XTS encryption circuit and decryption circuit for processing continuous input data

By introducing a cache unit into the XTS encrypting/decrypting circuit, the data blocks that need to be processed need to be processed are cached, which solves the processing efficiency problem when the data block is less than 128 bits, realizes continuous input and output, and improves the overall processing efficiency.

CN120238281APending Publication Date: 2025-07-01CHENGDU STARBLAZE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311844703.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing XTS encrypting/decrypting circuit needs to wait for the previous data block to be calculated after processing data blocks less than 128 bits, resulting in a decrease in processing efficiency and the inability to continuously input and output data, affecting the overall processing efficiency.

Method used

By introducing a cache unit in the encrypt/decryption module, the cache needs to wait for the last set of data blocks that are not 128 bits that are processed by the ciphertext stealing process, and input the data blocks of the next data unit during the waiting period, ensuring that the encrypt/decryption module continues to work and avoid idleness.

Benefits of technology

It realizes the continuous input of the next data block during the time of waiting for the calculation result of the previous data block, making full use of the encrypting/decrypting module, improving the processing efficiency of the XTS encrypting/decrypting circuit, avoiding idle time, and ensuring a continuous data processing flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238281A_ABST
    Figure CN120238281A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an XTS encryption circuit and decryption circuit for processing continuous input data, and relates to the technical field of information security, the encryption circuit comprises a first round of key expansion module, a second round of key expansion module, a first encryption module, a second encryption module, a modular multiplication module, a first summator, a second summator and a first cache unit, the first cache unit is used for caching the mth data block of the target data unit input into the second encryption module so as to input the first to (m-1) th data blocks of the next target data unit in the process that the second encryption module performs ciphertext stealing processing on the (m-1) th data block of the target data unit, therefore, continuous input to the second encryption module is formed. According to the encryption circuit, the second encryption module still has processed data in the time of waiting for the calculation result of the (m-1)-th data block of the previous data unit, so that idle space is avoided, and the processing efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to an XTS encryption circuit and a decryption circuit for processing continuous input data. Background Art

[0002] In cryptography, a block cipher is a symmetric key algorithm that divides plaintext into multiple blocks of equal length, and then encrypts them one by one until all the data blocks are encrypted. The SM4 cipher algorithm is a block cipher standard. The SM4 cipher algorithm has different encryption / decryption methods, such as XTS mode (XEX Tweakable BlockCipher with Ciphertext Stealing), CBC mode (Cipher BlockChaining), and ECB mode (Electronic Codebook Book). The encryption / decryption calculation process is different in different modes.

[0003] Figure 1 FIG. 2 shows a schematic diagram of the structure of the XTS mode encryption / decryption circuit. Figure 1 As shown, the encryption / decryption circuit of the XTS mode includes a round key expansion module Round_key_expand 1, an encryption / decryption module Endec 1, a round key expansion module Round_key_expand_2, an encryption / decryption module Endec_2, a modular multiplication module Mod-mul, an adder E1 and an adder E2.

[0004] The round key expansion module Round_key_expand_1 and the round key expansion module Round_key_expand_2 expand the keys key1 and key2 respectively, and output the round keys Rk1 and Rk2. The encryption / decryption module Endec_1 calculates the round key Rk1 output by the round key expansion module Round_key_expand1 and the adjustment value Tweak_value, and outputs the intermediate data Tw. The modular multiplication module Mod-mul is based on the parameter a j The output data Tw of the encryption / decryption module Endec_1 is subjected to modular multiplication operation, and output is Tw', where j represents the round. The adder E1 receives the plaintext data Din and the output data Tw' of the modular multiplication module Mod-mul, performs a logical addition operation, and outputs the intermediate data D1. The encryption / decryption module Endec_2 calculates the output data D1 of the adder E1, and outputs D2. The adder E2 performs a logical addition operation on the output data D2 of the encryption / decryption module Endec_2 and the output data Tw' of the modular multiplication module Mod-mul, and outputs the ciphertext data Dout.

[0005] When the XTS encryption / decryption circuit encrypts plaintext data or decrypts ciphertext data, the plaintext data or ciphertext data is divided into multiple data units (DataUnit, abbreviated as DU) according to a specified size, and encryption calculations are performed according to the data units. For example, the specified size of a data unit is 520 bytes (bytes). Each time the data Din input to the XTS encryption / decryption circuit is a data unit of 520 bytes, and each data unit is encrypted by XTS to obtain a ciphertext, denoted as CipherUnit, CipherUnit = {C1~C m}, and the output data CipherUnit is also a data unit of 520 bytes.

[0006] Each data unit includes m data blocks (blocks). Let P represent the data block, then DU = {P1~P m}, the sizes of P1 to P m-1 are all 128 bits, and P m can be equal to 128 bits or less than 128 bits. The encryption / decryption module Endec_2 encrypts or decrypts each data block, and the encryption / decryption algorithm is a publicly available standard. Taking the encryption algorithm as an example, it is denoted as C i = endec(P i ), 1 <= i <= m - 2. If P m is 128 bits, then the above formula also applies to the cases of i = m - 1 and m, that is, C m-1 = endec(P m-1 ), C m = endec(P m ). If P m is less than 128 bits, then ciphertext stealing is required during the encryption process of P m-1 and P m .

[0007] Figure 2 shows a schematic diagram of the ciphertext stealing process in the XTS mode. As Figure 2 shown, the encryption / decryption module Endec encrypts P m-1 (other information required for calculating P Figure 2 is not shown in m-1 , such as the round key corresponding to P m-1 ), generates C m and C p , denoted as {C m , C p} = endec(P m-1 ). C p and P mConcatenate to form a 128-bit data block, and input this data block into the encryption / decryption module Endec (other information required for calculating P Figure 2 is not shown in m , such as the round key corresponding to P m ). The encryption / decryption module Endec encrypts the 128-bit data block formed by concatenation, and the output result is C m-1 , denoted as C m-1 = endec({C p , P m}), where {,} represents the concatenation operation.

[0008] Among them, the data block formed by concatenating C m and C p is 128 bits, and their respective sizes depend on the size of P m . The size after concatenating C p with P m is 128 bits.

[0009] The encryption / decryption module Endec performs encryption calculations on DU = {P1~P m}, and obtains the calculation result CipherUnit = {C1~C m}, and sequentially outputs C1~C m-2 , C m-1 , C m .

[0010] For example, the XTS encryption / decryption circuit requires 32 cycles to encrypt and calculate a 128-bit data block (from inputting the data block to outputting the calculation result). For the data blocks P1 - P m-1 , each data block is 128 bits, and the encryption calculation process of each data block is independent and does not depend on the calculation result of the previous data block when encrypting and calculating it. Therefore, the data blocks P1 - P m-1 can be continuously input into the encryption / decryption module Endec. For the data block P m , since it is less than 128 bits, it is necessary to wait for the completion of the operation of Pm - 1 to obtain C p before starting the encryption calculation (C p and P m form a data block with a length of 128 bits). That is, it is necessary to wait for the completion of the calculation of P m-1 before starting the calculation of P m . Therefore, after inputting the data block P m-1 into the encryption / decryption module Endec, it is necessary to wait 32 cycles before calculating the data block P mCalculations are performed. Thus, during the 32 cycles of waiting for the Pm-1 operation, the XTS encryption / decryption circuit is not fully utilized, and the processing efficiency is affected.

[0011] Figure 3 Fig. shows the timing diagram of the XTS encryption / decryption circuit processing 3 data units (DU1, DU2, DU3). In Figure 3 it, the 3 data units DU1, DU2, and DU3 of 520 Byte each are shown by legends of different colors respectively. The "Endec input" line represents the data input to Endec, the "Endec output" line represents the data output by Endec, and the "XTS Output" line represents the output data of the XTS encryption / decryption circuit. Each 520 Byte data unit includes 33 data blocks (data block 1 to data block 33). Among them, data blocks 1 to 32 are all 128 bit, and data block 33 is less than 128 bit. Each data block requires 32 cycles from input to corresponding data output. Data blocks 1 to 32 are all 128 bit, and the encryption calculation process of each data block is independent and does not depend on the calculation result of the previous data block during its encryption calculation. Therefore, data blocks 1 to 32 can be continuously input to endec. Since data block 33 is less than 128 bit, ciphertext stealing processing is required during the calculation of data block 32 and data block 33, and data block 33 needs to wait for data block 32 to complete the calculation (wait for 32 cycles) before it can be input to endec. Furthermore, in the timing diagram as shown in Figure 3 it, data blocks 1 to 32 in DU1 are continuously input to the encryption / decryption module Endec (such as the blue legend marked with DU1(1-32) in the "Endec input" line in Figure 3 ), wait for 32 cycles, and then input data block 33 in DU1 (such as the blue legend marked with 33 in the "Endec input" line in Figure 3 ); data blocks 1 to 32 in DU2 are continuously input (such as the pink legend marked with DU2(1-32) in the "Endec input" line in Figure 3 ), wait for 32 cycles, and then input data block 33 in DU2 (such as the pink legend marked with 33 in the "Endec input" line in Figure 3 ); data blocks 1 to 32 in DU3 are continuously input (such as the yellow legend marked with DU1(1-32) in the "Endec input" line in Figure 3 ), wait for 32 cycles, and then input data block 33 in DU3 (such as the yellow legend marked with 33 in the "Endec input" line in Figure 3In the "Endec input" row, there is a yellow legend marked with 33). It can be seen from this that there will be an idle time of 32 cycles when the XTS encryption / decryption circuit calculates a 520-byte data, and it is impossible to continuously input data to it. Similarly, there is an idle time of 32 cycles when outputting the calculation result corresponding to the 520-byte data, and it is impossible to continuously output, which affects the processing efficiency of the XTS encryption / decryption circuit.

[0012] The encryption process and decryption process of the XTS mode are symmetric. If the last data block contained in the ciphertext data is less than 128 bits during the decryption process, ciphertext stealing is also required when decrypting the ciphertext data, that is, continuous input / output is also impossible during the decryption process, thereby affecting the processing efficiency of the XTS encryption / decryption circuit. Summary of the Invention

[0013] To solve the above technical problems or at least partially solve the above technical problems, an embodiment of the present application provides an XTS encryption circuit and an XTS decryption circuit.

[0014] In a first aspect, an embodiment of the present application provides an XTS encryption circuit. The encryption circuit is applicable to perform an encryption operation on a data unit based on a block encryption algorithm in the XTS mode. The data unit includes m data blocks. The first data block to the (m - 1)th data block each have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes. m is an integer greater than 1. The encryption circuit includes a first round key expansion module, a second round key expansion module, a first encryption module, a second encryption module, a modular multiplication module, a first adder, and a second adder;

[0015] The encryption circuit further includes a first buffer unit, which is used to buffer the mth data block of the target data unit input to the second encryption module, so as to input the first to (m - 1)th data blocks of the next target data unit during the process of the second encryption module performing ciphertext stealing processing on the (m - 1)th data block of the target data unit, so as to form a continuous input to the second encryption module.

[0016] In an optional embodiment, the encryption circuit further includes: a second buffer unit, a third buffer unit, a fourth buffer unit, a fifth buffer unit, a first multiplexer, and a second multiplexer;

[0017] The second cache unit caches the calculation results corresponding to the 1st to the (m - 2)th data blocks of the target data unit processed by the second encryption module; the third cache unit caches the calculation result corresponding to the (m - 1)th data block of the target data unit processed by the second encryption module; the calculation result corresponding to the (m - 1)th data block includes a first data shard and a second data shard, and the data block formed by splicing the second data shard and the mth data block of the target data unit has a preset number of bytes; the fourth cache unit caches the first data shard; the fifth cache unit caches the calculation result corresponding to the mth data block of the target data unit processed by the second encryption module; the output end of the first multiplexer is coupled to the first adder, and is used to select data blocks from the 1st to the (m - 1)th data blocks, the mth data block cached by the first cache unit, and the second data shard cached by the third cache unit and provide them to the first adder; the second multiplexer sequentially obtains the calculation results corresponding to the 1st to the (m - 2)th data blocks from the second cache unit, the calculation result corresponding to the mth data block from the fifth cache unit, and the first data shard from the fourth cache unit and outputs them.

