SM4 encryption and decryption circuit for realizing side channel protection
By introducing masks in the encrypting/decrypting process of SM4 algorithm, the processing weakens or eliminates the correlation between key and power consumption, the problem of insufficient defense against power consumption analysis attacks in the prior art is solved, and higher data security is achieved.
Patent Information
- Application Number
- CN202311869590.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-01
AI Technical Summary
The prior art has shortcomings in defending against power consumption analysis attacks, resulting in the risk of key leakage and reduces the security of data.
The mask is introduced during the encrypting/decryption process of the SM4 algorithm, and the correlation between the key and power consumption is weakened or eliminated through masking processing, thereby improving the side channel protection capability.
Effectively defend against power consumption analysis attacks, reduce the risk of key leakage, and improve data security.
Smart Images

Figure CN120238283A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to an SM4 encryption and decryption circuit for implementing side-channel protection. Background Technique
[0002] The national standard GM / T 0002-2012 published by the National Cryptography Administration of China defines the SM4 block cipher algorithm. The SM4 algorithm is a block encryption algorithm, and both the block length and the key length are 128 bits. The SM4 algorithm consists of a key expansion algorithm and an encryption and decryption algorithm, both of which adopt a 32-round non-linear iterative structure. The encryption and decryption algorithms have the same structure, except that the order of using the round keys is reversed, and the decryption round key is the reverse order of the encryption round key. Let the plaintext input be X = (X0, X1, X2, X3) ∈ (GF(2 32 )) 4 , the ciphertext output be Y = (Y0, Y1, Y2, Y3) ∈ (GF(2 32 )) 4 , the input of the i-th round operation be (X i-1 , X i , X i+1 , X i+2 ), the round key be rk i ∈ GF(2 32 ), i = 0, 1, 2,... 31, and the encryption transformation of the SM4 algorithm is defined as:
[0003]
[0004] (Y0, Y1, Y2, Y3) = R(X 32 , X 33 , X 34 , X 35 ) = (X 35 , X 34 , X 33 , X 32 )
[0005] Among them, F represents the round function. T represents the composite permutation function, which is an invertible transformation and is composed of the non-linear transformation τ and the linear transformation L. The non-linear transformation τ consists of 4 parallel S-boxes. The input of the linear transformation L is the output of the non-linear transformation τ. Let the input of the linear transformation L be B and the output be C, then <<<i represents a 32-bit cyclic left shift by i bits.
[0006] The decryption transformation has the same structure as the encryption transformation, except for the order of using the round keys. The order of using the round keys during encryption is (rk0, rk1,..., rk 31 ), and the order of using the round keys during decryption is (rk31 ,rk 30 ,…,rk0).
[0007] In this algorithm, the round keys of the encryption algorithm are generated from the encryption key through the key expansion algorithm. The encryption key MK = (MK0, MK1, MK2, MK3). Let Round key Then the round key generation method is as follows:
[0008] First,
[0009] Then,
[0010] where FK0, FK1, FK2, FK3 represent system parameters, and CK i represents a fixed parameter.
[0011] In cryptography, the power analysis attack and protection of hardware devices for implementing information security have a crucial impact on data security. The power analysis attack technology uses the power consumption generated during the operation of the cryptographic hardware device, combines the input and output data for analysis, and obtains the key stored inside the circuit. Since the encryption key or key can be obtained through the power analysis attack technology, there is a risk of key leakage, reducing the data security. Summary of the Invention
[0012] In view of this, the embodiments of the present application provide a technical solution for resisting power analysis, improving the circuit structure of the SM4 algorithm, introducing a mask in the encryption / decryption process of the SM4 algorithm, and using the mask to perform mask processing on the vulnerable points in the algorithm process, so as to weaken or even eliminate the correlation between the key and the power consumption, making it impossible for other users to obtain the encryption / decryption key through the power analysis attack technology, improving the side-channel protection ability, and further improving the data security.
[0013] In a first aspect, the embodiments of the present application provide an SM4 encryption / decryption circuit, which is applicable to encryption operations or decryption operations in the XTS mode. The encryption / decryption circuit includes: a first round key expansion module, a first encryption / decryption module, a second round key expansion module, a second encryption / decryption module, a modular multiplication module, a first adder, and a second adder;
[0014] wherein, the first round key expansion module receives the first key data and the first mask data, uses the first mask data to perform masking processing on the first key data, and performs operations on the masked first key data, and outputs the masked first round key data and the unmasked first de-round key data;
[0015] The first encryption / decryption module is coupled to the first round key expansion module. The first encryption / decryption module receives second masked data, an adjustment value, the first round key data, and the first de-round key data, performs masking processing on the adjustment value using the second masked data, and performs operations on the masked adjustment value using the first round key data and the first de-round key data, and outputs masked first intermediate data and unmasked first de-intermediate data;
[0016] The modular multiplication module is coupled to the first encryption / decryption module. The modular multiplication module receives preset parameters, the first intermediate data, and the first de-intermediate data, performs operations on the first intermediate data and the first de-intermediate data using the preset parameters, and outputs masked second intermediate data and unmasked second de-intermediate data;
[0017] The second round key expansion module receives second key data and third masked data, performs masking processing on the second key data using the third masked data, and performs operations on the masked second key data, and outputs masked second round key data and unmasked second de-round key data;
[0018] The first adder receives first target data to be encrypted or decrypted and the second intermediate data, performs operations on the first target data and the second intermediate data, and outputs third intermediate data;
[0019] The second encryption / decryption module is coupled to the second round key expansion module and the first adder. The second encryption / decryption module receives fourth masked data, the second de-intermediate data, the third intermediate data, the second round key data, and the second de-round key data, and outputs fourth intermediate data;
[0020] The second adder is coupled to the second encryption / decryption module and the modular multiplication module. The second adder receives the fourth intermediate data and the exclusive OR data of the second intermediate data and the second de-intermediate data, and outputs second target data after encryption or decryption.
[0021] Optionally, the first round key expansion module, the first encryption / decryption module, the second round key expansion module, and the second encryption / decryption module each include cascaded N-level operation circuits and a first confusion circuit. The output end of the Nth operation circuit is coupled to the input end of the first confusion circuit. N-round non-linear iterative operations are implemented through the cascaded N-level operation circuits, where each operation circuit performs one round of non-linear iterative operation, and N is a positive integer;
[0022] The second encryption / decryption module further includes a second confusion circuit and a third confusion circuit. The output end of the second confusion circuit is coupled to the input end of the first-stage operation circuit in the second encryption / decryption module, and the input end of the third confusion circuit is coupled to the output end of the first confusion circuit.
[0023] Optionally, each stage of the operation circuit includes a fourth confusion circuit and a round calculation circuit. The output end of the fourth confusion circuit is coupled to the input end of the round calculation circuit; the output end of the round calculation circuit of the previous-stage operation circuit is coupled to the input end of the fourth confusion circuit of the next-stage operation circuit; the output end of the round calculation circuit of the Nth-stage operation circuit is coupled to the input end of the first confusion circuit.
[0024] Optionally, at least one of the first round key expansion module, the first encryption / decryption module, the second round key expansion module, and the second encryption / decryption module includes a first-stage operation circuit and a first confusion circuit, and N rounds of non-linear iterative operations are performed through the first-stage operation circuit.
[0025] Optionally, the fourth confusion circuit includes a first input end, a second input end, a third input end, a fourth input end, a first output end, and a second output end;
[0026] The first input end of the fourth confusion circuit in each stage of the operation circuit receives corresponding first target mask data, the second input end receives first data, the third input end receives corresponding second target mask data, the fourth input end receives second data, and the first data and the second data are respectively masked by the first target mask data and the second target mask data to obtain first masked data and first demasked data; and the first masked data is transmitted to the round calculation circuit in the first-stage operation circuit through the first output end, and the first demasked data is transmitted to the round calculation circuit in the first-stage operation circuit through the second output end; wherein, the first data is key data or the output data of the round calculation circuit in the previous-stage operation circuit or the output data of the second confusion circuit, the second data is preset initialization data or the output data of the round calculation circuit in the previous-stage operation circuit, and the first demasked data and the first masked data are demasked to obtain data without a mask.
[0027] Optionally, the round calculation circuit includes at least a fifth input end, a sixth input end, a seventh input end, a third output end, and a fourth output end;
[0028] The fifth input terminal of the round calculation circuit in each stage of the operation circuit is coupled to the first output terminal of the fourth confusion circuit of the same stage, and receives the first masked data; the sixth input terminal is coupled to the second output terminal of the fourth confusion circuit of the same stage, and receives the first demasked data; the seventh input terminal receives the third data; wherein, the third data is the specified bit data in the masked first-round key data and the specified bit data in the demasked first-round key data, the specified bit data in the masked second-round key data and the specified bit data in the demasked second-round key data, or the specified data;
[0029] The round calculation circuit performs an operation on the first masked data according to the third data to obtain a second masked data; and performs an operation on the first demasked data according to the third data to obtain a second demasked data; the third output terminal outputs the second masked data, and the fourth output terminal outputs the second demasked data; wherein, the second demasked data and the second masked data are demasked to obtain unmasked data.
[0030] Optionally, the second input terminal of the fourth confusion circuit in the second-stage to the Nth-stage operation circuits is coupled to the third output terminal of the round calculation circuit in the previous-stage operation circuit, and the second input terminal of the fourth confusion circuit in the second-stage to the Nth-stage operation circuits is coupled to the fourth output terminal of the round calculation circuit in the previous-stage operation circuit.
[0031] Optionally, the first output terminal of the fourth confusion circuit in the ith-stage operation circuit outputs the first masked data (X i-1 、X i 、X i+1 、X i+2 ), and the second output terminal of the fourth confusion circuit in the ith-stage operation circuit outputs the first demasked data (R i-1 0、R i- 11、R i-1 2、R i-1 3);
[0032] The fifth input terminal of the round calculation circuit in the ith-stage operation circuit receives (X i 、X i+1 、X i+2 ), and the sixth output terminal receives (R i-1 1、R i-1 2、R i-1 3);
[0033] The third data received by the seventh input terminal of the round calculation circuit in the ith-stage operation circuit in the first encryption / decryption module includes the specified bit data output by the third output terminal of the round calculation circuit in the ith-stage operation circuit of the first-round key expansion module and the specified bit data output by the fourth output terminal of the first-round key data;
[0034] The third data received at the seventh input terminal of the round calculation circuit in the i-th level operation circuit of the second encryption / decryption module is the specified bit data in the second-round key data output from the third output terminal of the round calculation circuit in the i-th level operation circuit of the second-round key expansion module and the specified bit data in the second-round unround key data output from the fourth output terminal;
[0035] The third data received at the seventh input terminal of the round calculation circuit in the i-th level operation circuit of the first-round key expansion module and the second-round key expansion module is the specified data;
[0036] The round calculation circuit in the i-th level operation circuit performs an operation on (X i 、X i+1 、X i+2 ) received at the fifth input terminal and the third data received at the seventh input terminal to obtain X i+3 , and performs an operation on (R i-1 1, R i-1 2, R i-1 3) received at the sixth input terminal and the third data received at the seventh input terminal to obtain R io ;
[0037] The third output terminal of the round calculation circuit in the i-th level operation circuit outputs the second masked data (X i 、X i+1 、X i+2 、X i+3 ), and the fourth output terminal outputs the second unmasked data (R i-1 1, R i-1 2, R i-1 3, R io );
[0038] Among them, X i-1 、X i 、X i+1 、X i+2 、R i-1 0、R i-1 1、R i-1 2、R i-1 3、、X i+3 and R io are all data with a predetermined number of bytes.
