Encryption / decryption device and encryption / decryption method thereof

By introducing a verification mechanism in the encryption/decryption device, the correctness of multiplication inverse elements and binary field multiplication operations is detected, and the problem of insufficient verification of encryption steps and decryption steps in the prior art is solved, and data security and encryption process security are improved.

CN120238284APending Publication Date: 2025-07-01NUVOTON
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411779369.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-05
Publication Date
2025-07-01

Smart Images

  • Figure CN120238284A_ABST
    Figure CN120238284A_ABST
Patent Text Reader

Abstract

The invention provides an encryption / decryption device and an encryption / decryption method thereof. The device comprises a row shift / reverse row shift unit, a bit group substitution / reverse bit group substitution unit, a dual row shift / reverse row shift unit, an encoder, a decoder and a first verification unit. The row shift / reverse row shift unit performs row shift / reverse row shift operation on the result data to generate an input state array. The bit group replacement / anti-bit group replacement unit converts the input state array to generate an output state array. The dual row shift / reverse row shift unit performs row shift / reverse row shift operation on the dual result data to generate a dual input state array. The encoder encodes the dual input state array to generate encoded data. The decoder decodes the encoded data to generate decoded data. The first verification unit verifies the relationship between the decoded data and the output state array to generate a first verification signal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to an encryption / decryption device based on the Advanced Encryption Standard (AES) and its encryption / decryption method, and particularly to an encryption / decryption device and its encryption / decryption method for verifying whether the Advanced Encryption Standard performs correct encryption / decryption. Background Art

[0002] In cryptography, the term "encryption" refers to the process of protecting the content by changing plaintext into ciphertext that is difficult to understand. Only a device with a decryption method can restore the ciphertext to normal readable content through the decryption process. Ideally, only authorized personnel can read the information conveyed by the ciphertext. Encryption itself cannot prevent the interception of information transmission, but it can prevent the interceptor from understanding the content of the information.

[0003] To prevent the key from being leaked due to an attack on the encryption / decryption device, it is necessary to verify the correctness of each encryption step and decryption step, thereby ensuring the security of the encryption / decryption device. Summary of the Invention

[0004] This application proposes an encryption / decryption device with a verification mechanism, which is applicable to any implementation method of byte substitution transformation. Although there are many implementation methods for byte substitution transformation or inverse byte substitution transformation, the verification mechanism of the encryption / decryption device in this application can detect whether an error occurs in the operation when the input value of the multiplicative inverse is 0x0, and can detect whether an error occurs in the binary field multiplication operation in the mix column operation and the inverse mix column operation. In addition, the verification mechanism proposed in this application can also protect the decryption program to ensure the security of the encrypted or decrypted data. Moreover, the verification mechanism proposed in this application can also determine whether an error occurs during the data transmission process, thereby improving the security during the encryption and decryption processes.

[0005] In view of this, the present application provides an encryption / decryption device, which includes a row shift / inverse row shift unit, a byte substitution / inverse byte substitution unit, a dual row shift / inverse row shift unit, an encoder, a decoder, a first verification unit, and a controller. The above-mentioned row shift / inverse row shift unit performs a row shift / inverse row shift operation on a result data to generate an input state array. The above-mentioned byte substitution / inverse byte substitution unit performs a conversion on the above-mentioned input state array to generate an output state array. The above-mentioned dual row shift / inverse row shift unit performs the above-mentioned row shift / inverse row shift operation on a pair of dual result data to generate a pair of dual input state arrays. The above-mentioned encoder encodes the above-mentioned pair of dual input state arrays to generate an encoded data. The above-mentioned decoder decodes the above-mentioned encoded data to generate a decoded data. The above-mentioned first verification unit verifies the correspondence between the above-mentioned decoded data and the above-mentioned output state array to generate a first verification signal. The above-mentioned controller determines whether the above-mentioned conversion performed by the above-mentioned byte substitution / inverse byte substitution unit is correct according to the above-mentioned first verification signal.

[0006] The present application further provides an encryption / decryption method, which includes performing a row shift / inverse row shift operation on a result data to generate an input state array; performing a byte substitution / inverse byte substitution conversion on the above-mentioned input state array to generate an output state array; using a dual row shift / inverse row shift unit to perform the above-mentioned row shift / inverse row shift operation on a pair of dual result data to generate a pair of dual input state arrays; encoding the above-mentioned pair of dual input state arrays to generate an encoded data; decoding the above-mentioned encoded data to generate a decoded data; and determining whether the above-mentioned byte substitution / inverse byte substitution conversion is correct according to the correspondence between the above-mentioned decoded data and the above-mentioned output state array.

[0007] The present application further provides an encryption / decryption method, which includes performing a row shift / inverse row shift operation on a result data to generate an input state array; performing a byte substitution / inverse byte substitution conversion on the above-mentioned input state array to generate an output state array; using a dual row shift / inverse row shift unit to perform the above-mentioned row shift / inverse row shift operation on a pair of dual result data to generate a pair of dual input state arrays; encoding the above-mentioned pair of dual input state arrays to generate an encoded data; decoding the above-mentioned encoded data to generate a decoded data; performing a multiply-by-two operation on the above-mentioned output state array to generate a multiply-by-two array; performing a divide-by-two operation on the above-mentioned multiply-by-two array to generate a multiply-by-two divide-by-two array; and determining whether the above-mentioned byte substitution / inverse byte substitution conversion is correct according to the correspondence between the above-mentioned decoded data and the above-mentioned multiply-by-two divide-by-two array. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 is a block diagram showing an encryption / decryption device according to an embodiment of the present application;

[0009] Figure 2 is a block diagram showing a byte substitution / inverse byte substitution unit according to an embodiment of the present application;

[0010] Figure 3 is a schematic diagram showing a second verification unit according to an embodiment of the present application;

[0011] Figure 4 is a schematic diagram showing a divide-by-two circuit according to an embodiment of the present application;

[0012] Figure 5 is a schematic diagram showing a first verification unit according to an embodiment of the present application;

[0013] Figure 6 is a schematic diagram showing a third verification unit according to an embodiment of the present application;

[0014] Figure 7 is a block diagram showing an encryption / decryption device according to another embodiment of the present application;

[0015] Figure 8 is a block diagram showing an encryption / decryption device according to still another embodiment of the present application;

[0016] Figure 9 is a block diagram showing an encryption / decryption device according to still another embodiment of the present application;

[0017] Figure 10 is a schematic diagram showing encoding operations and decoding operations according to an embodiment of the present application;

[0018] Figure 11 is a flowchart showing an encryption / decryption method according to an embodiment of the present application; and

[0019] Figure 12 is a flowchart showing an encryption / decryption method according to an embodiment of the present application.