[0018] In an alternative embodiment, the first multiplexer continuously provides the 1st to the (m - 1)th data blocks in the first data unit to the second encryption module, and the second encryption module operates on the 1st to the (m - 1)th data blocks in the first data unit; it takes (m - 1) cycles for the second encryption module to receive the output calculation result for each data block; the mth data block in the first data unit is cached in the first cache unit so that the 1st to the (m - 1)th data blocks in the second data unit are input to the second encryption module during the ciphertext stealing process of the (m - 1)th data block in the first data unit;

[0019] In response to caching the mth data block in the first data unit in the first cache unit, the first multiplexer continuously provides the 1st to the (m - 1)th data blocks in the second data unit to the second encryption module; the mth data block in the second data unit is cached in the first cache unit;

[0020] While receiving the first to the (m - 1)-th data blocks in the second data unit, the second encryption module sequentially outputs the calculation results corresponding to the first to the (m - 1)-th data blocks in the first data unit, caches the calculation results corresponding to the first to the (m - 2)-th data blocks in the first data unit into the second cache unit, caches the first and second data shards corresponding to the (m - 1)-th data block in the first data unit into the third cache unit, and caches the first data shard corresponding to the (m - 1)-th data block in the first data unit into the fourth cache unit;

[0021] In response to providing the (m - 1)-th data block in the second data unit to the second encryption module, the first multiplexer obtains the second data shard corresponding to the first data unit from the third cache unit and the m-th data block in the first data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block to the second encryption module;

[0022] While receiving the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block, the second encryption module sequentially outputs the calculation results corresponding to the first to the (m - 1)-th data blocks in the second data unit, caches the calculation results corresponding to the first to the (m - 2)-th data blocks in the second data unit into the second cache unit, caches the first and second data shards corresponding to the (m - 1)-th data block in the second data unit into the third cache unit, and caches the first data shard corresponding to the (m - 1)-th data block in the second data unit into the fourth cache unit;

[0023] In response to providing the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block to the second encryption module, the first multiplexer continuously provides the first to the (m - 1)-th data blocks in the third data unit to the second encryption module; caches the m-th data block in the third data unit into the first cache unit;

[0024] In response to providing the (m - 1)-th data block in the third data unit to the second encryption module, the first multiplexer obtains the second data shard corresponding to the second data unit from the third cache unit and the m-th data block in the second data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block to the second encryption module;

[0025] While receiving the (m-2)-th data block in the third data unit, the second encryption module outputs the calculation result corresponding to the m-th data block in the first data unit, and caches the calculation result corresponding to the m-th data block in the first data unit into the fifth cache unit.

[0026] In an alternative embodiment, the encryption circuit sequentially obtains the calculation results corresponding to the 1st to (m-2)-th data blocks in the first data unit from the second cache unit, obtains the calculation result corresponding to the m-th data block in the first data unit from the fifth cache unit, and obtains the first data shard output corresponding to the (m-1)-th data block in the first data unit from the fourth cache unit and outputs it; in response to the completion of the output of the first data shard corresponding to the (m-1)-th data block in the first data unit, the encryption circuit obtains the calculation results corresponding to the 1st to (m-2)-th data blocks in the second data unit from the second cache unit, obtains the calculation result corresponding to the m-th data block in the second data unit from the fifth cache unit, and obtains the first data shard output corresponding to the (m-1)-th data block in the second data unit from the fourth cache unit and outputs it.

[0027] In an alternative embodiment, the first cache unit, the second cache unit, the third cache unit, the fourth cache unit, and the fifth cache unit are all hardware queues. Data is added to the tail of the hardware queue, and data is retrieved from the head of the hardware queue.

[0028] In an alternative embodiment, after obtaining the calculation result corresponding to the m-th data block in the first data, the encryption circuit outputs the results corresponding to each data block in the first data unit, or after obtaining the calculation results corresponding to the 1st to (m-2)-th data blocks in the first data unit, outputs the calculation results corresponding to the 1st to (m-2)-th data blocks, and after obtaining the calculation result corresponding to the m-th data block in the first data unit, outputs the calculation result of the m-th data block in the first data unit and the calculation result of the (m-1)-th data block in the first data unit.

[0029] In an alternative embodiment, the first cache unit is further configured to cache data related to the m-th data block.

[0030] In an alternative embodiment, the encryption circuit further includes a sixth cache unit; the sixth cache unit is coupled to the first encryption module and is configured to cache the data output by the first encryption module.

[0031] In an alternative embodiment, the encryption circuit further includes a seventh cache unit, an eighth cache unit, and a third multiplexer;

[0032] The seventh cache unit is coupled to the second round key expansion module and is configured to cache the round key data corresponding to the second data unit output by the second round key expansion module; the eighth cache unit is configured to cache the round key data corresponding to the first data unit output by the second round key expansion module, where the first data unit is input to the second encryption module prior to the second data unit; the output end of the third multiplexer is coupled to the second encryption module, and the third multiplexer is configured to obtain the round key data corresponding to the data block input to the second encryption module from the seventh cache unit or the eighth cache unit and provide it to the second encryption module.

[0033] In an alternative embodiment, the encryption circuit further includes a ninth cache unit, and the ninth cache unit is configured to cache the identification information of the data unit input to the encryption circuit.

[0034] In an alternative embodiment, the first multiplexer continuously provides data blocks to the second encryption module in a first data mode, and the first data mode is shown in the following formula (1):

[0035] xDU_i = {sDU(i - 2)33, sDU(i)1 - 32} (1)

[0036] Where xDU_i represents the data block provided to the second encryption module. If m is 33, sDU(i - 2)33 represents the data block obtained by splicing the second data shard corresponding to the (m - 1)th data block in the (i - 2)th data unit and the mth data block in the (i - 2)th data unit, and sDU(i)1 - 32 represents the first to (m - 1)th data blocks in the ith data unit; i is an integer greater than or equal to 3.

[0037] The second encryption module outputs the calculation result in a second data mode, and the second data mode is shown in the following formula (2):

[0038] xCipher_i = {sCU(i - 2)33, sCU(i)1 - 32} (2)

[0039] xCipher_i represents the calculation result output by the second encryption module, sCU(i - 2)33 represents the calculation result of the mth data block in the (i - 2)th data unit, and sCU(i)1 - 32 represents the calculation results corresponding to the first to (m - 1)th data blocks in the ith data unit.

[0040] The encryption circuit outputs the encrypted data in a third data mode, and the third data mode is shown in the following formula (3):

[0041] xCU_j = {CU(j)1 - 31, CU(j)32 - 33} (3)

[0042] xCU_j represents the encrypted data output by the encryption circuit, CU(j)1-31 represents the calculation results of the first to the (m-2)th data blocks in the jth data unit, CU(j)32-33 represents the calculation result of the mth data block and the calculation result corresponding to the (m-1)th data block in the jth data unit, and j = i-1.

[0043] In an alternative embodiment, each data block of the xDU_i is continuously input into the second encryption module, where one data block of the xDU_i is input into the second encryption module in each cycle; the second encryption module continuously outputs each data block of the xCipher_i, where one data block of the xCipher_i is output from the second encryption module in each cycle; and the encryption circuit continuously outputs each data block of the xCU_j, where one data block of the xCU_j is output from the encryption circuit in each cycle.

[0044] In an alternative embodiment, each data block of the DU_i and the xDU_(i+1) is continuously input into the second encryption module, where the first data block of the xDU_(i+1) is input into the second encryption module in the next cycle after the last data block of the xDU_i is input into the second encryption module; the second encryption module continuously outputs each data block of the xCipher_i and the xCipher_(i+1), where the first data block of the xCipher_(i+1) is output from the second encryption module in the next cycle after the last data block of the xCipher_i is output from the second encryption module; and the encryption circuit continuously outputs each data block of the xCU_j and the xCU_(j+1), where the first data block of the xCU_(j+1) is output from the encryption circuit in the next cycle after the last data block of the xCU_j is output from the encryption circuit.

[0045] Second aspect, an embodiment of the present application provides an XTS decryption circuit, which is applicable to decrypting a data unit based on a block decryption algorithm in XTS mode. The data unit includes m data blocks. The first to the (m - 1)th data blocks each have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes. m is an integer greater than 1. The decryption circuit includes a first-round key expansion module, a second-round key expansion module, a first decryption module, a second decryption module, a modular multiplication module, a first adder, and a second adder; the decryption circuit further includes a first buffer unit, which is used to buffer the mth data block of the target data unit input to the second decryption module, so as to input the first to the (m - 1)th data blocks of the next target data unit during the process of the second decryption module performing ciphertext stealing processing on the (m - 1)th data block of the target data unit, so as to form a continuous input to the second decryption module.

[0046] The XTS encryption / decryption circuit provided by the embodiment of the present application caches the mth data block of the target data unit (the previous data unit) input to the second encryption / decryption module into the first buffer unit. During the process of performing ciphertext stealing processing on the (m - 1)th data block of the previous target data unit, the first to the (m - 1)th data blocks of the next target data unit are input to the second encryption / decryption module, so that data blocks are continuously input to the second encryption / decryption module during the time of waiting for the calculation result of the (m - 1)th data block of the previous data unit. During the time of waiting for the calculation result of the (m - 1)th data block of the previous data unit, the second encryption / decryption module still has data to process and will not be idle, making full use of the second encryption / decryption module and improving the processing efficiency of the XTS encryption / decryption circuit. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings described below are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0048] Figure 1 Shows a schematic structural diagram of a standard XTS encryption / decryption circuit provided by the prior art;

[0049] Figure 2 Shows a schematic flowchart of the XTS encryption / decryption circuit performing ciphertext stealing processing;

[0050] Figure 3 Shows a timing diagram of a standard XTS encryption / decryption circuit provided by the prior art;

[0051] Figure 4 Shows the structural diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0052] Figure 5 Shows the structural diagram of the XTS encryption / decryption circuit provided by another embodiment of the present application;

[0053] Figure 6 Shows the structural diagram of the XTS encryption / decryption circuit provided by yet another embodiment of the present application;

[0054] Figure 7 Shows the timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0055] Figure 8A 、 8B And 8C show the data mode of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0056] Figure 9 Shows the data input / output mode of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0057] Figure 10 Shows the structural diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0058] Figure 11 Shows the structural diagram of the XTS encryption / decryption circuit provided by another embodiment of the present application;

[0059] Figure 12 Shows the structural diagram of the XTS encryption / decryption circuit provided by yet another embodiment of the present application;

[0060] Figure 13 Shows the timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0061] Figure 14A 、 14B And 14C show the data mode of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0062] Figure 15 Shows the data input / output mode of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0063] Figure 16 Shows another timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0064] Figure 17 Shows yet another timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0065] Figure 18Shows another timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application. Detailed implementation manners

[0066] The following combines the accompanying drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0067] Figure 4 Shows the structural diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application.

[0068] As Figure 4 shown, the XTS encryption / decryption circuit includes a round key expansion module Round_key_Expand_1, a round key expansion module Round_key_Expand_2, an encryption / decryption module Endec_1, an encryption / decryption module Endec_2, a modular multiplication module Mod-mul, an adder E1, an adder E2, a multiplexer mux1, a multiplexer mux2, a buffer unit Buffer1, a buffer unit Buffer2, a buffer unit Buffer3, a buffer unit Buffer4, and a buffer unit Buffer5.

[0069] Among them, the functions of the round key expansion module Round_key_Expand_1, the round key expansion module Round_key_Expand_2, the encryption / decryption module Endec_1, the encryption / decryption module Endec_2, the modular multiplication module Mod-mul, the adder E1, and the adder E2 are the same as those of Figure 1 the standard XTS encryption / decryption circuit shown. To avoid repetition, they will not be described here again.

[0070] The XTS encryption process and the decryption process are symmetric. Taking the encryption process as an example, the XTS encryption / decryption circuit of the embodiment of the present application will be described. The following uses the data unit DU = {P1~P m}, where the sizes of P1 to P m-1 are all 128 bits, and P m is less than 128 bits as an example to illustrate the circuit provided in this embodiment.

[0071] The buffer unit Buffer1 is used to buffer the data block P m . If the last data block of the current data unit input to the XTS encryption / decryption circuit is not 128 bits, then the last data block P m is buffered in Buffer1, so that when processing P of the current data unitm-1 During the encryption and ciphertext stealing processes, the 128-bit data block of the next data unit can be input into the circuit first, so as to continuously input data to Endec_2 and prevent it from being idle due to ciphertext stealing. As an example, P m-1 The encryption process of P includes, for example, 32 cycles. In these cycles, 32 128-bit data blocks of the next data unit are sequentially input to Endec_2. Since the first 32 data blocks of the data unit are sequentially input to Endec_2, these data blocks do not need to be cached in the buffer unit Buffer1. Therefore, the size of the buffer unit Buffer1 only needs to accommodate 1 128-bit data block.