[0039] Optionally, the third confusion circuit includes an eighth input terminal, a ninth input terminal, and a fifth output terminal; the eighth input terminal is coupled to the third output terminal of the round calculation circuit in the Nth-level operation circuit to receive the second masked data output by the third output terminal, and the ninth input terminal is coupled to the fourth output terminal of the round calculation circuit in the Nth-level operation circuit to receive the second unmasked data output by the fourth output terminal. The second masked data and the second unmasked data are unmasked to obtain the fourth intermediate data, and the fifth output terminal outputs the fourth intermediate data.
[0040] Optionally, the second input terminal of the fourth confusion circuit in the first-level operation circuit receives the key data or the output data of the second confusion circuit, and the fourth input terminal receives the preset initialization data; the second input terminal of the fourth confusion circuit in the second-level to Nth-level operation circuits receives the output data of the round calculation circuit in the previous-level operation circuit, and the second input terminal of the fourth confusion circuit in the second-level to Nth-level operation circuits receives the output data of the round calculation circuit in the previous-level operation circuit.
[0041] Optionally, the first target masked data received by the first input terminal of the fourth confusion circuit in the ith-level operation circuit is the same as the second target masked data received by the third input terminal of the fourth confusion circuit in the ith-level operation circuit, where 1 ≤ i ≤ N and i is a positive integer.
[0042] Optionally, the first data received by the second input terminal of the fourth confusion circuit in the first-level operation circuit of the first round key expansion module is the first key data, and the second data received by the fourth input terminal of the fourth confusion circuit in the first-level operation circuit is the first initialization value.
[0043] Optionally, the first data received by the second input terminal of the fourth confusion circuit in the first-level operation circuit of the second round key expansion module is the second key data, and the second data received by the fourth input terminal of the fourth confusion circuit in the first-level operation circuit is the second initialization value.
[0044] Optionally, the first data received by the second input terminal of the fourth confusion circuit in the first-level operation circuit of the first encryption / decryption module is the adjustment value, and the second data received by the fourth input terminal of the fourth confusion circuit in the first-level operation circuit is the third initialization value.
[0045] Optionally, the first data received by the second input terminal of the fourth confusion circuit in the first-level operation circuit of the second encryption / decryption module is the output data of the second confusion circuit, and the second data received by the fourth input terminal of the fourth confusion circuit in the first-level operation circuit is the fourth initialization value.
[0046] Optionally, the second confusion circuit includes a tenth input terminal, an eleventh input terminal, and a sixth output terminal; the tenth input terminal receives the second intermediate data after demasking, the eleventh input terminal receives the third intermediate data, and the sixth output terminal is coupled to the second input terminal of the fourth confusion circuit in the first-stage operation circuit.
[0047] Optionally, the first confusion circuit includes a twelfth input terminal, a thirteenth input terminal, a fourteenth input terminal, a fifteenth input terminal, a seventh output terminal, and an eighth output terminal; the twelfth input terminal of the first confusion circuit receives the corresponding third target mask data, the thirteenth input terminal is coupled to the third output terminal of the round calculation circuit in the Nth-stage operation circuit, the fourteenth input terminal receives the corresponding fourth target mask data, and the fifteenth input terminal is coupled to the fourth output terminal of the round calculation circuit in the Nth-stage operation circuit; the calculation result of the first confusion circuit includes a first target sequence and a second target sequence, the fifth output terminal of the first confusion circuit outputs the first target sequence in reverse order, and the sixth output terminal outputs the second target sequence in reverse order.
[0048] Optionally, the fourth confusion circuit includes a third adder and a fourth adder, the third adder receives the first target mask data and the first data, and outputs the first masked data, and the fourth adder receives the second target mask data and the second data, and outputs the second demasked data.
[0049] Optionally, the round calculation circuit includes a fifth adder, a sixth adder, a seventh adder, an eighth adder, and a composite permutation circuit; the fifth adder receives the first masked data and the third data, and outputs the first calculation data, the composite permutation circuit receives the first calculation data and outputs the second calculation data, and the seventh adder receives the second calculation data and the first masked data, and outputs the third calculation data; the sixth adder receives the first demasked data and the third data, and outputs the fourth calculation data, the composite permutation circuit receives the fourth calculation data and outputs the fifth calculation data; the eighth adder receives the fifth calculation data and the first demasked data, and outputs the sixth calculation data.
[0050] Optionally, the third confusion circuit includes a ninth adder, and the ninth adder receives the second masked data and the second demasked data, and outputs the fourth intermediate data.
[0051] Optionally, the second confusion circuit includes a tenth adder, the tenth adder receives the second intermediate data after demasking and the third intermediate data, outputs the seventh calculation data, and provides the seventh calculation data to the second input terminal of the fourth confusion circuit in the first-stage operation circuit.
[0052] Optionally, the first confusion circuit includes an eleventh adder and a twelfth adder; the eleventh adder receives the third target mask data and the second masked data, obtains the first target sequence, and outputs the first target sequence in reverse order; the twelfth adder receives the fourth target mask data and the second demasked data, obtains the second target sequence, and outputs the second target sequence in reverse order.
[0053] In a second aspect, an embodiment of the present application provides an SM4 encryption circuit, and the encryption circuit is applicable to encryption operations in the CBC mode; the data to be encrypted input into the encryption circuit is divided into multiple data blocks to be encrypted;
[0054] The encryption circuit includes M cascaded extended calculation circuits. Each level of the extended calculation circuit receives third key data, a corresponding data block to be encrypted, a corresponding first calculation mask data, and a corresponding second calculation mask data, uses the first calculation mask data to mask the third key data and uses the corresponding second calculation mask data to mask the data block to be encrypted, and performs an encryption operation on the masked data block to be encrypted using the masked third key data, and outputs ciphertext data; M is a positive integer.
[0055] Optionally, each level of the extended calculation circuit includes a third round key expansion module, a thirteenth adder, and an encryption module;
[0056] Each level of the third round key expansion module receives the third key data and the corresponding first calculation mask data, uses the corresponding first calculation mask data to mask the third key data, performs an operation on the masked third key data, and outputs masked third round key data and demasked third round key data;
[0057] Each level of the thirteenth adder receives a corresponding data block to be encrypted and a first specific data, performs an operation on the corresponding data block to be encrypted and the first specific data, and outputs a first intermediate data block; the first specific data received by the first level of the thirteenth adder is the initial vector, and the first specific data received by the second level to the Mth level of the thirteenth adder is the encrypted data block output by the previous level of the encryption module.
[0058] The input end of each encryption module is coupled to the output end of the third key expansion module and the output end of the thirteenth adder at the same level. The encryption module receives the corresponding second calculation mask data, the first intermediate data block, the third round key data, and the third de-round key data, uses the corresponding second calculation mask data to mask the first intermediate data block, and uses the third round key data and the third de-round key data to perform an encryption operation on the masked first intermediate data, and outputs the corresponding encrypted data block.
[0059] In a third aspect, an embodiment of the present application provides an SM4 decryption circuit, which is applicable to the decryption operation in the CBC mode; the data to be decrypted input to the decryption circuit is divided into multiple data blocks to be decrypted;
[0060] The encryption circuit includes a cascaded P-stage extended calculation circuit. Each stage of the extended calculation circuit receives the fourth key data, the corresponding data block to be decrypted, the corresponding third calculation mask data, and the corresponding fourth calculation mask data, uses the third calculation mask data to mask the fourth key data and uses the corresponding fourth calculation mask data to mask the data block to be decrypted, and uses the masked third key data to perform a decryption operation on the masked data block to be decrypted, and outputs the plaintext data; P is a positive integer.
[0061] Optionally, each stage of the extended calculation circuit includes a fourth round key expansion module, a decryption module, and a fourteenth adder;
[0062] Each stage of the fourth round key expansion module receives the fourth key data and the corresponding third calculation mask data, uses the corresponding third calculation mask data to mask the fourth key data, performs an operation on the masked fourth key data, and outputs the masked fourth round key data and the de-masked fourth de-round key data;
[0063] Each stage of the decryption module receives the corresponding fourth calculation mask data and the corresponding data block to be decrypted, uses the fourth calculation mask data to mask the corresponding data block to be decrypted, and outputs the decryption intermediate data;
[0064] Each stage of the fourteenth adder receives the decryption intermediate data and the second specific data, calculates the decryption intermediate data and the second specific data, and outputs the decryption data block; the second specific data received by the first stage of the fourteenth adder is the initial vector, and the second specific data received by the fourteenth adders from the second stage to the Pth stage is the data block to be decrypted received by the previous stage of the decryption module.
[0065] Fourthly, an embodiment of the present application provides an SM4 encryption and decryption circuit, which is applicable to encryption operations or decryption operations in the ECB mode.
[0066] The encryption and decryption circuit includes a fourth-round key expansion module and a third encryption and decryption module. The fourth-round key expansion module receives fifth key data and fifth mask data, performs masking processing on the fifth key data using the fifth mask data, performs operations on the masked fifth key data, and outputs masked fifth-round key data and demasked fifth-round key data.
[0067] The input end of the third encryption and decryption module is coupled to the output end of the fourth-round key expansion module. The third encryption and decryption module receives sixth mask data, third target data to be encrypted or decrypted, the fifth-round key data, and the fifth-round key data. The third encryption and decryption module performs masking processing on the third target data using the sixth mask data, and performs operations on the masked third target data using the fifth-round key data and the fifth-round key data, and outputs fourth target data after encryption or decryption.
[0068] The SM4 encryption and decryption circuit provided by the embodiment of the present application improves the circuit structure of the SM4 algorithm, introduces a mask in the encryption / decryption process of the SM4 algorithm, performs masking processing on vulnerable points in the algorithm process using the mask, weakens or even eliminates the correlation between the key and power consumption, so that other users cannot obtain the encryption / decryption key through power analysis attack technology, and improves the side-channel protection ability and data security. Description of the Drawings
[0069] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.
