Dual-core high-bandwidth XTS encryption and decryption circuit

By introducing a cache unit and a multiplexer into the XTS encrypted/decrypted circuit, a continuous input of the data block pair is formed, which solves the idle time problem in the XTS encrypted/decrypted circuit when processing the data unit and improves the processing efficiency.

CN120238282APending Publication Date: 2025-07-01CHENGDU STARBLAZE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311869568.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The XTS encrypt/decryption circuit has 32 cycles of idle time when processing the data unit, which affects the processing efficiency, especially when the data block is less than 128 bits, the ciphertext stealing process is required.

Method used

An XTS encryption circuit and an XTS decryption circuit are designed. By introducing a cache unit and a multiplexer, the input data blocks and calculation results are cached to form a continuous input of the data block pair to avoid idle time.

Benefits of technology

The continuous computing of the XTS encrypted/decrypted circuit is realized, making full use of the processing capabilities of the encrypted/decrypted module, improving processing efficiency, and avoiding idle time caused by ciphertext theft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238282A_ABST
    Figure CN120238282A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a dual-core high-bandwidth XTS encryption and decryption circuit, and relates to the technical field of information security. The circuit comprises a first round key expansion module, a second round key expansion module, a first encryption module, a modular multiplication module, a first summator, a second summator, a second encryption module and a first cache unit, and the second encryption module comprises a first encryption component and a second encryption component. Two adjacent data blocks from the first data block to the (m-1) th data block of the target data unit form a data block pair, and the first encryption component and the second encryption component respectively calculate one data block in the data block pair and output corresponding calculation results; the first cache unit caches the mth data block of the target data unit so as to input a data block pair formed by the first to (m-1) th data blocks of the next target data unit in the ciphertext stealing processing process of the (m-1) th data block of the target data unit, and continuous input to the second encryption module is formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a dual-core high-bandwidth XTS encryption and decryption circuit. Background Art

[0002] In cryptography, a block cipher is a symmetric key algorithm that divides plaintext into multiple blocks of equal length, and then encrypts them one by one until all the data blocks are encrypted. The SM4 cipher algorithm is a block cipher standard. The SM4 cipher algorithm has different encryption / decryption methods, such as XTS mode (XEX Tweakable BlockCipher with Ciphertext Stealing), CBC mode (Cipher BlockChaining), and ECB mode (Electronic Codebook Book). The encryption / decryption calculation process is different in different modes.

[0003] Figure 1 FIG. 2 shows a schematic diagram of the structure of the XTS mode encryption / decryption circuit. Figure 1 As shown, the encryption / decryption circuit of the XTS mode includes a round key expansion module Round_key_expand 1, an encryption / decryption module Endec 1, a round key expansion module Round_key_expand_2, an encryption / decryption module Endec_2, a modular multiplication module Mod-mul, an adder E1 and an adder E2.

[0004] The round key expansion module Round_key_expand_1 and the round key expansion module Round_key_expand_2 expand the keys key1 and key2 respectively, and output the round keys Rk1 and Rk2. The encryption / decryption module Endec_1 calculates the round key Rk1 output by the round key expansion module Round_key_expand1 and the adjustment value Tweak_value, and outputs the intermediate data Tw. The modular multiplication module Mod-mul is based on the parameter a j The output data Tw of the encryption / decryption module Endec_1 is subjected to modular multiplication operation, and output is Tw', where j represents the round. The adder E1 receives the plaintext data Din and the output data Tw' of the modular multiplication module Mod-mul, performs a logical addition operation, and outputs the intermediate data D1. The encryption / decryption module Endec_2 calculates the output data D1 of the adder E1, and outputs D2. The adder E2 performs a logical addition operation on the output data D2 of the encryption / decryption module Endec_2 and the output data Tw' of the modular multiplication module Mod-mul, and outputs the ciphertext data Dout.

[0005] When the XTS encryption / decryption circuit encrypts plaintext data or decrypts ciphertext data, the plaintext data or ciphertext data is divided into multiple data units (DataUnit, abbreviated as DU) according to a specified size, and the encryption calculation is performed according to the data units. For example, the specified size of the data unit is 520 Byte (bytes). Each time the data Din input to the XTS encryption / decryption circuit is a data unit of 520 Byte, and each data unit is encrypted by XTS to obtain a ciphertext, denoted as CipherUnit, CipherUnit = {C1~C m}, and the output data CipherUnit is also a data unit of 520 Byte.

[0006] Each data unit includes m data blocks (block). Let P represent the data block, then DU = {P1~P m}, and the sizes of P1 to P m-1 are all 128 bit. P m can be equal to 128 bit or less than 128 bit. The encryption / decryption module Endec_2 encrypts or decrypts each data block, and the encryption / decryption algorithm is a publicly available standard. Taking the encryption algorithm as an example, it is denoted as C i = endec(P i ), 1 <= i <= m - 2. If P m is 128 bit, then the above formula also applies to the cases of i = m - 1 and m, that is, C m-1 = endec(P m-1 ), C m = endec(P m ). If P m is less than 128 bit, then ciphertext stealing is required during the encryption process of P m-1 and P m .

[0007] Figure 2 shows a schematic diagram of the ciphertext stealing process in the XTS mode. As Figure 2 shown, the encryption / decryption module Endec encrypts P m-1 (other information required for calculating P Figure 2 is not shown in m-1 , such as the round key corresponding to P m-1 ), generates C m and C p , denoted as {C m , C p} = endec(P m-1 ). C p and P mConcatenate to form a 128-bit data block, and input this data block into the encryption / decryption module Endec (the other information required for calculating P Figure 2 is not shown in m , such as the round key corresponding to P m ). The encryption / decryption module Endec encrypts the 128-bit data block formed by concatenation, and the output result is C m-1 , denoted as C m-1 = endec({C p , P m}), where {,} represents the concatenation operation.

[0008] Among them, the data block formed by concatenating C m and C p is 128 bits, and their respective sizes depend on the size of P m . The size after concatenating C p and P m is 128 bits.

[0009] The encryption / decryption module Endec performs encryption calculations on DU = {P1~P m}, and obtains the calculation result CipherUnit = {C1~C m}, and outputs C1~C m-2 , C m-1 , C m in sequence.

[0010] For example, the XTS encryption / decryption circuit needs 32 cycles to encrypt and calculate a 128-bit data block (from inputting the data block to outputting the calculation result). For the data blocks P1 - P m-1 , each data block is 128 bits, and the encryption calculation process of each data block is independent and does not depend on the calculation result of the previous data block when encrypting it. Therefore, the data blocks P1 - P m-1 can be continuously input into the encryption / decryption module Endec. For the data block P m , since it is less than 128 bits, it needs to wait for the completion of the operation of Pm - 1 to obtain C p before starting the encryption calculation (C p and P m form a data block with a length of 128 bits). That is, the calculation of P m-1 needs to be completed before starting the calculation of P m . Therefore, after inputting the data block P m-1 into the encryption / decryption module Endec, it needs to wait 32 cycles before calculating the data block P mCalculations are performed. Thus, during the 32 cycles of waiting for the Pm-1 operation, the XTS encryption / decryption circuit is not fully utilized, and the processing efficiency is affected.

[0011] Figure 3 The timing diagram showing the XTS encryption / decryption circuit processing 3 data units (DU1, DU2, DU3) is shown. In Figure 3 it, the 3 data units DU1, DU2, and DU3 of 520 Byte each are shown by legends of different colors respectively. The "Endec input" line represents the data input to Endec, the "Endec output" line represents the data output by Endec, and the "XTS Output" line represents the output data of the XTS encryption / decryption circuit. Each 520 Byte data unit includes 33 data blocks (data block 1 to data block 33). Among them, data blocks 1 to 32 are all 128 bit, and data block 33 is less than 128 bit. Each data block requires 32 cycles from input to corresponding data output. Data blocks 1 to 32 are all 128 bit, and the encryption calculation process of each data block is independent and does not depend on the calculation result of the previous data block when encrypting it. Therefore, data blocks 1 to 32 can be continuously input to endec. Since data block 33 is less than 128 bit, ciphertext stealing processing is required during the calculation of data block 32 and data block 33, and data block 33 needs to wait for data block 32 to complete the calculation (wait for 32 cycles) before it can be input to endec. Furthermore, in the timing diagram as Figure 3 shown, data blocks 1 to 32 in DU1 are continuously input to the encryption / decryption module Endec (such as the blue legend marked with DU1(1 - 32) in the "Endec input" line in Figure 3 ), wait for 32 cycles, and then input data block 33 in DU1 (such as the blue legend marked with 33 in the "Endec input" line in Figure 3 ); continuously input data blocks 1 to 32 in DU2 (such as the pink legend marked with DU2(1 - 32) in the "Endec input" line in Figure 3 ), wait for 32 cycles, and then input data block 33 in DU2 (such as the pink legend marked with 33 in the "Endec input" line in Figure 3 ); continuously input data blocks 1 to 32 in DU3 (such as the yellow legend marked with DU1(1 - 32) in the "Endec input" line in Figure 3 ), wait for 32 cycles, and then input data block 33 in DU3 (such as the yellow legend marked with 33 in the "Endec input" line in Figure 3(as shown by the yellow legend marked with 33 in the "Endec input" line). It can be seen from this that there will be an idle time of 32 cycles when the XTS encryption / decryption circuit calculates a 520-Byte data, and it is impossible to continuously input data to it. Similarly, there is an idle time of 32 cycles when outputting the calculation result corresponding to the 520-Byte data, and it is impossible to continuously output, which affects the processing efficiency of the XTS encryption / decryption circuit.

[0012] The encryption process and decryption process of the XTS mode are symmetric. If the last data block contained in the ciphertext data is less than 128 bits during the decryption process, ciphertext stealing is also required when decrypting the ciphertext data, that is, continuous input / output is also impossible during the decryption process, thereby affecting the processing efficiency of the XTS encryption / decryption circuit. Summary of the Invention

[0013] To solve the above technical problems or at least partially solve the above technical problems, an embodiment of the present application provides an XTS encryption circuit and an XTS decryption circuit.

[0014] In a first aspect, an embodiment of the present application provides an XTS encryption circuit. The encryption circuit is applicable to perform encryption operations on data units based on a block encryption algorithm in the XTS mode. The data unit includes m data blocks. The first to the (m - 1)th data blocks all have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes. m is an integer greater than 1. The encryption circuit includes a first-round key expansion module, a second-round key expansion module, a first encryption module, a modular multiplication module, a first adder, and a second adder;

[0015] The encryption circuit further includes a second encryption module and a first buffer unit; the second encryption module includes a first encryption component and a second encryption component. Two adjacent data blocks in the first to the (m - 1)th data blocks of the target data unit form a data block pair. The second encryption module receives the data block pair, and the first encryption component and the second encryption component respectively calculate one data block in the data block pair and output the corresponding calculation result;

[0016] The first buffer unit is used to buffer the mth data block of the target data unit input to the second encryption module, so as to input the data block pair composed of the first to the (m - 1)th data blocks of the next target data unit during the ciphertext stealing process of the second encryption module for the (m - 1)th data block of the target data unit, so as to form a continuous input to the second encryption module.

[0017] Optionally, the first encryption component and the second encryption component calculate the data blocks of the data block pair in parallel, and the first encryption component and the second encryption component are independent of each other.

[0018] Optionally, the encryption circuit further includes: a second cache unit, a third cache unit, a fourth cache unit, a fifth cache unit, a first multiplexer, and a second multiplexer;

[0019] The second cache unit caches the calculation results corresponding to the first to (m - 3)th data blocks processed by the second encryption module for the target data unit;

[0020] The third cache unit caches the calculation results corresponding to the (m - 2)th data block and the (m - 1)th data block processed by the second encryption module for the target data unit; the calculation result corresponding to the (m - 1)th data block includes a first data shard and a second data shard, and the data block formed by splicing the second data shard and the mth data block of the target data unit has a preset number of bytes;

[0021] The fourth cache unit caches the calculation result corresponding to the (m - 2)th data block and the first data shard;

[0022] The fifth cache unit caches the calculation result corresponding to the mth data block processed by the second encryption module for the target data unit;

[0023] The output end of the first multiplexer is coupled to the first adder, and is used to select a data block from the data block pair composed of the first to (m - 1)th data blocks, the mth data block cached by the first cache unit, and the second data shard cached by the third cache unit and provide it to the first adder;

[0024] The second multiplexer sequentially obtains the calculation results corresponding to the first to (m - 3)th data blocks from the second cache unit, the calculation result corresponding to the (m - 2)th data block from the fourth cache unit, the calculation result corresponding to the mth data block from the fifth cache unit, and the first data shard from the fourth cache unit and outputs them.

[0025] Optionally, in response to caching the calculation result corresponding to the (m - 1)-th data block in the target data unit into the third cache unit, the first multiplexer obtains the second data shard in the calculation result from the third cache unit, and simultaneously provides the data block formed by splicing the second data shard and the m-th data block in the target data unit to the first encryption component and the second encryption component, or provides the data block formed by splicing the second data shard and the m-th data block in the target data unit only to the first encryption component, or provides the data block formed by splicing the second data shard and the m-th data block in the target data unit only to the second encryption component.