[0020] Symbol Explanation

[0021] 100, 700, 800, 900: Encryption / decryption device

[0022] 110: Includes a bus interface

[0023] 120: Input / output buffer

[0024] 130: Controller

[0025] 140: Encryption / decryption circuit

[0026] 141: Key Expansion Unit

[0027] 142: Inverse Mix Column Unit

[0028] 143: Shift Row / Inverse Shift Row Unit

[0029] 144: Register

[0030] 145,200: Byte Substitution / Inverse Byte Substitution Unit

[0031] 146: Mix Column / Inverse Mix Column Unit

[0032] 147: Round Key Addition Unit

[0033] 210: Inverse Affine Transformation Unit

[0034] 220: Multiplicative Inverse Element Unit

[0035] 230: Affine Transformation Unit

[0036] 300,701: Second Verification Unit

[0037] 301: First Divide-by-Two Circuit

[0038] 302: Second Divide-by-Two Circuit

[0039] 303: Third Divide-by-Two Circuit

[0040] 400: Divide-by-Two Circuit

[0041] 500,702,810,910: First Verification Unit

[0042] 501: First Numerical Generator

[0043] 502: Second Numerical Generator

[0044] 503: Inverse Affine Transformation Unit

[0045] 504: Multiplier

[0046] 600,703: Third Verification Unit

[0047] 601: First Byte Partitioning Device

[0048] 602: Second Byte Partitioning Device

[0049] 603: Third Byte Partitioning Device

[0050] 604: First Logic Operation Unit

[0051] 605: Second Logic Operation Unit

[0052] 606: Third Logic Operation Unit

[0053] 607: Fourth Logic Operation Unit

[0054] 801: Dual Round Key Addition Unit

[0055] 802: Dual Row Shift / Inverse Row Shift Unit

[0056] 803: Encoder

[0057] 804: Dual Register

[0058] 805: Decoder

[0059] 1010: Encoder

[0060] 1011: First Transposition Unit

[0061] 1012: First Binary Field Addition Unit

[0062] 1020: Decoder

[0063] 1021: Second Binary Field Addition Unit

[0064] 1022: Second Transposition Unit

[0065] MUX0: First Multiplexer

[0066] MUX1: Second Multiplexer

[0067] MUX2: Third Multiplexer

[0068] MUX3: Fourth Multiplexer

[0069] MUX4: Fifth Multiplexer

[0070] MUX5: Sixth Multiplexer

[0071] MUX6: Seventh Multiplexer

[0072] DIN: Input Data

[0073] BUS: Bus

[0074] KEY: Key

[0075] DOUT: Encrypted / Decrypted Data

[0076] ST: Status Data

[0077] CTRL: Control Signal

[0078] RK: Round Key

[0079] ARK: Result Data

[0080] SR: Shift Data

[0081] SBI, ISBI, SI: Input status array

[0082] SBO, ISBO, SO: Output status array

[0083] CMP1: First comparator

[0084] CMP2: Second comparator

[0085] CMP3: Third comparator

[0086] CMP4: Fourth comparator

[0087] CMP5: Fifth comparator

[0088] CMP6: Sixth comparator

[0089] CMP7: Seventh comparator

[0090] LG: Logic gate

[0091] M: Multiplicand array

[0092] MX2: Multiply-by-two array

[0093] MX4: Multiply-by-four array

[0094] MX8: Multiply-by-eight array

[0095] MC: Mixing / anti-mixing array

[0096] DIV2(MX2): First result

[0097] DIV2(MX4): Second result

[0098] DIV2(MX8): Third result

[0099] CM1: First comparison result

[0100] CM2: Second comparison result

[0101] CM3: Third comparison result

[0102] CM4: Fourth comparison result

[0103] CM5: Fifth comparison result

[0104] CM6: Sixth comparison result

[0105] DARK: Dual result data

[0106] DSR: Dual shift data

[0107] ENC: Encoded data

[0108] DEC: Decoded Data

[0109] MX2D2: Multiply-by-Two Divide-by-Two Array

[0110] INV: Inverse Element

[0111] IN[7:0]: Input Array

[0112] OUT[7:0]: Output Array

[0113] XOR1: First Exclusive-OR Gate

[0114] XOR2: Second Exclusive-OR Gate

[0115] XOR3: Third Exclusive-OR Gate

[0116] CI: First Given Value

[0117] CO: Second Given Value

[0118] V2: Second Value

[0119] SEL1: First Selection Array

[0120] SEL2: Second Selection Array

[0121] R4: Fourth Result

[0122] R5: Fifth Result

[0123] R6: Sixth Result

[0124] SBOXi[7:0]: Simplified Output Status Array

[0125] RKXi[7:0]: Simplified Round Key

[0126] ARKXi[7:0]: Simplified Result Data

[0127] VF1: First Verification Signal

[0128] VF2: Second Verification Signal

[0129] VF3: Third Verification Signal

[0130] A: First Encoded Data

[0131] B: Second Encoded Data

[0132] C: Third Encoded Data

[0133] D: Fourth Encoded Data

[0134] X0: First Transposed Data

[0135] X1: Second Transposed Data

[0136] X2: Third transposition data

[0137] X3: Fourth transposition data

[0138] O0: First encoded data

[0139] O1: Second encoded data

[0140] O2: Third encoded data

[0141] O3: Fourth encoded data

[0142] Y0: First exclusive-OR data

[0143] Y1: Second exclusive-OR data

[0144] Y2: Third exclusive-OR data

[0145] Y3: Fourth exclusive-OR data

[0146] A’: First decoded data

[0147] B’: Second decoded data

[0148] C’: Third decoded data

[0149] D’: Fourth decoded data Detailed implementation manners

[0150] The following description is about the embodiments of the present application. Its purpose is to illustrate the general principles of the present application by way of examples and should not be regarded as a limitation of the present application. The scope of the present application shall be defined by the claims.