[0070] Figure 1 Shows a block diagram of the masked SM4 encryption / decryption circuit in the XTS mode provided by the embodiment of the present application;
[0071] Figure 2A Shows a block diagram of the arithmetic circuit Q1 in the XTS mode provided by the embodiment of the present application;
[0072] Figure 2B Shows a block diagram of the confusion circuit H1 in the XTS mode provided by the embodiment of the present application;
[0073] Figure 2CShows the block diagram of the encryption / decryption module Endec_2 in the XTS mode provided by the embodiments of the present application;
[0074] Figure 3 Shows the block diagram of the round key expansion module Round_key_expand_1 in the XTS mode provided by the embodiments of the present application;
[0075] Figure 4 Shows the block diagram of the round key expansion module Round_key_expand_2 in the XTS mode provided by the embodiments of the present application;
[0076] Figure 5 Shows the block diagram of the encryption / decryption module Endec_1 in the XTS mode provided by the embodiments of the present application;
[0077] Figure 6 Shows the block diagram of the encryption / decryption module Endec_2 in the XTS mode provided by the embodiments of the present application;
[0078] Figure 7 Shows the block diagram of the arithmetic circuit Q1 in the XTS mode provided by another embodiment of the present application;
[0079] Figure 8 Shows the block diagram of the round calculation circuit provided by the embodiments of the present application;
[0080] Figure 9 Shows the block diagram of the SM4 encryption circuit in the CBC mode;
[0081] Figure 10 Shows the block diagram of the SM4 decryption circuit in the CBC mode;
[0082] Figure 11 Shows the block diagram of the masked SM4 encryption / decryption circuit in the ECB mode. Detailed implementation manners
[0083] Next, in combination with the accompanying drawings in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0084] The SM4 cipher algorithm has different encryption and decryption methods, such as including the XTS mode (XEX Tweakable Block Cipher with Ciphertext Stealing), the CBC mode (Cipher Block Chaining), and the ECB mode (Electronic Codebook Book). The encryption / decryption calculation processes are different under different modes. The following describes the masked SM4 encryption / decryption circuit according to the embodiments of the present application for different modes respectively.
[0085] Figure 1 A block diagram of a masked SM4 encryption / decryption circuit according to an embodiment of the present application is shown. Figure 1 The shown SM4 encryption / decryption circuit is applicable to the encryption / decryption method of the XTS mode.
[0086] As Figure 1 shown, the SM4 encryption / decryption circuit includes a round key expansion module Round_key_expand_1, an encryption / decryption module Endec_1, a round key expansion module Round_key_expand_2, an encryption / decryption module Endec_2, a modular multiplication module Mod-mul, an adder E1, and an adder E2.
[0087] The input data of the masked SM4 encryption / decryption circuit includes data Din, key data key1, key2, a tweak value Tweak_value, mask data mask1, mask2, mask3, and mask4, and the output data is Dout. For example, data Din is the data to be encrypted, and Dout is the ciphertext data; or data Din is the data to be decrypted, and Dout is the plaintext data.
[0088] Among them, the round key expansion module Round_key_expand_1 receives the key data key1 and the mask data mask1, and outputs the masked round key data Rk1 and the demasked round key data Rk1_Mask. The masked round key data Rk1 and the demasked round key data Rk1_Mask perform, for example, a logical exclusive OR operation to eliminate the mask data in the masked round key data Rk1, and obtain the unmasked round key data Rk1_nm.
[0089] The encryption / decryption module Endec_1 is coupled with the round key expansion module Round_key_expand_1. The encryption / decryption module Endec_1 receives Rk1, Rk1_Mask output by the round key expansion module Round_key_expand_1, as well as the mask data mask2 and the adjustment value Tweak_value from external input, and outputs the intermediate data Tw and the intermediate data Tw_mask. Among them, Tw is the masked intermediate data, Tw_mask is the demasked intermediate data, and logical operation (such as exclusive OR) between Tw and Tw_mask can eliminate the mask data in Tw to obtain the unmasked intermediate data Tw_nm.
[0090] The modular multiplication module Mod-mul is coupled with the encryption / decryption module Endec_1. The modular multiplication module Mod-mul receives the intermediate data Tw, Tw_mask and the parameter a j (j represents the round), and outputs the intermediate data Tw’ and the intermediate data Tw’_mask. Among them, Tw’ is the masked intermediate data, Tw’_mask is the demasked intermediate data, and Tw’_mask can be used to eliminate the mask carried by Tw’. For example, logical exclusive OR operation between Tw’ and Tw_mask’ can eliminate the mask data in Tw’ to obtain the unmasked intermediate data Tw’_nm.
[0091] The round key expansion module Round_key_expand_2 receives the key data key2 and the mask data mask3, and outputs the masked round key data Rk2 and the demasked round key data Rk2_Mask. Logical operation such as exclusive OR between the masked round key data Rk2 and the demasked round key data Rk2_Mask can eliminate the mask data in the masked round key data Rk2 to obtain the unmasked round key data Rk2_nm.
[0092] The adder E1 receives the data Din and the intermediate data Tw’, and outputs the intermediate data D1.
[0093] The encryption / decryption module Endec_2 is coupled with the round key expansion module Round_key_expand_2 and the adder E1. The encryption / decryption module Endec_2 receives the round key data Rk2, Rk2_Mask, the mask data mask4, the intermediate data Tw’_mask and the intermediate data D1, and outputs the intermediate data D2.
[0094] The adder E2 is coupled to the encryption / decryption module Endec_2 and the modular multiplication module Mod-mul. The adder E2 receives the intermediate data D2 and the exclusive-OR data of the intermediate data Tw’ and Tw’_mask, and outputs the data Dout. The exclusive-OR data of the intermediate data Tw’ and Tw’_mask refers to the data obtained by performing a logical exclusive-OR operation on Tw’ and Tw’_mask.
[0095] Among them, the round key expansion module Round_key_expand_1, the encryption / decryption module Endec_1, the round key expansion module Round_key_expand_2, and the encryption / decryption module Endec_2 all adopt 32 rounds of non-linear iterative operations, and one iterative operation is a round transformation. During the 32 rounds of non-linear iterative operations of the round key expansion module Round_key_expand_1, the encryption / decryption module Endec_1, the round key expansion module Round_key_expand_2, and the encryption / decryption module Endec_2, the output data of the previous round of iterative operation will be used as part of the input data of the next round of iterative operation, and new mask data needs to be re-input in each round. Taking the round key expansion module Round_key_expand_1 as an example, the round key expansion module Round_key_expand_1 only needs to input the key data once for 32 rounds of non-linear iterative operations, and 32 rounds of mask data need to be input, and the 32 rounds of mask data input can be different. In each iterative operation of the round key expansion module Round_key_expand_1, the round key expansion module Round_key_expand_1 not only receives the output data of the previous round of iterative operation, but also receives the input mask data, and performs mask processing on the output data of the previous round of iterative operation through the received mask data to eliminate the correlation between the round key data and the power consumption. Similarly, in each iterative operation of the encryption / decryption module Endec_1, the encryption / decryption module Endec_1 not only receives the output data of the previous round of iterative operation and the corresponding round key data, but also receives the input mask data, performs mask processing on the output data of the previous round of iterative operation and the corresponding round key data through the mask data, and performs encryption / decryption operations on the output data of the previous round of iterative operation through the masked round key data, further reducing the correlation between each round of iterative operation and the power consumption. The processes of the round key expansion module Round_key_expand_2 and the encryption / decryption module Endec_2 performing 32 rounds of non-linear iterative operations are similar to those of the round key expansion module Round_key_expand_1 and the encryption / decryption module Endec_1, and will not be elaborated here.
[0096] Optionally, the mask data mask1, mask2, mask3, mask4 are random numbers. The round key expansion module Round_key_expand_1, the encryption / decryption module Endec_1, the round key expansion module Round_key_expand_2, and the encryption / decryption module Endec_2 all need to go through 32 rounds of non-linear iterative operations to obtain the output data. A random number is re-input in the calculation process of each round of non-linear iteration, and the random number input in each round is random.
[0097] Optionally, as Figure 2A shown, the round key expansion module Round_key_expand_1, the round key expansion module Round_key_expand_2, and the encryption / decryption module Endec_1 all include 32 cascaded operation circuits Q1 and a confusion circuit Q2; each level of operation circuit Q1 includes a confusion circuit H1 and a round calculation circuit H2. In the 32 cascaded operation circuits Q1, the output end of the confusion circuit H1 is coupled to the input end of the round calculation circuit H2, and the output end of the round calculation circuit H2 in the previous level of operation circuit Q1 is coupled to the input end of the confusion circuit H1 in the next level of operation circuit Q1. The input end of the confusion circuit Q2 is coupled to the output end of the round calculation circuit H2 in the 32nd level of operation circuit Q1.
[0098] Optionally, each level of confusion circuit H1 is a logical exclusive OR operation circuit, which performs a logical exclusive OR operation on the input data input to the confusion circuit H1. In an alternative embodiment, as Figure 2B shown, each level of confusion circuit H1 includes an adder E3 and an adder E4. The adder E3 includes an input terminal f31, an input terminal f32, and an output terminal o33, and the adder E4 includes an input terminal f41, an input terminal f42, and an output terminal o43.
[0099] Each level of round calculation circuit H2 is used to perform a non-linear iterative operation on the input data to obtain two output data, one output data is masked data, and the other output data is demasked data. The demasked data output by each level of round calculation circuit H2 can eliminate the masked data in the output masked data. Among them, the process of each level of round calculation circuit H2 performing a non-linear iterative operation on the input data refers to the Figure 8 shown embodiment.
[0100] Optionally, the confusion circuit Q2 is a logical exclusive OR operation circuit, which performs a logical exclusive OR operation on the input data input to the confusion circuit Q2. In an alternative embodiment, each level of confusion circuit Q2 includes an adder E5 and an adder E6.
[0101] Optionally, as Figure 2CAs shown, the encryption / decryption module Endec_2 includes 32 cascaded arithmetic circuits Q1, confusion circuits Q2, Q3, and Q4. Each arithmetic circuit Q1 includes a confusion circuit H1 and a round calculation circuit H2. In the 32 cascaded arithmetic circuits Q1, the output terminal of the confusion circuit H1 is coupled to the input terminal of the round calculation circuit H2, and the output terminal of the round calculation circuit H2 in the previous arithmetic circuit Q1 is coupled to the input terminal of the confusion circuit H1 in the next arithmetic circuit Q1.
[0102] The input terminal of the confusion circuit Q3 receives the intermediate data D1 and Tw’_mask, and the output terminal of the confusion circuit Q3 is coupled to the input terminal of the first-stage confusion circuit H1 of the encryption / decryption module Endec_2. Optionally, the confusion circuit Q3 is a logical exclusive OR circuit, which includes an adder E7 for performing a logical exclusive OR operation on D1 and Tw’_mask.