[0026] Optionally, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the first data unit to the second encryption module, and the second encryption module calculates the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the first data unit, wherein the first encryption component and the second encryption component in the second encryption module respectively calculate one data block in the received data block pair; it takes (m - 1) cycles for the first encryption component and the second encryption component to calculate each data block from reception to output of the calculation result; cache the m-th data block in the first data unit into the first cache unit, so as to input the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the second data unit to the second encryption module before the ciphertext stealing process for the (m - 1)-th data block in the first data unit is completed;

[0027] In response to caching the m-th data block in the first data unit into the first cache unit, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the second data unit to the second encryption module; cache the m-th data block in the second data unit into the first cache unit;

[0028] In response to caching the m-th data block in the second data unit into the first cache unit, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the third data unit to the second encryption module;

[0029] While receiving the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the third data unit, the second encryption module sequentially outputs the calculation results corresponding to the 1st to the (m - 1)th data blocks in the first data unit, caches the calculation results corresponding to the 1st to the (m - 3)th data blocks in the first data unit into the second cache unit, caches the calculation result corresponding to the (m - 2)th data block and the first data shard and the second data shard corresponding to the (m - 1)th data block in the first data unit into the third cache unit, and caches the calculation result corresponding to the (m - 2)th data block and the first data shard corresponding to the (m - 1)th data block in the first data unit into the fourth cache unit;

[0030] In response to inputting the data block pair formed by the (m - 2)th data block and the (m - 1)th data block in the third data unit into the second encryption module, the first multiplexer obtains the second data shard corresponding to the first data unit from the third cache unit and obtains the mth data block in the first data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the first data unit and the mth data block to the second encryption module, wherein the data block formed by splicing the second data shard corresponding to the first data unit and the mth data block is provided to the first encryption component and the second encryption component in the second encryption module simultaneously;

[0031] In response to inputting the data block formed by splicing the second data shard corresponding to the first data unit and the mth data block into the second encryption module, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the fourth data unit to the second encryption module; caches the mth data block in the fourth data unit into the first cache unit;

[0032] When receiving the data block formed by splicing the second data shard corresponding to the first data unit and the mth data block, the second encryption module starts to sequentially output the calculation results corresponding to the 1st to the (m - 1)th data blocks in the second data unit, caches the calculation results corresponding to the 1st to the (m - 3)th data blocks in the second data unit into the second cache unit, caches the calculation result corresponding to the (m - 2)th data block and the first data shard and the second data shard corresponding to the (m - 1)th data block in the second data unit into the third cache unit, and caches the calculation result corresponding to the (m - 2)th data block and the first data shard corresponding to the (m - 1)th data block in the second data unit into the fourth cache unit;

[0033] In response to inputting the data block pair formed by the (m - 2)-th data block and the (m - 1)-th data block in the fourth data unit into the second encryption module, the first multiplexer obtains the second data shard corresponding to the second data unit from the third cache unit and the m-th data block in the second data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block to the second encryption module, wherein the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block is provided to the first encryption component and the second encryption component in the second encryption module simultaneously;

[0034] In response to providing the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block to the second encryption module, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the fifth data unit to the second encryption module; the m-th data block in the fifth data unit is cached to the first cache unit;

[0035] While receiving the data block pair formed by the (m - 2)-th data block and the (m - 1)-th data block in the fourth data unit, the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block, and the data block pairs formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the fifth data unit, the second encryption module starts to sequentially output the calculation results corresponding to the first to (m - 1)-th data blocks in the third data unit and the calculation result corresponding to the m-th data block in the first data unit, caches the calculation results corresponding to the first to (m - 3)-th data blocks in the third data unit to the second cache unit, caches the calculation results corresponding to the (m - 2)-th data block and the first data shard and the second data shard corresponding to the (m - 1)-th data block in the third data unit to the third cache unit, caches the calculation results corresponding to the (m - 2)-th data block and the first data shard corresponding to the (m - 1)-th data block in the third data unit to the fourth cache unit, and caches the calculation result corresponding to the m-th data block in the first data unit to the fifth cache unit.

[0036] Optionally, the encryption circuit sequentially obtains the calculation results corresponding to the 1st to the (m - 3)th data blocks in the first data unit from the second cache unit, obtains the calculation result corresponding to the (m - 2)th data block in the first data unit from the fourth cache unit, obtains the calculation result corresponding to the mth data block in the first data unit from the fifth cache unit, and obtains the first data shard output corresponding to the (m - 1)th data block in the first data unit from the fourth cache unit; in response to the completion of the first data shard output corresponding to the (m - 1)th data block in the first data unit, obtains the calculation results corresponding to the 1st to the (m - 3)th data blocks in the second data unit from the second cache unit.

[0037] Optionally, the first cache unit, the second cache unit, the third cache unit, the fourth cache unit, and the fifth cache unit are all hardware queues. Data is added to the tail of the hardware queue, and data is retrieved from the head of the hardware queue.

[0038] Optionally, after obtaining the calculation result corresponding to the mth data block in the first data, the encryption circuit outputs the results corresponding to each data block in the first data unit. Alternatively, after obtaining the calculation results corresponding to the 1st to the (m - 3)th data blocks in the first data unit, it outputs the calculation results corresponding to the 1st to the (m - 3)th data blocks. After obtaining the calculation result corresponding to the mth data block in the first data unit, it outputs the calculation result corresponding to the (m - 2)th data block in the first data unit, the calculation result of the mth data block, and the calculation result corresponding to the (m - 1)th data block in the first data unit.

[0039] Optionally, the first cache unit is further configured to cache data related to the mth data block.

[0040] Optionally, the encryption circuit further includes a sixth cache unit; the sixth cache unit is coupled to the first encryption module and is configured to cache the data output by the first encryption module.

[0041] Optionally, the encryption circuit further includes a seventh cache unit, an eighth cache unit, and a third multiplexer;

[0042] The seventh cache unit is coupled to the second round key expansion module and is configured to cache the round key data corresponding to the second data unit output by the second round key expansion module;

[0043] The eighth cache unit is configured to cache the round key data corresponding to the first data unit output by the second round key expansion module, and the first data unit is input to the second encryption module prior to the second data unit;

[0044] The output end of the third multiplexer is coupled to the second encryption module. The third multiplexer is configured to obtain round key data corresponding to the data block input to the second encryption module from the seventh cache unit or the eighth cache unit, and provide it to the second encryption module.

[0045] Optionally, the encryption circuit further includes a ninth cache unit configured to cache the identification information of the data unit input to the encryption circuit.

[0046] Optionally, the first multiplexer continuously provides data block pairs to the second encryption module in a first data mode, and the first data mode is shown in the following formula (1):

[0047] xDU_i_d = {sDU(i - 3)17_d, sDU(i)_d} (1)

[0048] Wherein, xDU_i_d represents the data block pair provided to the second encryption module, sDU(i - 3)17_d represents the data block pair formed by splicing the second data shard corresponding to the (m - 1)-th data block in the (i - 3)-th data unit and the m-th data block in the (i - 3)-th data unit, and sDU(i)_d represents the data block pair formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the i-th data unit; i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 4;

[0049] The second encryption module outputs the calculation result in a second data mode, and the second data mode is shown in the following formula (2):

[0050] xCipher _i_d = {sCU(i - 3)17, sCU(i)_d} (2)

[0051] xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the m-th data block in the (i - 3)-th data unit, and sCU(i)_d represents the calculation results corresponding to the first to (m - 1)-th data blocks in the i-th data unit;

[0052] The encryption circuit outputs encrypted data in a third data mode, and the third data mode is shown in the following formula (3):

[0053] xCU_j = {CU(j)1 - 31, CU(j)33 - 32} (3)

[0054] xCU_j represents the encrypted data output by the encryption circuit, CU(j)1-31 represents the calculation results of the 1st to the (m-2)nd data blocks in the jth data unit, CU(j)33-32 represents the calculation result of the mth data block and the calculation result corresponding to the (m-1)th data block in the jth data unit, and j = i - 2.

[0055] Optionally, the first multiplexer continuously provides data block pairs to the second encryption module in a fourth data mode, and the fourth data mode is shown in the following formula (4):

[0056] xDU_i_d = {sDU(i-3)17_d, sDU(i-1)15-16_d, sDU(i)1-14_d} (4)

[0057] xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair formed by the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit and the data block obtained by splicing the mth data block in the (i-3)th data unit, sDU(i)15-16_d represents the data block pair formed by the (m-4)th data block and the (m-3)th data block in the (i-1)th data unit and the data block pair formed by the (m-2)th data block and the (m-1)th data block, sDU(i)1-14_d represents the data block pairs formed by adjacent two data blocks among the 1st to the (m-5)th data blocks in the ith data unit, i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 6;

[0058] The second encryption module outputs calculation results in a fifth data mode, and the fifth data mode is shown in the following formula (5):

[0059] xCipher_i_d = {sCU(i-3)17, sCU(i-1)15-16_d, sCU(i)1-14_d} (5)

[0060] xCipher_i_d represents the calculation results output by the second encryption module, sCU(i-3)17 represents the calculation result of the mth data block in the (i-3)th data unit, sCU(i)15-16_d represents the calculation results corresponding to the (m-4)th data block, the (m-3)th data block, the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-14_d represents the calculation results corresponding to the 1st to the (m-5)th data blocks in the ith data unit;

[0061] The encryption circuit outputs encrypted data in a sixth data mode, and the sixth data mode is shown in the following formula (6):

[0062] xCU_j = {CU(j)1-31, CU(j)33-32} (6)

[0063] xCU_j represents the encrypted data output by the encryption circuit, CU(j)1-31 represents the calculation results of the first to the (m-2)th data blocks in the jth data unit, CU(j)33-32 represents the calculation results of the mth data block and the calculation results corresponding to the (m-1)th data block in the jth data unit, and j = i-4.

[0064] Optionally, the first multiplexer continuously provides data block pairs to the second encryption module in a seventh data mode, and the seventh data mode is shown in the following formula (7):

[0065] xDU_i_d = {sDU(i-3)17_d, sDU(i-1)16_d, sDU(i)1-15_d} (7)

[0066] xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair formed by the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit and the data block obtained by splicing the mth data block in the (i-3)th data unit, sDU(i-1)16_d represents the data block pair formed by the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, sDU(i)1-15_d represents the data block pairs formed by adjacent two data blocks among the first to the (m-3)th data blocks in the ith data unit, i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 7;

[0067] The second encryption module outputs calculation results in an eighth data mode, and the eighth data mode is shown in the following formula (8):

[0068] xCipher_i_d = {sCU(i-3)17, sCU(i-1)16_d, sCU(i)1-15_d} (8)

[0069] xCipher_i_d represents the calculation results output by the second encryption module, sCU(i-3)17 represents the calculation results of the mth data block in the (i-3)th data unit, sCU(i)16_d represents the calculation results corresponding to the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-15_d represents the calculation results corresponding to the first to the (m-3)th data blocks in the ith data unit;

[0070] The encryption circuit outputs encrypted data in a ninth data mode, and the ninth data mode is shown in the following formula (9):

[0071] xCU_j = {CU(j)1-31, CU(j)33-32} (9)

[0072] xCU_j represents the encrypted data output by the encryption circuit, CU(j)1-31 represents the calculation results of the first to the (m-2)th data blocks in the jth data unit, CU(j)33-32 represents the calculation results of the mth data block and the calculation results corresponding to the (m-1)th data block in the jth data unit, and j = i-5.

[0073] Optionally, the first multiplexer continuously provides data block pairs to the second encryption module in a tenth data mode, and the tenth data mode is shown in the following formula (10):

[0074] xDU_i_d = {sDU(i-3)17_d, sDU(i-1)16_d, sDU(i)1-15_d} (10)

[0075] xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair formed by the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit and the data block obtained by splicing the mth data block in the (i-3)th data unit, sDU(i-1)16_d represents the data block pair formed by the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, sDU(i)1-15_d represents the data block pairs formed by adjacent two data blocks among the first to the (m-3)th data blocks in the ith data unit, i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 5;

[0076] The second encryption module outputs calculation results in an eleventh data mode, and the eleventh data mode is shown in the following formula (11):

[0077] xCipher_i_d = {sCU(i-3)17, sCU(i-1)16, sCU(i)1-15_d} (11)

[0078] xCipher_i_d represents the calculation results output by the second encryption module, sCU(i-3)17 represents the calculation results of the mth data block in the (i-3)th data unit, sCU(i)16_d represents the calculation results corresponding to the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-15_d represents the calculation results corresponding to the first to the (m-3)th data blocks in the ith data unit;

[0079] The encryption circuit outputs encrypted data in a twelfth data mode, and the twelfth data mode is shown in the following formula (12):

[0080] xCU_j = {CU(j)1-31, CU(j)33-32} (12)

[0081] xCU_j represents the encrypted data output by the encryption circuit, CU(j)1-31 represents the calculation results of the first to the (m-2)th data blocks in the jth data unit, CU(j)33-32 represents the calculation results of the mth data block and the calculation results corresponding to the (m-1)th data block in the jth data unit, and j = i-3.

[0082] Optionally, each data block pair of the xDU_i is continuously input into the second encryption module, and in each cycle, a data block pair composed of two adjacent data blocks in the xDU_i is input into the second encryption module;

[0083] The second encryption module continuously outputs each data block of the xCipher_i, and in each cycle, two data blocks of the xCipher_i are output from the second encryption module; and

[0084] The encryption circuit continuously outputs each data block of the xCU_j, and in each cycle, one data block of the xCU_j is output from the encryption circuit.

[0085] Optionally, each data block pair of xDU_i and xDU_(i+1) is continuously input into the second encryption module, and in the next cycle after the last data block pair of xDU_i is input into the second encryption module, the first data block pair of xDU_(i+1) is input into the second encryption module;

[0086] The second encryption module continuously outputs each data block pair of xCipher_i and xCipher_(i+1), and in the next cycle after the last data block pair of xCipher_i is output from the second encryption module, the first data block pair of xCipher_(i+1) is output from the second encryption module; and

[0087] The encryption circuit continuously outputs each data block of xCU_j and xCU_(j+1), and in the next cycle after the last data block of xCU_j is output from the encryption circuit, the first data block of xCU_(j+1) is output from the encryption circuit.

[0088] Second aspect, an embodiment of the present application provides an XTS decryption circuit, which is applicable to decrypting data units based on a block decryption algorithm in XTS mode. The data unit includes m data blocks. The first to the (m - 1)th data blocks each have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes, where m is an integer greater than 1. The decryption circuit includes a first-round key expansion module, a second-round key expansion module, a first decryption module, a modular multiplication module, a first adder, and a second adder;

[0089] The decryption circuit further includes a second decryption module and a first buffer unit;

[0090] The second decryption module includes a first decryption component and a second decryption component. In the target data unit, two adjacent data blocks among the first to the (m - 1)th data blocks form a data block pair. The second decryption module receives the data block pair, and the first decryption component and the second decryption component respectively calculate one data block in the data block pair and output corresponding calculation results;

[0091] The first buffer unit is used to buffer the mth data block of the target data unit input to the second decryption module, so as to input the data block pair formed by the first to the (m - 1)th data blocks of the next target data unit during the process of ciphertext stealing processing of the (m - 1)th data block of the target data unit, so as to form continuous input to the second decryption module.

[0092] In the XTS encryption / decryption circuit provided by the embodiment of the present application, the second encryption / decryption module includes a first encryption component and a second encryption component. The second encryption / decryption module receives the data block pair formed by two adjacent data blocks in the data unit. The first encryption component and the second encryption component respectively perform operations on one data block in the data block pair, and can perform operations on two data blocks simultaneously, improving data processing efficiency. At the same time, the mth data block of the target data unit (the previous data unit) input to the second encryption / decryption module is buffered in the first buffer unit. Before the ciphertext stealing processing of the (m - 1)th data block of the previous target data unit is completed, the data block pair formed by the first to the (m - 1)th data blocks of the next target data unit is input to the second encryption / decryption module, so that data blocks are continuously input to the second encryption / decryption module during the time of waiting for the calculation result of the (m - 1)th data block of the previous data unit. During the time of waiting for the calculation result of the (m - 1)th data block of the previous data unit, the second encryption / decryption module still has data to process and will not be idle, making full use of the second encryption / decryption module and improving the processing efficiency of the XTS encryption / decryption circuit. Description of the Drawings

[0093] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.

