentiality, integrity and authenticity in the actual application of future quantum computing, as well as the forward security threats such as "store first and then decrypt" faced in practical applications, the authenticated encryption scheme must not only have the security of the classical computing model, but also have the security under the quantum computing model. At present, most classical authenticated encryption schemes (such as GCM (Galois / Counter Mode), OCB (Offset Codebook Mode), etc.) do not have the security under the quantum computing model, and there are quantum forgery attacks or quantum distinguishability attacks. There are relatively few authenticated encryption schemes that can be proven secure under the quantum computing model. Typical design schemes include QCB (Quantum-secure Codebook Mode), SLAE (Sponge-based Leakage-resilient Authenticated Encryption), etc. QCB is designed based on an adjustable block cipher. Although it can perform parallel computing, it needs to call the adjustable block cipher, which puts higher and more complex requirements on the underlying cryptographic primitives and usually reduces the implementation efficiency of the authenticated encryption scheme. SLAE is designed based on the Sponge structure and cannot perform parallel operations during encryption and decryption, which limits the data encryption and decryption efficiency and is difficult to meet the high-efficiency requirements in the actual application of the authenticated encryption scheme. Most of the authenticated encryption schemes that can be proven secure under the classical computing model are directly constructed based on block ciphers, which have advantages in terms of efficiency and design flexibility. However, there is currently no publicly available authenticated encryption scheme that can be proven secure under the quantum computing model and is directly designed based on block ciphers. Therefore, designing an authenticated encryption scheme that can be proven secure under the quantum computing model based on block ciphers has important theoretical significance and practical value for enhancing the confidentiality, integrity and authenticity of data under quantum computing conditions.

[0003] There is no publicly available authenticated encryption scheme that can be proven secure under the quantum computing model and is directly designed based on block ciphers in the existing public literature. Other authenticated encryption schemes that can be proven secure under the quantum computing model, such as QCB based on adjustable block ciphers and SLAE based on the Sponge structure, cannot meet the application requirements of high security and high computing efficiency under the quantum computing model. Summary of the Invention

[0004] In view of this, the present application provides an authenticated encryption method, a verified decryption method, a system and a device based on block cipher, including an authenticated encryption method and a verified decryption method, which have the advantages of security and parallelism under the quantum computing model, and provide a new method for the design of symmetric encryption working mode based on block cipher, which has important theoretical significance and practical value for enhancing the confidentiality, integrity and authentication of data under quantum computing.

[0005] The present application discloses an authentication encryption method based on block cipher, which is applied to a sending end or an encryption party, and includes: Step 1: Determine the underlying block cipher used and key , select the current key The initialization vector that has not been used in encryption , the initial vector , Linked Data , Plain text The triplet of As input to the authenticated encryption algorithm; Step 2: Encryption part uses codebook mode to encrypt the masked plaintext , get the ciphertext ; The mask is based on the initial vector Sure; Step 3: The authentication part uses the PMAC mode to process the masked association data , get the certified intermediate value , XOR the plaintext blocks and encrypt them with a block cipher, and then authenticate the intermediate value XOR with the result of encryption using the block cipher to generate the authentication tag ; Step 4: Initialize the vector , Linked Data 、Ciphertext , Certification Label Composed of It is sent to the receiving end as a ciphertext message or stored for decryption.

[0006] Furthermore, the sender or encryptor shares a key with the receiver or decryptor , the plaintext By block cipher The length of the group The total number of groups is ,but , the last group The length of In the same way, the associated data Grouping, the total number of groups is ,but , where the length of the last block is in the range .

[0007] Furthermore, step 2 includes: using a block cipher to encrypt the initialization vector to obtain a secret value , and adding 1 to the secret value and then using the block cipher to encrypt to obtain a secret value . For , that is, the -th plaintext block except the last block is XORed with the mask and then encrypted using the block cipher , and then XORed with the mask to generate a ciphertext block . is the XOR operation symbol, denotes encryption using the block cipher with key K ; For the last plaintext block , the length of the plaintext is encoded as 1 block , masked using and then encrypted using the block cipher . The encrypted value is XORed with the mask , truncated to the same length as the last plaintext block and then XORed with to generate the last ciphertext block ; is the length function; Concatenating all the ciphertext blocks gives the ciphertext , that is, . is the concatenation symbol.