[0103] The confusion circuit Q4 is coupled to the confusion circuit Q2, receives the sequence output after the confusion circuit Q2 reverses its calculation result, and performs an operation on the sequence to output Dout. For example, the calculation result of the confusion circuit Q2 is the sequence A, where A = {a1, a2, a3, a4}, and a1, a2, a3, and a4 are 4 32-bit data; the confusion circuit Q2 reverses the sequence A and outputs the sequence A’ = {a4, a3, a2, a1}. Optionally, the confusion circuit Q4 is a logical exclusive OR circuit, which includes an adder E8 for performing a logical exclusive OR operation on the reversed sequence of the sequence output by the 32nd-stage confusion circuit H1 to output Dout.
[0104] Figure 3 The structural schematic diagram of the round key expansion module Round_key_expand_1 provided by the embodiment of the present application is shown.
[0105] Refer to Figure 2A 、 2B and Figure 3, in the round key expansion module Round_key_expand_1, the input terminal f31 of the adder E3 in each stage of the confusion circuit H1 receives masked data. For example, the input terminal f31 of the adder E3 in the first-stage confusion circuit H1 receives the masked data R1, the input terminal f31 of the adder E3 in the second-stage confusion circuit H1 receives the masked data R2, …, the input terminal f31 of the adder E3 in the 32nd-stage confusion circuit H1 receives the masked data R32; where R1, R2, …, R32 are random numbers, such as 128-bit random numbers, and R1, R2, …, R32 can be the same or different (e.g., R1 is a 128-bit data, and R2, …, R32 are 32-bit data). The input terminal f41 of the adder E4 in each stage of the confusion circuit H1 receives the corresponding masked data. For example, the masked data received by the input terminal f41 of the adder E4 in the same-stage confusion circuit H1 is the same as the masked data received by the input terminal f31 of the adder E3.
[0106] The input terminal f32 of the adder E3 in the first-stage confusion circuit H1 receives the key key1, and the input terminal f42 of the adder E4 in the first-stage confusion circuit H1 receives the initialization value m1. The input terminal f32 of the adder E3 in each stage of the confusion circuit H1 from the 2nd stage to the 32nd stage is connected to the output terminal of the previous-stage round calculation circuit H2. For example, the input terminal f32 of the adder E3 in the 2nd-stage confusion circuit H1 is coupled to the output terminal of the 1st-stage round calculation circuit H2; the input terminal f32 of the adder E3 in the 3rd-stage confusion circuit H1 is coupled to the output terminal of the 2nd-stage round calculation circuit H2. The input terminal f42 of the adder E4 in each stage of the confusion circuit H1 from the 2nd stage to the 32nd stage is connected to another output terminal of the previous-stage round calculation circuit H2.
[0107] The output terminal o33 of the adder E3 in each stage of the confusion circuit H1 is connected to the input terminal of the coupled round calculation circuit H2, and the output terminal o43 of the adder E4 in each stage of the confusion circuit H1 is connected to another input terminal of the coupled round calculation circuit.
[0108] Each stage of the round calculation circuit H2 includes two output terminals. One output terminal outputs the masked round key data Rk1 i , and the other output terminal outputs the unmasked round key data Rk1 i _mask, where i represents the i-th stage of the round calculation circuit, 1 ≤ i ≤ 32, and i is a positive integer. Among them, the masked round key data and the unmasked round key data output by each stage of the round calculation circuit H2 are not only input as the input data of the next-stage round calculation circuit H2 into the next-stage round calculation circuit H2, but also input as the input data of the encryption / decryption module Endec_1 into the encryption / decryption module Endec_1. For example, the masked round key data Rk1 output by the i-th stage of the round calculation circuit H2 iRound key data Rk1 of the reconciliation mask i _mask is respectively input into adder E3 and adder E4 in the (i + 1)-th round calculation circuit H2 as the input data of the (i + 1)-th round calculation circuit H2, and is also input into the encryption / decryption module Endec_1 as the input data of the i-th round calculation circuit H2 in the encryption / decryption module Endec_1.
[0109] Two output terminals of the last-stage round calculation circuit H2 of the round key expansion module Round_key_expand_1 are respectively connected to the input terminals of adder E5 and adder E6 of the confusion circuit Q2. The other input terminals of adder E5 and adder E6 respectively receive the input masked data R33.
[0110] Both adder E5 and adder E6 will output the calculation results in reverse order. For example, the calculation result of adder E5 is the sequence S1 = {X32, X33, X34, X35}, and the calculation result of adder E6 is the sequence S2 = {M3, M2, M1, M0}. Adder E5 outputs the calculation result S1 in reverse order to get S1’ = {X35, X34, X33, X32}, and adder E6 outputs the sequence S2 in reverse order to get S2’ = {M0, M1, M2, M3}. Among them, S1’ is the masked data, and S2’ is the unmasked data. X32, X33, X34, X35, M3, M2, M1, M0 respectively represent 32-bit data. In Figure 3 、 Figure 4 、 Figure 5 and Figure 6 In the embodiments shown, the output data of adder E5 and adder E6 in the confusion circuit Q2 are represented by X32, X33, X34, X35, M3, M2, M1, M0, but the data represented by X32, X33, X34, X35, M3, M2, M1, M0 are different in different embodiments.
[0111] Figure 4 Fig. shows the structural schematic diagram of the round key expansion module Round_key_expand_2 provided by the embodiment of the present application.
[0112] Refer to Figure 2A 、 2B and Figure 4, in the round key expansion module Round_key_expand_2, the input terminal f31 of the adder E3 in each stage of the confusion circuit H1 receives the corresponding masked data. For example, the input terminal f31 of the adder E3 in the first-stage confusion circuit H1 receives the masked data P1, the input terminal f31 of the adder E3 in the second-stage confusion circuit H1 receives the masked data P2, …, the input terminal f31 of the adder E3 in the 32nd-stage confusion circuit H1 receives the masked data P32; where P1, P2, …, P32 are random numbers, such as 128-bit random numbers, and P1, P2, …, P32 can be the same or different (for example, P1 is 128-bit data and P2 - P32 are 32-bit data). The input terminal f41 of the adder E4 in each stage of the confusion circuit H1 receives the corresponding masked data. For example, the masked data received by the input terminal f41 of the adder E4 in the same-stage confusion circuit H1 is the same as the masked data received by the input terminal f31 of the adder E3.
[0113] The input terminal f32 of the adder E3 in the first-stage confusion circuit H1 receives the key key2, and the input terminal f42 of the adder E4 in the first-stage confusion circuit H1 receives the initial value m2. The input terminal f32 of the adder E3 in each stage of the confusion circuit H1 from the 2nd stage to the 32nd stage is connected to the output terminal of the previous-stage round calculation circuit H2. For example, the input terminal f32 of the adder E3 in the 2nd-stage confusion circuit H1 is coupled to the output terminal of the 1st-stage round calculation circuit H2; the input terminal f32 of the adder E3 in the 3rd-stage confusion circuit H1 is coupled to the output terminal of the 2nd-stage round calculation circuit H2. The input terminal f42 of the adder E4 in each stage of the confusion circuit H1 from the 2nd stage to the 32nd stage is connected to another output terminal of the previous-stage round calculation circuit H2.
[0114] The output terminal o33 of the adder E3 in each stage of the confusion circuit H1 is connected to the input terminal of the coupled round calculation circuit H2, and the output terminal o43 of the adder E4 in each stage of the confusion circuit H1 is connected to another input terminal of the coupled round calculation circuit.
[0115] Each stage of the round calculation circuit H2 includes two output terminals. One output terminal outputs the masked round key data Rk2 i , and the other output terminal outputs the demasked round key data Rk2 i _mask, where i represents the i-th stage of the round calculation circuit, 1 ≤ i ≤ 32, and i is a positive integer. Among them, the masked round key data and the demasked round key data output by each stage of the round calculation circuit H2 are not only input as the input data of the next-stage round calculation circuit H2 into the next-stage round calculation circuit H2, but also input as the input data of the encryption / decryption module Endec_2 into the encryption / decryption module Endec_2. For example, the masked round key data Rk2 output by the i-th stage of the round calculation circuit H2 iRound key data Rk2 of the reconciliation mask i _mask is respectively input into adder E3 and adder E4 in the (i + 1)-th stage round calculation circuit H2 as the input data of the (i + 1)-th stage round calculation circuit H2, and is also input into the encryption / decryption module Endec_2 as the input data of the i-th stage round calculation circuit H2 in the encryption / decryption module Endec_2.
[0116] Two output terminals of the last stage round calculation circuit H2 of the round key expansion module Round_key_expand_2 are respectively connected to the input terminals of adder E5 and adder E6 of the confusion circuit H3. The other input terminals of adder E5 and adder E6 respectively receive the input masked data P33.
[0117] For example, the calculation result of adder E5 in the round key expansion module Round_key_expand_2 is the sequence S3 = {X32, X33, X34, X35}, and the calculation result of adder E6 is the sequence S4 = {M3, M2, M1, M0}. Adder E5 outputs the calculation result S3 in reverse order to obtain S3' = {X35, X34, X33, X32}, and adder E6 outputs the sequence S4 in reverse order to obtain S4' = {M0, M1, M2, M3}. Among them, S3' is the masked data and S4' is the unmasked data.
[0118] Figure 5 Shows the structural schematic diagram of the encryption / decryption module Endec_1 provided by the embodiment of the present application.
[0119] Reference Figure 2A 、 2B And Figure 5 , the input terminal f31 of adder E3 of each stage confusion circuit H1 of the encryption / decryption module Endec_1 receives the corresponding masked data. For example, the input terminal f31 of adder E3 of the first stage confusion circuit H1 receives the masked data Q1, the input terminal f31 of adder E3 of the second stage confusion circuit H1 receives the masked data Q2,..., the input terminal f31 of adder E3 of the 32nd stage confusion circuit H1 receives the masked data Q32; among them, Q1, Q2,..., Q32 are random numbers, such as 128-bit random numbers, and Q1, Q2,..., Q32 can be the same or different (for example, Q1 is 128-bit data and Q2 - Q32 are 32-bit data). The input terminal f41 of adder E4 of each stage confusion circuit H1 receives the corresponding masked data. For example, the masked data received by the input terminal f41 of adder E4 of the same stage confusion circuit H1 is the same as the masked data received by the input terminal f31 of adder E3.