[0151] It should be noted that the content disclosed below can provide multiple embodiments or examples for practicing different features of the present application. The specific element examples and arrangements described below are only used to briefly illustrate the spirit of the present application and are not used to limit the scope of the present application. In addition, the following description may reuse the same element symbols or words in multiple examples. However, the purpose of reuse is only to provide a simplified and clear description and is not used to limit the relationship between the multiple embodiments and / or configurations discussed below.

[0152] In addition, the descriptions such as one feature being connected to, coupled to, and / or formed on another feature in the following description may actually include multiple different embodiments, including the direct contact of these features, or including other additional features formed between these features, etc., such that these features are not in direct contact.

[0153] In addition, relative terms such as "lower" or "bottom" and "higher" or "top" may be used in the embodiments to describe the relative relationship of one element of the drawing to another element. It is understood that if the device in the drawing is flipped upside down, the element described on the "lower" side will become the element on the "higher" side.

[0154] It is understood that although terms such as "first", "second", "third", etc. may be used herein to describe various elements, components, regions, layers, and / or parts, these elements, components, regions, layers, and / or parts should not be limited by these terms, and these terms are only used to distinguish different elements, components, regions, layers, and / or parts. Therefore, a first element, component, region, layer, and / or part discussed below may be referred to as a second element, component, region, layer, and / or part without departing from the teachings of some embodiments of the present application.

[0155] Some embodiments of the present application can be understood in conjunction with the drawings, and the drawings of the embodiments of the present application are also regarded as a part of the description of the embodiments of the present application. It should be understood that the drawings of the embodiments of the present application are not drawn to the scale of actual devices and elements. In the drawings, the shapes and thicknesses of the embodiments may be exaggerated to clearly show the features of the embodiments of the present application. In addition, the structures and devices in the drawings are shown in a schematic manner to clearly show the features of the embodiments of the present application.

[0156] Herein, the terms "about", "approximately", "substantially" generally mean within 20% of a given value or range, preferably within 10%, and more preferably within 5%, or 3%, or 2%, or 1%, or 0.5%. The quantity given herein is an approximate quantity, that is, the meaning of "about", "approximately", "substantially" may still be implied even without specifically stating "about", "approximately", "substantially".

[0157] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which this disclosure belongs. It is understood that these terms, such as those defined in a commonly used dictionary, should be interpreted to have a meaning consistent with the relevant technology and the background or context of the present application, and should not be interpreted in an idealized or overly formal manner, unless specifically defined in the embodiments of the present application.

[0158] In some embodiments of the present application, terms related to joining and connection such as "connect" and "interconnect", unless specifically defined, may mean that two structures are in direct contact, or may also mean that two structures are not in direct contact, and other structures are provided between these two structures. And these terms related to joining and connection may also include the cases where both structures can move, or both structures are fixed.

[0159] In the drawings, similar elements and / or features may have the same element symbols. Various elements of the same type may be distinguished by adding a letter or number after the element symbol for distinguishing similar elements and / or similar features.

[0160] Figure 1 is a block diagram showing an encryption / decryption device according to an embodiment of the present application. As Figure 1 shown, the encryption / decryption device 100 includes a bus interface 110, an input / output buffer 120, a controller 130, and an encryption / decryption circuit 140. Input data DIN is temporarily stored in the input / output buffer 120 through the bus interface 110 via the bus BUS. When the bus interface 110 receives the input of the input data DIN, the controller 130 generates a key KEY and provides it to the encryption / decryption circuit 140, and controls the encryption / decryption circuit 140 to generate encrypted / decrypted data DOUT according to the input data DIN and the key KEY by using a control signal CTRL.

[0161] According to some embodiments of the present application, the encryption / decryption circuit 140 uses the advanced encryption standard (AES) to perform an encryption program or a decryption program on the input data DIN to generate the encrypted / decrypted data DOUT. As Figure 1 shown, the encryption / decryption circuit 140 includes a key expansion unit 141, an InvMixColumns unit 142, and a first multiplexer MUX0. According to an embodiment of the present application, when the encryption / decryption circuit 140 executes the encryption program, the first multiplexer MUX0 outputs the result output by the key expansion unit 141 according to the key KEY as the round key RK. According to another embodiment of the present application, when the encryption / decryption circuit 140 executes the decryption program, the first multiplexer MUX0 selects to output the result generated by the key KEY through the key expansion unit 141 and the InvMixColumns unit 142 as the round key RK.

[0162] As Figure 1 shown, the encryption / decryption circuit 140 further includes a ShiftRow / InvShiftRow unit 143, a register 144, a SubbBytes / InvSubBytes unit 145, a MixColumns / InvMixColumns unit 146, a second multiplexer MUX1, and an addroundkey unit 147.

[0163] According to an embodiment of the present application, when the input data DIN is just input to the encryption / decryption circuit 140, the second multiplexer MUX1 provides the input data DIN to the round key addition unit 147, so that the round key addition unit 147 performs a binary field addition operation on the input data DIN and the round key RK, and generates the result data ARK, and provides the generated result data ARK to the row shift / inverse row shift unit 143. According to an embodiment of the present application, when the round key addition unit 147 performs a binary field addition operation on the input data DIN and the round key RK, the round key addition unit 147 performs an exclusive OR operation on the input data DIN and the round key RK, and generates the result data ARK.

[0164] The row shift / inverse row shift unit 143 circularly shifts each horizontal row in the result data ARK to generate the shifted data SR. The register 144 stores the shifted data SR and provides the shifted data SR as the input state array SBI / ISBI to the byte substitution / inverse byte substitution unit 145. The byte substitution / inverse byte substitution unit 145 converts the input state array SBI / ISBI to generate the output state array SBO / ISBO.