[0072] The buffer unit Buffer2 is used to cache the data blocks P1 - P m-2 and the corresponding calculation results C1 - C m-2 .

[0073] The buffer unit Buffer3 is used to cache the data blocks P m-1 and the corresponding calculation results C p and C m . The buffer unit Buffer4 caches C m . Since it is necessary to splice the calculation result C m-1 corresponding to the data block P p with the data block P m to form a 128-bit data block and input it into the encryption / decryption module Endec2, it is necessary to cache the calculation result C m-1 corresponding to the data block P p and C m in Buffer3. To ensure that the cached C p is not lost when outputting C m , C m is further cached in Buffer4.

[0074] The buffer unit Buffer5 is used to cache the calculation result C m corresponding to the last data block P m-1 .

[0075] Optionally, when the XTS encryption / decryption circuit outputs the calculation results corresponding to P1 to P m , it can obtain and output data from the buffer units Buffer2, Buffer5, and Buffer4 in the order of C1 - C m when the calculation of the data block P m is completed, or it can also output the calculation results C1 - C m-2 corresponding to P1 - P m-2 first, and when the calculation result C m corresponding to Pm-1 Then output C m-1 and P m-1 The corresponding calculation result C m . If P is calculated m The corresponding calculation result C m-1 When, C1 - C m-2 Has not been output yet, first cache C m-1 Into Buffer5.

[0076] The multiplexer Mux is used to select a signal from multiple digital input signals and forward it, outputting different selected signals to the same output line. In this embodiment, the input end of the multiplexer mux1 receives the data block P1 - P of the data unit DU externally input to the XTS encryption / decryption circuit m-1 , P provided by the buffer unit Buffer3 m-1 The corresponding calculation result C p , and P cached in the buffer unit Buffer1 m . The output end of the multiplexer mux1 is coupled to the input end of the adder E1. The multiplexer mux1 selects the data input to the adder E1 from the data block P1 - P m-1 , P m-1 The corresponding calculation result C p , P cached in the buffer unit Buffer1 m . The input end of the multiplexer mux2 is coupled to the buffer units Buffer2, Buffer4 and Buffer5, and obtains and outputs data from the buffer units Buffer2, Buffer5 and Buffer4 in the order of C1 - C m .

[0077] Taking the data unit DU a ={P 1a ~P 33a}, DU b ={P 1b ~P 33b}, DU c ={P 1c ~P 33c}, P 1a To P 32a Are all 128bit in size, P 33a Is less than 128bit, P 1b To P 32b Are all 128bit in size, P 33b Is less than 128bit, P 1c To P 32c Are all 128bit in size, P 33cTaking the case of less than 128 bits as an example to illustrate the processing process of the XTS encryption / decryption circuit according to the embodiments of the present application, where each data block of the data unit DU is sequentially provided to the XTS encryption / decryption circuit:

[0078] (1) Input the data blocks P 1a to P 32a continuously into the encryption / decryption module Endec, cache the data block P 33a into Buffer1. After 32 cycles when the data block P 1a is input to Endec, cache the corresponding encryption results C 1a to P 31a sequentially into Buffer2, cache the encryption result C 1a corresponding to P 31a and C 32a into Buffer3, and cache the C pa cached in Buffer3 into Buffer4. 33a 33a 33a 1b

[0079] (2) After caching the data block P 33a into Buffer1, input the data blocks P 1b to P 32b continuously into the encryption / decryption module Endec. Optionally, there is no gap between the data block P 32a and the data block P 1b , but they are input into the encryption / decryption module Endec continuously in time to maximize the utilization rate of the input encryption / decryption module Endec. And cache the data block P 33b into Buffer1. Cache the corresponding encryption results C 1b to P 31b into Buffer2, cache the encryption result C 1b corresponding to P 31b and C 32b into Buffer3, and cache the C pb cached in Buffer3 into Buffer4. 33b 33b 32b 32a

[0080] (3) After the data block P 32b is input to Endec, at this time, 32 cycles have passed since the data block P 32a was input to Endec, and the corresponding C pa has been calculated and cached in the cache unit Buffer3. Next, take out P 33a from the cache unit Buffer1, take out C pa from the cache unit Buffer3, and take P33a and C pa They are concatenated into a 128-bit data block and input to the encryption / decryption module Endec. Next, the data block P 1c from P 32c is continuously input to the encryption / decryption module Endec. Optionally, P 33a and C pa are concatenated into a 128-bit data block. There is no gap between the data block and the data block P 1c being respectively input to the input encryption / decryption module Endec, but they are continuously input to the encryption / decryption module Endec in time to maximize the utilization rate of the input encryption / decryption module Endec. The data block P 33c is cached in Buffer1. The corresponding encryption result C 33a of P 32a is cached in Buffer5.

[0081] In the above processing, the data block P 33a is cached in Buffer1. During the ciphertext stealing process for DU a , the first 32 data blocks P b of DU 1b from P 32b are input to the encryption / decryption module Endec2, so that data blocks are continuously input to the encryption / decryption module Endec during the time of waiting for C pa . During the time of waiting for C pa , the encryption / decryption module Endec still has data to process and there will be no idle time, fully utilizing the encryption / decryption module Endec and improving the processing efficiency of the XTS encryption / decryption circuit.

[0082] In an alternative embodiment, the buffer unit Buffer1 can also cache the corresponding Tw or other control information of the data block P m .

[0083] Figure 4 The buffer units (Buffer) shown in are, for example, hardware queues. Data is added to the buffer unit only through the queue tail, and data is taken out of the buffer unit only through the queue head, without supporting access to other elements of the queue except the queue head / queue tail. And each element of the queue has a determined size and is accessed as a whole. Thus, compared with a general random access memory, the hardware queue has higher performance and occupies less hardware resources.

[0084] Figure 5 shows the structural diagram of the XTS encryption / decryption circuit according to another embodiment of the present application. As Figure 5 shown, this XTS encryption / decryption circuit is in Figure 4Based on the illustrated embodiment, it further includes buffer unit Buffer6, buffer unit Buffer7, buffer unit Buffer8, and multiplexer mux3.

[0085] Buffer unit Buffer6 is coupled to the encryption / decryption module Endec_1 and is used to cache the output data of the encryption / decryption module Endec_1. To improve the encryption calculation speed and ensure that when each data block of the data unit DU is input to the encryption / decryption module Endec_2, its corresponding Tw has been calculated, the Tweak_value is encrypted in advance. Since the Tweak_value will be encrypted in advance, Buffer6 is required to cache its encryption result. In an alternative embodiment, Buffer6 can also cache control information related to Tw, such as the data length of the data unit, the encryption / decryption enable signal, the encryption / decryption selection signal, etc. Optionally, since the calculation of Tw does not depend on the data unit DU, the Tw required for each data unit DU can be calculated beforehand or additionally, rather than using Figure 5 the circuit structure including Endec_1 and Buffer6 shown.

[0086] Buffer unit Buffer7 is coupled to the round key expansion module Round_key_Expand_2 and is used to cache the round key Rk2 output by Round_key_Expand_2. To improve the encryption calculation speed and ensure that when the data unit DU is input to the encryption / decryption module Endec_2, its corresponding round key Rk2 has been calculated, the key2 is expanded in advance and the obtained round key Rk2 is cached in Buffer7.

[0087] To improve the processing efficiency of the XTS encryption / decryption circuit, during the ciphertext stealing process of the previous data unit, the next data unit is input to it. To ensure that the round key Rk2 corresponding to the previous data unit is not overwritten by the round key Rk2 corresponding to the next data unit, the round key Rk2 corresponding to the previous data unit cached in Buffer7 is cached in Buffer8.

[0088] Multiplexer mux3 is coupled to buffer unit Buffer7 and buffer unit Buffer8, and reads the round key Rk2 corresponding to each of the multiple data blocks currently processed by the encryption / decryption module Endec2 from Buffer7 and Buffer8.

[0089] Figure 6 The structure diagram of the XTS encryption / decryption circuit according to another embodiment of the present application is shown. As Figure 6 shown, this XTS encryption / decryption circuit is in Figure 5Based on the illustrated embodiment, it further includes a cache unit Buffer9. In order to ensure that when the XTS encryption / decryption circuit outputs data, the data unit corresponding to the output data can be determined, the cache unit Buffer9 is used to cache the identification information of the data unit. According to this identification information, the data unit corresponding to the current calculation result output by the XTS encryption / decryption circuit can be determined. In an alternative embodiment, the identification information cached in Buffer9 can be the length of the data unit, and counting control is performed according to the length of the data unit to ensure the normal output of the data. In other alternative embodiments, other control information can also be cached in Buffer9, such as encryption / decryption enable signals, encryption / decryption selection signals, etc.

[0090] Figure 7 shows the timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application. In Figure 7 , legends of different colors represent different data units. For example, the blue legend represents the data unit DU(1), the pink legend represents the data unit DU(2), the yellow legend represents the data unit DU(3), and the white legend represents the data unit DU(4). "sDU(i)1-32" represents the 1st to 32nd 128-bit data blocks in the data unit DU(i), that is, sDU(i)1-32 = {P1, P2, P3,..., P31, P32} i ."sDU(i)33" represents the 128-bit data block formed by splicing the calculation result C p of the 32nd data block in the data unit DU(i) with the 33rd data block, that is, sDU(i)33 = {Cp, P33} i , {C33, Cp} = Cipher(P32), and Cipher(P32) represents the calculation result of P32. "sCU(i)1-31" represents the calculation results corresponding to the 1st to 31st data blocks in the data unit DU(i), sCU(i)1-31 = {C1, C2, C3......, C29, C30, C31} i ."sCU(i)33" represents the calculation result corresponding to the 33rd data block in the data unit DU(i), sCU(i)33 = {C32} i ."sCU(i)32" represents the calculation result corresponding to the 32nd data block in the data unit DU(i), sCU(i)32 = {C33} i ."Endec input" represents the input data of the encryption / decryption module Endec, "Endec output" represents the output data of the encryption / decryption module Endec, and "XTS Output" represents the output data of the XTS encryption / decryption circuit.

[0091] As Figure 7As shown, first, the first to the 32nd 128-bit data blocks in the data unit DU(1) (such as Figure 7 the blue legend marked with sDU1(1 - 32) in the "Endecinput" row in Figure 7 ) are continuously input into Endec. Then, the first to the 32nd 128-bit data blocks in the data unit DU(2) (such as p the pink legend marked with sDU2(1 - 32) in the "Endec input" row in p ) are continuously input into Endec. For example, it takes 32 cycles for Endec to encrypt and calculate a 128-bit data block (from inputting the data block to outputting the calculation result). When the 32nd data block in the data unit DU(2) is input to Endec, the calculation of the 32nd data block in the data unit DU(1) is completed, and the corresponding C Figure 7 can be obtained. The 128-bit data block formed by splicing C Figure 7 with the 33rd data block in the data unit DU(1) can be input into Endec. Therefore, after the first to the 32nd 128-bit data blocks in the data unit DU(2) are input, the 33rd data block in the data unit DU(1) (such as p the blue legend marked with 33 in the "Endec input" row in p ) is input. After the 33rd data block in the data unit DU(1) is input to Endec, the calculation of the 32nd data block in the data unit DU(2) is not yet completed. To prevent Endec from being idle, the first to the 32nd data blocks in the data unit DU(3) (such as Figure 7 the yellow legend marked with sDU3(1 - 32) in the "Endec input" row in Figure 7In the "Endec input" row, the white legend marked with sDU4(1 - 32). When the 32nd data block in the data unit DU(4) of the Endec input is completed, the calculation of the 32nd data block in the data unit DU(3) is completed, obtaining the corresponding C p , C can be p input into the Endec as a 128-bit data block formed by splicing with the 33rd data block in the data unit DU(3). Therefore, after the input of the 1st to 32nd 128-bit data blocks in the data unit DU(2) is completed, the 33rd data block in the data unit DU(3) is input (as shown in Figure 7 the yellow legend marked with 33 in the "Endec input" row in

[0092] The encryption / decryption module Endec outputs the corresponding calculation results in the order of the input data. The calculation of each data block by Endec requires 32 cycles. Therefore, the output of the calculation result corresponding to each data block lags 32 cycles behind the input of that data block. When the 1st data block in the data unit DU(2) is input, the calculation of the 1st data block in the data unit DU(1) by Endec is completed, obtaining its calculation result. The moment when Endec outputs the calculation result of the 1st data block in the data unit DU(1) is the same as the moment when the 1st data block in the data unit DU(2) is input. Therefore, in Figure 7 the "Endec output" row, the starting end of the blue legend marked with sCU(1)1 - 32 is horizontally aligned with the starting end of the pink legend marked with sDU(2)1 - 32 in the "Endec input" row (the horizontal right direction represents the direction of time passage). Also, because it takes 32 cycles to input sDU(2)1 - 32 and 32 cycles to output sCU(1)1 - 32, the ending end of the blue legend marked with sCU(1)1 - 32 is horizontally flush with the ending end of the pink legend marked with sDU(2)1 - 32 in the "Endec input" row. After the calculation of the 1st to 32nd data blocks in the data unit DU(1) is completed, the calculation of the 1st to 32nd data blocks in the data unit DU(2) starts. Then, after the output of the calculation results of the 1st to 32nd data blocks in the data unit DU(1) is completed, the output of the calculation results of the 1st to 32nd data blocks in the data unit DU(2) starts (as shown in Figure 7In the "Endec output" row, there is a pink legend marked with sCU(2)1-32). When the calculation results of the 1st to 32nd data blocks in the data unit DU(2) are output, at this time, 32 cycles have passed since the 33rd data block in the input data unit DU(1), then the calculation of the 33rd data block in the data unit DU(1) is completed at this time, and the calculation result of the 33rd data block in the data unit DU(1) can be output (such as Figure 7 In the "Endec output" row, there is a blue legend marked with 33). After the calculation result of the 33rd data block in the data unit DU(1) is output, the calculation results of the 1st to 32nd data blocks in the data unit DU(3) start to be output (such as Figure 7 In the "Endec output" row, there is a yellow legend marked with sCU(3)1-32). When the calculation results of the 1st to 32nd data blocks in the data unit DU(3) are output, at this time, 32 cycles have passed since the 33rd data block in the input data unit DU(2), then the calculation of the 33rd data block in the data unit DU(2) is completed at this time, and the calculation result of the 33rd data block in the data unit DU(2) can be output (such as Figure 7 In the "Endec output" row, there is a pink legend marked with 33).