[0094] Figure 1 Fig. shows a schematic structural diagram of a standard XTS encryption / decryption circuit provided by the prior art;

[0095] Figure 2 Fig. shows a schematic flow diagram of the ciphertext stealing process performed by the XTS encryption / decryption circuit;

[0096] Figure 3 Fig. shows a timing diagram of the standard XTS encryption / decryption circuit provided by the prior art;

[0097] Figure 4 Fig. shows a structural diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0098] Figure 5 Fig. shows a structural diagram of the XTS encryption / decryption circuit provided by another embodiment of the present application;

[0099] Figure 6 Fig. shows a structural diagram of the XTS encryption / decryption circuit provided by yet another embodiment of the present application;

[0100] Figure 7 Fig. shows a timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0101] Figure 8A 、 8B and 8C show the data mode of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0102] Figure 9 Fig. shows the data input / output mode of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0103] Figure 10 Fig. shows a structural diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0104] Figure 11 Fig. shows a structural diagram of the XTS encryption / decryption circuit provided by another embodiment of the present application;

[0105] Figure 12 Fig. shows a structural diagram of the XTS encryption / decryption circuit provided by yet another embodiment of the present application;

[0106] Figure 13 Fig. shows a timing diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application;

[0107] Figure 14A 、 14B and 14C illustrate the data mode of the XTS encryption / decryption circuit provided by the embodiment of the present application;

[0108] Figure 15 illustrates the data input / output mode of the XTS encryption / decryption circuit provided by the embodiment of the present application;

[0109] Figure 16 illustrates another timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application;

[0110] Figure 17 illustrates yet another timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application;

[0111] Figure 18 illustrates yet another timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application. Detailed implementation manners

[0112] Next, in combination with the accompanying drawings in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0113] Figure 4 illustrates the structural diagram of the XTS encryption / decryption circuit provided by an embodiment of the present application.

[0114] As Figure 4 shown, the XTS encryption / decryption circuit includes a round key expansion module Round_key_Expand_1, a round key expansion module Round_key_Expand_2, an encryption / decryption module Endec_1, an encryption / decryption module Endec_2, a modular multiplication module Mod-mul, an adder E1, an adder E2, a multiplexer mux1, a multiplexer mux2, a buffer unit Buffer1, a buffer unit Buffer2, a buffer unit Buffer3, a buffer unit Buffer4, and a buffer unit Buffer5.

[0115] Among them, the functions of the round key expansion module Round_key_Expand_1, the round key expansion module Round_key_Expand_2, the encryption / decryption module Endec_1, the encryption / decryption module Endec_2, the modular multiplication module Mod-mul, the adder E1, and the adder E2 are the same as Figure 1It is the same as the standard XTS encryption / decryption circuit shown. To avoid repetition, it will not be elaborated here.

[0116] The XTS encryption process and the decryption process are symmetric. Taking the encryption process as an example, the XTS encryption / decryption circuit of the embodiment of the present application will be described. Hereinafter, taking the data unit DU = {P1~P m}, the sizes of P1 to P m-1 are all 128 bits, and P m is less than 128 bits as an example to illustrate the circuit provided in this embodiment.

[0117] The buffer unit Buffer1 is used to buffer the data block P m . If the last data block of the current data unit input to the XTS encryption / decryption circuit is not 128 bits, then the last data block P m is buffered in Buffer1, so that during the encryption of P m-1 of the current data unit and the ciphertext stealing process, the 128-bit data block of the next data unit can be input to the circuit first, so as to continuously input data to Endec_2 and prevent it from being idle due to ciphertext stealing. As an example, the encryption process of P m-1 includes, for example, 32 cycles, and 32 128-bit data blocks of the next data unit are sequentially input to Endec_2 during these cycles. Since the first 32 data blocks of the data unit are sequentially input to Endec_2, these data blocks do not need to be buffered in the buffer unit Buffer1. Therefore, the size of the buffer unit Buffer1 only needs to accommodate 1 128-bit data block.

[0118] The buffer unit Buffer2 is used to buffer the calculation results C1 - C m-2 corresponding to the data blocks P1 - P m-2 .

[0119] The buffer unit Buffer3 is used to buffer the calculation results C m-1 corresponding to the data block P p and C m . The buffer unit Buffer4 buffers C m . Since it is necessary to splice the calculation result C m-1 corresponding to the data block P p with the data block P m to form a 128-bit data block and input it to the encryption / decryption module Endec2, it is necessary to buffer the calculation result C m-1 corresponding to the data block P p and C m in Buffer3. To ensure that the buffered C p is not lost when outputting C m , Cm Further cache it into Buffer4.

[0120] The cache unit Buffer5 is used to cache the last data block P m The corresponding calculation result C m-1 .

[0121] Optionally, when the XTS encryption / decryption circuit outputs P1 to P m The corresponding calculation result, it can obtain and output data from the cache units Buffer2, Buffer5, and Buffer4 in the order of C1 - C m when the calculation of the data block P is completed, or it can also output P1 - P m The corresponding calculation result C1 - C m-2 first, and when the calculation result C m-2 corresponding to P is obtained m then output C m-1 as well as P m-1 The corresponding calculation result C m-1 . If when the calculation result C m corresponding to P is obtained m and C1 - C m-1 has not been completely output yet, first cache C m-2 into Buffer5. m-1

[0122] The multiplexer Mux is used to select a certain signal from multiple digital input signals and forward it, and output different selected signals to the same output line. In this embodiment, the input end of the multiplexer mux1 receives the data block P1 - P of the data unit DU externally input to the XTS encryption / decryption circuit m-1 , the calculation result C m-1 corresponding to P provided by the cache unit Buffer3 p , and the P m cached in the cache unit Buffer1. The output end of the multiplexer mux1 is coupled to the input end of the adder E1. The multiplexer mux1 selects the data input to the adder E1 from the data block P1 - P m-1 , P m-1 The corresponding calculation result C p , and the P m cached in the cache unit Buffer1. The input end of the multiplexer mux2 is coupled to the cache units Buffer2, Buffer4, and Buffer5, and obtains and outputs data from the cache units Buffer2, Buffer5, and Buffer4 in the order of C1 - C m .

[0123] Taking the data unit DUa = {P 1a ~ P 33a}, DU b = {P 1b ~ P 33b}, DU c = {P 1c ~ P 33c}, P 1a to P 32a are all 128 bits in size, P 33a is less than 128 bits, P 1b to P 32b are all 128 bits in size, P 33b is less than 128 bits, P 1c to P 32c are all 128 bits in size, P 33c is less than 128 bits as an example to illustrate the processing process of the XTS encryption / decryption circuit of this application embodiment. Among them, each data block of the data unit DU is sequentially provided to the XTS encryption / decryption circuit:

[0124] (1) Continuously input the data blocks P 1a to P 32a into the encryption / decryption module Endec, cache the data block P 33a into Buffer1. After 32 cycles when the data block P 1a is input to Endec, sequentially cache the corresponding encryption results C 1a to P 31a into Buffer2, cache the encryption result C 1a - C 31a corresponding to P 32a into Buffer3, and cache the C pa and C 33a cached in Buffer3 into Buffer4. 33a

[0125] (2) After caching the data block P 33a into Buffer1, continuously input the data blocks P 1b to P 32b into the encryption / decryption module Endec. Optionally, there is no gap between the data block P 32a and the data block P 1b , but they are continuously input into the encryption / decryption module Endec in time to maximize the utilization rate of the encryption / decryption module Endec. And cache the data block P 33b into Buffer1. Cache the corresponding encryption results C 1b to P 31b 1b - C​​31b Cache it into Buffer2, and for P 32b The corresponding encrypted result C pb and C 33b Cache it into Buffer3, and cache the C cached in Buffer3 33b into Buffer4.

[0126] (3) After the data block P 32b is input to Endec, at this time, 32 cycles have passed since the data block P 32a was input to Endec, and the corresponding C pa has been calculated and cached in the cache unit Buffer3. Next, take out P 33a from the cache unit Buffer1, take out C pa from the cache unit Buffer3, and combine P 33a and C pa to form a 128-bit data block and input it into the encryption / decryption module Endec. Next, continuously input the data blocks P1c to P 32c into the encryption / decryption module Endec. Optionally, there is no gap between combining P 33a and C pa to form a 128-bit data block and inputting the data block P 1c into the input encryption / decryption module Endec respectively, but they are continuously input into the encryption / decryption module Endec in time to maximize the utilization rate of the input encryption / decryption module Endec. Cache the data block P 33c into Buffer1. Cache the C 33a corresponding to P 32a into Buffer5.

[0127] During the above processing, cache the data block P 33a into Buffer1. During the ciphertext stealing process for DU a , input the first 32 data blocks P b of DU 1b to P 32b into the encryption / decryption module Endec2, so that data blocks are continuously input into the encryption / decryption module Endec during the time of waiting for C pa , and there is still data to be processed by the encryption / decryption module Endec during the time of waiting for C pa , without idling, making full use of the encryption / decryption module Endec and improving the processing efficiency of the XTS encryption / decryption circuit.

[0128] In an alternative embodiment, the cache unit Buffer1 can also cache the data block P mThe corresponding Tw or other control information.

[0129] Figure 4 Each buffer unit (Buffer) shown in the figure is, for example, a hardware queue. Data is added to the buffer unit only through the tail of the queue, and data is retrieved from the buffer unit only through the head of the queue, without supporting access to other elements of the queue except the head / tail of the queue. Moreover, each element of the queue has a determined size and is accessed as a whole. Thus, compared with a general random access memory, the hardware queue has higher performance and occupies less hardware resources.

[0130] Figure 5 The structural diagram of the XTS encryption / decryption circuit according to another embodiment of the present application is shown. As Figure 5 shown, on the basis of the embodiment shown in Figure 4 the XTS encryption / decryption circuit further includes a buffer unit Buffer6, a buffer unit Buffer7, a buffer unit Buffer8, and a multiplexer mux3.

[0131] The buffer unit Buffer6 is coupled to the encryption / decryption module Endec_1 and is used to cache the output data of the encryption / decryption module Endec_1. To improve the encryption calculation speed and ensure that when each data block of the data unit DU is input to the encryption / decryption module Endec_2, its corresponding Tw has been calculated, the Tweak_value is encrypted in advance. Since the Tweak_value will be encrypted in advance, Buffer6 is required to cache its encryption result. In an optional embodiment, the buffer unit Buffer6 may also cache control information related to Tw, such as the data length of the data unit, the encryption / decryption enable signal, the encryption / decryption selection signal, etc. Optionally, since the calculation of Tw does not depend on the data unit DU, the Tw required for each data unit DU can be calculated in advance or additionally, without having to adopt the Figure 5 circuit structure including Endec_1 and Buffer6 shown.

[0132] The buffer unit Buffer7 is coupled to the round key expansion module Round_key_Expand_2 and is used to cache the round key Rk2 output by the Round_key_Expand_2. To improve the encryption calculation speed and ensure that when the data unit DU is input to the encryption / decryption module Endec_2, its corresponding round key Rk2 has been calculated, the key2 is expanded in advance and the obtained round key Rk2 is cached in Buffer7.

[0133] In order to improve the processing efficiency of the XTS encryption / decryption circuit, the next data unit is input during the ciphertext stealing process of the previous data unit. To ensure that the round key Rk2 corresponding to the previous data unit is not overwritten by the round key Rk2 corresponding to the next data unit, the round key Rk2 corresponding to the previous data unit cached in Buffer7 is cached in Buffer8.

[0134] The multiplexer mux3 is coupled to the buffer unit Buffer7 and the buffer unit Buffer8, and reads the round key Rk2 corresponding to each of the multiple data blocks currently processed by the input encryption / decryption module Endec2 from Buffer7 and Buffer8.

[0135] Figure 6 The structural diagram of the XTS encryption / decryption circuit according to another embodiment of the present application is shown. As Figure 6 shown, the XTS encryption / decryption circuit further includes a buffer unit Buffer9 on the basis of the embodiment shown in Figure 5 To ensure that when the XTS encryption / decryption circuit outputs data, the data unit corresponding to the output data is determined, the buffer unit Buffer9 is used to cache the identification information of the data unit. According to this identification information, the data unit corresponding to the current calculation result output by the XTS encryption / decryption circuit can be determined. In an alternative embodiment, the identification information cached in Buffer9 may be the length of the data unit, and counting control is performed according to the length of the data unit to ensure the normal output of the data. In other alternative embodiments, other control information may also be cached in Buffer9, such as an encryption / decryption enable signal, an encryption / decryption selection signal, etc.

[0136] Figure 7 The timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application is shown. In Figure 7 it, legends of different colors represent different data units. For example, the blue legend represents the data unit DU(1), the pink legend represents the data unit DU(2), the yellow legend represents the data unit DU(3), and the white legend represents the data unit DU(4). "sDU(i)1-32" represents the 1st to 32nd 128-bit data blocks in the data unit DU(i), that is, sDU(i)1-32 = {P1, P2, P3,......, P31, P32} i . "sDU(i)33" represents a 128-bit data block formed by splicing the calculation result C p of the 32nd data block in the data unit DU(i) with the 33rd data block, that is, sDU(i)33 = {Cp, P33} i, {C33, Cp} = Cipher(P32), where Cipher(P32) represents the calculation result of P32. "sCU(i)1-31" represents the calculation results corresponding to the first to the 31st data blocks in the data unit DU(i), and sCU(i)1-31 = {C1, C2, C3......, C29, C30, C31} i ."sCU(i)33" represents the calculation result corresponding to the 33rd data block in the data unit DU(i), and sCU(i)33 = {C32} i ."sCU(i)32" represents the calculation result corresponding to the 32nd data block of the data unit DU(i), and sCU(i)32 = {C33} i ."Endec input" represents the input data of the encryption / decryption module Endec, "Endecoutput" represents the output data of the encryption / decryption module Endec, and "XTS Output" represents the output data of the XTS encryption / decryption circuit.