[0008] Furthermore, step 3 includes: Adding 2 to the secret value and then encrypting using the block cipher to obtain a secret value ; For , that is, the -th associated data block except the last block is XORed with the mask and then encrypted using the block cipher , that is, ; For the last associated data block, if it is a complete block, that is, its length is , then , XOR it with the mask and then encrypt it using the block cipher , that is ; if it is an incomplete block, i.e., the length is less than , pad it to a complete block, then , XOR it with the mask and then encrypt it using the block cipher , that is ; According to and , obtain the authentication intermediate value , ; according to and , obtain the authentication intermediate value , ; If the last block of the plaintext is an incomplete block, pad it to a complete block, and then perform an XOR operation on all plaintext blocks, that is ; after masking, encrypt it using the block cipher , and then XOR the encrypted result with the authentication intermediate value to generate the authentication tag .

[0009] This application also discloses a verification and decryption method based on block cipher, which is applied to the receiving end or the decryption party, and it includes: Step 1: Determine to use the same block cipher and the same key as the sending end or the encryption party, receive the ciphertext message from the sending end or read it from storage, and the ciphertext message includes the initialization vector , the associated data , the ciphertext , and the authentication tag ; Step 2: Decrypt the masked ciphertext using the electronic codebook mode to obtain the plaintext ; the mask is determined based on the initialization vector ; Step 3: Process the masked associated data using the PMAC mode to obtain the verification intermediate value , encrypt the XOR sum of the plaintext blocks using the block cipher, and XOR the verification intermediate value with the result of encryption using the block cipher to generate the verification tag ; Step 4: If the verification tag is equal to the authentication tag , the verification passes, and the decrypted plaintext is output .

[0010] Furthermore, the receiving end or the decrypting party shares the key with the sending end or the encrypting party , and the ciphertext is grouped according to the block length of the block cipher , and the total number of groups is , then , and the length of the last group is in the interval ; The associated data is grouped, and the total number of groups is , then , where the length of the last group is in the interval .

[0011] Furthermore, step 2 includes: Using the block cipher to encrypt the initial vector , to obtain the secret value , after adding 1, use the block cipher to encrypt to obtain the secret value ; For , that is, the th ciphertext block except the last block is XORed with the mask , then decrypted using the inverse operation of the block cipher , and then XORed with the mask to generate the plaintext block ; is the XOR operation symbol, represents encryption using the block cipher with key K, represents using the block cipher inverse operation to decrypt; For the last ciphertext block , the length of the ciphertext is encoded as 1 block , after masking with and then encrypting with the block cipher , the encrypted value is XORed with the mask , truncated to the same length as the last ciphertext block and then XORed with to generate the last plaintext block ; is the length function; Concatenate all the plaintext blocks to obtain the plaintext , that is 。

[0012] Further, step 3 includes: Adding 2 to the secret value and then encrypting it using a block cipher to obtain the secret value ; for , that is, the th associated data block except the last block is XORed with the mask and then encrypted using a block cipher , that is ; For the last associated data block, if it is a complete block, that is, its length is , then , it is XORed with the mask and then encrypted using a block cipher , that is ; if it is an incomplete block, that is, the length is less than , it is padded to a complete block, then , it is XORed with the mask and then encrypted using a block cipher , that is ; According to and , the verification intermediate value is obtained, ; according to and , the verification intermediate value is obtained, ; If the last block of the plaintext is an incomplete block, it is padded to a complete block, and then all plaintext blocks are XORed, that is , after masking, it is encrypted using a block cipher and then XORed with the verification intermediate value to generate the verification tag .

[0013] Further, step 4 includes: If the verification tag is not equal to the authentication tag , the verification fails, and a character indicating that the ciphertext message is invalid is output.

[0014] This application also discloses an authenticated encryption system based on a block cipher for implementing the authenticated encryption method based on a block cipher as described above, which includes: An input module for determining the block cipher used at the underlying layer and the key , select the current key and an initialization vector that has not been used in encryption , and use the initialization vector , associated data , and the plaintext as a triple as the input to the authenticated encryption algorithm; A ciphertext generation module for encrypting the plaintext masked by the electronic codebook mode in the encryption part to obtain the ciphertext ; the mask is determined based on the initialization vector ; An authentication tag generation module for processing the associated data masked by the PMAC mode in the authentication part to obtain an authentication intermediate value , XOR the sum of the plaintext groups and then encrypt using a block cipher, and XOR the authentication intermediate value with the result of encryption using the block cipher to generate an authentication tag ; A data sending module for sending the initialization vector , associated data , ciphertext , authentication tag constituted as a ciphertext message to the receiving end or storing it for decryption.