[0093] For the output XTS Output of the XTS encryption / decryption circuit, it starts to be output after the calculation results of several data blocks (such as the first 5 data blocks) in the data unit DU(1) are obtained (such as Figure 7 In the "XTS output" row, there is a blue legend marked with sCU(1)1-31). After the calculation result corresponding to the 31st data block is output, since the 33rd data block has not been calculated yet, it waits for the calculation of the 33rd data block to be completed. After the calculation of the 33rd data block is completed, the calculation result of the 33rd data block is output (such as Figure 7 In the "XTS output" row, there is a blue legend marked with 33), and the calculation result of the 32nd data block (such as Figure 7 In the "XTS output" row, there is a blue legend marked with 32). It can be understood that when the XTS encryption / decryption circuit outputs the calculation results of the data unit DU(1), Figure 7In the example, there is a gap between the output sCU(1)1-31 and the output sCU(1)33, rather than a continuous output. The size of this gap depends on the lag time of the XTS Output relative to the EndecOutput for CU(1). Optionally, by caching sCU(1)1-31 obtained from the Endec Output for multiple cycles, it is possible to achieve a continuous output of sCU(1)1-31, sCU(1)33, and sCU(1)32, but this requires an increase in the capacity of the cache unit.

[0094] If the calculations for the first to the 31st data blocks in data unit DU(2) have been completed before the calculation result of the 32nd data block in output data unit DU(1), then immediately after the calculation result of the 32nd data block in output data unit DU(1) is output, the calculation results of the first to the 31st data blocks in data unit DU(2) are output (as Figure 7 shown by the pink legend marked with sCU(2)1-31 in the "XTS output" row in Figure 7 ). When the calculation results of the first to the 31st data blocks in data unit DU(2) are completed, the calculations for the 32nd and 33rd data blocks in data unit DU(2) have also been completed, so the calculation result of the 33rd data block (as Figure 7 shown by the pink legend marked with 33 in the "XTS output" row in

[0095] and the calculation result of the 32nd data block (as

[0096] shown by the pink legend marked with 32 in the "XTS output" row in p can be immediately output, and there is no interruption during the process of outputting the corresponding calculation results of data unit DU(2).

[0097] Optionally, in the 15th cycle of calculating the 32nd data block in data unit DU(1), obtain the calculation result outputs corresponding to the 1st to 31st data blocks in data unit DU(1) from Buffer2, obtain the calculation result output corresponding to the 33rd data block in data unit DU(1) from Buffer4, and obtain the calculation result output corresponding to the 32nd data block in data unit DU(1) from Buffer5. This eliminates the gap between sCU(1)31 and sCU(1)33 in the XTS Output output. Then, obtain the calculation result outputs corresponding to the 1st to 31st data blocks in data unit DU(2) from Buffer2, obtain the calculation result output corresponding to the 33rd data block in data unit DU(2) from Buffer4, and obtain the calculation result output corresponding to the 32nd data block in data unit DU(2) from Buffer5. Finally, obtain the calculation result outputs corresponding to the 1st to 31st data blocks in data unit DU(3) from Buffer2, obtain the calculation result output corresponding to the 33rd data block in data unit DU(3) from Buffer4, and obtain the calculation result output corresponding to the 32nd data block in data unit DU(3) from Buffer5.

[0098] In the embodiment of the present application, a buffer unit Buffer1 is set in the XTS encryption / decryption circuit to buffer the last group of data blocks that are not 128 bits and need to wait for the result of ciphertext stealing processing. Thus, when waiting for the result of ciphertext stealing processing corresponding to the current data unit, calculate the 128-bit data blocks in the next data unit, avoiding the idle and pause of the encryption / decryption module Endec2 during operation, and improving the processing efficiency of the XTS encryption / decryption circuit. Similarly, to ensure that the calculation results of each data unit can be normally output and the calculation results of the current data unit are not overwritten by the calculation results of the next data unit, the embodiment of the present application caches the calculation results of the data unit through buffer units Buffer2, Buffer3, Buffer4, and Buffer5.

[0099] It can be seen from Figure 7 that after inputting the 128-bit data blocks in the first two data units to the encryption / decryption module Endec2, the input data (Endec input) has a specific pattern. For example, before inputting the 1st to 32nd data blocks in data unit DU(3) to the encryption / decryption module Endec2, input the 33rd data block in data unit DU(1); before inputting the 1st to 32nd data blocks in data unit DU(4), input the 33rd data block in data unit DU(2). For example Figure 8AAs shown, the input data is xDU_i = {sDU(i - 2)33, sDU(i)1 - 32}, where sDU(i - 2)33 represents a 128 - bit data block obtained by concatenating Cp in the calculation result of the 32nd data block and Pm in the 33rd data block in the (i - 2)th data unit (denoted as DU(i - 2){C p ,C m}), and sDU(i)1 - 32 represents the 1st to 32nd 128 - bit data blocks in the ith data unit (denoted as DU(i){P1 ~ P 32}), where i represents the number of the data unit input to Endec, and i is an integer greater than or equal to 3. The length of xDU_i is 33 * 128 bit.

[0100] For the output of the encryption / decryption module Endec (Endec output), the encryption / decryption module Endec outputs the corresponding calculation results in the order of the input data. Similar to the input, there is a specific data pattern in the output of Endec. As Figure 7 shown, after Endec continuously outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(1), it outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(2); then it outputs the calculation result corresponding to the 33rd data block in data unit DU(1), and outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(3); afterwards, it outputs the calculation result corresponding to the 33rd data block in data unit DU(2), and outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(4). It can be seen that there is a specific pattern in the calculation results output by the encryption / decryption module Endec after outputting the calculation results corresponding to 32 128 - bit data blocks in the first two data units. For example Figure 8B shown, the data output by Endec2 is xCipher_i = {sCU(i - 2)33, sCU(i)1 - 32}, where sCU(i - 2)33 represents the calculation result of the 33rd data block in the (i - 2)th data unit (denoted as CU(i - 2){C m-1}), and sCU(i)1 - 32 represents the calculation results corresponding to the 1st to 32nd 128 - bit data blocks in the ith data unit (denoted as CU(i){C1 ~ C m-2 ,C m +C p}), where {C m +C p} represents the concatenation of C m and C p , i represents the number of the data unit input to Endec, and i is an integer greater than or equal to 3. The length of xCipher_i is 33 * 128 bit.

[0101] For the output of the XTS encryption / decryption circuit (XTS Output), after the XTS encryption / decryption circuit outputs the calculation result corresponding to the first data unit, it continuously outputs the calculation results of subsequent data units, that is, the calculation results of the data units output by the XTS encryption / decryption circuit after outputting the calculation result of the first data unit are continuous, and there is no idle state in the middle. For example Figure 8C As shown, denote the output of the XTS encryption / decryption circuit as xCU_j = {CU(j)1-31, CU(j)32-33}, where CU(j)1-31 represents the calculation results of the 1st to 31st data blocks in the (j - 1)th data unit (denoted as CU(j){C1~C m-2}), and CU(j)32-33 represents the calculation result of the 33rd data block and the calculation result corresponding to the 32nd data block in the jth data unit (denoted as CU(j){C m-1 ,C m}, and j is an integer greater than or equal to 2. The length of xCu_j is the same as the length of the data unit, for example, 520 byte.

[0102] Combined with Figure 8A 、 8B and 8C, as Figure 9 shown, after continuously inputting data to the encryption / decryption module Endec2 and obtaining continuous output, regard the input data as a combination of multiple xDUs, regard the output of Endec as a combination of multiple xCiphers, and regard the output data of the XTS encryption / decryption circuit as a combination of xCUs. xCiphers and xDUs correspond one by one.

[0103] xDUs have some additional data (Cp) (a total of 33 * 128 bit) compared to DUs; xCUs are 520 Byte.

[0104] The data of xDU_i includes two parts, namely C p / P 33 of DU(i - 2), and P1~P 32 of DU(i).

[0105] The data of xCU_j includes two parts, namely the encryption results of the first 31 data blocks of DU(j), and the encryption results of the 33rd data block of DU(j) and the encryption result of the 32nd data block (C m ).

[0106] i is the number of the DU provided to Endec, and j is the number of the xCU output from the XTS encryption / decryption circuit.

[0107] The initial value of i is 3 (when 1 <= i < 3, it belongs to the initialization stage and no continuous data output is formed); at the start time when Endec forms continuous data output, the initial value of j is 2 (when j < 2, it belongs to the initialization stage and no continuous data output is formed). The difference between j and i is 1, indicating that the output of xCU lags behind that of xDU, but the lag distance is fixed at 1, and a buffer unit is needed to temporarily store the data between i and j.

[0108] It can be seen from Figure 9 that when the last data block in the data unit DU(2) that is not 128 bits is input to Endec, continuous input starts according to a specific pattern (also see Figure 8A ). The buffer unit Buffer1 needs to buffer at least the last data block in the data units DU(1) and DU(2) that is not 128 bits. Therefore, in an alternative embodiment, the depth of Buffer1 is 2, and the width is the size of the last data block in DU that is not 128 bits (for example, 64 bits, depending on the data size of DU in the actual application). The buffer unit Buffer2 needs to buffer the calculation results corresponding to the first 32 128-bit data blocks in the data units DU(1) and DU(2). The depth of Buffer2 is 64, and the width is 128 bits (the calculation result is also 128 bits). The buffer unit Buffer3 needs to buffer the calculation result Cp corresponding to the data units DU(1) and DU(2). The depth of Buffer3 is 2, and the width is 128 bits. The buffer unit Buffer4 needs to buffer the calculation result C 33 corresponding to the data units DU(1) and DU(2). The depth of Buffer4 is 2, and the width is 128 bits. The buffer unit Buffer5 needs to buffer the calculation result C 32 corresponding to 1 data unit. The depth of Buffer5 is 1, and the width is 128.

[0109] Figures 4 - 9 In the embodiment shown, the encryption / decryption module Endec includes an encryption / decryption component, which can only encrypt or decrypt one 128-bit data block at the same time. This also represents the bandwidth upper limit of the XTS encryption / decryption circuit for encryption / decryption calculation in these embodiments. To increase the bandwidth of the XTS encryption / decryption circuit, in an alternative embodiment, the encryption / decryption module Endec2 includes two or more encryption / decryption components, which encrypt or decrypt two or more 128-bit data blocks at the same time.