[0137] As Figure 7 shown, first, the first to the 32nd 128-bit data blocks in the data unit DU(1) (such as Figure 7 the blue legend marked with sDU1(1-32) in the "Endecinput" row in Figure 7 ) are continuously input into Endec, and then the first to the 32nd 128-bit data blocks of the data unit DU(2) (such as Figure 7 the pink legend marked with sDU2(1-32) in the "Endec input" row in p are continuously input into Endec. For example, it takes 32 cycles for Endec to encrypt and calculate a 128-bit data block (from the input data block to the output calculation result). When the 32nd data block in the data unit DU(2) is input to Endec, the calculation of the 32nd data block in the data unit DU(1) is completed, and the corresponding C p can be input into Endec by splicing with the 33rd data block in the data unit DU(1) to form a 128-bit data block. Therefore, after the first to the 32nd 128-bit data blocks in the data unit DU(2) are input, the 33rd data block in the data unit DU(1) (such as Figure 7 the blue legend marked with 33 in the "Endec input" row in Figure 7In the "Endec input" row, there is a yellow legend marked with sDU3(1 - 32). When the 32nd data block in the Endec input completed data unit DU(3) is input, the calculation of the 32nd data block in data unit DU(2) has been completed, obtaining the corresponding C p , C can be p input into Endec as a 128-bit data block formed by concatenating with the 33rd data block in data unit DU(2). Therefore, after the input of the 1st to 32nd 128-bit data blocks in data unit DU(3) is completed, the 33rd data block in data unit DU(2) is input (such as Figure 7 the pink legend marked with 33 in the "Endec input" row in). After inputting the 33rd data block in data unit DU(2) into Endec2, the calculation of the 32nd data block in data unit DU(3) has not been completed yet, so the 1st to 32nd data blocks in data unit DU(4) are input into Endec2 (such as Figure 7 the white legend marked with sDU4(1 - 32) in the "Endec input" row in). When the 32nd data block in data unit DU(4) is input into Endec and completed, the calculation of the 32nd data block in data unit DU(3) is completed, obtaining the corresponding C p , C can be p input into Endec as a 128-bit data block formed by concatenating with the 33rd data block in data unit DU(3). Therefore, after the input of the 1st to 32nd 128-bit data blocks in data unit DU(2) is completed, the 33rd data block in data unit DU(3) is input (such as Figure 7 the yellow legend marked with 33 in the "Endec input" row in).

[0138] The encryption / decryption module Endec outputs the corresponding calculation results in the order of the input data. Endec takes 32 cycles to calculate each data block. Therefore, the output of the calculation result corresponding to each data block lags 32 cycles behind the input of that data block. When the 1st data block in data unit DU(2) is input, the calculation of the 1st data block in data unit DU(1) by Endec is completed, obtaining its calculation result. The moment when Endec outputs the calculation result of the 1st data block in data unit DU(1) is the same as the moment when the 1st data block in data unit DU(2) is input to it. Therefore, in Figure 7In the "Endec output" row, the starting end of the blue legend marked with sCU(1)1 - 32 is horizontally aligned with the starting end of the pink legend marked with sDU(2)1 - 32 in the "Endec input" row (in the horizontal direction, the right represents the direction of time passage). Also, since the input sDU(2)1 - 32 takes 32 cycles and the output sCU(1)1 - 32 also takes 32 cycles, the ending end of the blue legend marked with sCU(1)1 - 32 is horizontally aligned with the ending end of the pink legend marked with sDU(2)1 - 32 in the "Endec input" row. After completing the calculation of the 1st to 32nd data blocks in data unit DU(1), the calculation of the 1st to 32nd data blocks in data unit DU(2) starts. Then, after the calculation results of the 1st to 32nd data blocks in data unit DU(1) are output, the calculation results of the 1st to 32nd data blocks in data unit DU(2) start to be output (such as Figure 7 the pink legend marked with sCU(2)1 - 32 in the "Endec output" row in Figure 7 When the calculation results of the 1st to 32nd data blocks in data unit DU(2) are output, 32 cycles have passed since the input of the 33rd data block in data unit DU(1). At this time, the calculation of the 33rd data block in data unit DU(1) is completed, and the calculation results of the 33rd data block in data unit DU(1) can be output (such as Figure 7 the blue legend marked with 33 in the "Endec output" row in Figure 7 After the calculation results of the 33rd data block in data unit DU(1) are output, the calculation results of the 1st to 32nd data blocks in data unit DU(3) start to be output (such as

[0139] For the output XTS Output of the XTS encryption - decryption circuit, after calculating the calculation results of several data blocks (such as the first 5 data blocks) of data unit DU(1), the output starts (such as Figure 7In the "XTS output" row, there is a blue legend marked with sCU(1)1-31. After the calculation results corresponding to the 31st data block are output, since the 33rd data block has not been calculated yet, it waits for the calculation of the 33rd data block to be completed. After the calculation of the 33rd data block is completed, the calculation results of the 33rd data block are output (as Figure 7 In the "XTS output" row, there is a blue legend marked with 33), and the calculation results of the 32nd data block (as Figure 7 In the "XTS output" row, there is a blue legend marked with 32). It can be understood that when the XTS encryption / decryption circuit outputs the calculation results of the data unit DU(1), in the Figure 7 example, there is a gap between the output of sCU(1)1-31 and the output of sCU(1)33, rather than continuous output. The size of this gap depends on the latency of XTS Output relative to EndecOutput for CU(1). Optionally, by caching sCU(1)1-31 obtained from Endec Output for multiple cycles, continuous output of sCU(1)1-31, sCU(1)33, and sCU(1)32 can be achieved, but this requires an increase in the capacity of the cache unit.

[0140] Before the calculation results of the 32nd data block in the data unit DU(1) are output, the calculations of the 1st to 31st data blocks in the data unit DU(2) have been completed. Then, immediately after the calculation results of the 32nd data block in the data unit DU(1) are output, the calculation results of the 1st to 31st data blocks in the data unit DU(2) are output (as Figure 7 In the "XTS output" row, there is a pink legend marked with sCU(2)1-31). When the calculation results of the 1st to 31st data blocks in the data unit DU(2) are completed, the calculations of the 32nd and 33rd data blocks in the data unit DU(2) have also been completed. Then, the calculation results of the 33rd data block (as Figure 7 In the "XTS output" row, there is a pink legend marked with 33) and the calculation results of the 32nd data block (as Figure 7 In the "XTS output" row, there is a pink legend marked with 32) can be output immediately, and the output is continuous without interruption during the process of outputting the calculation results corresponding to the data unit DU(2).

[0141] According to the embodiments of the present application, the XTS encryption / decryption circuit can continuously and uninterruptedly receive input data blocks, and after continuously receiving 3 data units DU, it can continuously and uninterruptedly output calculation results, maximizing the utilization rate of the XTS encryption / decryption circuit.

[0142] Optionally, cache the calculation results corresponding to the 1st to 31st data blocks in data units DU(1), DU(2), and DU(3) into Buffer2, and cache C33 in the calculation result corresponding to the 32nd data block in data units DU(1), DU(2), and DU(3) and C p into Buffer3, cache each C33 into Buffer4, and cache the calculation result C32 corresponding to the 33rd data block in data units DU(1), DU(2), and DU(3) into Buffer5.

[0143] Optionally, in the 15th cycle of calculating the 32nd data block in data unit DU(1), obtain and output the calculation results corresponding to the 1st to 31st data blocks in data unit DU(1) from Buffer2, obtain and output the calculation result corresponding to the 33rd data block in data unit DU(1) from Buffer4, and obtain and output the calculation result corresponding to the 32nd data block in data unit DU(1) from Buffer5. This eliminates the gap between sCU(1)31 and sCU(1)33 in the XTS Output output. Then, obtain and output the calculation results corresponding to the 1st to 31st data blocks in data unit DU(2) from Buffer2, obtain and output the calculation result corresponding to the 33rd data block in data unit DU(2) from Buffer4, and obtain and output the calculation result corresponding to the 32nd data block in data unit DU(2) from Buffer5. Finally, obtain and output the calculation results corresponding to the 1st to 31st data blocks in data unit DU(3) from Buffer2, obtain and output the calculation result corresponding to the 33rd data block in data unit DU(3) from Buffer4, and obtain and output the calculation result corresponding to the 32nd data block in data unit DU(3) from Buffer5.

[0144] In the embodiment of the present application, a cache unit Buffer1 is set in the XTS encryption / decryption circuit to cache the last group of data blocks that are not 128 bits and need to wait for the result of ciphertext stealing processing. Thus, when waiting for the result of ciphertext stealing processing corresponding to the current data unit, calculate the 128-bit data blocks in the next data unit, avoiding the idleness and pause of the encryption / decryption module Endec2 during operation, and improving the processing efficiency of the XTS encryption / decryption circuit. Similarly, to ensure that the calculation results of each data unit can be normally output and the calculation results of the current data unit are not overwritten by the calculation results of the next data unit, the embodiment of the present application caches the calculation results of the data unit through cache units Buffer2, Buffer3, Buffer4, and Buffer5.

[0145] As can be seen from Figure 7 , after the 128-bit data blocks in the first two data units are input to the encryption / decryption module Endec2, the data (Endec input) input to it has a specific pattern. For example, before the 1st to 32nd data blocks in data unit DU(3) are input to the encryption / decryption module Endec2, the 33rd data block in data unit DU(1) is input; before the 1st to 32nd data blocks in data unit DU(4) are input, the 33rd data block in data unit DU(2) is input. For example Figure 8A as shown, the data input to it is xDU_i = {sDU(i - 2)33, sDU(i)1 - 32}, where sDU(i - 2)33 represents the 128-bit data block obtained by concatenating Cp in the calculation result of the 33rd data block and Pm in the 33rd data block in the (i - 2)th data unit (denoted as DU(i - 2){C p ,C m}), sDU(i)1 - 32 represents the 1st to 32nd 128-bit data blocks in the ith data unit (denoted as DU(i){P1~P 32}), i represents the number of the data unit input to Endec, and i is an integer greater than or equal to 3. The length of xDU_i is 33 * 128 bit.

[0146] For the output (Endec output) of the encryption / decryption module Endec, the encryption / decryption module Endec outputs the corresponding calculation results in the order of the input data. Similar to the input, there is also a specific data pattern in the output of Endec. As Figure 7 shown, after Endec continuously outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(1), it outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(2); then it outputs the calculation result corresponding to the 33rd data block in data unit DU(1), and outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(3); afterwards, it outputs the calculation result corresponding to the 33rd data block in data unit DU(2), and outputs the calculation results corresponding to the 1st to 32nd data blocks in data unit DU(4). It can be seen that there is a specific pattern in the calculation results output by the encryption / decryption module Endec after the calculation results corresponding to the 32 128-bit data blocks in the first two data units are output. For example Figure 8B as shown, the data output by Endec2 is xCipher_i = {sCU(i - 2)33, sCU(i)1 - 32}, where sCU(i - 2)33 represents the calculation result of the 33rd data block in the (i - 2)th data unit (denoted as CU(i - 2){C m-1}), sCU(i)1 - 32 represents the calculation results corresponding to the 1st to 32nd 128 - bit data blocks in the i - th data unit (denoted as CU(i){C1~C m-2 ,C m +C p}), where {C m +C p} represents the concatenation of C m and C p . i represents the number of the data unit input to the Endec, and i is an integer greater than or equal to 3. The length of xCipher_i is 33 * 128 bit.

[0147] For the output of the XTS encryption / decryption circuit (XTS Output), after the XTS encryption / decryption circuit outputs the calculation result corresponding to the first data unit, it continuously outputs the calculation results of subsequent data units, that is, the calculation results of the data units output by the XTS encryption / decryption circuit after outputting the calculation result of the first data unit are continuous, and there is no idle in the middle. For example Figure 8C As shown, denote the output of the XTS encryption / decryption circuit as xCU_j = {CU(j)1 - 31, CU(j)33 - 32}, CU(j)1 - 31 represents the calculation results of the 1st to 31st data blocks in the (j - 1) - th data unit (denoted as CU(j){C1~C m-2}), CU(j)33 - 32 represents the calculation result of the 33rd data block and the calculation result corresponding to the 32nd data block in the j - th data unit (denoted as CU(j){C m-1 ,C m}, and j is an integer greater than or equal to 2. The length of xCu_j is the same as the length of the data unit, for example, 520 byte.

[0148] Combined with Figure 8A 、 8B and 8C, as Figure 9 shown, after forming continuous data input to the encryption / decryption module Endec2 and obtaining continuous output, regard the input data as a combination of multiple xDUs, regard the output of Endec as a combination of multiple xCiphers, and regard the output data of the XTS encryption / decryption circuit as a combination of xCUs. xCipher and xDU correspond one - to - one.

[0149] xDU has more data (Cp) (a total of 33 * 128 bit) than DU; xCU is 520 Byte.

[0150] The data of xDU_i includes two parts, which are C p / P 33 of DU(i - 2) and P1~P 32 of DU(i).

[0151] The data of xCU_j includes two parts, namely the encryption results of the first 31 data blocks of DU(j), and the encryption results of the 33rd data block and the 32nd data block of DU(j) (C m ).

[0152] i is the number of DU provided to Endec, and j is the number of xCU output from the XTS encryption / decryption circuit.

[0153] The initial value of i is 3 (when 1 <= i < 3, it belongs to the initialization stage and continuous data output has not been formed); at the start time when Endec forms continuous data output, the initial value of j is 2 (when j < 2, it belongs to the initialization stage and continuous data output has not been formed). The difference between j and i is 1, indicating that the output of xCU lags behind that of xDU, but the lag distance is fixed at 1, and a buffer unit is required to temporarily store the data between i and j.

[0154] From Figure 9 it can be seen that when inputting the last data block in data unit DU(2) to Endec that is not 128 bits, continuous input starts according to a specific pattern (also see Figure 8A ). The buffer unit Buffer1 needs to buffer at least the last data block in data units DU(1) and DU(2) that is not 128 bits. Therefore, in an alternative embodiment, the depth of Buffer1 is 2 and the width is the size of the last data block in DU that is not 128 bits (for example, 64 bits, depending on the data size of DU in actual applications). The buffer unit Buffer2 needs to buffer the calculation results corresponding to the first 32 128-bit data blocks in data units DU(1) and DU(2). The depth of Buffer2 is 64 and the width is 128 bits (the calculation result is also 128 bits). The buffer unit Buffer3 needs to buffer the calculation results Cp corresponding to data units DU(1) and DU(2). The depth of Buffer3 is 2 and the width is 128 bits. The buffer unit Buffer4 needs to buffer the calculation results C 33 corresponding to data units DU(1) and DU(2). The depth of Buffer4 is 2 and the width is 128 bits. The buffer unit Buffer5 needs to buffer the calculation result C 32 corresponding to 1 data unit. The depth of Buffer5 is 1 and the width is 128.

[0155] Figures 4 - 9In the illustrated embodiment, the encryption / decryption module Endec includes an encryption / decryption component, which can only encrypt or decrypt one 128-bit data block at a time. This also represents the bandwidth limit for the encryption / decryption calculation of the XTS encryption / decryption circuit in these embodiments. To increase the bandwidth of the XTS encryption / decryption circuit, in an alternative embodiment, the encryption / decryption module Endec2 includes two or more encryption / decryption components, which encrypt or decrypt two or more 128-bit data blocks simultaneously.