[0120] The input terminal f32 of the adder E3 of the first-level confusion circuit H1 receives the adjustment value Tweak_value, and the input terminal f42 of the adder E4 of the first-level confusion circuit H1 receives the initialization value m3. The input terminal f32 of the adder E3 of each level of the confusion circuit H1 from the second level to the 32nd level is connected to the output terminal of the previous-level round calculation circuit H2. For example, the input terminal f32 of the adder E3 of the second-level confusion circuit H1 is coupled to the output terminal of the first-level round calculation circuit H2; the input terminal f32 of the adder E3 of the third-level confusion circuit H1 is coupled to the output terminal of the second-level round calculation circuit H2. The input terminal f42 of the adder E4 of each level of the confusion circuit H1 from the second level to the 32nd level is connected to the other output terminal of the previous-level round calculation circuit H2.
[0121] The output terminal o33 of the adder E3 of each level of the confusion circuit H1 is connected to the input terminal of the coupled round calculation circuit H2, and the output terminal o43 of the adder E4 of each level of the confusion circuit H1 is connected to the other input terminal of the coupled round calculation circuit.
[0122] Each level of the round calculation circuit H2 includes two output terminals, one output terminal outputs the masked intermediate data Tw i , and the other output terminal outputs the unmasked intermediate data Tw i _mask, where i represents the i-th level of the round calculation circuit, 1 ≤ i ≤ 32, and i is a positive integer. Among them, the masked intermediate data and the unmasked intermediate data output by each level of the round calculation circuit H2 are used as the input data of the adder E3 and the adder E4 of the next-level round calculation circuit H2 and input into the next-level round calculation circuit H2.
[0123] The two output terminals of the last-level round calculation circuit H2 of the encryption / decryption module Endec_1 are respectively connected to the input terminals of the adders E5 and E6 of the confusion circuit H3. The other input terminals of the adders E5 and E6 respectively receive the input masked data Q33.
[0124] For example, the calculation result of the adder E5 in the encryption / decryption module Endec_1 is the sequence S5 = {X32, X33, X34, X35}, and the calculation result of the adder E6 is the sequence S6 = {M3, M2, M1, M0}. The adder E5 outputs the calculation result S5 in reverse order to obtain S5' = {X35, X34, X33, X32}, and the adder E6 outputs the sequence S6 in reverse order to obtain S6' = {M0, M1, M2, M3}. Among them, S5' is the masked data, and S6' is the unmasked data.
[0125] Figure 6 Shows the structural schematic diagram of the encryption / decryption module Endec_2 provided by the embodiment of the present application.
[0126] ReferenceFigure 2B , 2C and Figure 6 , in the encryption / decryption module Endec_2, the confusion circuit Q3 includes an adder E7; wherein, the input end of the adder E7 receives the intermediate data D1 and Tw’_mask, and the output end of the adder E7 outputs D1’. The output end of the adder E7 is connected to the input end f32 of the adder E3 of the first-level confusion circuit H1 of the encryption / decryption module Endec_2. The input end f42 of the adder E4 of the first-level confusion circuit H1 receives the initial value m4.
[0127] The input end f31 of the adder E3 of each-level confusion circuit H1 of the encryption / decryption module Endec_2 receives the corresponding mask data. For example, the input end f31 of the adder E3 of the first-level confusion circuit H1 receives the mask data T1, the input end f31 of the adder E3 of the second-level confusion circuit H1 receives the mask data T2, …, the input end f31 of the adder E3 of the 32nd-level confusion circuit H1 receives the mask data T32; wherein, T1, T2, …, T32 are random numbers, for example, 128-bit random numbers, and T1, T2, …, T32 can be the same or different (for example, T1 is 128-bit data, and T2 - T32 are 32-bit data). The input end f41 of the adder E4 of each-level confusion circuit H1 receives the corresponding mask data. For example, the mask data received by the input end f41 of the adder E4 of the same-level confusion circuit H1 is the same as the mask data received by the input end f31 of the adder E3.
[0128] The output end o33 of the adder E3 of each-level confusion circuit H1 is connected to the input end of the coupled round calculation circuit H2, and the output end o43 of the adder E4 of each-level confusion circuit H1 is connected to the other input end of the coupled round calculation circuit.
[0129] Each-level round calculation circuit H2 includes two output ends, one output end outputs the masked intermediate data Ec i , and the other output end outputs the demasked intermediate data Ec i _mask, where i represents the i-th level round calculation circuit, 1 ≤ i ≤ 32, and i is a positive integer. Among them, the masked intermediate data and the demasked intermediate data output by each-level round calculation circuit H2 are used as the input data of the next-level round calculation circuit H2 and input into the adder E3 and adder E4 of the next-level round calculation circuit H2.
[0130] The two output ends of the last-level round calculation circuit H2 of the encryption / decryption module Endec_2 are respectively connected to the input ends of the adder E5 and adder E6 of the confusion circuit Q4. The other ends of the adder E5 and adder E6 respectively receive the input mask data T33.
[0131] For example, in the encryption / decryption module Endec_2, the calculation result of the adder E5 is the sequence S7 = {X32, X33, X34, X35}, and the calculation result of the adder E6 is the sequence S8 = {M3, M2, M1, M0}. The reverse output of the sequence S7 is obtained as S7' = {X35, X34, X33, X32}, and the reverse output of the sequence S8 is obtained as S8' = {M0, M1, M2, M3}; where S7' is the masked data and S8' is the unmasked data.
[0132] The confusion circuit Q4 includes an adder E8; the adder E8 receives S7' and S8', and performs an exclusive OR operation on S7' and S8' to obtain the output data D2; where D2 is the unmasked data.
[0133] In an alternative embodiment, the round key expansion module Round_key_expand_1 has only one-level operation circuit Q1, and the operation circuit Q1 includes a confusion circuit H1 and a round calculation circuit H2. 32 rounds of non-linear iterative operations are implemented through the one-level operation circuit Q1. During the 32 rounds of non-linear iterative operations, the output data of the previous round of iterative operations is used as part of the input data for the next round of iterative operations, and new masked data needs to be re-input in each round. Taking the round key expansion module Round_key_expand_1 as an example, refer to Figure 7, in the first round of non - linear iterative operation, the input terminal f31 of the adder E3 of the confusion circuit H1 receives masked data, such as R1. The adder E4 receives the corresponding masked data, such as the same masked data R1 as received by the adder E3; the input terminal f32 of the adder E3 receives the key key1, and the input terminal f42 of the adder E4 receives the initialization value m1. One input terminal of the round - calculation circuit H2 receives the output data of the adder E3, and the other input terminal receives the output data of the adder E4, operates on the output data of the adder E3 and the output data of the adder E4, and outputs the masked round - key data rk11 and the un - masked round - key data rk11_mask. The masked round - key data rk11 and the un - masked round - key data rk11_mask are subjected to, for example, a logical exclusive - OR operation to eliminate the masked data in the masked round - key data rk11, and obtain the un - masked round - key data rk11_nm. In the second round of non - linear iterative operation, the input terminal f31 of the adder E3 receives masked data, such as R2. The adder E4 receives the same masked data R2 as received by the adder E3; the input terminal f32 of the adder E3 receives the masked round - key data rk12 output by the round - calculation circuit H2, and the input terminal f42 of the adder E4 receives the un - masked round - key data rk12_mask output by the round - calculation circuit H2; one input terminal of the round - calculation circuit H2 receives the output data of the adder E3, and the other input terminal receives the output data of the adder E4, operates on the output data of the adder E3 and the output data of the adder E4, and outputs the masked round - key data rk12 and the un - masked round - key data rk12_mask. And so on, in the i - th round of non - linear iterative operation (2 ≤ i ≤ 32, i is an integer), the input terminal f31 of the adder E3 receives masked data, such as Ri. The adder E4 receives the same masked data Ri as received by the adder E3; the input terminal f32 of the adder E3 receives the masked round - key data rk1 output by the round - calculation circuit H2 in the (i - 1) - th non - linear iterative operation i-1 , the input terminal f42 of the adder E4 receives the un - masked round - key data rk1 output by the round - calculation circuit H2 in the (i - 1) - th non - linear iterative operation i-1 _mask; one input terminal of the round - calculation circuit H2 receives the output data of the adder E3, and the other input terminal receives the output data of the adder E4, operates on the output data of the adder E3 and the output data of the adder E4, and outputs the masked round - key data rk1 i and the un - masked round - key data rk1 i _mask.
[0134] In an alternative embodiment, the round key expansion module Round_key_expand_2, the encryption / decryption module Endec_1, and the encryption / decryption module Endec_2 also have only one - level arithmetic circuit Q1. The 32 - round non - linear iterative operation is implemented through the one - level arithmetic circuit Q1. During the 32 - round non - linear iterative operation, the output data of the previous round of iterative operation is used as part of the input data for the next round of iterative operation, and new mask data needs to be input again in each round. Among them, the process of implementing the 32 - round non - linear iterative operation by the round key expansion module Round_key_expand_2, the encryption / decryption module Endec_1, and the encryption / decryption module Endec_2 through the one - level arithmetic circuit Q1 is similar to that of the round key expansion module Round_key_expand_1. To avoid repetition, it will not be elaborated here.
[0135] Figure 8 The block diagram of the round calculation circuit H2 according to the embodiment of the present application is shown.
[0136] As Figure 8 shown, each level of the round calculation circuit H2 includes an adder E9, an adder E10, a composite permutation circuit T, an adder E11, and an adder E12. The composite permutation circuit includes an S - box circuit 4τ and a linear transformation circuit L. Among them, the S - box circuit 4τ includes 4 parallel masked S - box circuits (τ). The masked S - box circuit can refer to the S - box circuit for anti - power consumption analysis provided in Chinese Patent 2023107802163. The input end of the composite permutation circuit is coupled to the output end of the adder E9, and the output end of the composite permutation circuit is coupled to the input end of the adder E10.