[0165] According to an embodiment of the present application, when the encryption / decryption circuit 140 performs an encryption program, the byte substitution / inverse byte substitution unit 145 performs a byte substitution conversion on the input state array SBI to generate the output state array SBO. According to another embodiment of the present application, when the encryption / decryption circuit 140 performs a decryption program, the byte substitution / inverse byte substitution unit 145 performs an inverse byte substitution conversion on the input state array ISBI to generate the output state array ISBO. According to some embodiments of the present application, the byte substitution conversion and the inverse byte substitution conversion are inverse functions of each other, and both the byte substitution conversion and the inverse byte substitution conversion include linear conversion and non-linear conversion.

[0166] Figure 2 is a block diagram showing the byte substitution / inverse byte substitution unit according to an embodiment of the present application. As Figure 2 shown, the byte substitution / inverse byte substitution unit 200 includes an inverse affine transformation unit 210, a third multiplexer MUX2, a multiplicative inverse unit 220, an affine transformation unit 230, and a fourth multiplexer MUX3. According to an embodiment of the present application, the byte substitution / inverse byte substitution unit 200 corresponds to Figure 1Byte substitution / Inverse byte substitution unit 145.

[0167] According to an embodiment of the present application, when Figure 1 the encryption / decryption circuit 140 executes an encryption program, the third multiplexer MUX2 provides the input state array SBI to the multiplicative inverse element unit 220. The multiplicative inverse element unit 220 performs a non-linear transformation on the input state array SBI to generate an inverse element INV. Then, the affine transformation unit 230 performs an affine transformation on the inverse element INV to generate an output state array SBO. Subsequently, the fourth multiplexer MUX3 outputs the output state array SBO.

[0168] According to another embodiment of the present application, when Figure 1 the encryption / decryption circuit 140 executes a decryption program, the third multiplexer MUX2 provides the result of the inverse affine transformation performed by the inverse affine transformation unit 210 on the input state array ISBI to the multiplicative inverse element unit 220. The multiplicative inverse element unit 220 performs a non-linear transformation on the result of the inverse affine transformation performed by the inverse affine transformation unit 210 to generate an inverse element INV. Subsequently, the fourth multiplexer MUX3 outputs the inverse element INV as an output state array ISBO.

[0169] According to some embodiments of the present application, since the byte substitution / inverse byte substitution unit 200 shares the most complex multiplicative inverse element unit 220 during the encryption program and the decryption program, for the convenience of subsequent explanation, the input state array and the output state array of the encryption program are respectively labeled as SBI and SBO, and the input state array and the output state array of the decryption program are respectively labeled as ISBI and ISBO.

[0170] Returning to Figure 1 , the mix column / inverse mix column unit 146 performs a mix column / inverse mix column operation on the output state array SBO / ISBO to generate a mix / inverse mix array MC. The round key addition unit 147 performs a binary field addition operation on the mix / inverse mix array MC (or the output state array SBO / ISBO) and the round key RK to generate a result data ARK. According to an embodiment of the present application, the binary field addition operation is a logical exclusive OR operation. According to some embodiments of the present application, when the shift / inverse shift unit 143, the register 144, the byte substitution / inverse byte substitution unit 145, the mix column / inverse mix column unit 146, and the round key addition unit 147 execute multiple rounds, the round key addition unit 147 generates the encrypted / decrypted data DOUT and outputs it through the input / output buffer 120, the bus interface 110, and the bus BUS.

[0171] To ensure the correctness of the encryption and decryption programs executed by the encryption / decryption circuit 140 and prevent the differential fault analysis method from intercepting the key, the encryption / decryption circuit 140 requires a strong countermeasure to detect the occurrence of errors.

[0172] As Figure 2 shown, when performing the encryption program, assume that the input state array SBI[7:0] and the output state array SBO[7:0] are the input value and output value of the byte substitution / inverse byte substitution unit 200 during the encryption program respectively. The transformation performed by the multiplicative inverse element unit 220 is labeled as -1 power, and the affine transformation performed by the affine transformation unit 230 is labeled as AT. Therefore, the relationship between the input state array SBI[7:0] and the output state array SBO[7:0] is as shown in Equation 1:

[0173] SBO[7:0] = AT((SBI[7:0]) -1 ) (Equation 1)

[0174] Performing the inverse affine transformation (i.e., AT -1 ) on both sides of Equation 1 forms Equation 2.

[0175] AT -1 (SBO[7:0]) = (SBI[7:0]) -1 (Equation 2) Then, multiplying both sides of Equation 2 by the input state array SBI[7:0] forms Equation 3.

[0176] AT -1 (SBO[7:0]) * (SBI[7:0]) = 0x1, where SBI[7:0] ≠ 0x0 during encryption

[0177] AT -1 (SBO[7:0]) * (SBI[7:0]) = 0x0, where SBI[7:0] = 0x0 during encrption

[0178] (Equation 3)

[0179] According to an embodiment of the present application, when the input state array SBI[7:0] is 0x0, the result of the binary field multiplication operation must be 0x0. According to another embodiment of the present application, when the input state array SBI[7:0] is not 0x0, the result of the binary field multiplication operation must be 0x1. However, when the input state array SBI[7:0] is 0x0, no matter what the attacker does to AT -1(SBO[7:0]) Inserting any incorrect value will make Equation 3 hold. In other words, Equation 3 cannot detect the arithmetic error that occurs when the input status array SBI[7:0] is 0x0.

[0180] To overcome the above drawbacks, when the input status array SBI[7:0] is 0x0, the output status array SBO[7:0] is set to 0x63 according to the look-up table. Therefore, the detection method of Equation 3 can be modified to determine whether the input status array SBI[7:0] is 0x0. When the input status array SBI[7:0] is 0x0, determine whether the output status array SBO[7:0] is 0x63. When the output status array SBO[7:0] is 0x63, it means that the operation of the byte substitution / inverse byte substitution unit 200 is correct. When the output status array SBO[7:0] is not 0x63, it means that the operation of the byte substitution / inverse byte substitution unit 200 is incorrect.