[0156] Figure 10 FIG. shows a schematic structural diagram of an XTS encryption / decryption circuit provided by another embodiment of the present application. As Figure 10 shown, the XTS encryption / decryption circuit includes a round key expansion module Round_key_Expand_1, a round key expansion module Round_key_Expand_2, an encryption / decryption module Endec_1, an encryption / decryption module Endec_2’, a modular multiplication module Mod-mul, an adder E1, an adder E2, a multiplexer mux4, a multiplexer mux5, a buffer unit Buffer9, a buffer unit Buffer10, a buffer unit Buffer11, a buffer unit Buffer12, and a buffer unit Buffer13. Among them, the round key expansion module Round_key_Expand_1, the round key expansion module Round_key_Expand_2, the encryption / decryption module Endec_1, the modular multiplication module Mod-mul, the adder E1, and the adder E2 are Figure 4 similar in function to the embodiment shown, and will not be described in detail here to avoid repetition.

[0157] The encryption / decryption module Endec_2’ includes two encryption / decryption components: endecA and endecB. endecA and endecB work in parallel and are independent of each other, and both can encrypt 128-bit data blocks. It takes 32 cycles for endecA to encrypt a 128-bit data block, and it also takes 32 cycles for endecB to encrypt a 128-bit data block. Compared with the encryption / decryption module Endec_2, the processing speed of the encryption / decryption module Endec_2’ for 128-bit data has not changed, but one more data block is processed at the same time. Therefore, a pair of data blocks, that is, two 128-bit data blocks, are input to the encryption / decryption module Endec_2’. Taking the data unit DU = {P1~P m}, the sizes of P1 to P m-1 are all 128 bits, and P m is less than 128 bits as an example, P1~P m-1Divide into multiple data block pairs, such as (P1, P2), (P3, P4), (P5, P6)... (P m-2 , P m-1 ), input (P1, P2), (P3, P4), (P5, P6)…(P m-4 , P m-3 ), (P m-2 , P m-1 ). If (P1, P2) is input to Endec_2', then endecA performs encryption calculation on P1, and endecB performs encryption calculation on P2. If (P3, P4) is input to Endec_2', then endecA performs encryption calculation on P3, and endecB performs encryption calculation on P4. And so on, until you need to input P to Endec_2'. m . Due to P m Less than 128 bits, so P m With P m-1 The calculation result C p The 128-bit data blocks ({Pm, Cp}) are concatenated and then input into Endec_2'. Optionally, 128-bit data blocks ({Pm, Cp}) can be input into both endecA and endecB at the same time to obtain two identical calculation results C m-1 The advantage of this is that the two encryption / decryption components always process the same data, so the same control signal can be used to control the operation of the two encryption / decryption components at the same time. Optionally, the 128-bit data block ({Pm, Cp}) is provided to one of endecA and endecB, and the encryption / decryption component that is not provided with the 128-bit data block ({Pm, Cp}) is dormant accordingly to reduce power consumption.

[0158] Buffer9 and Figure 4 The functions of Buffer1 shown are the same, both are used to cache data block P m That is, if the last data block of the data unit input to the XTS encryption / decryption circuit is not 128 bits, the last data block is cached in Buffer 9, so that during the ciphertext stealing process of the current data unit, the next data unit can be input into the circuit first, so that data can be continuously input into it without idle time due to ciphertext stealing.

[0159] Cache unit Buffer10 caches P1-P m-3 The calculation results C1-C corresponding to each data block in m-3 . That is, cache (P1, P2), (P3, P4), (P5, P6)... (P m-4 , P m-3) The calculated results C1 - C m-3 .

[0160] The cache unit Buffer11 caches the calculation results C corresponding to the data block pair (P m-2 , P m-1 ). m-2 , C p and C m . The cache unit Buffer12 is used to cache C m-2 , C m . Since it is necessary to splice the calculation result C corresponding to the data block P m-1 with the data block P m to form a 128-bit data block and input it into the encryption / decryption module Endec_2’, the calculation results C p corresponding to the data block pair (P m-2 , P m-1 ) are cached in Buffer11. To ensure that when outputting C m-2 , the C p and C m cached in Buffer11 are not lost, C p and C m-2 are further cached in Buffer12. m m-2 and C m

[0161] The cache unit Buffer13 is used to cache the calculation result C m corresponding to the data block P m-1 . C p and P m The data block formed by splicing is calculated by endecA and endecB to obtain two identical calculation results C m-1 , and one C m-1 is cached in Buffer13. Optionally, when the XTS encryption / decryption circuit outputs the calculation results corresponding to P1 to P m , it can obtain and output data from the cache units Buffer10, Buffer13, and Buffer12 in the order of C1 - C m when the calculation of the data block P m is completed, or it can first output the calculation results C1 - C m-2 corresponding to P1 - P m-2 , and then output C m and C m-1 after calculating the calculation result C m-1 corresponding to P m . If when calculating the calculation result C m corresponding to P m-1 , C1 - C m-2 ​​The output is not complete yet. First, cache C m-1 into Buffer13.

[0162] In this embodiment, the input end of the multiplexer mux4 receives the data block pair of the data unit DU, P m-1 the corresponding calculation result C p , and P cached in the cache unit Buffer9 m . The output end of the multiplexer mux4 is coupled to the input end of the adder E1. The input end of the multiplexer mux5 is coupled to the cache units Buffer10, Buffer12, and Buffe13, and obtains and outputs data from the cache units Buffer10, Buffer13, and Buffer12 in the order of C1 - C m .

[0163] Taking the data unit DU d ={P 1d ~P 33d}, DU e ={P 1e ~P 33e}, DU f ={P 1f ~P 33f}, DU g ={P 1g ~P 33g}, DU h ={P 1h ~P 33h}, P 1d to P 32d all have a size of 128 bit, P 33d is less than 128 bit, P 1e to P 32e all have a size of 128 bit, P 33e is less than 128 bit, P 1f to P 32f all have a size of 128 bit, P 33f is less than 128 bit, P 1g to P 32g all have a size of 128 bit, P 33g is less than 128 bit, P 1h to P 32h all have a size of 128 bit, P 33h is less than 128 bit as an example to illustrate the processing process of the XTS encryption / decryption circuit of the present application embodiment:

[0164] (1) The data blocks P 1d to P 32dThe data blocks are continuously input into the encryption / decryption module Endec_2' in the form of data block pairs, and the data block P 33d is cached in Buffer9. After 32 cycles when the data block pair (P 1d , P 2d ) is input to the encryption / decryption module Endec_2', the encryption results C 1d to C 30d corresponding to P 1d -C 30d are sequentially cached in Buffer10, and the calculation results C 31d , C 32d and C 31d (i.e., C pd and C 33d ) corresponding to the data block pair (P md ) are cached in Buffer11. The C 31d and C 33d cached in Buffer11 are cached in Buffer12.

[0165] (2) After the data block pair (P 31d , P 32d ) is input to the encryption / decryption module Endec_2', the data blocks P 1e to P 32e are continuously input into the encryption / decryption module Endec_2' in the form of data block pairs. Optionally, there is no gap between the data block pair (P 31d , P 32d ) and the data block pair (P 1e , P 2e ), but they are continuously input into the encryption / decryption module Endec_2' in time to maximize the utilization rate of the encryption / decryption module Endec_2'. The data block P 33e is cached in Buffer9. The encryption results C 1e to C 30e corresponding to P 1e -C 30e are cached in Buffer10, and the calculation results C 31e , C 32e and C 31e (i.e., C pe and C 33e ) corresponding to the data block pair (P me ) are cached in Buffer11. The C 31e and C 33e cached in Buffer11 are cached in Buffer12.

[0166] (3) After the data block pair (P 31e , P 32eAfter the input encryption / decryption module Endec_2', the data block P 1f to P 32f is continuously input into the encryption / decryption module Endec_2' in the form of data block pairs. Optionally, there is no gap between the data block pair (P 31e , P 32e ) and the data block pair (P 1f , P 2f ), but they are continuously input into the encryption / decryption module Endec_2' in time to maximize the utilization rate of the input encryption / decryption module Endec_2'.

[0167] (4) When the encryption / decryption module Endec_2' receives a data block composed of two adjacent data blocks among the data blocks P 1f to P 32f , it outputs the encryption result corresponding to P d to P 32d in the data unit DU 1d , caches the encryption results C 1d to P 30d corresponding to P 1d -C 30d in Buffer10 in sequence, and caches the calculation results C 31d , C 32d and C 31d , C pd and C 33d (i.e., C md ) corresponding to the data block pair (P 31d , P 33d ) in Buffer11. C 31f and C 32f cached in Buffer11 are cached in Buffer12. After the data block pair (P 31d , P 32d ) is input into the encryption / decryption module Endec_2', 32 cycles have passed since the data block pair (P pd , P 33d ) was input into Endec2', and the corresponding C pd has been calculated and cached in the cache unit Buffer11. Next, P 33d is taken out from the cache unit Buffer9, C pd is taken out from the cache unit Buffer11, P 33d and C 32d are spliced into a 128 - dit data block and input into the encryption / decryption module Endec_2', and the encryption result C 33d corresponding to P pd is cached in Buffer13. (5) When P 1g and Cpd After being spliced into 128 - bit data blocks and input into the encryption / decryption module Endec_2', the data block P 1g to P 32g is continuously input into the encryption / decryption module Endec_2' in the form of data - block pairs. Optionally, there is no gap between the 128 - bit data block spliced from P 33d and C pd and the data - block pair (P 1g , P 2g ), but they are continuously input into the encryption / decryption module Endec_2' in time to maximize the utilization rate of the encryption / decryption module Endec_2'. After the data blocks P 1g to P 32g are continuously input into the encryption / decryption module Endec_2' in the form of data - block pairs, the data block P 33g is cached in Buffer9.

[0169] (6) After the data - block pair (P 31g , P 32g ) is input into the encryption / decryption module Endec_2', at this time, 32 cycles have passed since the data - block pair (P 31e , P 32e ) was input into Endec2', and the corresponding C pe has been calculated and cached in the cache unit Buffer11. Next, P 33e is taken out from the cache unit Buffer9, C pe is taken out from the cache unit Buffer11, the 128 - bit data block spliced from P 33e and C pe is input into the encryption / decryption module Endec_2', and the encryption result C 33e corresponding to P 32e is cached in Buffer13. After the 128 - bit data block spliced from P 33e and C pe is input into the encryption / decryption module Endec_2', the data blocks P 1h to P 32h are continuously input into the encryption / decryption module Endec_2' in the form of data - block pairs. Optionally, there is no gap between the 128 - bit data block spliced from P 33e and C pe and the data - block pair (P 1h , P 2h ), but they are continuously input into the encryption / decryption module Endec_2' in time to maximize the utilization rate of the encryption / decryption module Endec_2'. The data blocks P 1h to P 32hAfter continuously inputting into the encryption / decryption module Endec_2’ in the form of data block pairs, the data block P 33h is cached in Buffer9.

[0170] (7) Endec2’ receives the data unit DU h in which P 29h and P 29h form a data block. At the same time, it outputs the calculation result of P 33d , and caches the calculation result corresponding to the data block P 33d in Buffer13.

[0171] In the above processing process, (P1, P2), (P3, P4), (P5, P6)…(P m-4 , P m-3 ), (P m-2 , P m-1 ), (P m + C p , P m + C p ) are input into the encryption / decryption module Endec_2’ in the form of data block pairs, enabling the encryption / decryption module Endec_2’ to process two 128-bit data blocks simultaneously, improving the data processing efficiency.

[0172] Figure 11 shows the structural diagram of the XTS encryption / decryption circuit according to another embodiment of the present application. As Figure 11 shown, this XTS encryption / decryption circuit adds a cache unit Buffer14, a cache unit Buffer15, a cache unit Buffer16, and a multiplexer mux6 on the basis of the embodiment shown in Figure 10 .

[0173] The cache unit Buffer14 is coupled to the encryption / decryption module Endec1 and is used to cache the output data of the encryption / decryption module Endec_1. To improve the encryption calculation speed and ensure that the corresponding Tw has been calculated when inputting each data block pair of the data unit DU to the encryption / decryption module Endec_2’, the Tweak_value is encrypted in advance. Since the Tweak_value will be encrypted in advance, Buffer14 is required to cache its encryption result. In an alternative embodiment, Buffer14 can also cache control information related to Tw, such as the data length of the data unit, the encryption / decryption enable signal, the encryption / decryption selection signal, etc.

[0174] The buffer unit Buffer15 is coupled to the round key expansion module Round_key_Expand_2 and is used to buffer the round key Rk2 output by Round_key_Expand_2. To improve the encryption calculation speed and ensure that for each data block of the data unit DU input to the input encryption / decryption module Endec_2’, its corresponding round key Rk2 has been calculated, the key2 is pre-expanded and the obtained round key Rk2 is buffered in Buffer15.

[0175] To improve the processing efficiency of the XTS encryption / decryption circuit, the next data unit is input during the ciphertext stealing process of the previous data unit. To ensure that the round key Rk2 corresponding to the previous data unit is not overwritten by the round key Rk2 corresponding to the next data unit, the round key Rk2 corresponding to the previous data unit buffered in Buffer15 is buffered in Buffer16.

[0176] The multiplexer mux6 is coupled to the buffer unit Buffer15 and the buffer unit Buffer16, and reads the round key Rk2 corresponding to the data block pair input to the encryption / decryption module Endec_2’ from Buffer15 and Buffer16.

[0177] Figure 12 The structural diagram of the XTS encryption / decryption circuit according to another embodiment of the present application is shown. As Figure 12 shown, on the basis of the embodiment shown in Figure 11 the XTS encryption / decryption circuit further includes a buffer unit Buffer17. To ensure that when the XTS encryption / decryption circuit outputs data, the data unit corresponding to the output data is determined, the buffer unit Buffer17 is used to buffer the identification information of the data unit. According to this identification information, the data unit corresponding to the calculation result currently output by the XTS encryption / decryption circuit can be determined. In an optional embodiment, the identification information buffered in Buffer17 may be the length of the data unit, and counting control is performed according to the length of the data unit to ensure the normal output of the data. In other optional embodiments, other control information may also be buffered in Buffer17, such as an encryption / decryption enable signal, an encryption / decryption selection signal, etc.