[0137] As an example, each round calculation circuit H2 in the encryption / decryption module Endec_1 and the encryption / decryption module Endec_2 includes 4 input ends and 2 output ends, namely input end 1, input end 2, input end 3, input end 4, output end 1, and output end 2. In an alternative embodiment, the SM4 encryption / decryption circuit performs encryption or decryption operations in units of 128 bits. Among them, the output end o33 of the adder E3 of the i - th level of the confusion circuit H1 outputs (X i-1 、X i 、X i+1 、X i+2 ), and the input end 1 of the i - th level of the round calculation circuit H2 is coupled to the output end o33 of the adder E3 of the i - th level of the confusion circuit H1 to receive (X i-1 、X i 、X i+1 、X i+2 ); the output end o43 of the adder E4 of the i - th level of the confusion circuit H1 outputs (R i-1 0、R i-1 1、R i-1 2、Ri-1 3), the input terminal 2 of the i-th stage round calculation circuit H2 is coupled to the output terminal o43 of the adder E4 of the i-th stage confusion circuit H1 to receive (R i-1 0, R i-1 1, R i-1 2, R i-1 3). The SM4 encryption / decryption circuit performs encryption or decryption operations in units of 128 bits, and X i-1 , X i , X i+1 , X i+2 , R i-1 0, R i-1 1, R i-1 2, R i-1 3 are 32-bit data blocks respectively. "R i-1 0, R i-1 1, R i-1 2, R i-1 3" in which "0, 1, 2, 3" respectively represent the first 32-bit data block, the second 32-bit data block, the third 32-bit data block, and the fourth 32-bit data block. X i-1 , X i , X i+1 , X i+2 are all masked data, and R i-1 0, R i-1 1, R i-1 2, R i-1 3 are all unmasked data. Performing a logical operation such as a logical exclusive OR operation on R i-1 0 and X i-1 can eliminate the masked data in X i-1 to obtain unmasked data. Performing a logical operation such as a logical exclusive OR operation on R i-1 1 and X i can eliminate the masked data in X i to obtain unmasked data. Performing a logical operation such as a logical exclusive OR operation on R i-1 2 and X i+1 can eliminate the masked data in X i+1 to obtain unmasked data. Performing a logical operation such as a logical exclusive OR operation on R i-1 3 and X i+2 can eliminate the masked data in X i+2 to obtain unmasked data. The input terminal 3 inputs Rk i and the input terminal 4 inputs Rk i _mask; wherein, if the i-th stage round calculation circuit H2 is the round calculation circuit of the encryption / decryption module Endec_1, then the Rk i input by the input terminal 3 of the i-th stage round calculation circuit H2 is Rk1i , the Rk input at the input end 4 i _mask is Rk1 i _mask. If the i-th round calculation circuit H2 is the round calculation circuit of the encryption / decryption module Endec_2, then the Rk input at the input end 3 of the i-th round calculation circuit H2 i is Rk2 i , the Rk input at the input end 4 i _mask is Rk2 i _mask.
[0138] As another example, each round calculation circuit H2 in the round key expansion module Round_key_expand_1 and the round key expansion module Round_key_expand_2 includes 3 input ends and two output ends, namely input end 1', input end 2', input end 3' and output end 1' and output end 2'. For the i-th round calculation circuit H2, the data input at its input end 1' is (X i-1 , X i , X i+1 , X i+2 ), the data input at the input end 2' is (R i-1 0, R i-1 1, R i-1 2, R i-1 3), and the data input at the input end 3' is Ck i , where Ck i is a specified value input externally.
[0139] If the i-th round calculation circuit H2 is the round calculation circuit of the encryption / decryption module Endec_1, the adder E9 of the i-th round calculation circuit H2 receives (X i , X i+1 , X i+2 ), Rk1 i and Rk1 i _mask, and performs a logical exclusive OR operation on (X i , X i+1 , X i+2 ), Rk1 i and Rk1 i _mask, and outputs the data K i ; the adder E10 receives (R i-1 1, R i-1 2, R i-1 3), Rk1 i and Rk1 i _mask, and performs a logical exclusive OR operation on (R i-1 1, R i-1 2, R i-1 3), Rk1 iand Rk1 i Perform a logical exclusive OR operation with _mask and output data M i . If the i-th round calculation circuit H2 is the round calculation circuit of the encryption / decryption module Endec_2, the adder E9 of the i-th round calculation circuit H2 receives (X i , X i+1 , X i+2 ), Rk2 i and Rk2 i _mask, perform a logical exclusive OR operation on (X i , X i+1 , X i+2 ), Rk2 i and Rk2 i _mask, and output data K i ; the adder E10 receives (R i-1 1, R i-1 2, R i-1 3), Rk2 i and Rk2 i _mask, perform a logical exclusive OR operation on (R i-1 1, R i-1 2, R i-1 3), Rk2 i and Rk2 i _mask, and output data M i . If the i-th round calculation circuit H2 is the round calculation circuit of the round key expansion module Round_key_expand_1, the adder E9 of the i-th round calculation circuit H2 receives (X i , X i+1 , X i+2 ) and Ck i , perform a logical exclusive OR operation on (X i , X i+1 , X i+2 ) and Ck i , and output data K i ; the adder E10 receives (R i-1 1, R i- 12, R i-1 3) and Ck i , perform a logical exclusive OR operation on (X i , X i+1 , X i+2 ) and Ck i , and output data M i . If the i-th round calculation circuit H2 is the round calculation circuit of the round key expansion module Round_key_expand_2, the adder E9 of the i-th round calculation circuit H2 receives (X i , X i+1 , Xi+2 ) and Ck i , perform an exclusive OR operation on (X i , X i+1 , X i+2 ) and Ck i and output data K i ; The adder E10 receives (R i-1 1, R i-1 2, R i-1 3) and Ck i , perform an exclusive OR operation on (X i , X i+1 , X i+2 ) and Ck i and output data M i .
[0140] It should be understood that the input data (such as the data input at input terminal 1 and input terminal 1', the data input at input terminal 2 and input terminal 2', etc.) and some intermediate data (such as M i , K i , etc.) in the i-th round calculation circuit H2 of the round key expansion module Round_key_expand_1, the round key expansion module Round_key_expand_2, the encryption / decryption module Endec_1, and the encryption / decryption module Endec_2 are represented by the same symbols, but their values are different for different modules.
[0141] In Figure 8 , if the i-th round calculation circuit is the round calculation circuit of the encryption / decryption module Endec_1, Rk i and Rk i _mask are the round key data and the decryption round key data output by the i-th round calculation of the round key expansion module Round_key_expand_1, that is, Rk1 i and Rk1 i _mask; if the i-th round calculation circuit is the round calculation circuit of the encryption / decryption module Endec_2, Rk i and Rk i _mask are the round key data and the decryption round key data output by the i-th round calculation of the round key expansion module Round_key_expand_2, that is, Rk2 i and Rk2 i _mask.
[0142] The synthesis permutation circuit T of the i-th round calculation circuit H2 receives data K i and M i , calculates the data K i and outputs data K i ', calculates the data M iPerform calculations and output data M i ′.
[0143] The adder E11 of the i-th stage round calculation circuit H2 receives X i-1 , K i ′, and performs a logical exclusive OR operation on X i-1 and K i ′ to obtain X i+3 ; the adder E12 receives R i-1 0 and M i ′, and performs a logical exclusive OR operation on R i-1 0 and M i ′ to obtain R io , and outputs X i+3 , R io .
[0144] According to the above content, if the i-th stage round calculation circuit H2 is the round calculation circuit of the encryption / decryption module Endec_1, If the i-th stage round calculation circuit H2 is the round calculation circuit of the encryption / decryption module Endec_2, If the i-th stage round calculation circuit H2 is the round key expansion module Round_key_expand_1's round calculation circuit, If the i-th stage round calculation circuit H2 is the round key expansion module Round_key_expand_2's round calculation circuit,
[0145] The output terminal 1 of the i-th stage round calculation circuit outputs (X i , X i+1 , X i+2 , X i+3 ), and the output terminal 2 outputs (R i-1 1, R i-1 2, R i-1 3, R io ); where i = 0, 1, 2, 3... 31. X i , X i+1 , X i+2 , X i+3 are input to the input terminal of the adder E3 of the (i + 1)-th stage confusion circuit H1, and R i-1 1, R i-1 2, R i-1 3, R io are input to the input terminal of the adder E4 of the (i + 1)-th stage confusion circuit H1. Among them, if the i-th stage round calculation circuit is the round calculation circuit of the encryption / decryption module Endec_1, then the (X i, X i+1 , X i+2 , X i+3 ) is the masked intermediate data Tw i , and the (R i-1 1, R i-1 2, R i-1 3, R io ) output from output terminal 2 is the unmasked intermediate data Tw i _mask. If the i-th round calculation circuit is the round calculation circuit of the encryption / decryption module Endec_2, then the (X i , X i+1 , X i+2 , X i+2 ) output from output terminal 1 of the i-th round calculation circuit is the masked intermediate data Ec i , and the (R i-1 1, R i-1 2, R i-1 3, R io ) output from output terminal 2 is the unmasked intermediate data Ec i _mask. If the i-th round calculation circuit is the round key expansion module Round_key_expand_1's round calculation circuit, then the (X i , X i+1 , X i+2 , X i+3 ) output from output terminal 1' of the i-th round calculation circuit is the masked round key data Rk1 i , and the (R i-1 1, R i-1 2, R i-1 3, R io ) output from output terminal 2' is the unmasked intermediate data Rk1 i _mask. If the i-th round calculation circuit is the round key expansion module Round_key_expand_2's round calculation circuit, then the (X i , X i+1 , X i+2 , X i+3 ) output from output terminal 1' of the i-th round calculation circuit is the masked round key data Rk2 i , and the (R i-1 1, R i-1 2, R i-1 3, R io ) output from output terminal 2' is the unmasked intermediate data Rk2 i _mask.
[0146] The data (X i , X i+1 , X i+2 , Xi+3 ) and the data (R i-1 1, R i-1 2, R i-1 3, R io ) only X i+3 and R io are the newly calculated results, and other data such as X i , X i+1 , X i+2 , R i- 11, R i-1 2, R i-1 3 are obtained by the round calculation circuit before the i-th stage round calculation circuit. X i , X i+1 , X i+2 , R i-1 1, R i-1 2, R i-1 3 have been masked. Therefore, when the output data (X o , X o+1 , X i+2 , X i+3 ) and (R i-1 1, R i-1 2, R i-1 3, R io ) of the i-th stage round calculation circuit are input into the (i + 1)-th stage confusion circuit H1, the (i + 1)-th stage confusion circuit H1 only needs to mask X i+3 and R io . Therefore, the mask data received by the input terminal f31 of the adder E3 and the input terminal f41 of the adder E4 of the confusion circuits H1 from the 2nd stage to the 32nd stage is 32 bits. For example, Figure 3 R2 - R32 in Figure 4 P2 - P32 in Figure 5 Q2 - Q32 in Figure 6 T2 - T32 in
[0147] are 32-bit data. And, the data received by the input terminal f32 of the adder E3 and the input terminal f42 of the adder E4 of the 1st stage confusion circuit H1, such as the key key1, the initialization value m1, the key key2, the initialization value m2, the adjustment value Tweak_value, the initialization m3, the intermediate data D1', and the initialization value m4, are 128 bits. Therefore, the mask data received by the input terminal f31 of the adder E3 and the input terminal f41 of the adder E4 of the 1st stage confusion circuit H1 is 128 bits.The SM4 encryption / decryption circuit provided by the embodiment of the present application performs masking processing on each round key generation process and each round encryption / decryption process in the XTS mode through masking data, obtaining masked round key data, unmasked round key data, masked encrypted data (or masked decrypted data), and unmasked encrypted data (or unmasked decrypted data). The unmasked round key data and the masked round key data are subjected to, for example, a logical exclusive OR operation to obtain unmasked round key data. The unmasked encrypted data and the masked encrypted data are subjected to, for example, a logical exclusive OR operation to obtain unmasked encrypted data, or the unmasked decrypted data and the masked decrypted data are subjected to, for example, a logical exclusive OR operation to obtain unmasked decrypted data. By performing masking processing on each round key generation process and each round encryption / decryption process in the XTS mode through masking data, the embodiment of the present application weakens or even eliminates the correlation between the key and power consumption, making it impossible for other users to obtain the encryption / decryption key through power analysis attack techniques, improving the power analysis attack and protection capabilities, and further enhancing the security of data.