[0181] When the input status array SBI[7:0] is not 0x0, judge AT -1 (SBO[7:0]) and the product of the input status array SBI[7:0] is 0x1. When AT -1 (SBO[7:0]) and the product of the input status array SBI[7:0] is 0x1, it means that the operation of the byte substitution / inverse byte substitution unit 200 is correct. When AT -1 (SBO[7:0]) and the product of the input status array SBI[7:0] is not 0x1, it means that the operation of the byte substitution / inverse byte substitution unit 200 is incorrect.

[0182] The above judgment method can be described as Equation 4, where Equation 4 is as follows:

[0183] (SBI[7:0] == 0x0)? (SBO[7:0] == 0x63) : (AT -1 (SBO[7:0]) * (SBI[7:0]) == 0x1)

[0184] (Equation 4)

[0185] Among them, the combination of the question mark (i.e.,?) and the colon (i.e., :) in Formula 4 is a ternary operator. The expression on the left side of the question mark is the condition of the ternary operator, and the expression on the right side is the corresponding result when the condition of the ternary operator holds or not. When the condition holds, the expression on the left side of the colon is returned as the result. When the condition does not hold, the expression on the right side of the colon is returned. Therefore, when the input status array SBI[7:0] is 0x0, Formula 4 returns the result of whether the output status array SBO[7:0] is equal to 0x63. When the input status array SBI[7:0] is not 0x0, the result of whether the binary field multiplication result is equal to 0x1 is returned. Therefore, it is possible to detect whether an error occurs in the conversion operation of the byte substitution / inverse byte substitution unit 200 during the encryption process by Formula 4.

[0186] As Figure 2 shown, when performing the decryption process, assume that the input status array ISBI[7:0] and the output status array ISBO[7:0] are respectively the input value and the output value of the byte substitution / inverse byte substitution unit 200 during the decryption process, and the inverse affine transformation performed by the inverse affine transformation unit 210 is marked as AT -1 , and the transformation performed by the multiplicative inverse element unit 220 is marked as the -1 power. Therefore, the relationship between the input status array ISBI[7:0] and the output status array ISBO[7:0] is as shown in Formula 5:

[0187] ISBO[7:0] = (AT -1 (ISBI[7:0])) -1 (Formula 5)

[0188] Multiply both sides of the equal sign in Formula 5 by AT -1 (ISBI[7:0]) to form Formula 6.

[0189] ISBO[7:0] * AT -1 (ISBI[7:0]) = 0x1, where ISBI[7:0] ≠ 0x63 during decryption

[0190] ISBO[7:0] * AT -1 (ISBI[7:0]) = 0x0, where ISBI[7:0] = 0x63 during decryption

[0191] (Formula 6)

[0192] When the input status array ISBI[7:0] is 0x63, the result of the binary field multiplication operation must be 0x0, and vice versa it must be 0x1. In addition, according to FIPS197, Advanced Encryption Standard (AES) published on November 26, 2001, when the input status array ISBI[7:0] is 0x63, the output status array ISBO[7:0] must be 0x0. Therefore, we can rewrite Equation 6 as Equation 7.

[0193] (ISBI[7:0] == 0x63)? (ISBO[7:0] == 0x0) : ISBO[7:0] * AT -1 (ISBI[7:0])

[0194] == 0x1

[0195] (Equation 7)

[0196] As shown in Equation 7, when the input status array ISBI[7:0] is 0x63, return the comparison result of whether the output status array ISBO[7:0] is equal to 0x0. Conversely, return the result of whether the binary field multiplication operation result is equal to 0x1. Therefore, the conversion operation of the byte substitution / inverse byte substitution unit 200 during the decryption process can be detected by Equation 7.

[0197] In other words, it can be judged respectively through Equation 4 and Equation 7 Figure 1 whether there is an error in the conversion operation of the byte substitution / inverse byte substitution unit 145 during the encryption process and the decryption process. And when the input status array ISBI[7:0] is 0x63 or the input status array SBI[7:0] is equal to 0x0, it can also be judged through Equation 4 and Equation 7 whether there is an error in the conversion operation of the byte substitution / inverse byte substitution unit 145 during the encryption process and the decryption process. In addition, there is still a lack of error verification methods for the mix column / inverse mix column unit 146 and the round key addition unit 147.

[0198] Suppose Figure 2 the inverse element INV[127:0], the round key RK[127:0], and the result data ARK[127:0] generated by the multiplication inverse element unit 220 of

[0199] INV[127:0] = {INV3[31:0], INV1[31:0}, INV2[31:0], INV0[31:0]}

[0200] RK[127:0] = {RK3[31:0], RK1[31:0], RK2[31:0], RK0[31:0]}

[0201] AK[127:0] = {ARK3[31:0], ARK1[31:0], ARK2[31:0], ARK0[31:0]}

[0202] (Formula 8)

[0203] The 4 bytes of the inverse element INV[127:0] (i.e., I0, I1, I2, I3) are subjected to 3 binary field addition operations (i.e., exclusive OR operations) to form the simplified inverse element INVXi[7:0] as shown in Formula 9.

[0204] INVXi[7:0] = (INVi[31:24] ⊕ INVi[23:16} ⊕ INVi[15:8] ⊕ INVi[7:0])

[0205] = I3 ⊕ I2 ⊕ I1 ⊕ I0, where 0 ≤ i ≤ 3

[0206] (Formula 9)

[0207] Formula 10 performs 3 binary field addition operations on the 4 bytes of the round key RK[127:0] (i.e., R0, R1, R2, R3) to form the simplified round key RKXi[7:0].

[0208] RKXi[7:0] = (RKi[31:24] ⊕ RKi[23:16} ⊕ RKi[15:8] ⊕ RKi[7:0])

[0209] = R3 ⊕ R2 ⊕ R1 ⊕ R0, where 0 ≤ i ≤ 3

[0210] (Formula 10)

[0211] Formula 11 performs 3 binary field addition operations on the 4 bytes of the result data ARK[127:0] (i.e., A0, A1, A2, A3) to form the simplified result data ARKXi[7:0].