[0110] Figure 10 shows a schematic structural diagram of the XTS encryption / decryption circuit provided by another embodiment of the present application. As shown in Figure 10As shown in the figure, the XTS encryption / decryption circuit includes a round key expansion module Round_key_Expand_1, a round key expansion module Round_key_Expand_2, an encryption / decryption module Endec_1, an encryption / decryption module Endec_2’, a modular multiplication module Mod-mul, an adder E1, an adder E2, a multiplexer mux4, a multiplexer mux5, a buffer unit Buffer9, a buffer unit Buffer10, a buffer unit Buffer11, a buffer unit Buffer12, and a buffer unit Buffer13. Among them, the round key expansion module Round_key_Expand_1, the round key expansion module Round_key_Expand_2, the encryption / decryption module Endec_1, the modular multiplication module Mod-mul, the adder E1, and the adder E2 are similar to the functions of the Figure 4 embodiment shown. To avoid repetition, they will not be elaborated here.

[0111] The encryption / decryption module Endec_2’ includes two encryption / decryption components: endecA and endecB. endecA and endecB work in parallel and are independent of each other, and both can perform encryption calculations on 128-bit data blocks. endecA requires 32 cycles to perform encryption calculations on a 128-bit data block, and endecB also requires 32 cycles to perform encryption calculations on a 128-bit data block. Compared with the encryption / decryption module Endec_2, the processing speed of the encryption / decryption module Endec_2’ for 128-bit data has not changed, but it processes one more data block at the same time. Therefore, paired data blocks are input into the encryption / decryption module Endec_2’, that is, two 128-bit data blocks are input. Taking the data unit DU = {P1~P m}, the sizes of P1 to P m-1 are all 128 bits, and P m is less than 128 bits as an example, P1~P m-1 are divided into multiple data block pairs, such as (P1, P2), (P3, P4), (P5, P6)……(P m-2 , P m-1 ), and (P1, P2), (P3, P4), (P5, P6)…(P m-4 , P m-3 ) are input into Endec_2’ in sequence. (P m-2 , P m-1)。If (P1, P2) is input to Endec_2’, then endecA performs encryption calculation on P1, and endecB performs encryption calculation on P2. If (P3, P4) is input to Endec_2’, then endecA performs encryption calculation on P3, and endecB performs encryption calculation on P4. And so on, until P needs to be input to Endec_2’ m Since P m is less than 128 bits, it is necessary to splice P m with the calculation result C m-1 of P p to form a 128-bit data block ({Pm, Cp}) and then input it to Endec_2’. Optionally, a 128-bit data block ({Pm, Cp}) can be input to endecA and endecB simultaneously to obtain two identical calculation results C m-1 . The advantage of doing this is that the two encryption / decryption components always process the same data, so the same control signal can be used to control the operation of the two encryption / decryption components simultaneously. Optionally, the 128-bit data block ({Pm, Cp}) is provided to one of endecA and endecB, and the encryption / decryption component that is not provided with the 128-bit data block ({Pm, Cp}) sleeps accordingly to reduce power consumption.

[0112] The buffer unit Buffer9 has the same function as Buffer1 shown in Figure 4 , and both are used to cache the data block P m . That is, if the last data block of the data unit input to the XTS encryption / decryption circuit is not 128 bits, the last data block is cached in Buffer9, so that during the ciphertext stealing process of the current data unit, the next data unit can be input to the circuit first, so that data can be continuously input to it without idling due to ciphertext stealing.

[0113] The buffer unit Buffer10 caches the corresponding calculation results C1 - C m-3 of each data block in P1 - P m-3 . That is, it caches the calculation results C1 - C m-4 of (P1, P2), (P3, P4), (P5, P6)…(P m-3 ), P m-3 .

[0114] The buffer unit Buffer11 caches the calculation results C m-2 , C m-1 corresponding to the data block pair (P m-2 , P p ) and C m . The buffer unit Buffer12 is used to cache Cm-2 , C m . Since it is necessary to splice the calculation result C corresponding to the data block P m-1 with the data block P p to form a 128-bit data block and input it into the encryption / decryption module Endec_2’, the calculation results C m corresponding to the data block pair (P m-2 , P m-1 ) are cached in Buffer11. To ensure that the C m-2 , C p and C m cached in Buffer11 are not lost when outputting C p , C m-2 and C m are further cached in Buffer12. m-2 and C m

[0115] The cache unit Buffer13 is used to cache the calculation result C m corresponding to the data block P m-1 . The data block formed by splicing C p and P m is calculated by endecA and endecB to obtain two identical calculation results C m-1 , and one C m-1 is cached in Buffer13. Optionally, when the XTS encryption / decryption circuit outputs the calculation results corresponding to P1 to P m , it can obtain and output data from the cache units Buffer10, Buffer13, and Buffer12 in the order of C1-C m when the calculation of the data block P m is completed, or it can first output the calculation results C1-C m-2 corresponding to P1-P m-2 , and then output C m and C m-1 after calculating the calculation result C m-1 corresponding to P m . If when calculating the calculation result C m corresponding to P m-1 , C1-C m-2 has not been output yet, C m-1 is first cached in Buffer13.

[0116] In this embodiment, the input end of the multiplexer mux4 receives the data block pair of the data unit DU, the calculation result C m-1 corresponding to P p , and the P m cached in the cache unit Buffer9, the output terminal of the multiplexer mux4 is coupled to the input terminal of the adder E1. The input terminals of the multiplexer mux5 are coupled to the buffer units Buffer10, Buffer12, and Buffe13, and data is fetched from the buffer units Buffer10, Buffer13, and Buffer12 and output in the order of C1 - C m and output in the order of C1 - C

[0117] Taking the data unit DU d ={P 1d ~P 33d}, DU e ={P 1e ~P 33e}, DU f ={P 1f ~P 33f}, DU g ={P 1g ~P 33g}, DU h ={P 1h ~P 33h}, P 1d to P 32d are all 128 bits in size, P 33d is less than 128 bits, P 1e to P 32e are all 128 bits in size, P 33e is less than 128 bits, P 1f to P 32f are all 128 bits in size, P 33f is less than 128 bits, P 1g to P 32g are all 128 bits in size, P 33g is less than 128 bits, P 1h to P 32h are all 128 bits in size, P 33h is less than 128 bits as an example to illustrate the processing process of the XTS encryption / decryption circuit of the embodiment of the present application:

[0118] (1) Continuously input the data blocks P 1d to P 32d to the encryption / decryption module Endec_2' in the form of data block pairs, and cache the data block P 33d to Buffer9. After 32 cycles when the data block pair (P 1d , P 2d ) is input to the encryption / decryption module Endec_2', the corresponding encryption results C 1d to P 30d C 1d -C 30dCached into Buffer10 in sequence, and the calculation results C 31d , P 32d ) corresponding to C 31d , C pd and C 33d (i.e., C md ) are cached into Buffer11. The C 31d and C 33d cached in Buffer11 are cached into Buffer12.

[0119] (2) After inputting the data block pair (P 31d , P 32d ) into the encryption / decryption module Endec_2’, the data blocks P 1e to P 32e are continuously input into the encryption / decryption module Endec_2’ in the form of data block pairs. Optionally, there is no gap between the data block pair (P 31d , P 32d ) and the data block pair (P 1e , P 2e ), but they are continuously input into the encryption / decryption module Endec_2’ in time to maximize the utilization rate of the encryption / decryption module Endec_2’. The data block P 33e is cached into Buffer9. The encryption results C 1e - C 30e corresponding to P 1e to P 30e are cached into Buffer10, and the calculation results C 31e , C pe and C 33e (i.e., C me ) corresponding to the data block pair (P 31e , P 32e ) are cached into Buffer11. The C 31e and C 33e cached in Buffer11 are cached into Buffer12.

[0120] (3) After inputting the data block pair (P 31e , P 32e ) into the encryption / decryption module Endec_2’, the data blocks P 1f to P 32f are continuously input into the encryption / decryption module Endec_2’ in the form of data block pairs. Optionally, there is no gap between the data block pair (P 31e , P 32e ) and the data block pair (P 1f , P 2fThere is no gap between them, but the encryption / decryption module Endec_2' is input continuously in time to maximize the utilization rate of the encryption / decryption module Endec_2'.

[0121] (4) When the encryption / decryption module Endec_2' receives the data block P 1f to P 32f in the data block formed by two adjacent data blocks, it outputs the data unit DU d in P 1d to P 32d corresponding encryption results, and caches the encryption results C 1d to P 30d corresponding to C 1d -C 30d into Buffer10 in sequence, and caches the calculation results C 31d , P 32d ) corresponding to the data block pair (P 31d , C pd and C 33d (i.e., C md ) into Buffer11. Cache the C 31d and C 33d cached in Buffer11 into Buffer12. After inputting the data block pair (P 31f , P 32f ) into the encryption / decryption module Endec_2', at this time, 32 cycles have passed since the data block pair (P 31d , P 32d ) was input into Endec2', and the corresponding C pd has been calculated and cached in the cache unit Buffer11. Next, take out P 33d from the cache unit Buffer9, take out C pd from the cache unit Buffer11, splice P 33d and C pd into a 128 - dit data block and input it into the encryption / decryption module Endec_2', and cache the encryption result C 33d corresponding to P 32d into Buffer13.

[0122] (5) After splicing P 33d and C pd into a 128 - dit data block and inputting it into the encryption / decryption module Endec_2', input the data blocks P 1g to P 32g into the encryption / decryption module Endec_2' continuously in the form of data block pairs. Optionally, P 33d and C pd spliced into a 128 - dit data block and the data block pair (P1g , P 2g ) there is no gap, but the encryption / decryption module Endec_2’ is continuously input in time to maximize the utilization rate of the encryption / decryption module Endec_2’. After continuously inputting the data blocks P 1g to P 32g in the form of data block pairs into the encryption / decryption module Endec_2’, the data block P 33g is cached in Buffer9.

[0123] (6) After inputting the data block pair (P 31g , P 32g ) into the encryption / decryption module Endec_2’, at this time, 32 cycles have passed since the data block pair (P 31e , P 32e ) was input into Endec2’, and the corresponding C pe has been calculated and cached in the cache unit Buffer11. Next, take out P 33e from the cache unit Buffer9, take out C pc from the cache unit Buffer11, splice P 33e and C pe into a 128 - dit data block and input it into the encryption / decryption module Endec_2’, and cache the encryption result C 33e corresponding to P 32e in Buffer13. After splicing P 33e and C pe into a 128 - dit data block and inputting it into the encryption / decryption module Endec_2’, the data blocks P 1h to P 32h are continuously input into the encryption / decryption module Endec_2’ in the form of data block pairs. Optionally, there is no gap between the 128 - dit data block spliced by P 33e and C pe and the data block pair (P 1h , P 2h ), but the encryption / decryption module Endec_2’ is continuously input in time to maximize the utilization rate of the encryption / decryption module Endec_2’. After continuously inputting the data blocks P 1h to P 32h in the form of data block pairs into the encryption / decryption module Endec_2’, the data block P 33h is cached in Buffer9.

[0124] (7) While receiving the data block composed of P h and P 29h in the data unit DU 29h , Endec2’ outputs P33d For the calculation result, cache the data block P 33d corresponding to the calculation result in Buffer13.

[0125] In the above processing, (P1, P2), (P3, P4), (P5, P6)…(P m-4 , P m-3 ), (P m-2 , P m-1 ), (P m + C p , P m + C p ) are input into the encryption / decryption module Endec_2' in the form of data block pairs, enabling the encryption / decryption module Endec_2' to process two 128-bit data blocks simultaneously, improving the data processing efficiency.

[0126] Figure 11 FIG. shows the structural diagram of the XTS encryption / decryption circuit according to another embodiment of the present application. As Figure 11 shown, the XTS encryption / decryption circuit adds a cache unit Buffer14, a cache unit Buffer15, a cache unit Buffer16, and a multiplexer mux6 on the basis of the embodiment shown in Figure 10 .

[0127] The cache unit Buffer14 is coupled to the encryption / decryption module Endec1 and is used to cache the output data of the encryption / decryption module Endec_1. To improve the encryption calculation speed and ensure that when each data block pair of the data unit DU is input into the encryption / decryption module Endec_2', its corresponding Tw has been calculated, the Tweak_value is encrypted in advance. Since the Tweak_value will be encrypted in advance, Buffer14 needs to cache its encryption result. In an alternative embodiment, Buffer14 can also cache control information related to Tw, such as the data length of the data unit, the encryption / decryption enable signal, the encryption / decryption selection signal, etc.

[0128] The cache unit Buffer15 is coupled to the round key expansion module Round_key_Expand_2 and is used to cache the round key Rk2 output by Round_key_Expand_2. To improve the encryption calculation speed and ensure that when each data block pair of the data unit DU is input into the encryption / decryption module Endec_2', its corresponding round key Rk2 has been calculated, the key2 is expanded in advance and the obtained round key Rk2 is cached in Buffer15.