[0015] This application also discloses a verification and decryption system based on a block cipher for implementing the verification and decryption method based on a block cipher described above, including: An input module for determining the same block cipher and the same key as the sender or the encrypting party, receiving the ciphertext message from the sender or reading it from storage as the input to the verification and decryption algorithm, and the ciphertext message includes an initialization vector , associated data , ciphertext , authentication tag ; A plaintext generation module for decrypting the ciphertext masked by the electronic codebook mode in the decryption part to obtain the plaintext ; the mask is determined based on the initialization vector ; A verification tag generation module for verifying the associated data masked by the PMAC mode in the verification part to obtain a verification intermediate value , the exclusive OR sum of the plaintext blocks is encrypted using a block cipher, and the verification intermediate value is XORed with the result of encryption using the block cipher to generate a verification tag ; A data verification module for data integrity verification. If the verification tag is equal to the authentication tag , the verification passes, and the decrypted plaintext is output.

[0016] This application also discloses an electronic device, including a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the above-mentioned authentication and encryption method based on block cipher is implemented, or the above-mentioned verification and decryption method based on block cipher is implemented.

[0017] Due to the above technical solutions, this application has the following advantages: 1. It has provable security under the quantum computing model. The authentication and encryption method and the verification and decryption method of this application have the ability to resist quantum computing attacks, and can achieve secure encrypted communication or encrypted storage under the Q2 quantum computing model, protecting the confidentiality and integrity of data.

[0018] 2. It is directly designed based on block cipher. The authentication and encryption method and the verification and decryption method of this application are directly designed based on the encryption and decryption algorithms of block cipher at the bottom layer, and the underlying block cipher only needs to meet the security requirements under the quantum computing model.

[0019] 3. It can be parallelized. In the authentication and encryption method and the verification and decryption method of this application, the processes of encrypting plaintext, processing associated data, and decrypting ciphertext can all be fully parallelized, with high computing efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the embodiments of this application, and those of ordinary skill in the art can also obtain other drawings based on these drawings.

[0021] Figure 1 is a schematic flow chart of an authentication and encryption method based on block cipher according to an embodiment of this application; Figure 2 is a schematic diagram of the principle of the encryption part in an authentication and encryption method based on block cipher according to an embodiment of this application; Figure 3 is a schematic diagram of the principle of the authentication part in an authentication and encryption method based on block cipher according to an embodiment of this application; Figure 4Schematic flowchart of a verification and decryption method based on block cipher according to an embodiment of the present application; Figure 5 Schematic diagram of the principle of the decryption part in a verification and decryption method based on block cipher according to an embodiment of the present application; Figure 6 Schematic diagram of the principle of the verification part in a verification and decryption method based on block cipher according to an embodiment of the present application. Detailed implementation manners

[0022] The present application will be further described in conjunction with the accompanying drawings and embodiments. The described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art shall fall within the scope of protection of the embodiments of the present application.

[0023] See Figure 1 , an embodiment of an authentication and encryption method based on block cipher is provided in the present application, which is applied to a sending end or an encrypting party. This embodiment includes: The sending end or the encrypting party shares a key with the receiving end or the decrypting party , and encrypts the plaintext message into a ciphertext message , where is the initial vector, is the associated data, is the plaintext, is the ciphertext, is the authentication tag. The plaintext is grouped according to the block length of the underlying block cipher, and the total number of groups is , then , and the length of the last group is in the interval . Similarly, the associated data is grouped, and the total number of groups is , then , where the length of the last group is in the interval . The authentication and encryption process is as shown in Figure 1 , including steps S1 to S4: S1, determine the underlying block cipher and randomly select a key . Public designs such as AES, SM4, etc. or other block ciphers with quantum security can be selected. The key for the method of using the underlying block cipher. Select an initial vector that has not been used under the current key . Then the triple of the initial vector, the associated data, and the plaintext ​​​​​​​​​​​​​​​​​​​​​​As the input of the authenticated encryption algorithm.