[0212] ARKXi[7:0] = (ARKi[31:24] ⊕ ARKi[23:16} ⊕ ARKi[15:8] ⊕ ARKi[7:0])

[0213] = A3 ⊕ A2 ⊕ A1 ⊕ A0, where 0 ≤ i ≤ 3

[0214] (Formula 11)

[0215] Figure 2The affine transformation performed by the affine transformation unit 230 is to perform matrix multiplication (hereinafter referred to as MM operation) on the simplified inverse element INVXi[7:0] and then perform a binary field addition operation (that is, the result of the MM operation is exclusive-ored with 0x63). The result obtained by the simplified inverse element INVXi[7:0] through the affine transformation unit 230, the mix column / inverse mix column unit 146, and the round key addition unit 147 is as shown in Formula 12.

[0216] A0 = (0x2 * (MM(I0) ⊕ 0x63)) ⊕ (0x3 * (MM(I1) ⊕ 0x63)) ⊕ (0x1

[0217] * (MM(I2) ⊕ 0x63)) ⊕ (0x1 * (MM(I3) ⊕ 0x63)) ⊕ R0;

[0218] A1 = (0x1 * (MM(I0) ⊕ 0x63)) ⊕ (0x2 * (MM(I1) ⊕ 0x63)) ⊕ (0x3

[0219] * (MM(I2) ⊕ 0x63)) ⊕ (0x1 * (MM(I3) ⊕ 0x63)) ⊕ R1;

[0220] A2 = (0x1 * (MM(I0) ⊕ 0x63)) ⊕ (0x1 * (MM(I1) ⊕ 0x63)) ⊕ (0x2

[0221] * (MM(I2) ⊕ 0x63)) ⊕ (0x3 * (MM(I3) ⊕ 0x63)) ⊕ R2;

[0222] A3 = (0x3 * (MM(I0) ⊕ 0x63)) ⊕ (0x1 * (MM(I1) ⊕ 0x63)) ⊕ (0x1

[0223] * (MM(I2) ⊕ 0x63)) ⊕ (0x2 * (MM(I3) ⊕ 0x63)) ⊕ R3;

[0224] (Formula 12)

[0225] The simplified result data ARKXi[7:0] is as shown in Formula 13.

[0226] ARKXi = A0 ⊕ A1 ⊕ A2 ⊕ A3

[0227] = MM(I0) ⊕ MM(I1) ⊕ MM(I2) ⊕ MM(I3) ⊕ R0 ⊕ R1 ⊕ R2

[0228] ⊕ R3 = MM(I0 ⊕ I1 ⊕ I2 ⊕ I3) ⊕ R0 ⊕ R1 ⊕ R2 ⊕ R3

[0229] (Equation 13) Substituting Equation 9 and Equation 10 into Equation 13 gives Equation 14.

[0230] ARKXi = MM(INVXi) ⊕ RKXi, where 0 ≤ i ≤ 3 (Equation 14)

[0231] Assume that the variable MMI0 is the output byte of the affine transformation (i.e., the input byte of the MixColumn / InvMixColumn unit 146), as shown in Equation 15.

[0232] MMI0 = (MM(I0) ⊕ 0x63) (Equation 15)

[0233] To optimize software performance or hardware area, the binary field multiplication by two operation will first perform a left shift of the multiplicand MMI0. If the most significant bit (i.e., MSB) of MMI0 is 0x1, then take the remainder using the irreducible polynomial (i.e., 0x11B), as shown in Equation 16.

[0234] 0x2 * MMI0 = (MMI0 << 0x1) ⊕ 0x11B, where the MSB of MMI0 = 0x1

[0235] 0x2 * MMI0 = (MMI0 << 0x1), where the MSB of MMI0 = 0x0

[0236] (Equation 16)

[0237] As for the simplest method of the binary field multiplication by three operation in Equation 12, it is to add the result of the binary field multiplication by two operation to MMI0, as shown in Equation 17.

[0238] 0x3 * MMI0 = (0x2 * MMI0) ⊕ MMI0 (Equation 17) If an attacker can insert an error value Er during the binary field multiplication by two operation, as shown in Equation 18.

[0239] (0x2 * MMI0) ⊕ Er (Equation 18) This will also cause an error value Er to be inserted into the result of the binary field multiplication by three operation, as shown in Equation 19.

[0240] (0x2 * MMI0) ⊕ Er ⊕ MMI0 = (0x3 * MMI0) ⊕ Er (Equation 19)

[0241] According to Equation 12, the above two error values Er will accumulate to A0 and A3, forming the variables A0' and A3' in Equation 20.

[0242] A0′ = A0 ⊕ Er

[0243] A3 ′ = A3 ⊕ Er

[0244] (Formula 20)

[0245] After executing Formula 14, the actual value of the information redundancy mechanism (i.e., ARKXi') will cancel out the two error values Er, making the actual value equal to the estimated value (i.e., MM(INVXi) ⊕ RKXi), as shown in Formula 21.

[0246] ARKXi ′ = A0 ′ ⊕ A1 ⊕ A2 ⊕ A3 ′

[0247] = A0 ⊕ Er ⊕ A1 ⊕ A2 ⊕ A3 ⊕ Er

[0248] = A0 ⊕ A1 ⊕ A2 ⊕ A3

[0249] = ARKXi = MM(INVX0) ⊕ RKX0

[0250] (Formula 21)

[0251] As shown in Formula 21, since the two error values Er will cancel each other out after performing a binary field addition operation, an effective verification method is required to facilitate the detection of errors in the binary field multiplication by two operation.

[0252] In the encryption program, the output state array SBO generated by the byte substitution / inverse byte substitution conversion of the byte substitution / inverse byte substitution unit 145 is as shown in Formula 22.

[0253] SBO[127:0] = {SBO3[31:0], SBO1[31:0], SBO2[31:0], SBO0[31:0]}

[0254] (Formula 22)

[0255] Since the mix column / inverse mix column unit 146 performs mix column conversion in units of 32 bits, the SBO[127:0] in Formula 22 will be divided into 4 representations of 32 bits. Formula 23 is to perform 3 binary field addition operations on SBO0, SBO1, SBO2, and SBO3 to generate the simplified output state array SBOXi[7:0].