[0129] In order to improve the processing efficiency of the XTS encryption / decryption circuit, the next data unit is input during the ciphertext stealing process of the previous data unit. To ensure that the round key Rk2 corresponding to the previous data unit is not overwritten by the round key Rk2 corresponding to the next data unit, the round key Rk2 corresponding to the previous data unit cached in Buffer15 is cached in Buffer16.

[0130] The multiplexer mux6 is coupled to the buffer unit Buffer15 and the buffer unit Buffer16, and reads the round key Rk2 corresponding to the data block pair input to the encryption / decryption module Endec_2' from Buffer15 and Buffer16.

[0131] Figure 12 The structure diagram of the XTS encryption / decryption circuit according to another embodiment of the present application is shown. As Figure 12 shown, the XTS encryption / decryption circuit further includes a buffer unit Buffer17 on the basis of the embodiment shown in Figure 11 In order to ensure that when the XTS encryption / decryption circuit outputs data, the data unit corresponding to the output data is determined, the buffer unit Buffer17 is used to cache the identification information of the data unit. According to this identification information, the data unit corresponding to the current calculation result output by the XTS encryption / decryption circuit can be determined. In an optional embodiment, the identification information cached in Buffer17 may be the length of the data unit, and counting control is performed according to the length of the data unit to ensure the normal output of the data. In other optional embodiments, other control information may also be cached in Buffer17, such as an encryption / decryption enable signal, an encryption / decryption selection signal, etc.

[0132] Figure 13 The timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application is shown. In Figure 13 it, legends of different colors represent different data units. For example, the blue legend represents the data unit DU(1), the pink legend represents the data unit DU(2), the yellow legend represents the data unit DU(3), the green legend represents the data unit DU(4), the purple legend represents the data unit DU(5), the white legend represents the data unit DU(6), the orange legend represents the data unit DU(7), and the gray legend represents the data unit DU(8). "sDU(i)_0 = {P1, P3, P5......, P31} i " represents the 1st data block, the 3rd data block, the 5th data block... the 31st data block in the data unit DU(i). "sDU(i)_1 = {P2, P4, P6......, P32} i" represents the 2nd, 4th, 6th... 32nd data blocks in the data unit DU(i). The '0' after the underscore in'sDU(i)_0' indicates that it is processed by EndecA, and the '1' after the underscore in'sDU(i)_1' indicates that it is processed by EndecB. Each of sDU(i)_0 and sDU(i)_1 contains 16 data blocks. "sDU(i)17 = {Cp, P33} i "(shown as a box with label 17 in Figure 13 ) represents a 128-bit data block formed by concatenating the calculation result Cp of the 33rd data block and the 32nd data block in the data unit DU(i).

[0133] "sCU(i)_0" represents the calculation results corresponding to the 1st, 3rd, 5th... 31st data blocks in the data unit DU(i). sCU(i)_0 = {C1, C3......, C29, C31} i ."sCU(i)_1" represents the calculation results corresponding to the 2nd, 4th, 6th... 32nd data blocks of the data unit DU(i), sCU(i)_1 = {C2, C4......, C30, C33} i , where C33 is the result obtained by EndecB processing P32. The '0' after the underscore in "sCU(i)_0" indicates that it is the result of EndecA processing, and the '1' after the underscore in "sDU(i)_1" indicates that it is the result of EndecB processing. "sCU(i)17" represents the calculation result corresponding to the 33rd data block ({Cp, P33} i ) of the data unit DU(i), sCU(i)17 = {C32} i .

[0134] "EndecA input" represents the input data of the encryption / decryption component endecA in the input encryption / decryption module Endec_2'. "EndecB input" represents the input data of the encryption / decryption component endecB in the input encryption / decryption module Endec_2'. "EndecA output" represents the output data of the encryption / decryption component endecA, and "EndecB output" represents the output data of the encryption / decryption component endecA. "XTS Output" represents the output data of the XTS encryption / decryption circuit.

[0135] As Figure 13 shown, data block pairs formed by pairwise data blocks in sDU(1)_0 and sDU(1)_1 respectively (such as Figure 13The blue legends marked with sDU(1)_0 and sDU(1)_1 are input into endecA and endecB simultaneously, and the 33rd data block sDU(1)17 in the data unit DU(1) is cached into Buffer9. After the data block pair (P31, P32) composed of the 31st data block and the 32nd data block in the data unit DU(1) is input into endecA and endecB simultaneously, the data block pairs (such as Figure 13 the pink legends marked with sDU(2)_0 and sDU(2)_1) are input into endecA and endecB. Optionally, there is no gap between the data block pair (P31, P32) in the data unit DU(1) and the data block pair (P1, P2) in the data unit DU(2), but they are input continuously in time. Inputting sDU(2)_0 and sDU(2)_1 into endecA and endecB requires 16 cycles. At this time, the calculation of the 32nd data block in the data unit DU(1) has not been completed yet. Therefore, the 33rd data block in the data unit DU(1) cannot be input, but sDU(3)_0 and sDU(3)_1 (such as Figure 13 the yellow legends marked with sDU(3)_0 and sDU(3)_1) are input immediately after inputting the data block pair (P31, P32) composed of the 31st data block and the 32nd data block in the data unit DU(2). Inputting sDU(3)_0 and sDU(3)_1 into endecA and endecB requires 16 cycles. At this time, 32 cycles have passed since the input of the 32nd data block in the data unit DU(1), and the calculation of the 32nd data block in the data unit DU(1) has been completed. Therefore, after Figure 13 inputting sDU(3)_0 and sDU(3)_1 into endecA and endecB in the figure, sDU(1)17 (such as Figure 13 the blue legend marked with 17) is input. When the input of sDU(1)17 is completed, the calculation of the 32nd data block in the data unit DU(2) has not been completed yet. Therefore, the 33rd data block in the data unit DU(2) cannot be input, but sDU(4)_0 and sDU(4)_1 (such as Figure 13 the green legends marked with sDU(4)_0 and sDU(4)_1) are input ( Figure 13Among them, the green legend marked with 16 is a part of sDU(4)_0 or sDU(4)_1, which is used to identify the timing when P32 of DU(4) is input into the Endec, rather than representing that P32 is repeatedly input into the Endec. And P32 is input to EndecB for processing. At the position corresponding to EndecAinput, although it is marked with 16, the data block it inputs is P31 of the DU. In this article, a similar marking method expresses a similar meaning). When the input of sDU(4)_0 and sDU(4)_1 is completed, 32 cycles have passed since the 32nd data block in the input data unit DU(2), and the calculation of the 32nd data block in the data unit DU(2) has been completed. Therefore, after Figure 13 inputting sDU(4)_0 and sDU(4)_1 into endecA and endecB, sDU(2)17 is input (such as the pink legend marked with 17 in Figure 13 ). And so on, subsequently, sDU(5)_0 and sDU(5)_1 are input in sequence (such as the purple legend marked with sDU(5)_0 and sDU(5)_1 in Figure 13 ), sDU(3)17 (such as the yellow legend marked with 17 in Figure 13 ), sDU(6)_0 and sDU(6)_1 (such as the white legend marked with sDU(6)_0 and sDU(6)_1 in Figure 13 ), sDU(4)17 (such as the green legend marked with 17 in Figure 13 ), sDU(7)_0 and sDU(7)_1 (such as the orange legend marked with sDU(7)_0 and sDU(7)_1 in Figure 13 ), sDU(5)17 (such as the purple legend marked with 17 in Figure 13 ), sDU(8)_0 and sDU(8)_1 (such as the grey legend marked with sDU(8)_0 and sDU(8)_1 in Figure 13 ), sDU(6)17 (such as the white legend marked with 17 in Figure 13 ).

[0136] For EndecA output and EndecB output, the corresponding calculation results are output in the order of the input data. The calculation of each data block by endecA and endecB takes 32 cycles. Therefore, the output of the calculation results corresponding to each data block lags 32 cycles behind the input of that data block. For example, when the input of sCU(2)_0 and sCU(2)_1 to endecA and endecB is completed, 32 cycles have passed since the first data block in the input data unit DU(1). The encryption calculation of the first data block has been completed, and from this moment on, the calculation results of the first to the 32nd data blocks in the data unit DU(1) (denoted as sCU(1)_0 and sCU(1)_1) are output. Therefore, in Figure 13 it, the starting ends of the legends representing sCU(1)_0 and sCU(1)_1 are horizontally aligned with the ending ends of the legends representing sDU(2)_0 and sDU(2)_1. It takes 16 cycles to output sCU(1)_0 and sCU(1)_1. Therefore, the ending ends of the legends of sCU(1)_0 and sCU(1)_1 are flush with the ending ends of the legends representing sDU(3)_0 and sDU(3)_1. After the output of sCU(1)_0 and sCU(1)_1 is completed, sCU(2)_0 and sCU(2)_1, sCU(3)_0 and sCU(3)_1 are output in sequence. When the output of sCU(3)_0 and sCU(3)_1 is completed, 32 cycles have passed since the 33rd data block (the blue legend marked with 17 in the EndecA input row or EndecB input row) in the input data unit DU(1). The calculation of the 33rd data block in the data unit DU(1) is completed. Therefore, the calculation result sCU(1)17 (the blue legend marked with 17 in the EndecA output row or EndecB output row) of the 33rd data block in the data unit DU(1) is output. And so on, sCU(4)_0 and sCU(4)_1, sCU(2)17, sCU(5)_0 and sCU(5)_1, sCU(3)17, sCU(6)_0 and sCU(6)_1, sCU(4)17, sCU(7)_0 and sCU(7)_1, sCU(5)17, sCU(8)_0 and sCU(8)_1, sCU(6)17, sCU(9)_0 and sCU(9)_1, sCU(7)17 are output in sequence.

[0137] It can be understood that in each cycle, endecA and endecB each receive a data block as input. The calculation of each data block in endec takes 32 cycles, and then the calculation result corresponding to the data block is obtained. In Figure 13In the example, in a plurality of consecutive cycles, input data blocks are continuously provided to endecA and endecB respectively (also referred to as continuously), and after a lag of 32 cycles, in a plurality of consecutive cycles, the calculation results of each data block are continuously output from endecA and endecB. Each calculation result lags 32 cycles behind the input of its data block. Thus, the order in which the input data blocks are provided to endecA and endecB determines the order in which endecA and endecB output the calculation results of the data blocks.

[0138] For XTS Output, output starts after calculating the calculation results of several data blocks (such as the first 5 data blocks) of data unit DU(1). After outputting the calculation result corresponding to the 31st data block, if the calculation of the 33rd data block is not completed yet, wait for the calculation of the 33rd data block to complete, and then output the calculation result of the 33rd data block and the calculation result of the 32nd data block. If the calculation of the 1st to 31st data blocks in data unit DU(2) has been completed before outputting the calculation result of the 32nd data block in data unit DU(1), then immediately output the calculation results of the 1st to 31st data blocks in data unit DU(2) after outputting the calculation result of the 32nd data block in data unit DU(1). When the calculation results of the 1st to 31st data blocks in data unit DU(2) are completely output, the calculation of the 32nd and 33rd data blocks in data unit DU(2) has also been completed, so the calculation results of the 33rd and 32nd data blocks in data unit DU(2) can be immediately output without interruption.

[0139] Optionally, cache the calculation results corresponding to the 1st to 30th data blocks in data units DU(1), DU(2), DU(3), and DU(4) into Buffer10, and cache the calculation results C31 of the 31st data block and C33 and C p corresponding to the 32nd data block in data units DU(1), DU(2), DU(3), and DU(4) into Buffer11, and then cache C31 and C33 into Buffer12. Here, C31, C33, and Cp are all cached into Buffer11 because these calculation results are calculated by EndecA and EndecB simultaneously. Adopting the same control method (caching into Buffer11) for the simultaneously generated calculation results is beneficial to simplifying the design of the circuit (data path and control circuit). Cache the calculation result C32 corresponding to the 33rd data block in data units DU(1), DU(2), DU(3), and DU(4) into Buffer13.