[0024] S2. The encryption part encrypts the masked plaintext using the Electronic Codebook (ECB) mode to obtain the ciphertext .

[0025] Specifically, refer to Figure 2 , first encrypt the Initialization Vector (IV) using a block cipher to obtain the secret value , add 1 and then encrypt it using the block cipher to obtain the secret value . For , that is, the th plaintext block except the last one is XORed with the mask , encrypted using the block cipher , and then XORed with the mask to generate the ciphertext block , where the multiplication is in the finite field multiplication, and the same applies hereinafter. denotes encryption using the block cipher with key K .

[0026] For the last plaintext block , first encode the length of the plaintext into 1 block , use to mask it and then encrypt it using the block cipher . The encrypted value is XORed with the mask , truncated to the same length as the last plaintext block and then XORed with to generate the last ciphertext block ; is the length function.

[0027] Concatenate the ciphertext blocks to obtain the ciphertext , that is .

[0028] S3. The authentication part processes the associated data using the PMAC (Parallelizable MAC) mode . The exclusive OR sum (Checksum) of the plaintext blocks is encrypted using a block cipher, and the results of the two are XORed to generate the authentication tag .

[0029] Specifically, first add 2 to the secret value and encrypt it using the block cipher to obtain the secret value . For , i.e., the th associated data packet except the last packet is XORed with the mask and then encrypted using a block cipher , i.e., .

[0030] For the last associated data packet, if it is a complete packet, i.e., its length is , then , it is XORed with the mask and then encrypted using a block cipher , i.e., ; if it is an incomplete packet, i.e., the length is less than , it is padded with 1 one and several 0s to form a complete packet, then , it is XORed with the mask and then encrypted using a block cipher , i.e., .

[0031] The values obtained by masking and encrypting the above associated data packets are XORed together to obtain the authentication intermediate value or .

[0032] If the last packet of the plaintext is an incomplete packet, it is first padded with 0s to form a complete packet, and then all the plaintext packets are XORed together, i.e., . After masking, it is encrypted using a block cipher and then XORed with the authentication intermediate value to generate the authentication tag , as shown in Figure 3 .

[0033] S4. The initial vector, associated data, ciphertext, and authentication tag are sent to the receiving end as a ciphertext message or stored for decryption.

[0034] See Figure 4 . This application also provides an embodiment of a verification and decryption method based on a block cipher, which is applied to the receiving end or the decryption party. This embodiment includes: The receiving end or the decryption party shares the key with the sending end or the encryption party, and verifies and decrypts the ciphertext message into the plaintext or gives a character indicating that the ciphertext message is invalid , where is the initial vector, is the associated data, is the plaintext, is the ciphertext, is the authentication tag. The ciphertext Group by the block length of the underlying block cipher, and the total number of groups is , then , the length of the last block is in the range . Similarly, group the associated data , and the total number of groups is , then , where the length of the last block is in the range . The verification decryption process is as Figure 4 shown, including steps S5 to S8: S5, determine to use the same underlying block cipher and the same key as the sender or the encrypting party, and the inverse operation of the block cipher . Receive the ciphertext message from the sender or read it from storage, including the initialization vector , the associated data , the ciphertext , and the authentication tag .

[0035] S6, decrypt the masked ciphertext using the electronic codebook mode (ECB) in the decryption part to obtain the plaintext .

[0036] Specifically, refer to Figure 5 , first encrypt the initialization vector using the block cipher to obtain the secret value , add 1 and then encrypt it using the block cipher to obtain the secret value . For , that is, the th ciphertext block except the last block, after XOR with the mask , decrypt it using the inverse operation of the block cipher, and then XOR with the mask to generate the plaintext block .

[0037] For the last ciphertext block , first encode the length of the ciphertext into 1 block , use the mask and then encrypt it using the block cipher . XOR the encrypted value with the mask , truncate it to the same length as the last ciphertext block and then XOR with XOR to generate the last plaintext block .

[0038] Concatenate the plaintext blocks to obtain the plaintext , that is .

[0039] S7. For the authentication part, process the associated data using the PMAC mode . XOR the checksum of the plaintext blocks and then encrypt it using a block cipher. XOR the results of the two operations to generate the authentication tag .