[0148] The masked SM4 encryption / decryption circuit in the CBC mode will be described below. The encryption and decryption processes in the CBC mode are asymmetric, but the number of encryption and decryption rounds is the same. The number of encryption and decryption rounds is related to the size of the input data. For example, the number of encryption and decryption rounds N = input data / 128 bits, and the data to be encrypted is an integer multiple of 128 bits.
[0149] Figure 9 The schematic diagram of the SM4 encryption circuit according to another embodiment of the present invention is shown. As Figure 9 shown, this SM4 encryption circuit is applicable to the encryption method in the CBC mode. As Figure 9 shown, the SM4 encryption / decryption circuit includes a cascaded multi-stage extended calculation circuit G1. Each stage of the extended calculation circuit G1 includes a round key expansion module 1, an encryption module 1, and an adder E13. Among them, the output end of the round key expansion module 1 is coupled to the input end of the encryption module 1, and the output end of the adder E13 is coupled to the input end of the encryption module 1. The output end of the encryption module 1 in the first-stage extended calculation circuit and the intermediate-stage extended calculation circuit is coupled to the input end of the adder E13 in the next-stage extended calculation circuit.
[0150] In the first - stage extended computing circuit G1, the round - key expansion module 1 receives the key key1 and the mask data mask1, masks the key key1 with the mask data mask1, and outputs the masked round - key data rk1 and the un - masked round - key data rk1_mask1. The masked round - key data rk1 and the un - masked round - key data rk1_mask1 perform an operation such as logical exclusive - OR operation to eliminate the mask data in the masked round - key data Rk2, and obtain the un - masked round - key data. The adder E13 in the first - stage extended computing circuit G1 receives the initial vector IV and the data to be encrypted Plain0, performs a logical exclusive - OR operation on the initial vector IV and the data to be encrypted Plain0, and outputs the intermediate data W1. The encryption module 1 in the first - stage extended computing circuit G1 receives the intermediate data W1, the mask data mask2, the masked round - key data rk1 and the un - masked round - key data rk1_mask1, masks the intermediate data W1 with the mask data mask2, and performs an operation such as exclusive - OR operation on the un - masked round - key data rk1_mask1 and the masked round - key data rk1 to obtain the un - masked round - key data rk1_nm, and then encrypts the masked intermediate data W1 with the un - masked round - key data rk1_nm, and outputs the intermediate data Cipher0.
[0151] In the second - stage extended computing circuit G1, the round - key expansion module 1 receives the key key1 and the mask data mask3, masks the key key1 with the mask data mask3, and outputs the masked round - key data rk2 and the un - masked round - key data rk2_mask3. The adder E13 in the first - stage extended computing circuit G1 receives Cipher0 and the data to be encrypted Plain1, performs a logical exclusive - OR operation on Cipher0 and the data to be encrypted Plain1, and outputs the intermediate data W2. The encryption module 1 in the second - stage extended computing circuit G1 receives W2, the mask data mask4, the masked round - key data rk2 and the un - masked round - key data rk2_mask3, masks the intermediate data W2 with the mask data mask4, and performs an operation such as exclusive - OR operation on the un - masked round - key data rk2_mask1 and the masked round - key data rk2 to obtain the un - masked round - key data rk2_nm, and then encrypts the masked intermediate data W2 with the un - masked round - key data rk1_nm, and outputs Cipher1.
[0152] By analogy, in the Nth-level extended computing circuit G1, the round key expansion module 1 receives the key key1 and the mask data mask(2N - 1), and outputs the masked round key data rkN and the unmasked round key data rkN_mask(2N - 1). The adder E13 in the Nth-level extended computing circuit G1 receives CipherN-1 output by the (N - 1)th-level extended computing circuit and the data to be encrypted PlainN, performs a logical exclusive OR operation on CipherN-1 and the data to be encrypted PlainN, and outputs the intermediate data WN. The encryption module 1 in the Nth-level extended computing circuit G1 receives the intermediate data WN, the mask data mask2N, the masked round key data rkN and the unmasked round key data rkN_mask(2N - 1), and outputs the encrypted data CipherN.
[0153] In each level of the extended computing circuit G1, the round key expansion module 1, the encryption module 1 and Figure 1 and Figure 3 the round key expansion module Round_key_expand_1 shown in have the same structure, which will not be elaborated here.
[0154] Figure 10 FIG. shows a schematic diagram of the SM4 decryption circuit according to another embodiment of the present invention. As Figure 10 shown, the SM4 encryption / decryption circuit is applicable to the decryption mode of the CBC mode. As Figure 10 shown, the SM4 encryption / decryption circuit includes a cascade of multiple levels of extended computing circuits G2. Each level of the extended computing circuit includes a round key expansion module 2, a decryption module 2 and an adder E14. Among them, the output end of the round key expansion module 2 is coupled to the input end of the decryption module 2, and the output end of the decryption module 2 is coupled to the input end of the adder E14.
[0155] In the first-level extended computing circuit G2, the round key expansion module 2 receives the key key1 and the masked data mask1'. The key key1 is masked by the masked data mask1', and the masked round key data rk1' and the demasked round key data rk1'_mask1 are output. The masked round key data rk1' and the demasked round key data rk1'_mask1 are subjected to, for example, a logical exclusive OR operation to eliminate the masked data in the masked round key data Rk2, and the unmasked round key data is obtained. In the first-level extended computing circuit G2, the decryption module 2 receives the data to be decrypted Cipher0, the masked data mask2', the masked round key data rk1' and the demasked round key data rk1'_mask1. The data to be decrypted Cipher0 is masked by the masked data mask2', and the demasked round key data rk1'_mask1 and the masked round key data rk1' are subjected to, for example, an exclusive OR operation to obtain the unmasked round key data rk1'_nm. Then, the masked intermediate data W1 is decrypted by the unmasked round key data rk1'_nm, and the intermediate data Cipher0' is output. The adder E14 receives the intermediate data Cipher0' and the initial vector IV, and outputs Plain0.
[0156] In the second-level extended computing circuit G2, the round key expansion module 2 receives the key key1 and the masked data mask3'. The key key1 is masked by the masked data mask3', and the masked round key data rk2' and the demasked round key data rk2'_mask2 are output. In the second-level extended computing circuit G2, the decryption module 2 receives Cipher1, the masked data mask4', the masked round key data rk2' and the demasked round key data rk2'_mask2. The data to be decrypted Cipher1 is masked by the masked data mask4', and the demasked round key data rk2'_mask2 and the masked round key data rk2' are subjected to, for example, an exclusive OR operation to obtain the unmasked round key data rk2'_nm. Then, the masked intermediate data W2 is decrypted by the unmasked round key data rk2'_nm, and the intermediate data Cipher1' is output. The adder E14 in the second-level extended computing circuit G2 receives the intermediate data Cipher1' and Cipher0, and outputs Plain1.
[0157] By analogy, in the Nth-level extended computing circuit G2, the round key expansion module 2 in the round key expansion module 2 receives the key key1 and the mask data mask(2N-1)’, and outputs the masked round key data rkN’ and the unmasked round key data rkN’_mask(2N-1)’. The decryption module 2 in the second-level extended computing circuit G2 receives CipherN, mask data mask(2N)’, masked round key data rkN’ and unmasked round key data rkN’_mask(2N-1)’, and outputs intermediate data CipherN’. The adder E14 in the Nth-level extended computing circuit G2 receives the intermediate data CipherN’ and CipherN-1, and outputs PlainN.
[0158] In each-level extended computing circuit G2, the round key expansion module 2, the decryption module 2 and Figure 1 , Figure 2A , Figure 3 and Figure 5 The structures of the round key expansion module Round_key_expand_1 and the encryption / decryption module Endec_1 shown are the same, and will not be elaborated here.
[0159] Figure 11 Fig. shows a block diagram of a masked SM4 encryption / decryption circuit according to an embodiment of the present application. Figure 11 The SM4 encryption / decryption circuit shown is applicable to the encryption / decryption method in the ECB mode. As Figure 11 shown, the masked SM4 encryption / decryption circuit includes a round key expansion module 3 and an encryption / decryption module 3.
[0160] The round key expansion module 3 receives the key data key and the mask data mask1, masks the key data key through the mask data mask1, and performs operations on the masked key data, and outputs the masked round key data rk and the unmasked round key data rk_mask1.
[0161] The encryption / decryption module 3 is coupled to the round key expansion module 3 and receives the rk and rk_mask1 output from the round key expansion module 3. The encryption / decryption module 3 can either encrypt the plaintext data to obtain ciphertext data or decrypt the ciphertext data to obtain plaintext data.
[0162] Taking the operation of encrypting plaintext data by the encryption / decryption module 3 to obtain ciphertext data as an example, the encryption / decryption module 3 receives the data to be encrypted Din (plaintext data), rk and rk_mask1, and the mask data mask2 through 4 input terminals, performs masking processing on the data to be encrypted Din through the mask data mask2, and performs an XOR operation on the unmasked round key data rk_mask1 and the masked round key data rk to obtain the unmasked round key data Rk'. Then, the encrypted data Din after masking processing is encrypted through the unmasked round key data rk', and the ciphertext data Dout is output.
[0163] During the process of the encryption / decryption module 3 decrypting the ciphertext data to obtain plaintext data, the Din received by the encryption / decryption module 3 is ciphertext data, and the Dout output is plaintext data. The process of the encryption / decryption module 3 decrypting the ciphertext data to obtain plaintext data is similar to the process of encrypting the plaintext data to obtain ciphertext data, which will not be elaborated here.