[0178] Figure 13 The timing diagram of the XTS encryption / decryption circuit provided by the embodiment of the present application is shown. In Figure 13Among them, legends of different colors represent different data units. For example, the blue legend represents data unit DU(1), the pink legend represents data unit DU(2), the yellow legend represents data unit DU(3), the green legend represents data unit DU(4), the purple legend represents data unit DU(5), the white legend represents data unit DU(6), the orange legend represents data unit DU(7), and the gray legend represents data unit DU(8). "sDU(i)_0 = {P1, P3, P5......, P31} i " represents the 1st data block, the 3rd data block, the 5th data block... the 31st data block in data unit DU(i). "sDU(i)_1 = {P2, P4, P6......, P32} i " represents the 2nd data block, the 4th data block, the 6th data block... the 32nd data block in data unit DU(i). The "0" after the underscore of "sDU(i)_0" indicates that it is processed by EndecA, and the "1" after the underscore of "sDU(i)_1" indicates that it is processed by EndecB. Both sDU(i)_0 and sDU(i)_1 contain 16 data blocks. "sDU(i)17 = {Cp, P33} i " (shown as a box with label 17 in Figure 13 ) represents a 128-bit data block formed by splicing the calculation result Cp of the 33rd data block and the 32nd data block in data unit DU(i).

[0179] "sCU(i)_0" represents the calculation results corresponding to the 1st data block, the 3rd data block, the 5th data block... the 31st data block in data unit DU(i). sCU(i)_0 = {C1, C3......, C29, C31} i . "sCU(i)_1" represents the calculation results corresponding to the 2nd data block, the 4th data block, the 6th data block... the 32nd data block of data unit DU(i), sCU(i)_1 = {C2, C4......, C30, C33} i , where C33 is the result obtained by EndecB processing P32. The "0" after the underscore of "sCU(i)_0" indicates that it is the result of EndecA processing, and the "1" after the underscore of "sDU(i)_1" indicates that it is the result of EndecB processing. "sCU(i)17" represents the calculation result corresponding to the 33rd data block ({Cp, P33} i ) of data unit DU(i), sCU(i)17 = {C32} i .

[0180] "EndecA input" represents the input data of the encryption / decryption component endecA in the input encryption / decryption module Endec_2', and "EndecB input" represents the input data of the encryption / decryption component endecB in the input encryption / decryption module Endec_2'. "EndecA output" represents the output data of the encryption / decryption component endecA, and "EndecB output" represents the output data of the encryption / decryption component endecA. "XTS Output" represents the output data of the XTS encryption / decryption circuit.

[0181] As Figure 13 shown, the data block pairs (such as Figure 13 the blue legends marked with sDU(1)_0 and sDU(1)_1) composed of pairwise data blocks in sDU(1)_0 and sDU(1)_1 are simultaneously input into endecA and endecB, and the 33rd data block sDU(1)17 in the data unit DU(1) is cached in Buffer9. After the data block pair (P31, P32) composed of the 31st and 32nd data blocks in the data unit DU(1) is simultaneously input into endecA and endecB, the data block pairs (such as Figure 13 the pink legends marked with sDU(2)_0 and sDU(2)_1) composed of pairwise data blocks in sDU(2)_0 and sDU(2)_1 are input into endecA and endecB. Optionally, there is no gap between the data block pair (P31, P32) in the data unit DU(1) and the data block pair (P1, P2) in the data unit DU(2), but they are input continuously in time. It takes 16 cycles to input sDU(2)_0 and sDU(2)_1 into endecA and endecB. At this time, the calculation of the 32nd data block in the data unit DU(1) has not been completed, so the 33rd data block in the data unit DU(1) cannot be input. Instead, sDU(3)_0 and sDU(3)_1 (such as Figure 13 the yellow legends marked with sDU(3)_0 and sDU(3)_1) are input immediately after the data block pair (P31, P32) composed of the 31st and 32nd data blocks in the data unit DU(2) is input. It takes 16 cycles to input sDU(3)_0 and sDU(3)_1 into endecA and endecB. At this time, 32 cycles have passed since the 32nd data block in the data unit DU(1) was input, and the calculation of the 32nd data block in the data unit DU(1) has been completed. Therefore, after sDU(3)_0 and sDU(3)_1 are input into endecA and endecB in Figure 13 , sDU(1)17 is input (such as Figure 13(The blue legend marked with 17). When the input of sDU(1)17 is completed, the calculation of the 32nd data block in the data unit DU(2) has not been completed yet. Therefore, the 33rd data block in the data unit DU(2) cannot be input, but sDU(4)_0 and sDU(4)_1 are input (as Figure 13 (The green legend marked with sDU(4)_0 and sDU(4)_1) Figure 13 In, the green legend marked with 16 is a part of sDU(4)_0 or sDU(4)_1, which is used to identify the timing when P32 of DU(4) is input to the Endec, rather than representing that P32 is repeatedly input to the Endec. And P32 is input to the EndecB for processing. At the position corresponding to EndecAinput, although it is marked with 16, the data block it inputs is P31 of the DU. In this article, similar marking methods express similar meanings). When the input of sDU(4)_0 and sDU(4)_1 is completed, 32 cycles have passed since the input of the 32nd data block in the data unit DU(2), and the calculation of the 32nd data block in the data unit DU(2) has been completed. Therefore, after Figure 13 sDU(4)_0 and sDU(4)_1 are input to endecA and endecB in, sDU(2)17 is input (as Figure 13 (The pink legend marked with 17). And so on, sDU(5)_0 and sDU(5)_1 are input subsequently (as Figure 13 (The purple legend marked with sDU(5)_0 and sDU(5)_1), sDU(3)17 (as Figure 13 (The yellow legend marked with 17), sDU(6)_0 and sDU(6)_1 (as Figure 13 (The white legend marked with sDU(6)_0 and sDU(6)_1), sDU(4)17 (as Figure 13 (The green legend marked with 17), sDU(7)_0 and sDU(7)_1 (as Figure 13 (The orange legend marked with sDU(7)_0 and sDU(7)_1), sDU(5)17 (as Figure 13 (The purple legend marked with 17), sDU(8)_0 and sDU(8)_1 (as Figure 13 (The gray legend marked with sDU(8)_0 and sDU(8)_1), sDU(6)17 (as Figure 13 (The white legend marked with 17).

[0182] For EndecA output and EndecB output, the corresponding calculation results are output in the order of the input data. The calculation of each data block by endecA and endecB takes 32 cycles. Therefore, the output of the calculation results corresponding to each data block lags 32 cycles behind the input of that data block. For example, when the input of sCU(2)_0 and sCU(2)_1 to endecA and endecB is completed, 32 cycles have passed since the first data block in the input data unit DU(1). The encryption calculation of the first data block has been completed, and from this moment on, the calculation results of the first to the 32nd data blocks in the data unit DU(1) (denoted as sCU(1)_0 and sCU(1)_1) are output. Therefore, in Figure 13 it, the starting ends of the legends representing sCU(1)_0 and sCU(1)_1 are horizontally aligned with the ending ends of the legends representing sDU(2)_0 and sDU(2)_1. It takes 16 cycles to output sCU(1)_0 and sCU(1)_1. Therefore, the ending ends of the legends of sCU(1)_0 and sCU(1)_1 are flush with the ending ends of the legends representing sDU(3)_0 and sDU(3)_1. After the output of sCU(1)_0 and sCU(1)_1 is completed, sCU(2)_0 and sCU(2)_1, sCU(3)_0 and sCU(3)_1 are output in sequence. When the output of sCU(3)_0 and sCU(3)_1 is completed, 32 cycles have passed since the 33rd data block (the blue legend marked with 17 in the EndecA input row or EndecB input row) in the input data unit DU(1). The calculation of the 33rd data block in the data unit DU(1) is completed. Therefore, the calculation result sCU(1)17 (the blue legend marked with 17 in the EndecA output row or EndecB output row) of the 33rd data block in the data unit DU(1) is output. And so on, sCU(4)_0 and sCU(4)_1, sCU(2)17, sCU(5)_0 and sCU(5)_1, sCU(3)17, sCU(6)_0 and sCU(6)_1, sCU(4)17, sCU(7)_0 and sCU(7)_1, sCU(5)17, sCU(8)_0 and sCU(8)_1, sCU(6)17, sCU(9)_0 and sCU(9)_1, sCU(7)17 are output in sequence.

[0183] It can be understood that in each cycle, endecA and endecB each receive a data block as input. The calculation of each data block in endec takes 32 cycles, and then the calculation results corresponding to the data block are obtained. In Figure 13In the example, in a plurality of consecutive cycles, input data blocks are continuously (also referred to as continuously) provided to endecA and endecB respectively. After a lag of 32 cycles, in a plurality of consecutive cycles, the calculation results of each data block are continuously output from endecA and endecB. Each calculation result lags 32 cycles behind the input of its data block. Thus, the order in which the input data blocks are provided to endecA and endecB determines the order in which endecA and endecB output the calculation results of the data blocks.

[0184] For XTS Output, output starts after calculating the calculation results of several data blocks (such as the first 5 data blocks) of data unit DU(1). After outputting the calculation result corresponding to the 31st data block, if the calculation of the 33rd data block is not completed, wait for the calculation of the 33rd data block to be completed, and then output the calculation result of the 33rd data block and the calculation result of the 32nd data block. If the calculation of the 1st to 31st data blocks in data unit DU(2) has been completed before outputting the calculation result of the 32nd data block in data unit DU(1), then immediately output the calculation results of the 1st to 31st data blocks in data unit DU(2) after outputting the calculation result of the 32nd data block in data unit DU(1). When the calculation results of the 1st to 31st data blocks in data unit DU(2) are completed, the calculations of the 32nd and 33rd data blocks in data unit DU(2) are also completed, so the calculation results of the 33rd and 32nd data blocks in data unit DU(2) can be immediately output without interruption.

[0185] Optionally, cache the calculation results corresponding to the 1st to 30th data blocks in data units DU(1), DU(2), DU(3), and DU(4) into Buffer10, and cache the calculation results C31 of the 31st data block and C33 and C p corresponding to the 32nd data block in data units DU(1), DU(2), DU(3), and DU(4) into Buffer11, and then cache C31 and C33 into Buffer12. Here, C31, C33, and Cp are all cached into Buffer11 because these calculation results are calculated by EndecA and EndecB simultaneously. Using the same control method (caching into Buffer11) for the simultaneously generated calculation results is beneficial for simplifying the design of the circuit (data path and control circuit). Cache the calculation result C32 corresponding to the 33rd data block in data units DU(1), DU(2), DU(3), and DU(4) into Buffer13.

[0186] It can be seen from Figure 13 that before inputting the 1st to 32nd data blocks in the data unit DU(4) into endecA and endecB, the 33rd data block in the data unit DU(1) is input; before inputting the 1st to 32nd data blocks in the data unit DU(5), the 33rd data block in the data unit DU(2) is input. Thus, it can be known that after inputting the first three data units into endecA and endecB, the input data has a specific pattern. The processing processes of endecA and endecB are the same, and endecA is taken as an example for illustration. As Figure 14A shown, the data input into endecA is xDU_i_0 = {sDU(i - 3)17, sDU(i)_0}, where sDU(i - 3)17 represents the calculation result C p corresponding to the 32nd data block in the (i - 3)th data unit, which is concatenated with the 33rd data block to form a data block (denoted as DU(i - 3){C p , C m}), and sDU(i)_0 represents 16 128-bit data blocks in the ith data unit (denoted as DU(i)_0{P1, P3, P5......, P31}). i represents the number of the data unit input into endecA, and i is an integer greater than or equal to 4. The length of xDU_i is 17 * 128 bit. Optionally, the data input into the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i - 3)17_d, sDU(i)_d}. xDU_i_d represents the data block pair provided to the second encryption module. sDU(i - 3)17_d represents the data block pair formed by concatenating the second data shard corresponding to the (m - 1)th data block in the (i - 3)th data unit with the mth data block in the (i - 3)th data unit. sDU(i)_d represents the data block pair formed by two adjacent data blocks among the 1st to (m - 1)th data blocks in the ith data unit. sDU(i)_d includes sDU(i)_0 and sDU(i)_1. sDU(i)_0 represents the data block provided to the first encryption component among the 1st to (m - 1)th data blocks in the ith data unit, and sDU(i)_1 represents the data block provided to the second encryption component among the 1st to (m - 1)th data blocks in the ith data unit.

[0187] For the output of endecA, it outputs the corresponding calculation results in the order of the input data. Then, similar to the input, there is also a specific data pattern in the output of endecA. As Figure 14BAs shown, the data output by endecA is xCipher_i_0 = {sCU(i - 3)17, sCU(i)_0}. sCU(i - 3)17 represents the calculation result of the 33rd data block in the (i - 3)th data unit, sCU(i - 3)17 represents the calculation result corresponding to the 33rd data block in the (i - 3)th data unit, sCU(i)_0 represents the calculation result corresponding to 16 128-bit data blocks in the ith data unit, and i represents the number of the data unit input to endecA, where i is an integer greater than or equal to 4. The length of xCipher_i is 17 * 128 bits. Optionally, the data output by the encryption / decryption module Endec_2' is denoted as xCipher_i_d = {sCU(i - 3)17, sCU(i)_d}. xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the mth data block in the (i - 3)th data unit, and sCU(i)_d represents the calculation result corresponding to the 1st to (m - 1)th data blocks in the ith data unit. xCipher_i_d includes xCipher_i_0 and xCipher_i_1. xCipher_i_0 represents the calculation result output by the first encryption component, and xCipher_i_1 represents the calculation result output by the second encryption component. sCU(i)_d includes sCU(i)_0 and sCU(i)_1. sCU(i)_0 represents the calculation result corresponding to the data block in the ith data unit processed by the first encryption component, and sCU(i)_1 represents the calculation result corresponding to the data block in the ith data unit processed by the second encryption component. In an alternative embodiment, the 33rd data block in the (i - 3)th data unit is provided to both encryption components endecA and endecB in the encryption / decryption module Endec_2'. Both endecA and endecB perform operations on the 33rd data block in the (i - 3)th data unit to obtain two calculation results, while the encryption / decryption module Endec_2' can output only one calculation result.

[0188] For the output of the XTS encryption / decryption circuit, after the XTS encryption / decryption circuit outputs the calculation result corresponding to the first data unit, it continuously outputs the calculation results of subsequent data units, that is, the calculation results of the data units output by the XTS encryption / decryption circuit after outputting the calculation result of the first data unit are continuous and there is no idle state in the middle. For example Figure 14C As shown, the output of the XTS encryption / decryption circuit is denoted as xCU_j = {CU(j)1 - 31, CU(j)33 - 32}. CU(j)1 - 31 represents the calculation result of the 1st to 31st data blocks in the jth data unit (denoted as CU(j){C1~C m-2}), CU(j)33 - 32 represents the calculation result corresponding to the 33rd data block and the calculation result corresponding to the 32nd data block in the jth data unit (denoted as CU(j){C m-1 , C m}), where j is an integer greater than or equal to 2. The length of xCu_j is the same as the length of the data unit DU(j), for example, 520 byte.