[0040] Specifically, first add 2 to the secret value and then encrypt it using a block cipher to obtain the secret value . For , that is, the th associated data block except the last one XOR it with the mask and then encrypt it using a block cipher , that is .

[0041] For the last associated data block, if it is a complete block, that is, its length is , then , XOR it with the mask and then encrypt it using a block cipher , that is ; if it is an incomplete block, that is, the length is less than , pad it with 1 one and several 0s to form a complete block, then , XOR it with the mask and then encrypt it using a block cipher , that is .

[0042] XOR the values obtained by masking and encrypting the above associated data blocks to obtain the authentication intermediate value or .

[0043] If the last block of the plaintext is an incomplete block, first pad it with 0s to form a complete block, and then XOR all the plaintext blocks together, that is . After masking, encrypt it using a block cipher and XOR it with the authentication intermediate value to generate the authentication tag , as shown in Figure 6 .

[0044] S8. Determine whether the authentication tag is equal to the certification tag. If , the verification passes and the decrypted plaintext is output .

[0045] S8 also includes: if , then the verification fails, and it outputs indicating that the ciphertext message is an invalid character .

[0046] This application also provides an embodiment of an authenticated encryption system based on block cipher for implementing the authenticated encryption method based on block cipher described in the above embodiment. It includes: An input module, used to determine the block cipher used at the underlying layer and the key , select an initialization vector that has not been used in encryption under the current key , and use the triple of the initialization vector , associated data , and plaintext as the input of the authenticated encryption algorithm; A ciphertext generation module, used to encrypt the plaintext masked by the electronic codebook mode for the encryption part , to obtain the ciphertext ; the mask is determined based on the initialization vector ; An authentication tag generation module, used to process the associated data masked by the PMAC mode for the authentication part , to obtain an authentication intermediate value , encrypt the exclusive OR sum of the plaintext blocks using the block cipher again, and perform an exclusive OR operation on the authentication intermediate value and the result encrypted using the block cipher to generate an authentication tag ; A data sending module, used to send the composed of the initialization vector , associated data , ciphertext , and authentication tag as a ciphertext message to the receiving end or store it for decryption.

[0047] This application also provides an embodiment of a verification and decryption system based on block cipher for implementing the verification and decryption method based on block cipher described in the above embodiment, including: An input module, used to determine the same block cipher and the same key as those used by the sending end or the encrypting party, receive the ciphertext message from the sending end or read it from the storage as the input of the verification and decryption algorithm. The ciphertext message includes the initialization vector , associated data , ciphertext , authentication tag ; Plaintext generation module, which is used to decrypt the ciphertext after decrypting the mask in the electronic codebook mode for part of it , to obtain the plaintext ; The mask is determined based on the initial vector ; Verification tag generation module, which is used to verify the associated data after processing the mask in the PMAC mode for part of it , to obtain the verification intermediate value , encrypt the exclusive OR sum of the plaintext groups using a block cipher, and perform an exclusive OR operation on the verification intermediate value and the result encrypted using the block cipher to generate the verification tag ; Data verification module, which is used for data integrity verification. If the verification tag is equal to the authentication tag , the verification passes, and the decrypted plaintext is output .

[0048] This application also provides an embodiment of an electronic device, including a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, it implements the above-mentioned authentication and encryption method based on block cipher, or implements the above-mentioned verification and decryption method based on block cipher.

[0049] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application and not to limit them. Although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: it is still possible to modify the specific implementation manners of the present application or make equivalent replacements, and any modification or equivalent replacement that does not depart from the spirit and scope of the present application shall be covered by the protection scope of the claims of the present application.

Claims

1. An authenticated encryption method based on block cipher, which is applied to a sender or an encrypting party, and is characterized in that including: Step 1: Determine the block cipher used at the underlying layer and the key , select the initial vector that has not been used in encryption under the current key , and use the triple of the initial vector , associated data , and plaintext as the input to the authenticated encryption algorithm; ​​ Step 2: The encrypted part encrypts the masked plaintext using the cipher block chaining (CBC) mode , to obtain the ciphertext ; The mask is determined based on the initial vector ; Step 3: The authentication part processes the masked associated data using the PMAC mode , to obtain an authentication intermediate value . Then, the exclusive-or sum of the plaintext blocks is encrypted using a block cipher, and the authentication intermediate value is exclusive-ored with the result of encryption using the block cipher to generate an authentication tag ; Step 4: Use the initial vector , associated data , ciphertext , authentication tag to form which is sent to the receiver as a ciphertext message or stored for decryption.