[0140] It can be seen from Figure 13 that before inputting the first to the 32nd data blocks in the data unit DU(4) to endecA and endecB, the 33rd data block in the data unit DU(1) is input; before inputting the first to the 32nd data blocks in the data unit DU(5), the 33rd data block in the data unit DU(2) is input. Thus, it can be seen that after inputting the first three data units to endecA and endecB, the input data has a specific pattern. The processing processes of endecA and endecB are the same, and endecA is taken as an example for illustration. As Figure 14A shown, the data input to endecA is xDU_i_0 = {sDU(i - 3)17, sDU(i)_0}, where sDU(i - 3)17 represents the data block obtained by splicing the calculation result Cp corresponding to the 32nd data block in the (i - 3)th data unit and the 33rd data block (denoted as DU(i - 3){C p , C m}), and sDU(i)_0 represents 16 128-bit data blocks in the ith data unit (denoted as DU(i)_0{P1, P3, P5......, P31}), and i represents the number of the data unit input to endecA, and i is an integer greater than or equal to 4. The length of xDU_i is 17 * 128 bit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i - 3)17_d, sDU(i)_d}. xDU_i_d represents the data block pair provided to the second encryption module. sDU(i - 3)17_d represents the data block pair formed by splicing the second data shard corresponding to the (m - 1)th data block in the (i - 3)th data unit and the mth data block in the (i - 3)th data unit. sDU(i)_d represents the data block pair formed by two adjacent data blocks among the first to the (m - 1)th data blocks in the ith data unit. sDU(i)_d includes sDU(i)_0 and sDU(i)_1. sDU(i)_0 represents the data block provided to the first encryption component among the first to the (m - 1)th data blocks in the ith data unit, and sDU(i)_1 represents the data block provided to the second encryption component among the first to the (m - 1)th data blocks in the ith data unit.

[0141] For the output of endecA, it outputs the corresponding calculation results in the order of the input data. Then, similar to the input, there is also a specific data pattern in the output of endecA. As Figure 14BAs shown, the data output by endecA is xCipher_i_0 = {sCU(i - 3)_17, sCU(j)_0}, where sCU(i - 3)_17 represents the calculation result of the 33rd data block in the (i - 3)th data unit, sCU(i - 3)_17 represents the calculation result corresponding to the 33rd data block in the (i - 3)th data unit, sCU(i)_0 represents the calculation result corresponding to 16 128-bit data blocks in the ith data unit, i represents the number of the data unit input to endecA, and i is an integer greater than or equal to 4. The length of xCipher_i is 17 * 128 bit. Optionally, the data output by the encryption / decryption module Endec_2' is denoted as xCipher_i_d = {sCU(i - 3)_17, sCU(i)_d}. xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)_17 represents the calculation result of the mth data block in the (i - 3)th data unit, and sCU(i)_d represents the calculation result corresponding to the 1st to (m - 1)th data blocks in the ith data unit. xCipher_i_d includes xCipher_i_0 and xCipher_i_1, where xCipher_i_0 represents the calculation result output by the first encryption component, and xCipher_i_1 represents the calculation result output by the second encryption component. sCU(i)_d includes sCU(i)_0 and sCU(i)_1, where sCU(i)_0 represents the calculation result corresponding to the data block in the ith data unit processed by the first encryption component, and sCU(i)_1 represents the calculation result corresponding to the data block in the ith data unit processed by the second encryption component. In an alternative embodiment, the 33rd data block in the (i - 3)th data unit is provided to both encryption components endecA and endecB in the encryption / decryption module Endec_2' simultaneously. Both endecA and endecB perform operations on the 33rd data block in the (i - 3)th data unit to obtain two calculation results, while the encryption / decryption module Endec_2' may output only one calculation result.

[0142] For the output of the XTS encryption / decryption circuit, after the XTS encryption / decryption circuit outputs the calculation result corresponding to the first data unit, it continuously outputs the calculation results of subsequent data units, that is, the calculation results of the data units output by the XTS encryption / decryption circuit after outputting the calculation result of the first data unit are continuous, and there is no idle state in the middle. For example Figure 14C As shown, the output of the XTS encryption / decryption circuit is denoted as xCU_j = {CU(j)_1 - 31, CU(j)_33 - 32}, where CU(j)_1 - 31 represents the calculation results of the 1st to 31st data blocks in the jth data unit (denoted as CU(j){C1~C m-2}), CU(j)33 - 32 represents the calculation result corresponding to the 33rd data block and the calculation result corresponding to the 32nd data block in the jth data unit (denoted as CU(j){C m-1 , C m}), where j is an integer greater than or equal to 2. The length of xCu_j is the same as the length of the data unit DU(j), for example, 520 bytes.

[0143] Combined with Figure 14A 、 14B and 14C, as Figure 15 shown, after forming continuous data input to Endec2’ and obtaining continuous output, the input data is regarded as a combination of continuous multiple xDUs, the output of Endec2’ is regarded as a combination of continuous multiple xCiphers, and the output data of the XTS encryption / decryption circuit is regarded as a combination of continuous multiple xCUs. xCipher corresponds to xDU one by one.

[0144] xDU has more partial data (C p )(a total of 17 * 128) than half of DU (for example, {P1, P3, P5......, P31, P33}). xCU has the same length as DU, which is 520 bytes.

[0145] The data of xDU_i includes two parts, which are C p / P m of DU(i - 3) and 16 data blocks of DU(i).

[0146] The data of xCU_j includes two parts, which are the encryption results CU(j){C1~C m-2} of the first 31 data blocks of DU(j) and the calculation results CU(j){C m-1 , C m} after ciphertext stealing of the 33rd and 32nd data blocks of DUU).

[0147] i is the number of DU provided to Endec2’, and j is the number of xCU output from the whole Endec2’.

[0148] At the start time of forming continuous data input to Endec2’, the initial value of i is 4 (when i < 4, it belongs to the initialization stage and continuous data input has not been formed); at the start time of forming continuous data output of Endec2’, the initial value of j is 2 (when j < 2, it belongs to the initialization stage and continuous data output has not been formed). The difference between j and i is 2, indicating that the output of xCU lags behind xDU, but the lag distance is fixed at 2, and a buffer unit is required to temporarily store the data between i and j.

[0149] In an alternative embodiment,Figures 10 - 13 The XTS encryption and decryption circuit shown in any one of the embodiments may also perform encryption calculations on data according to other timings.

[0150] Figure 16 Another timing diagram of the XTS encryption / decryption calculation circuit provided by the embodiments of the present application is shown. As Figure 16 shown, Figure 16 The difference between the embodiment shown and Figure 13 the embodiment shown is that: Figure 13 In the embodiment shown, the first 16 data block pairs of the data unit DU(4) are input first (such as Figure 13 the green legends marked with sDU(4)_0 and sDU(4)_1), and then the 33rd data block in the data unit DU(2) is input (such as Figure 13 the pink legend marked with 17). Since when the input of the 15th data block pair in the data unit DU(4) is completed, it is exactly 32 cycles away from the input of the 32nd data block in the data unit DU(2), and the calculation result of the 32nd data block in the data unit DU(2) is obtained, so Figure 16 In the embodiment shown, the 33rd data block in the data unit DU(2) is input first (such as Figure 16 the pink legend marked with 17 in Figure 16 ), and then the data block pairs in the data unit DU(4) are input (such as

[0151] In Figure 16 the embodiment shown, the mode of the data input by endecA is denoted as xDU_i_0 = {sDU(i - 3)17, sDU(i - 1)15 - 16_0, sDU(i)1 - 14_0}, and sDU(i - 3)17 represents the calculation result C corresponding to the 32nd data block in the (i - 3)th data unit pThe data block obtained by splicing with the 33rd data block, sDU(i)15-16_0 represents a data block in the 15th data block pair in the (i-1)th data unit and the data block input to endecA in the 16th data block pair, sDU(i)1-14_0 represents the data blocks input to endecA in the first 14 data block pairs in the ith data unit, i represents the number of the data unit input to endecA and endecB, and i is an integer greater than or equal to 6. The length of xDU_i is 17*128 bit. EndecA and endecB output their corresponding calculation results in the order of the input data. The output data pattern of endecA in this embodiment can be denoted as xCipher_i_0 = {sCU(i-3)17, sCU(i-1)15-16_0, sCU(i)1-14_0}, sCU(i-3)17 represents the calculation result of the 33rd data block in the (i-3)th data unit, sCU(i)15-16_0 represents the calculation results of the data blocks input to endecA in the 15th data block pair and the 16th data block pair in the (i-1)th data unit, and sDU(i)1-14_0 represents the calculation results of the data blocks input to endecA in the first 14 data block pairs in the ith data unit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i-3)17_d, sDU(i-1)15-16_d, sDU(i)1-14_d}. xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair composed of the data block obtained by splicing the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit and the mth data block in the (i-3)th data unit, sDU(i)15-16_d represents the data block pair composed of the (m-4)th data block and the (m-3)th data block and the data block pair composed of the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-14_d represents the data block pairs composed of two adjacent data blocks among the first to the (m-5)th data blocks in the ith data unit. The data output by the encryption / decryption module Endec_2’ is denoted as xCipher_i_d = {sCU(i-3)17, sCU(i-1)15-16_d, sCU(i)1-14_d}.xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the m-th data block in the (i - 3)-th data unit, sCU(i)15 - 16_d represents the calculation results corresponding to the (m - 4)-th, (m - 3)-th, (m - 2)-th, and (m - 1)-th data blocks in the (i - 1)-th data unit, and sDU(i)1 - 14_d represents the calculation results corresponding to the 1st to (m - 5)-th data blocks in the i-th data unit.

[0152] Figure 17 Another timing diagram of the XTS encryption / decryption calculation circuit provided by the embodiment of the present application is shown. Figure 17 The shown timing diagram and Figure 16 The difference between the shown timing diagram is that: in Figure 16 the shown embodiment, first input the first 14 data block pairs in the data unit DU(6) (such as Figure 16 the white legend marked with sDU(6)1 - 14 in Figure 16 ), then input the 33rd data block in the data unit DU(4) (such as Figure 16 the green legend marked with 17 in Figure 17 ), and then input the 15th data block pair and the 16th data block pair in the data unit DU(6) (such as Figure 17 the white legend marked with 15 - 16 in Figure 17 ). In Figure 17 the shown embodiment, when inputting the data unit DU(6), first input the first 15 data block pairs in the data unit DU(6) (such as

[0153] in Figure 17 the white legend marked with sDU(6)1 - 15 in pThe data block obtained by splicing with the 33rd data block, sDU(i - 1)16_0 represents the data block input to endecA in the 16th data block pair of the (i - 1)th data unit, sDU(i)1 - 15_0 represents the data blocks input to endecA in the first 15 data block pairs of the ith data unit, and i represents the number of the data unit input to endecA and endecB, where i is an integer greater than or equal to 7. The output data mode of endecA is denoted as xCipher_i_0 = {sCU(i - 3)17, sCU(i - 1)16_0, sCU(i)1 - 15_0}, sCU(i - 3)17 represents the calculation result of the 33rd data block in the (i - 3)th data unit, sCU(i)16_0 represents the calculation result of the data block input to endecA in the 16th data block pair of the (i - 1)th data unit, and sDU(i)1 - 15_0 represents the calculation results of the data blocks input to endecA in the first 15 data block pairs of the ith data unit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i - 3)17_d, sDU(i - 1)16_d, sDU(i)1 - 15_d}. xDU_i_d represents the data block pair provided to the second encryption module, sDU(i - 3)17_d represents the data block pair composed of the second data shard corresponding to the (m - 1)th data block in the (i - 3)th data unit and the data block obtained by splicing the (m)th data block in the (i - 3)th data unit, sDU(i)16_d represents the data block pair composed of the (m - 2)th data block and the (m - 1)th data block in the (i - 1)th data unit, and sDU(i)1 - 15_d represents the data block pairs composed of adjacent two data blocks among the first to the (m - 3)th data blocks in the ith data unit. The data output by the encryption / decryption module Endec_2’ is denoted as xCipher_i_d = {sCU(i - 3)17, sCU(i - 1)16_d, sCU(i)1 - 15_d}. xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the mth data block in the (i - 3)th data unit, sCU(i)16_d represents the calculation results corresponding to the (m - 2)th data block and the (m - 1)th data block in the (i - 1)th data unit, and sDU(i)1 - 14_d represents the calculation results corresponding to the first to the (m - 3)th data blocks in the ith data unit.

[0154] Figure 18 Fig. shows a timing diagram of an XTS encryption / decryption calculation circuit provided by an embodiment of the present application. Figure 18 The shown embodiment and Figure 17 The difference between the shown timing diagram is that: at Figure 17In the illustrated embodiment, when inputting data unit DU(5), first input the first 14 data block pairs in data unit DU(5) (such as Figure 17 the purple legend marked with sDU(5)1-14 in Figure 17 ), then input the 33rd data block in data unit DU(3) (such as Figure 17 the yellow legend marked with 17 in Figure 18 ), and then input the 15th and 16th data block pairs in data unit DU(5) (such as Figure 18 the purple legend marked with sDU(5)1-15 in Figure 18 ). In Figure 18 the illustrated embodiment, when inputting data unit DU(5), first input the first 15 data block pairs in data unit DU(5) (such as

[0155] the purple legend marked with sDU(5)1-15 in Figure 18 ), then input the 33rd data block in data unit DU(3) (such as p the yellow legend marked with 17 in ), and then input the 16th data block pair in data unit DU(5) (such as Figure 18 the purple legend marked with 16 in ).