[0164] Among them, both the round key expansion module 3 and the encryption / decryption module 3 adopt 32 rounds of non-linear iterative operations, and one iterative operation is one round of transformation. During the 32 rounds of non-linear iterative operations of the round key expansion module 3, the output data of the previous round of iterative operation will be used as part of the input data of the next round of iterative operation, and new mask data needs to be input in each round. For example, when the round key expansion module 3 performs 32 rounds of non-linear iterative operations, only the key data key needs to be input once, and 32 rounds of mask data need to be input, and the 32 rounds of mask data input can be different. In each iterative operation of the round key expansion module 3, the round key expansion module 3 not only receives the output data of the previous round of iterative operation, but also receives the input mask data, and performs masking processing on the output data of the previous round of iterative operation through the received mask data to eliminate the correlation between the round key data and the power consumption. Similarly, in each iterative operation of the encryption / decryption module 3, the encryption / decryption module 3 not only receives the output data of the previous round of iterative operation and the corresponding round key data, but also receives the input mask data, performs masking processing on the output data of the previous round of iterative operation and the corresponding round key data through the mask data, and performs encryption / decryption operations on the output data of the previous round of iterative operation through the masked round key data, further reducing the correlation between each round of iterative operation and the power consumption.
[0165] Although the preferred embodiments of the present application have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application. Obviously, those skilled in the art can make various changes and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A SM4 encryption and decryption circuit, characterized in that, The encryption and decryption circuit is applicable to the encryption operation or decryption operation in the XTS mode. The encryption and decryption circuit includes: a first-round key expansion module, a first encryption and decryption module, a second-round key expansion module, a second encryption and decryption module, a modular multiplication module, a first adder, and a second adder; Among them, the first-round key expansion module receives first key data and first mask data, uses the first mask data to perform masking processing on the first key data, and performs operations on the masked first key data, and outputs masked first-round key data and unmasked first-round decryption key data; The first encryption and decryption module is coupled to the first-round key expansion module. The first encryption and decryption module receives second mask data, an adjustment value, the first-round key data, and the first-round decryption key data, uses the second mask data to perform masking processing on the adjustment value, and uses the first-round key data and the first-round decryption key data to perform operations on the masked adjustment value, and outputs masked first intermediate data and unmasked first intermediate decryption data; The modular multiplication module is coupled to the first encryption and decryption module. The modular multiplication module receives preset parameters, the first intermediate data, and the first intermediate decryption data, uses the preset parameters to perform operations on the first intermediate data and the first intermediate decryption data, and outputs masked second intermediate data and unmasked second intermediate decryption data; The second-round key expansion module receives second key data and third mask data, uses the third mask data to perform masking processing on the second key data, and performs operations on the masked second key data, and outputs masked second-round key data and unmasked second-round decryption key data; The first adder receives first target data to be encrypted or decrypted and the second intermediate data, and performs operations on the first target data and the second intermediate data, and outputs third intermediate data; The second encryption and decryption module is coupled to the second-round key expansion module and the first adder. The second encryption and decryption module receives fourth mask data, the second intermediate decryption data, the third intermediate data, the second-round key data, and the second-round decryption key data, and outputs fourth intermediate data; The second adder is coupled to the second encryption and decryption module and the modular multiplication module. The second adder receives the fourth intermediate data and the exclusive OR data of the second intermediate data and the second intermediate decryption data, and outputs second target data after encryption or decryption.
2. The circuit according to claim 1, wherein The first-round key expansion module, the first encryption and decryption module, the second-round key expansion module, and the second encryption and decryption module all include cascaded N-level operation circuits and a first confusion circuit. The output end of the Nth operation circuit is coupled to the input end of the first confusion circuit. N rounds of non-linear iterative operations are implemented through the cascaded N-level operation circuits. Among them, each operation circuit performs one round of non-linear iterative operation, and N is a positive integer; The second encryption / decryption module further includes a second confusion circuit and a third confusion circuit. The output end of the second confusion circuit is coupled to the input end of the first-stage operation circuit in the second encryption / decryption module, and the input end of the third confusion circuit is coupled to the output end of the first confusion circuit.
3. The circuit according to claim 2, wherein Each stage of the operation circuit includes a fourth confusion circuit and a round calculation circuit. The output end of the fourth confusion circuit is coupled to the input end of the round calculation circuit; the output end of the round calculation circuit of the previous-stage operation circuit is coupled to the input end of the fourth confusion circuit of the next-stage operation circuit; the output end of the round calculation circuit of the Nth-stage operation circuit is coupled to the input end of the first confusion circuit.
4. The circuit according to claim 3, wherein The fourth confusion circuit includes a first input end, a second input end, a third input end, a fourth input end, a first output end, and a second output end; In each stage of the operation circuit, the first input end of the fourth confusion circuit receives the corresponding first target mask data, the second input end receives the first data, the third input end receives the corresponding second target mask data, the fourth input end receives the second data, and the first data and the second data are masked by using the first target mask data and the second target mask data respectively to obtain the first masked data and the first demasked data; and the first masked data is transmitted to the round calculation circuit in the first-stage operation circuit through the first output end, and the first demasked data is transmitted to the round calculation circuit in the first-stage operation circuit through the second output end; wherein, the first data is the key data, or the output data of the round calculation circuit in the previous-stage operation circuit, or the output data of the second confusion circuit, the second data is the preset initialization data or the output data of the round calculation circuit in the previous-stage operation circuit, and the first demasked data and the first masked data are demasked to obtain the data without mask.
5. The circuit according to claim 4, wherein The round calculation circuit includes at least a fifth input end, a sixth input end, a seventh input end, a third output end, and a fourth output end; In each stage of the operation circuit, the fifth input end of the round calculation circuit is coupled to the first output end of the fourth confusion circuit belonging to the same stage, and receives the first masked data; The sixth input end is coupled to the second output end of the fourth confusion circuit belonging to the same stage, and receives the first demasked data; The seventh input end receives the third data; wherein, the third data is the specified-bit data in the masked first-round key data and the demasked first-round key data, the specified-bit data in the masked second-round key data and the demasked second-round key data, or the specified data; The round calculation circuit operates on the first masked data according to the third data to obtain the second masked data; and operates on the first demasked data according to the third data to obtain the second demasked data; the third output end outputs the second masked data, and the fourth output end outputs the second demasked data; wherein, the second demasked data and the second masked data are demasked to obtain the data without mask.
6. The circuit according to claim 5, wherein The first output terminal of the fourth confusion circuit in the i-th level operation circuit outputs first masked data (X i-1 , X i , X i+1 , X i+2 ), and the second output terminal of the fourth confusion circuit in the i-th level operation circuit outputs first unmasked data (R i-1 0, R i-1 1, R i-1 2, R i-1 3); 1 ≤ i ≤ N, and i is a positive integer The fifth input terminal of the round calculation circuit in the i-th level operation circuit receives (X i , X i+1 , X i+2 ), and the sixth output terminal receives (Ri-11, R i-1 2, R i-1 3); The third data received at the seventh input terminal of the round calculation circuit in the i-th level operation circuit of the first encryption / decryption module includes the specified bit data in the first-round key data output from the third output terminal of the round calculation circuit in the i-th level operation circuit of the first-round key expansion module and the specified bit data in the first-round unrounding key data output from the fourth output terminal; The third data received at the seventh input terminal of the round calculation circuit in the i-th level operation circuit of the second encryption / decryption module is the specified bit data in the second-round key data output from the third output terminal of the round calculation circuit in the i-th level operation circuit of the second-round key expansion module and the specified bit data in the second-round unrounding key data output from the fourth output terminal; The third data received at the seventh input terminal of the round calculation circuit in the i-th level operation circuit of the first-round key expansion module and the second-round key expansion module is the specified data; In the i-th level operation circuit, the round calculation circuit performs operations on (X i , X i+1 , X i+2 ) received at the fifth input terminal and the third data received at the seventh input terminal to obtain X i+3 , and performs operations on (R i-1 1, R i-1 2, R i-1 3) received at the sixth input terminal and the third data received at the seventh input terminal to obtain R io ; The third output terminal of the round calculation circuit in the i-th level operation circuit outputs second masked data (X i 、X i+1 、X i+2 、X i+3 ), and the fourth output terminal outputs second unmasked data (R i-1 1、R i-1 2、R i-1 3、R io ); Among them, X i-1 , X i , X i+1 , X i+2 , R i-1 0, R i-1 1, R i-1 2, R i-1 3, X i+3 and R io are all data with a predetermined number of bytes.
7. The circuit according to claim 5 or 6, characterized in that, The third confusion circuit includes an eighth input terminal, a ninth input terminal, and a fifth output terminal; The eighth input terminal is coupled to the third output terminal of the round calculation circuit in the N-th level operation circuit to receive the second masked data output from the third output terminal. The ninth input terminal is coupled to the fourth output terminal of the round calculation circuit in the N-th level operation circuit to receive the second demasked data output from the fourth output terminal. The second masked data and the second demasked data are demasked to obtain the fourth intermediate data, and the fifth output terminal outputs the fourth intermediate data.
8. A SM4 encryption circuit, characterized in that, The encryption circuit is applicable to the encryption operation in the CBC mode; the data to be encrypted input to the encryption circuit is divided into multiple data blocks to be encrypted; The encryption circuit includes cascaded M-level extended calculation circuits. Each level of extended calculation circuit receives the third key data, the corresponding data block to be encrypted, the corresponding first calculation mask data, and the corresponding second calculation mask data. The first calculation mask data is used to mask the third key data, and the corresponding second calculation mask data is used to mask the data block to be encrypted. The masked third key data is used to perform an encryption operation on the masked data block to be encrypted, and ciphertext data is output; M is a positive integer.
9. A SM4 decryption circuit, characterized in that, The decryption circuit is applicable to the decryption operation in the CBC mode; the data to be decrypted input to the decryption circuit is divided into multiple data blocks to be decrypted; The encryption circuit includes cascaded P-level extended calculation circuits. Each level of extended calculation circuit receives the fourth key data, the corresponding data block to be decrypted, the corresponding third calculation mask data, and the corresponding fourth calculation mask data. The third calculation mask data is used to mask the fourth key data, and the corresponding fourth calculation mask data is used to mask the data block to be decrypted. The masked third key data is used to perform a decryption operation on the masked data block to be decrypted, and plaintext data is output; P is a positive integer.
10. A SM4 encryption and decryption circuit, characterized in that, The encryption / decryption circuit is applicable to the encryption operation or decryption operation in the ECB mode, The encryption and decryption circuit includes a fourth-round key expansion module and a third encryption and decryption module. The fourth-round key expansion module receives fifth key data and fifth mask data, uses the fifth mask data to perform a masking process on the fifth key data, performs operations on the masked fifth key data, and outputs masked fifth-round key data and unmasked fifth-round decryption key data. The input end of the third encryption and decryption module is coupled to the output end of the fourth-round key expansion module. The third encryption and decryption module receives sixth mask data, third target data to be encrypted or decrypted, the fifth-round key data, and the fifth-round decryption key data, uses the sixth mask data to perform a masking process on the third target data, and uses the fifth-round key data and the fifth-round decryption key data to perform operations on the masked third target data, and outputs fourth target data after encryption or decryption.