2. The authenticated encryption method based on block cipher according to claim 1, wherein The sender or the encrypting party shares a key with the receiver or the decrypting party , and the plaintext is grouped according to the block length of the block cipher . If the total number of groups is , then , the length of the last block is in the range . Similarly, the associated data is grouped, and if the total number of groups is , then , where the length of the last block is in the range .​ 3. The authenticated encryption method based on block cipher according to claim 1, wherein The said step 2 includes: Using a block cipher Encrypt the initial vector to obtain a secret value The secret value is incremented by 1 and then encrypted using a block cipher to obtain a secret value For where is the total number of groups, i.e., the th plaintext block except the last block is XORed with a mask and then encrypted using a block cipher and then XORed with a mask to generate a ciphertext block where is the XOR operator, denotes encryption using a block cipher with a key ; For the last plaintext block , encode the length of the plaintext as 1 block , mask it using and then encrypt it using the block cipher . XOR the encrypted value with the mask , truncate it to the same length as the last plaintext block and then XOR it with to generate the last ciphertext block ; is the length function; The ciphertext is obtained by concatenating all ciphertext groups , that is , is the concatenation symbol.

4. The authenticated encryption method based on block cipher according to claim 1, wherein The said step 3 includes: The secret value is incremented by 2 and then encrypted using a block cipher to obtain the secret value ; for , i.e., the th associated data block except the last block is XORed with a mask and then encrypted using a block cipher , i.e., , where is the XOR operation symbol, and denotes encryption using the block cipher with the key For the last associated data packet, if it is a complete packet, i.e., its length is , then , XOR it with the mask and then encrypt it using the block cipher , i.e., ; if it is an incomplete packet, i.e., the length is less than , pad it to a complete packet, then , XOR it with the mask and then encrypt it using the block cipher , i.e., ; is the total number of packets; According to and , the intermediate authentication value is obtained; according to ; according to and , the intermediate authentication value is obtained ; If the last block of the plaintext is an incomplete block, it is padded to a complete block, and then all plaintext blocks are XORed, i.e., ; after masking, use the block cipher encrypt and XOR with the authentication intermediate value to generate the authentication tag .

5. A verification and decryption method based on block cipher, which is applied to a receiving end or a decryption party, and is characterized in that, including: Step 1: Determine to use the same block cipher as the sender or the encrypting party and the same key , receive the ciphertext message from the sender or read it from storage , the ciphertext message includes an initialization vector , associated data , ciphertext , authentication tag ; Step 2: The decryption part decrypts the masked ciphertext using the cipher block chaining (CBC) mode to obtain the plaintext , and the mask is determined based on the initialization vector ; ; Step 3: The verification part processes the masked associated data using the PMAC mode , to obtain an intermediate verification value . The exclusive-or sum of the plaintext blocks is encrypted using a block cipher, and the intermediate verification value is exclusive-ored with the result of the encryption using the block cipher to generate a verification tag ; Step 4: If the verification tag is equal to the authentication tag , the verification is passed, and the decrypted plaintext is output.

6. The verification and decryption method based on block cipher according to claim 5, wherein The receiving end or the decryption party shares a key with the sending end or the encryption party , and divides the ciphertext into groups according to the block length of the block cipher . The total number of groups is . Then , and the length of the last group is in the interval ; Divide the associated data into groups. The total number of groups is . Then , where the length of the last group is in the interval .

7. The authentication and decryption method based on block cipher according to claim 5, wherein The said step 2 includes: Encrypt the initial vector using a block cipher to obtain a secret value . After adding 1, use the block cipher to encrypt and obtain a secret value ; for , is the total number of groups, that is, the th ciphertext group except the last group is XORed with the mask , then use the inverse operation of the block cipher to decrypt, and then XOR with the mask to generate the plaintext group ; is the XOR operation symbol, represents encrypting using the block cipher with key K , represents using the inverse operation of the block cipher with key of the block cipher to decrypt; ​ For the last ciphertext block , encode the length of the ciphertext as 1 block , use as the mask, then encrypt it using the block cipher . XOR the encrypted value with the mask , truncate it to the same length as the last ciphertext block , and then XOR it with to generate the last plaintext block ; is the length function; Concatenate all the plaintext groups to obtain the plaintext , that is .