[0155] In Figure 18 the illustrated embodiment, the input data mode of endecA is denoted as xDU_i_0 = {sDU(i - 3)17, sDU(i - 1)16_0, sDU(i)1-15_0}, where sDU(i - 3)17 represents the calculation result C corresponding to the 32nd data block in the (i - 3)th data unit pThe data block obtained by splicing with the 33rd data block, sDU(i-1)16_0 represents the data block input to endecA in the 16th data block pair of the (i-1)th data unit, sDU(i)1-15_0 represents the data blocks input to endecA in the first 15 data block pairs of the ith data unit, and i represents the number of the data unit input to endecA and endecB, where i is an integer greater than or equal to 5. The output data mode of endecA is denoted as xCipher_i_0 = {sCU(i-3)17, sCU(i-1)16_0, sCU(i)1-15_0}, where sCU(i-3)17 represents the calculation result of the 33rd data block in the (i-3)th data unit, sCU(i)16_0 represents the calculation result of the data block input to endecA in the 16th data block pair of the (i-1)th data unit, and sDU(i)1-15_0 represents the calculation results of the data blocks input to endecA in the first 15 data block pairs of the ith data unit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i-3)17_d, sDU(i-1)16_d, sDU(i)1-15_d}. xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair composed of the data block obtained by splicing the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit with the mth data block in the (i-3)th data unit, sDU(i)16_d represents the data block pair composed of the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-15_d represents the data block pairs composed of adjacent two data blocks among the first to the (m-3)th data blocks in the ith data unit. The data output by the encryption / decryption module Endec_2’ is denoted as xCipher_i_d = {sCU(i-3)17, sCU(i-1)16_d, sCU(i)1-15_d}. xCipher_i_d represents the calculation result output by the second encryption module, sCU(i-3)17 represents the calculation result of the mth data block in the (i-3)th data unit, sCU(i)16_d represents the calculation results corresponding to the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-14_d represents the calculation results corresponding to the first to the (m-3)th data blocks in the ith data unit.

[0156] The XTS encryption / decryption circuit provided by the embodiment of the present application calculates the 128-bit data block in the next data unit while waiting for the result of the ciphertext stealing process corresponding to the current data unit, avoiding the idle and pause during the operation of the encryption / decryption module Endec2’, and improving the processing efficiency of the XTS encryption / decryption circuit.

[0157] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments as well as all changes and modifications that fall within the scope of the present application. Obviously, those skilled in the art can make various changes and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. An XTS encryption circuit, which is applicable to perform encryption operations on data units based on the block encryption algorithm of the XTS mode. The data units include m data blocks. The first to the (m - 1)th data blocks each have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes. m is an integer greater than 1. The encryption circuit includes a first round key expansion module, a second round key expansion module, a first encryption module, a second encryption module, a modular multiplication module, a first adder, and a second adder; characterized in that, the encryption circuit further includes a first buffer unit, which is used to buffer the mth data block of the target data unit input to the second encryption module, so as to input the first to the (m - 1)th data blocks of the next target data unit during the process of the second encryption module performing ciphertext stealing processing on the (m - 1)th data block of the target data unit, so as to form a continuous input to the second encryption module.

2. The circuit according to claim 1, wherein The encryption circuit further includes: a second buffer unit, a third buffer unit, a fourth buffer unit, a fifth buffer unit, a first multiplexer, and a second multiplexer; the second buffer unit buffers the calculation results corresponding to the first to the (m - 2)th data blocks of the target data unit processed by the second encryption module; the third buffer unit buffers the calculation results corresponding to the (m - 1)th data block of the target data unit processed by the second encryption module; the calculation results corresponding to the (m - 1)th data block include a first data shard and a second data shard, and the data block formed by splicing the second data shard and the mth data block of the target data unit has a preset number of bytes; the fourth buffer unit buffers the first data shard; the fifth buffer unit buffers the calculation results corresponding to the mth data block of the target data unit processed by the second encryption module; the output end of the first multiplexer is coupled to the first adder, and is used to select data blocks from the first to the (m - 1)th data blocks, the mth data block buffered by the first buffer unit, and the second data shard buffered by the third buffer unit and provide them to the first adder; the second multiplexer sequentially obtains the calculation results corresponding to the first to the (m - 2)th data blocks from the second buffer unit, obtains the calculation results corresponding to the mth data block from the fifth buffer unit, and obtains the first data shard from the fourth buffer unit and outputs them.

3. The circuit according to claim 1, characterized in that, The first multiplexer continuously provides the first to the (m - 1)-th data blocks in the first data unit to the second encryption module, and the second encryption module operates on the first to the (m - 1)-th data blocks in the first data unit; it takes (m - 1) cycles for the second encryption module to calculate the result from receiving to output for each data block; the m-th data block in the first data unit is cached in the first cache unit so that the first to the (m - 1)-th data blocks in the second data unit are input to the second encryption module during the ciphertext stealing process of the (m - 1)-th data block in the first data unit; In response to caching the m-th data block in the first data unit in the first cache unit, the first multiplexer continuously provides the first to the (m - 1)-th data blocks in the second data unit to the second encryption module; The m-th data block in the second data unit is cached in the first cache unit; While receiving the first to the (m - 1)-th data blocks in the second data unit, the second encryption module sequentially outputs the calculation results corresponding to the first to the (m - 1)-th data blocks in the first data unit, caches the calculation results corresponding to the first to the (m - 2)-th data blocks in the first data unit in the second cache unit, caches the first and second data shards corresponding to the (m - 1)-th data block in the first data unit in the third cache unit, and caches the first data shard corresponding to the (m - 1)-th data block in the first data unit in the fourth cache unit; In response to providing the (m - 1)-th data block in the second data unit to the second encryption module, the first multiplexer obtains the second data shard corresponding to the first data unit from the third cache unit and the m-th data block in the first data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block to the second encryption module; While receiving the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block, the second encryption module sequentially outputs the calculation results corresponding to the first to the (m - 1)-th data blocks in the second data unit, caches the calculation results corresponding to the first to the (m - 2)-th data blocks in the second data unit in the second cache unit, caches the first and second data shards corresponding to the (m - 1)-th data block in the second data unit in the third cache unit, and caches the first data shard corresponding to the (m - 1)-th data block in the second data unit in the fourth cache unit; In response to providing the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block to the second encryption module, the first multiplexer continuously provides the first to the (m - 1)-th data blocks in the third data unit to the second encryption module; Cache the m-th data block in the third data unit into the first cache unit; In response to providing the (m - 1)-th data block in the third data unit to the second encryption module, the first multiplexer obtains the second data shard corresponding to the second data unit from the third cache unit and the m-th data block in the second data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block to the second encryption module; While receiving the (m - 2)-th data block in the third data unit, the second encryption module outputs the calculation result corresponding to the m-th data block in the first data unit, and caches the calculation result corresponding to the m-th data block in the first data unit into the fifth cache unit.

4. The circuit according to claim 3, characterized in that, The encryption circuit sequentially obtains the calculation results corresponding to the 1st to (m - 2)-th data blocks in the first data unit from the second cache unit, the calculation result corresponding to the m-th data block in the first data unit from the fifth cache unit, and outputs the first data shard corresponding to the (m - 1)-th data block in the first data unit from the fourth cache unit; In response to the completion of the output of the first data shard corresponding to the (m - 1)-th data block in the first data unit, it obtains the calculation results corresponding to the 1st to (m - 2)-th data blocks in the second data unit from the second cache unit, the calculation result corresponding to the m-th data block in the second data unit from the fifth cache unit, and outputs the first data shard corresponding to the (m - 1)-th data block in the second data unit from the fourth cache unit.

5. The circuit according to claim 4, characterized in that, After obtaining the calculation result corresponding to the m-th data block in the first data, the encryption circuit outputs the results corresponding to each data block in the first data unit, or after obtaining the calculation results corresponding to the 1st to (m - 2)-th data blocks in the first data unit, it outputs the calculation results corresponding to the 1st to (m - 2)-th data blocks, and after obtaining the calculation result corresponding to the m-th data block in the first data unit, it outputs the calculation result of the m-th data block in the first data unit and the calculation result of the (m - 1)-th data block in the first data unit.

6. The circuit according to any one of claims 1-5, characterized in that, The encryption circuit further includes a seventh cache unit, an eighth cache unit, and a third multiplexer; The seventh cache unit is coupled to the second round key expansion module for caching the round key data corresponding to the second data unit output by the second round key expansion module; The eighth cache unit is used for caching the round key data corresponding to the first data unit output by the second round key expansion module, and the first data unit is input to the second encryption module before the second data unit; The output end of the third multiplexer is coupled to the second encryption module, and the third multiplexer is used to obtain the round key data corresponding to the data block input to the second encryption module from the seventh cache unit or the eighth cache unit and provide it to the second encryption module.

7. The circuit according to any one of claims 3 - 6, wherein the first multiplexer continuously provides data blocks to the second encryption module in a first data mode, and the first data mode is shown as the following formula (1): xDU_i = {sDU(i - 2)33, sDU(i)1 - 32} (1) wherein, xDU_i represents the data block provided to the second encryption module. If m is 33, sDU(i - 2)33 represents the data block obtained by splicing the second data shard corresponding to the (m - 1)th data block in the (i - 2)th data unit and the mth data block in the (i - 2)th data unit, and sDU(i)1 - 32 represents the first to the (m - 1)th data blocks in the ith data unit; i is an integer greater than or equal to 3; the second encryption module outputs a calculation result in a second data mode, and the second data mode is shown as the following formula (2): xCipher_i = {sCU(i - 2)33, sCU(i)1 - 32} (2) xCipher_i represents the calculation result output by the second encryption module, sCU(i - 2)33 represents the calculation result of the mth data block in the (i - 2)th data unit, and sCU(i)1 - 32 represents the calculation results corresponding to the first to the (m - 1)th data blocks in the ith data unit; the encryption circuit outputs encrypted data in a third data mode, and the third data mode is shown as the following formula (3): xCU_j = {CU(j)1 - 31, CU(j)32 - 33} (3) xCU_j represents the encrypted data output by the encryption circuit, CU(j)1 - 31 represents the calculation results of the first to the (m - 2)th data blocks in the jth data unit, and CU(j)32 - 33 represents the calculation result of the mth data block in the jth data unit and the calculation result corresponding to the (m - 1)th data block, and j = i - 1.

8. The circuit according to claim 7, wherein each data block of xDU_i is continuously input into the second encryption module, and one data block of xDU_i is input into the second encryption module in each cycle; the second encryption module continuously outputs each data block of xCipher_i, and one data block of xCipher_i is output from the second encryption module in each cycle; and the encryption circuit continuously outputs each data block of xCU_j, and one data block of xCU_j is output from the encryption circuit in each cycle.

9. The circuit according to claim 8, wherein each data block of xDU_i and xDU_(i + 1) is continuously input into the second encryption module, and the first data block of xDU_(i + 1) is input into the second encryption module in the next cycle after the last data block of xDU_i is input into the second encryption module; The second encryption module continuously outputs data blocks of xCipher_i and xCipher_(i + 1), where the first data block of xCipher_(i + 1) is output from the second encryption module in the next cycle after the last data block of xCipher_i is output from the second encryption module; and The encryption circuit continuously outputs data blocks of xCU_j and xCU_(j + 1), where the first data block of xCU_(j + 1) is output from the encryption circuit in the next cycle after the last data block of xCU_j is output from the encryption circuit.

10. An XTS decryption circuit, which is applicable to perform decryption operations on data units based on a block decryption algorithm in XTS mode. The data units include m data blocks. The first to the (m - 1)th data blocks each have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes. m is an integer greater than 1. The decryption circuit includes a first round key expansion module, a second round key expansion module, a first decryption module, a second decryption module, a modular multiplication module, a first adder, and a second adder; characterized in that The decryption circuit further includes a first buffer unit, which is used to buffer the mth data block of the target data unit input to the second decryption module, so as to input the first to the (m - 1)th data blocks of the next target data unit during the process of the second decryption module performing ciphertext stealing processing on the (m - 1)th data block of the target data unit, so as to form a continuous input to the second decryption module.