[0256] SBOXi[7:0] = (SBOi[31:24] ⊕ SBOi[23:16] ⊕ SBOi[15:8] ⊕ SBOi[7:0]), where 0

[0257] ≤ i ≤ 3

[0258] = (MM(I3) ⊕ 0x63) ⊕ (MM(I2) ⊕ 0x63) ⊕ (MM(I1) ⊕ 0x63) ⊕ (MM(I0)

[0259] ⊕ 0x63)

[0260] = MM(I3) ⊕ MM(I2) ⊕ MM(I1) ⊕ MM(I0)

[0261] = MM(I3 ⊕ I2 ⊕ I1 ⊕ I0)

[0262] = MM(INVXi)

[0263] (Equation 23)

[0264] As Figure 2 shown, since the byte substitution operation of the byte substitution / inverse byte substitution unit 145 is composed of the multiplicative inverse element unit 220 and the affine transformation unit 230, and the affine transformation performed by the affine transformation unit 230 is composed of a matrix multiplication operation (i.e., the MM operation in Equation 12) and a binary field addition operation (i.e., the result of the MM operation is exclusive-ORed with 0x63). Therefore, Equation 23 can also be represented by I0, I1, I2, I3, and the MM operation.

[0265] Finally, through the optimization process of Equation 23, we can know that the simplified output state array SBOXi[7:0] is equal to the value of MM(INVXi). Substituting the result of Equation 23 into Equation 14 forms Equation 24. In addition, errors occurring in the mix column / inverse mix column conversion performed by the mix column / inverse mix column unit 146 and the conversion performed by the round key addition unit 147 can be detected through Equation 24.

[0266] ARKXi = MM(INVXi) ⊕ RKXi = SBOXi ⊕ RKXi, where 0 ≤ i ≤ 3

[0267] (Equation 24)

[0268] On the other hand, in the decryption program, the output state array ISBO generated by the inverse byte substitution conversion of the byte substitution / inverse byte substitution unit 145 is as shown in Equation 25.

[0269] ISBO[127:0] = {ISBO3[31:0], ISBO1[31:0], ISBO2[31:0], ISBO0[31:0]}

[0270] (Equation 25)

[0271] Since the inverse mix column / mix column unit 146 performs inverse mix column conversion in units of 32 bits, the ISBO[127:0] of Equation 25 is divided into 4 32-bit units. Equation 26 performs 3 binary field addition operations (i.e., Z0⊕Z1⊕Z2⊕Z3) on ISBO0, ISBO1, ISBO2, and ISBO3 to generate the simplified output state array ISBOXi[7:0].

[0272] ISBOXi[7:0] = (ISBOi[31:24]⊕ISBOi[23:16]⊕ISBOi[15:8]⊕ISBOi[7:0])

[0273] = Z0⊕Z1⊕Z2⊕Z3, where 0 ≤ i ≤ 3

[0274] (Equation 26)

[0275] Next, the inverse mix column conversion performed by the inverse mix column / mix column unit 146 is as shown in Equation 27.

[0276] A0 = (0xE*Z0)⊕(0xB*Z1))⊕(0xD*Z2))⊕(0x9*Z3))⊕R0;

[0277] A1 = (0x9*Z0)⊕(0xE*Z1))⊕(0xB*Z2))⊕(0xD*Z3))⊕R1;

[0278] A2 = (0xD*Z0)⊕(0x9*Z1))⊕(0xE*Z2))⊕(0xB*Z3))⊕R2;

[0279] A3 = (0xB*Z0)⊕(0xD*Z1))⊕(0x9*Z2))⊕(0xE*Z3))⊕R3;

[0280] (Equation 27)

[0281] From Equation 11, it can be seen that the result of adding A0, A1, A2, and A3 of Equation 27 is equal to the simplified result data ARKXi[7:0], as shown in Equation 28. The simplified result data ARKXi will be equal to the sum of the four output bytes of the simplified output state array ISBOXi[7:0] (i.e., ISBOXi = Z0⊕Z1⊕Z2⊕Z3), plus the sum of each byte of the simplified round key RKXi[7:0] as shown in Equation 10 (i.e., RKXi = R0⊕R1⊕R2⊕R3).

[0282] ARKXi = A0⊕A1⊕A2⊕A3

[0283] = Z0⊕Z1⊕Z2⊕Z3⊕R0⊕R1⊕R2⊕R3

[0284] = ISBOXi[7:0] ⊕ RKXi; where 0 ≤ i ≤ 3

[0285] (Equation 28)

[0286] Therefore, Equation 28 can detect errors that occur in the inverse mix column transformation performed by the mix column / inverse mix column unit 146 and the transformation performed by the round key addition unit 147.

[0287] To detect whether the binary field multiply-by-two operation, binary field multiply-by-four operation, and binary field multiply-by-eight operation of the mix column / inverse mix column transformation performed by the mix column / inverse mix column unit 146 are correct, the binary field multiply-by-two operation is as shown in Equation 29.

[0288] MX2[7:0] = 0x2 * M[7:0] = (M << 1) ⊕ (0x11B & {9{M[7]}})

[0289] = {M[7:0], 0x0} ⊕ {M[7], 0x0, 0x0, 0x0, M[7], M[7], 0x0, M[7], M[7]})

[0290] = {M[6:4], (M[3] ⊕ M[7]), (M[2] ⊕ M[7]), M[1], (M[0] ⊕ M[7]), M[7]}

[0291] (Equation 29)

[0292] Assume that the multiply-by-two array MX2 is the result of the binary field multiply-by-two operation on the multiplicand array M. For optimization, the binary field multiply-by-two operation will first perform a left shift on the multiplicand array M. If the most significant bit of the multiplicand array M (i.e., M[7]) is 0x1, then the irreducible polynomial (i.e., 0x11B) is added and the remainder is taken. Therefore, the multiply-by-two array MX2 can be simplified to a value composed only of the bits of the multiplicand array M, as shown in Equation 29.