8. The verification and decryption method based on block cipher according to claim 5, characterized in that, The said step 3 includes: The secret value is incremented by 2 and then encrypted using a block cipher to obtain the secret value ; for , is the total number of groups, i.e., the th associated data group except the last group is XORed with the mask and then encrypted using a block cipher , i.e., ; is the XOR operation symbol, indicates encryption using the block cipher with the key ; For the last associated data packet, if it is a complete packet, i.e., its length is , then , XOR it with the mask and then encrypt it using the block cipher , i.e., ; if it is an incomplete packet, i.e., the length is less than , pad it to a complete packet, then , XOR it with the mask and then encrypt it using the block cipher , i.e., ; According to and , the verification intermediate value is obtained; according to ; according to and , the verification intermediate value is obtained, ; If the last block of the plaintext is an incomplete block, it is padded to a complete block, and then all plaintext blocks are XORed, i.e., , after masking, use the block cipher encrypt and XOR with the verification intermediate value to generate the verification tag .

9. The authentication and decryption method based on block cipher according to claim 5, wherein The said step 4 includes: If the verification tag is not equal to the authentication tag , the verification fails, and the output indicates that the ciphertext message is an invalid character .

10. An authenticated encryption system based on block cipher, which is used to implement the block-cipher-based authenticated encryption method according to any one of claims 1-4, characterized in that including: An input module for determining the block cipher used at the underlying layer and the key , and selecting an initialization vector that has not been used in encryption under the current key , and using the initialization vector , the associated data , and the plaintext as the input to the authenticated encryption algorithm in a triple ; The ciphertext generation module is used to encrypt the plaintext after encrypting the mask in the electronic codebook mode for the encrypted part , to obtain the ciphertext ; the mask is determined based on the initial vector ; An authentication label generation module, which is used to process the associated data after masking in the authentication part using the PMAC mode , to obtain an authentication intermediate value . Then, XOR the sum of the plaintext groups and encrypt it using a block cipher. XOR the authentication intermediate value with the result after encryption using the block cipher to generate an authentication label ; A data sending module, which is used to send the initialization vector , associated data , ciphertext , authentication tag constituted as a ciphertext message to the receiving end or store it for decryption.

11. A verification and decryption system based on block cipher, which is used to implement the verification and decryption method based on block cipher according to any one of claims 5-9, characterized in that, including: An input module for determining to use the same block cipher as the sender or the encrypting party and the same key , receiving the ciphertext message from the sender or reading it from storage As the input for verifying the decryption algorithm, the ciphertext message includes an initialization vector , associated data , ciphertext , authentication tag ; A plaintext generation module for decrypting the ciphertext after decrypting the mask in the cipher block chaining (CBC) mode to obtain the plaintext , and obtaining the plaintext ; the mask is determined based on the initial vector; The verification tag generation module is used to verify the associated data after processing the mask using the PMAC mode to obtain a verification intermediate value , encrypt the exclusive OR sum of the plaintext groups using a block cipher, and XOR the verification intermediate value with the result of encryption using the block cipher to generate a verification tag ; A data verification module for data integrity verification. If the verification tag is equal to the authentication tag , the verification passes, and the decrypted plaintext is output.

12. An electronic device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the said computer program is executed by the said processor, it implements the authenticated encryption method based on block cipher as described in any one of claims 1-4, or implements the verified decryption method based on block cipher as described in any one of claims 5-9.

Citation Information

Patent Citations

  • Certification encrypting method between certificate public key system and identity public key system

    CN101594228A

  • Message discrimination method based on block cipher

    CN102136904A

  • Block cipher based message authentication method

    CN104113543A

  • Secret key updating method for cloud storage and implementation method of cloud data auditing system

    CN104811300A

  • Generation method for data authentication code

    CN107566360A

Cited By

  • Authentication and encryption method, device and equipment of ZUC stream cipher, medium and product

    CN121056120A