[0189] Combined with Figure 14A 、 14B and 14C, as Figure 15 shown, after forming continuous data input to Endec2’ and obtaining continuous output, the input data is regarded as a combination of continuous multiple xDUs, the output of Endec2’ is regarded as a combination of continuous multiple xCiphers, and the output data of the XTS encryption / decryption circuit is regarded as a combination of continuous multiple xCUs. xCipher corresponds to xDU one by one.

[0190] xDU is more than half of DU (for example, {P1, P3, P5......, P31, P33}) by some data (C p )(a total of 17 * 128). xCU has the same length as DU, which is 520 byte.

[0191] The data of xDU_i includes two parts, which are C p / P m of DU(i - 3) and 16 data blocks of DU(i).

[0192] The data of xCU_j includes two parts, which are the encryption results CU(j){C1~C m-2} of the first 31 data blocks of DU(j) and the calculation results CU(j){C m-1 , C m} after ciphertext stealing of the 33rd and 32nd data blocks of DU(j).

[0193] i is the number of DU provided to Endec2’, and j is the number of xCU output from the overall Endec2’.

[0194] At the start time of forming continuous data input to Endec2’, the initial value of i is 4 (when i < 4, it belongs to the initialization stage and continuous data input has not been formed); at the start time of forming continuous data output of Endec2’, the initial value of j is 2 (when j < 2, it belongs to the initialization stage and continuous data output has not been formed). The difference between j and i is 2, indicating that the output of xCU lags behind xDU, but the lag distance is fixed at 2, and a buffer unit is required to temporarily store the data between i and j.

[0195] In an alternative embodiment,Figures 10 - 13 The XTS encryption and decryption circuit shown in any one of the embodiments may also perform encryption calculations on data according to other timings.

[0196] Figure 16 Another timing diagram of the XTS encryption / decryption calculation circuit provided by the embodiments of the present application is shown. As Figure 16 shown, Figure 16 The difference between the embodiment shown and Figure 13 the embodiment shown is as follows: Figure 13 In the embodiment shown, the first 16 data block pairs of the data unit DU(4) are input first (such as Figure 13 the green legends marked with sDU(4)_0 and sDU(4)_1 in Figure 13 ), and then the 33rd data block in the data unit DU(2) is input (such as Figure 13 the pink legend marked with 17 in Figure 16 ). Since when the input of the 15th data block pair in the data unit DU(4) is completed, it is exactly 32 cycles away from the input of the 32nd data block in the data unit DU(2), and the calculation result of the 32nd data block in the data unit DU(2) is obtained, so Figure 16 in the embodiment shown, the 33rd data block in the data unit DU(2) is input first (such as Figure 16 the pink legend marked with 17 in Figure 16 ), and then the data block pairs in the data unit DU(4) are input (such as Figure 16 the green legend marked with 16 in Figure 16 ).

[0197] In Figure 16 the embodiment shown, the mode of the input data of endecA is denoted as xDU_i_0 = {sDU(i - 3)17, sDU(i - 1)15 - 16_0, sDU(i)1 - 14_0}, where sDU(i - 3)17 represents the calculation result C of the 32nd data block corresponding to the (i - 3)th data unit pThe data block obtained by splicing with the 33rd data block, sDU(i)15-16_0 represents a data block in the 15th data block pair in the (i-1)th data unit and the data block input to endecA in the 16th data block pair, sDU(i)1-14_0 represents the data blocks input to endecA in the first 14 data block pairs in the ith data unit, i represents the number of the data unit input to endecA and endecB, and i is an integer greater than or equal to 6. The length of xDU_i is 17*128 bit. EndecA and endecB output their corresponding calculation results in the order of the input data. The output data pattern of endecA in this embodiment can be denoted as xCipher_i_0 = {sCU(i-3)17, sCU(i-1)15-16_0, sCU(i)1-14_0}, sCU(i-3)17 represents the calculation result of the 33rd data block in the (i-3)th data unit, sCU(i)15-16_0 represents the calculation results of the data blocks input to endecA in the 15th data block pair and the 16th data block pair in the (i-1)th data unit, and sDU(i)1-14_0 represents the calculation results of the data blocks input to endecA in the first 14 data block pairs in the ith data unit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i-3)17_d, sDU(i-1)15-16_d, sDU(i)1-14_d}. xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair composed of the data block obtained by splicing the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit and the data block in the mth data block in the (i-3)th data unit, sDU(i)15-16_d represents the data block pair composed of the (m-4)th data block and the (m-3)th data block in the (i-1)th data unit and the data block pair composed of the (m-2)th data block and the (m-1)th data block, and sDU(i)1-14_d represents the data block pairs composed of two adjacent data blocks among the first to (m-5)th data blocks in the ith data unit. The data output by the encryption / decryption module Endec_2’ is denoted as xCipher_i_d = {sCU(i-3)17, sCU(i-1)15-16_d, sCU(i)1-14_d}.xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the m-th data block in the (i - 3)-th data unit, sCU(i)15 - 16_d represents the calculation results corresponding to the (m - 4)-th, (m - 3)-th, (m - 2)-th, and (m - 1)-th data blocks in the (i - 1)-th data unit, and sDU(i)1 - 14_d represents the calculation results corresponding to the 1st to (m - 5)-th data blocks in the i-th data unit.

[0198] Figure 17 Another timing diagram of the XTS encryption / decryption calculation circuit provided by the embodiment of the present application is shown. Figure 17 The shown timing diagram and Figure 16 The difference between the shown timing diagrams is that: in Figure 16 the shown embodiment, first, the first 14 data block pairs in the data unit DU(6) are input (such as Figure 16 the white legend marked with sDU(6)1 - 14 in Figure 16 ), then the 33rd data block in the data unit DU(4) is input (such as Figure 16 the green legend marked with 17 in Figure 17 ), and then the 15th data block pair and the 16th data block pair in the data unit DU(6) are input (such as Figure 17 the white legend marked with 15 - 16 in Figure 17 ). In Figure 17 the shown embodiment, when inputting the data unit DU(6), first, the first 15 data block pairs in the data unit DU(6) are input (such as

[0199] the white legend marked with sDU(6)1 - 15 in Figure 17 ), then the 33rd data block in the data unit DU(3) is input (such as p the green legend marked with 17 in ), and then the 16th data block pair in the data unit DU(6) is input (such as p the white legend marked with 16 in p ).

[0199] In Figure 17 the shown embodiment, the input data mode of endecA is denoted as xDU_i_0 = {sDU(i - 3)17, sDU(i - 1)16_0, sDU(i)1 - 15_0}, and sDU(i - 3)17 represents the calculation result C of the 32nd data block in the (i - 3)-th data unit pThe data block obtained by splicing with the 33rd data block, sDU(i - 1)16_0 represents the data block input to endecA in the 16th data block pair of the (i - 1)th data unit, sDU(i)1 - 15_0 represents the data blocks input to endecA in the first 15 data block pairs of the ith data unit, and i represents the number of the data unit input to endecA and endecB, where i is an integer greater than or equal to 7. The output data mode of endecA is denoted as xCipher_i_0 = {sCU(i - 3)17, sCU(i - 1)16_0, sCU(i)1 - 15_0}, sCU(i - 3)17 represents the calculation result of the 33rd data block in the (i - 3)th data unit, sCU(i)16_0 represents the calculation result of the data block input to endecA in the 16th data block pair of the (i - 1)th data unit, and sDU(i)1 - 15_0 represents the calculation results of the data blocks input to endecA in the first 15 data block pairs of the ith data unit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i - 3)17_d, sDU(i - 1)16_d, sDU(i)1 - 15_d}. xDU_i_d represents the data block pair provided to the second encryption module, sDU(i - 3)17_d represents the data block pair composed of the second data shard corresponding to the (m - 1)th data block in the (i - 3)th data unit and the data block obtained by splicing the (m)th data block in the (i - 3)th data unit, sDU(i)16_d represents the data block pair composed of the (m - 2)th data block and the (m - 1)th data block in the (i - 1)th data unit, and sDU(i)1 - 15_d represents the data block pairs composed of adjacent two data blocks among the first to the (m - 3)th data blocks in the ith data unit. The data output by the encryption / decryption module Endec_2’ is denoted as xCipher_i_d = {sCU(i - 3)17, sCU(i - 1)16_d, sCU(i)1 - 15_d}. xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the mth data block in the (i - 3)th data unit, sCU(i)16_d represents the calculation results corresponding to the (m - 2)th data block and the (m - 1)th data block in the (i - 1)th data unit, and sDU(i)1 - 14_d represents the calculation results corresponding to the first to the (m - 3)th data blocks in the ith data unit.

[0200] Figure 18 Fig. shows a timing diagram of an XTS encryption / decryption calculation circuit provided by an embodiment of the present application. Figure 18 The shown embodiment and Figure 17 The difference between the shown timing diagram is that: at Figure 17In the illustrated embodiment, when inputting data unit DU(5), first input the first 14 data block pairs in data unit DU(5) (such as Figure 17 the purple legend marked with sDU(5)1-14 in Figure 17 ), then input the 33rd data block in data unit DU(3) (such as Figure 17 the yellow legend marked with 17 in Figure 18 ), and then input the 15th and 16th data block pairs in data unit DU(5) (such as Figure 18 the purple legend marked with 15-16 in Figure 18 ). In Figure 18 the illustrated embodiment, when inputting data unit DU(5), first input the first 15 data block pairs in data unit DU(5) (such as

[0201] the purple legend marked with sDU(5)1-15 in Figure 18 ), then input the 33rd data block in data unit DU(3) (such as p the yellow legend marked with 17 in ), and then input the 16th data block pair in data unit DU(5) (such as Figure 18 the purple legend marked with 16 in ).

[0201] In Figure 18 the illustrated embodiment, the input data mode of endecA is denoted as xDU_i_0 = {sDU(i-3)17, sDU(i-1)16_0, sDU(i)1-15_0}, and sDU(i-3)17 represents the calculation result C corresponding to the 32nd data block in the (i-3)th data unit pThe data block obtained by splicing with the 33rd data block, sDU(i-1)16_0 represents the data block input to endecA in the 16th data block pair in the (i-1)th data unit, sDU(i)1-15_0 represents the data blocks input to endecA in the first 15 data block pairs in the ith data unit, and i represents the number of the data unit input to endecA and endecB, where i is an integer greater than or equal to 5. The output data mode of endecA is denoted as xCipher_i_0 = {sCU(i-3)17, sCU(i-1)16_0, sCU(i)1-15_0}, where sCU(i-3)17 represents the calculation result of the 33rd data block in the (i-3)th data unit, sCU(i)16_0 represents the calculation result of the data block input to endecA in the 16th data block pair in the (i-1)th data unit, and sDU(i)1-15_0 represents the calculation results of the data blocks input to endecA in the first 15 data block pairs in the ith data unit. Optionally, the data input to the encryption / decryption module Endec_2’ is denoted as xDU_i_d = {sDU(i-3)17_d, sDU(i-1)16_d, sDU(i)1-15_d}. xDU_i_d represents the data block pair provided to the second encryption module, sDU(i-3)17_d represents the data block pair composed of the data block obtained by splicing the second data shard corresponding to the (m-1)th data block in the (i-3)th data unit with the mth data block in the (i-3)th data unit, sDU(i)16_d represents the data block pair composed of the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-15_d represents the data block pairs composed of adjacent two data blocks among the first to the (m-3)th data blocks in the ith data unit. The data output by the encryption / decryption module Endec_2’ is denoted as xCipher_i_d = {sCU(i-3)17, sCU(i-1)16_d, sCU(i)1-15_d}. xCipher_i_d represents the calculation result output by the second encryption module, sCU(i-3)17 represents the calculation result of the mth data block in the (i-3)th data unit, sCU(i)16_d represents the calculation results corresponding to the (m-2)th data block and the (m-1)th data block in the (i-1)th data unit, and sDU(i)1-14_d represents the calculation results corresponding to the first to the (m-3)th data blocks in the ith data unit.

[0202] The XTS encryption / decryption circuit provided by the embodiment of the present application calculates the 128-bit data block in the next data unit when waiting for the result of the ciphertext stealing process corresponding to the current data unit, avoiding the idleness and pause of the encryption / decryption module Endec2’ during the working process, and improving the processing efficiency of the XTS encryption / decryption circuit.

[0203] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application. Obviously, those skilled in the art can make various changes and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. An XTS encryption circuit, which is applicable to perform encryption operations on data units based on the block encryption algorithm of the XTS mode. The data units include m data blocks. The first to the (m - 1)th data blocks each have a preset number of bytes, and the number of bytes of the mth data block is less than the preset number of bytes, where m is an integer greater than 1. The encryption circuit includes a first-round key expansion module, a second-round key expansion module, a first encryption module, a modular multiplication module, a first adder, and a second adder. It is characterized in that, the encryption circuit further includes a second encryption module and a first buffer unit; the second encryption module includes a first encryption component and a second encryption component. Two adjacent data blocks among the first to the (m - 1)th data blocks of the target data unit form a data block pair. The second encryption module receives the data block pair, and the first encryption component and the second encryption component respectively calculate one data block in the data block pair and output corresponding calculation results; the first buffer unit is used to buffer the mth data block of the target data unit input to the second encryption module, so as to input the data block pair composed of the first to the (m - 1)th data blocks of the next target data unit during the ciphertext stealing process of the (m - 1)th data block of the target data unit, so as to form continuous input to the second encryption module.

2. The circuit according to claim 1, wherein The encryption circuit further includes: a second buffer unit, a third buffer unit, a fourth buffer unit, a fifth buffer unit, a first multiplexer, and a second multiplexer; the second buffer unit buffers the calculation results corresponding to the first to the (m - 3)th data blocks of the target data unit processed by the second encryption module; the third buffer unit buffers the calculation results corresponding to the (m - 2)th data block and the (m - 1)th data block of the target data unit processed by the second encryption module. The calculation result corresponding to the (m - 1)th data block includes a first data shard and a second data shard. The data block formed by splicing the second data shard and the mth data block of the target data unit has a preset number of bytes; the fourth buffer unit buffers the calculation result corresponding to the (m - 2)th data block and the first data shard; the fifth buffer unit buffers the calculation result corresponding to the mth data block of the target data unit processed by the second encryption module; the output end of the first multiplexer is coupled to the first adder, and is used to select data blocks from the data block pair composed of the first to the (m - 1)th data blocks, the mth data block buffered by the first buffer unit, and the second data shard buffered by the third buffer unit and provide them to the first adder; The second multiplexer sequentially obtains the calculation results corresponding to the 1st to the (m - 3)th data blocks from the second cache unit, obtains the calculation result corresponding to the (m - 2)th data block from the fourth cache unit, obtains the calculation result corresponding to the mth data block from the fifth cache unit, and obtains the first data shard from the fourth cache unit and outputs it.

3. The circuit according to claim 2, wherein In response to caching the calculation result corresponding to the (m - 1)th data block in the target data unit into the third cache unit, the first multiplexer obtains the second data shard in the calculation result from the third cache unit, and simultaneously provides the data block formed by splicing the second data shard and the mth data block in the target data unit to the first encryption component and the second encryption component, or provides the data block formed by splicing the second data shard and the mth data block in the target data unit only to the first encryption component, or provides the data block formed by splicing the second data shard and the mth data block in the target data unit only to the second encryption component.

4. The circuit according to claim 3, wherein The first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the first data unit to the second encryption module. The second encryption module calculates the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the first data unit, wherein the first encryption component and the second encryption component in the second encryption module respectively calculate one data block in the received data block pair; it takes (m - 1) cycles for the first encryption component and the second encryption component to calculate each data block from receiving to outputting the calculation result; the mth data block in the first data unit is cached into the first cache unit, so as to input the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the second data unit to the second encryption module before the ciphertext stealing process for the (m - 1)th data block in the first data unit is completed; In response to caching the mth data block in the first data unit into the first cache unit, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the second data unit to the second encryption module; the mth data block in the second data unit is cached into the first cache unit; In response to caching the mth data block in the second data unit into the first cache unit, the first multiplexer continuously provides the data block pairs formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the third data unit to the second encryption module; While receiving data block pairs formed by two adjacent data blocks among the first to the (m - 1)-th data blocks in the third data unit, the second encryption module sequentially outputs the calculation results corresponding to the first to the (m - 1)-th data blocks in the first data unit, caches the calculation results corresponding to the first to the (m - 3)-th data blocks in the first data unit into the second cache unit, caches the calculation result corresponding to the (m - 2)-th data block and the first and second data shards corresponding to the (m - 1)-th data block in the first data unit into the third cache unit, and caches the calculation result corresponding to the (m - 2)-th data block and the first data shard corresponding to the (m - 1)-th data block in the first data unit into the fourth cache unit; In response to inputting the data block pair formed by the (m - 2)-th data block and the (m - 1)-th data block in the third data unit into the second encryption module, the first multiplexer obtains the second data shard corresponding to the first data unit from the third cache unit and obtains the m-th data block in the first data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block to the second encryption module, wherein the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block is provided to the first encryption component and the second encryption component in the second encryption module simultaneously; In response to inputting the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block into the second encryption module, the first multiplexer continuously provides data block pairs formed by two adjacent data blocks among the first to the (m - 1)-th data blocks in the fourth data unit to the second encryption module; caches the m-th data block in the fourth data unit into the first cache unit; At the moment when the second encryption module receives the data block formed by splicing the second data shard corresponding to the first data unit and the m-th data block, it starts to sequentially output the calculation results corresponding to the first to the (m - 1)-th data blocks in the second data unit, caches the calculation results corresponding to the first to the (m - 3)-th data blocks in the second data unit into the second cache unit, caches the calculation result corresponding to the (m - 2)-th data block and the first and second data shards corresponding to the (m - 1)-th data block in the second data unit into the third cache unit, and caches the calculation result corresponding to the (m - 2)-th data block and the first data shard corresponding to the (m - 1)-th data block in the second data unit into the fourth cache unit; In response to inputting the data block pair formed by the (m - 2)-th data block and the (m - 1)-th data block in the fourth data unit into the second encryption module, the first multiplexer obtains the second data shard corresponding to the second data unit from the third cache unit and the m-th data block in the second data unit from the first cache unit, and provides the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block to the second encryption module, wherein the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block is provided to the first encryption component and the second encryption component in the second encryption module simultaneously; In response to providing the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block to the second encryption module, the first multiplexer continuously provides the data block pair formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the fifth data unit to the second encryption module; the m-th data block in the fifth data unit is cached into the first cache unit; While receiving the data block pair formed by the (m - 2)-th data block and the (m - 1)-th data block in the fourth data unit, the data block formed by splicing the second data shard corresponding to the second data unit and the m-th data block, and the data block pair formed by two adjacent data blocks among the first to (m - 1)-th data blocks in the fifth data unit, the second encryption module starts to sequentially output the calculation results corresponding to the first to (m - 1)-th data blocks in the third data unit and the calculation result corresponding to the m-th data block in the first data unit, caches the calculation results corresponding to the first to (m - 3)-th data blocks in the third data unit into the second cache unit, caches the calculation results corresponding to the (m - 2)-th data block and the first data shard and the second data shard corresponding to the (m - 1)-th data block in the third data unit into the third cache unit, caches the calculation results corresponding to the (m - 2)-th data block and the first data shard corresponding to the (m - 1)-th data block in the third data unit into the fourth cache unit, and caches the calculation result corresponding to the m-th data block in the first data unit into the fifth cache unit.

5. The circuit according to claim 4, characterized in that, The encryption circuit sequentially obtains the calculation results corresponding to the 1st to the (m - 3)th data blocks in the first data unit from the second cache unit, the calculation result corresponding to the (m - 2)th data block in the first data unit from the fourth cache unit, the calculation result corresponding to the mth data block in the first data unit from the fifth cache unit, and the first data shard output corresponding to the (m - 1)th data block in the first data unit from the fourth cache unit; in response to the completion of the first data shard output corresponding to the (m - 1)th data block in the first data unit, it obtains the calculation results corresponding to the 1st to the (m - 3)th data blocks in the second data unit from the second cache unit.

6. The circuit according to claim 4 or 5, wherein the first multiplexer continuously provides data block pairs to the second encryption module in a first data mode, and the first data mode is shown in the following formula (1): xDU_i_d = {sDU(i - 3)17_d, sDU(i)_d} (1) wherein, xDU_i_d represents the data block pair provided to the second encryption module, sDU(i - 3)17_d represents the data block pair formed by the second data shard corresponding to the (m - 1)th data block in the (i - 3)th data unit and the data block obtained by splicing the mth data block in the (i - 3)th data unit, sDU(i)_d represents the data block pair formed by two adjacent data blocks among the 1st to the (m - 1)th data blocks in the ith data unit, i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 4; the second encryption module outputs calculation results in a second data mode, and the second data mode is shown in the following formula (2): xCipher_i_d = {sCU(i - 3)17, sCU(i)_d} (2) xCipher_i_d represents the calculation results output by the second encryption module, sCU(i - 3)17 represents the calculation result of the mth data block in the (i - 3)th data unit, and sCU(i)_d represents the calculation results corresponding to the 1st to the (m - 1)th data blocks in the ith data unit; the encryption circuit outputs encrypted data in a third data mode, and the third data mode is shown in the following formula (3): xCU_j = {CU(j)1 - 31, CU(j)33 - 32} (3) xCU_j represents the encrypted data output by the encryption circuit, CU(j)1 - 31 represents the calculation results of the 1st to the (m - 2)th data blocks in the jth data unit, CU(j)33 - 32 represents the calculation result of the mth data block and the calculation results corresponding to the (m - 1)th data block in the jth data unit, and j = i - 2.

7. The circuit according to claim 4 or 5, wherein the first multiplexer continuously provides data block pairs to the second encryption module in a fourth data mode, and the fourth data mode is shown in the following formula (4): xDU_i_d = {sDU(i - 3)17_d, sDU(i - 1)15 - 16_d, sDU(i)1 - 14_d} (4) xDU_i_d represents the data block pair provided to the second encryption module. sDU(i - 3)17_d represents the data block pair composed of the second data shard corresponding to the (m - 1)-th data block in the (i - 3)-th data unit and the data block obtained by splicing the m-th data block in the (i - 3)-th data unit. sDU(i)15 - 16_d represents the data block pairs composed of the (m - 4)-th data block and the (m - 3)-th data block, and the (m - 2)-th data block and the (m - 1)-th data block in the (i - 1)-th data unit. sDU(i)1 - 14_d represents the data block pairs composed of adjacent two data blocks among the 1st to the (m - 5)-th data blocks in the i-th data unit. i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 6; The second encryption module outputs the calculation result in the fifth data mode, and the fifth data mode is shown in the following formula (5): xCipher_i_d = {sCU(i - 3)17, sCU(i - 1)15 - 16_d, sCU(i)1 - 14_d} (5) xCipher_i_d represents the calculation result output by the second encryption module. sCU(i - 3)17 represents the calculation result of the m-th data block in the (i - 3)-th data unit. sCU(i)15 - 16_d represents the calculation results corresponding to the (m - 4)-th data block, the (m - 3)-th data block, the (m - 2)-th data block, and the (m - 1)-th data block in the (i - 1)-th data unit. sDU(i)1 - 14_d represents the calculation results corresponding to the 1st to the (m - 5)-th data blocks in the i-th data unit; The encryption circuit outputs the encrypted data in the sixth data mode, and the sixth data mode is shown in the following formula (6): xCU_j = {CU(j)1 - 31, CU(j)33 - 32} (6) xCU_j represents the encrypted data output by the encryption circuit. CU(j)1 - 31 represents the calculation results of the 1st to the (m - 2)-th data blocks in the j-th data unit. CU(j)33 - 32 represents the calculation result of the m-th data block and the calculation result corresponding to the (m - 1)-th data block in the j-th data unit, and j = i - 4.

8. The circuit according to claim 4 or 5, wherein The first multiplexer continuously provides data block pairs to the second encryption module in the seventh data mode, and the seventh data mode is shown in the following formula (7): xDU_i_d = {sDU(i - 3)17_d, sDU(i - 1)16_d, sDU(i)1 - 15_d} (7) xDU_i_d represents the data block pair provided to the second encryption module. sDU(i - 3)17_d represents the data block pair composed of the second data shard corresponding to the (m - 1)-th data block in the (i - 3)-th data unit and the data block obtained by splicing the m-th data block in the (i - 3)-th data unit. sDU(i - 1)16_d represents the data block pair composed of the (m - 2)-th data block and the (m - 1)-th data block in the (i - 1)-th data unit. sDU(i)1 - 15_d represents the data block pairs formed by adjacent two data blocks among the 1st to the (m - 3)-th data blocks in the i-th data unit. i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 7. The second encryption module outputs the calculation result in the eighth data mode, and the eighth data mode is shown in the following formula (8): xCipher_i_d ={sCU(i - 3)17, sCU(i - 1)16_d, sCU(i)1 - 15_d} (8) xCipher_i_d represents the calculation result output by the second encryption module. sCU(i - 3)17 represents the calculation result of the m-th data block in the (i - 3)-th data unit. sCU(i)16_d represents the calculation results corresponding to the (m - 2)-th data block and the (m - 1)-th data block in the (i - 1)-th data unit. sDU(i)1 - 15_d represents the calculation results corresponding to the 1st to the (m - 3)-th data blocks in the i-th data unit. The encryption circuit outputs the encrypted data in the ninth data mode, and the ninth data mode is shown in the following formula (9): xCU_j={CU(j)1 - 31, CU(j)33 - 32} (9) xCU_j represents the encrypted data output by the encryption circuit. CU(j)1 - 31 represents the calculation results of the 1st to the (m - 2)-th data blocks in the j-th data unit. CU(j)33 - 32 represents the calculation result of the m-th data block and the calculation result corresponding to the (m - 1)-th data block in the j-th data unit, and j = i - 5.

9. The circuit according to claim 4 or 5, wherein The first multiplexer continuously provides data block pairs to the second encryption module in the tenth data mode, and the tenth data mode is shown in the following formula (10): xDU_i_d ={sDU(i - 3)17_d, sDU(i - 1)16_d, sDU(i)1 - 15_d} (10) xDU_i_d represents the data block pair provided to the second encryption module, sDU(i - 3)17_d represents the data block pair composed of the second data shard corresponding to the (m - 1)-th data block in the (i - 3)-th data unit and the data block obtained by concatenating the m-th data block in the (i - 3)-th data unit, sDU(i - 1)16_d represents the data block pair composed of the (m - 2)-th data block and the (m - 1)-th data block in the (i - 1)-th data unit, sDU(i)1 - 15_d represents the data block pairs composed of adjacent two data blocks among the 1st to the (m - 3)-th data blocks in the i-th data unit, i represents the number of the data unit provided to the second encryption module, and i is an integer greater than or equal to 5; The second encryption module outputs the calculation result in the eleventh data mode, and the eleventh data mode is shown in the following formula (11): xCipher_i_d ={sCU(i - 3)17, sCU(i - 1)16, sCU(i)1 - 15_d} (11) xCipher_i_d represents the calculation result output by the second encryption module, sCU(i - 3)17 represents the calculation result of the m-th data block in the (i - 3)-th data unit, sCU(i)16_d represents the calculation results corresponding to the (m - 2)-th data block and the (m - 1)-th data block in the (i - 1)-th data unit, sDU(i)1 - 15_d represents the calculation results corresponding to the 1st to the (m - 3)-th data blocks in the i-th data unit; The encryption circuit outputs the encrypted data in the twelfth data mode, and the twelfth data mode is shown in the following formula (12): xCU_j={CU(j)1 - 31, CU(j)33 - 32} (12) xCU_j represents the encrypted data output by the encryption circuit, CU(j)1 - 31 represents the calculation results of the 1st to the (m - 2)-th data blocks in the j-th data unit, CU(j)33 - 32 represents the calculation result of the m-th data block and the calculation result corresponding to the (m - 1)-th data block in the j-th data unit, and j = i - 3.

10. An XTS decryption circuit, the decryption circuit is applicable to perform decryption operations on data units based on the XTS mode block decryption algorithm, the data unit includes m data blocks, the 1st to the (m - 1)-th data blocks all have a preset number of bytes, the number of bytes of the m-th data block is less than the preset number of bytes, and m is an integer greater than 1; the decryption circuit includes a first round key expansion module, a second round key expansion module, a first decryption module, a modular multiplication module, a first adder, and a second adder; characterized in that The decryption circuit further includes a second decryption module and a first cache unit; The second decryption module includes a first decryption component and a second decryption component. Two adjacent data blocks among the first to the (m - 1)th data blocks of the target data unit form a data block pair. The second decryption module receives the data block pair, and the first decryption component and the second decryption component respectively perform calculations on one data block in the data block pair and output corresponding calculation results; The first buffer unit is used to buffer the mth data block of the target data unit input to the second decryption module, so as to input a data block pair composed of the first to the (m - 1)th data blocks of the next target data unit during the process of performing ciphertext stealing processing on the (m - 1)th data block of the target data unit, so as to form a continuous input to the second decryption module.