[0293] Among them, {9{MX2[7]}} in Equation 29 refers to the 9 bits formed by repeating the 8th bit (i.e., the most significant bit) of the multiply-by-two array MX2. In other words, {9{MX2[7]}} is equal to {MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7], MX2[7]}. For the convenience of subsequent description, hereinafter, the binary field multiply-by-two operation is represented by MUL2(), as shown in Equation 30.

[0294] MUL2(M) = {M[6:4], (M[3] ⊕ M[7]), (M[2] ⊕ M[7]), M[1], (M[0] ⊕ M[7]), M[7]}

[0295] = MX2[7:0]

[0296] (Formula 30)

[0297] As shown in Formula 30, each bit value of the multiply-by-two array MX2 can be composed of the bit values of the multiplicand array M. In other words, each bit value of the multiplicand array M can also be composed of the bit values of the multiply-by-two array MX2.

[0298] M[6] = MX2[7];

[0299] M[5] = MX2[6];

[0300] M[4] = MX2[5];

[0301] M[1] = MX2[2];

[0302] M[7] = MX2[0];

[0303] (Formula 31)

[0304] First, in Formula 31, find the part of the one-to-one bit conversion corresponding to the values of the multiplicand array M and the multiply-by-two array MX2. At this time, we can know that the 7th, 6th, 5th, 2nd, and 8th bits of the multiplicand array M correspond to the 8th, 7th, 6th, 3rd, and 1st bits of the multiply-by-two array MX2 respectively.

[0305] Next, substitute the known bit values of the multiplicand array M into the non-one-to-one conversion bits of Formula 30 to find the remaining unknown bit values of the multiplicand array M. From Formula 30, we know that MX2[4] = (M[3] ⊕ M[7]). Adding M[7] to both sides of the equation gives M[3] = (MX2[4] ⊕ M[7]), as shown in Formula 32.

[0306] MX2[4] = (M[3] ⊕ M[7])

[0307] M[3] = MX2[4] ⊕ M[7] = MX2[4] ⊕ MX2[0]

[0308] (Formula 32)

[0309] M[2] is as shown in Formula 33.

[0310] MX2[3] = (M[2] ⊕ M[7])

[0311] M[2] = MX2[3] ⊕ M[7] = MX2[3] ⊕ MX2[0]

[0312] (Formula 33)

[0313] M[0] is as shown in Formula 34.

[0314] MX2[1] = (M[0] ⊕ M[7])

[0315] M[0] = MX2[1] ⊕ M[7] = MX2[1] ⊕ MX2[0]

[0316] (Formula 34)

[0317] DIV2() represents a binary field division by two operation. Formula 35 represents each bit of DIV2(MX2) (i.e., the division by two operation on the multiply-by-two array MX2) in terms of the bit values of the multiply-by-two array MX2.

[0318] DIV2(MX2) = {MX2[0], MX2[7:5], (MX2[0] ⊕ MX2[4]), (MX2[0]

[0319] ⊕ MX2[3]), MX2[2], (MX2[0] ⊕ MX2[1])}

[0320] = M

[0321] (Formula 35)

[0322] In other words, it is possible to detect whether the result of the binary field multiply-by-two operation (i.e., the multiply-by-two array MX2) is correct through Formula 35.

[0323] Assume that the multiply-by-four array MX4 is the result of the multiply-by-four operation on the binary field multiplicand array M value. As shown in Formula 36, the multiply-by-four array MX4 is the result after the multiply-by-two array MX2 passes through MUL2(), where MUL2() represents performing the binary field multiply-by-two operation.

[0324] MX4 = (MX2 << 1) ⊕ (0x11B & {9{MX2[7]}}) = MUL2(MX2)

[0325] (Formula 36)

[0326] Next, assume that the multiply-by-eight array MX8 is the result of the binary field multiply-by-eight operation on the multiplicand array M. As shown in Formula 37, the multiply-by-eight array MX8 is the result after the multiply-by-four array MX4 passes through MUL2(), as shown in Formula 37.

[0327] MX8 = (MX4 << 1) ⊕ (0x11B & {9{MX4[7]}})

[0328] = MUL2(MX4)

[0329] (Formula 37) As shown in Formula 38, the value of the multiply-by-eight array MX8 can be obtained as the multiply-by-four array MX4 after DIV2().

[0330] DIV2(MX8) = MX4 (Formula 38) Similarly, as shown in Formula 39, the value of the multiply-by-four array MX4 can be obtained as the multiply-by-two array MX2 after DIV2().

[0331] DIV2(MX4) = MX2 (Formula 39)

[0332] In other words, the binary field multiply-by-two operation, multiply-by-four operation, and multiply-by-eight operation can be checked through Formula 35, Formula 38, and Formula 39, as shown in Formula 40.

[0333] VF1 = (DIV2(MX2) == M) & (DIV2(MX4) == MX2) & (DIV2(MX8) == MX4)

[0334] (Formula 40)

[0335] Figure 3 is a schematic diagram showing a second verification unit according to an embodiment of the present application. According to an embodiment of the present application, Figure 3 the second verification unit 300 is used to execute Formula 40. As Figure 3 shown, the second verification unit 300 includes a first divide-by-two circuit 301, a second divide-by-two circuit 302, a third divide-by-two circuit 303, a first comparator CMP1, a second comparator CMP2, a third comparator CMP3, and a logic gate LG.

[0336] The first divide-by-two circuit 301 performs a divide-by-two operation on the multiply-by-two array MX2 to generate a first result DIV2(MX2). The second divide-by-two circuit 302 performs a divide-by-two operation on the multiply-by-four array MX4 to generate a second result DIV2(MX4). The third divide-by-two circuit 303 performs a divide-by-two operation on the multiply-by-eight array MX8 to generate a third result DIV2(MX8).

[0337] The first comparator CMP1 compares the multiplicand array M and the first result DIV2(MX2) to generate a first comparison result CM1. When the multiplicand array M and the first result DIV2(MX2) are equal, the first comparison result CM1 is at a first logic level.

[0338] The second comparator CMP2 compares the multiply-by-two array MX2 and the second result DIV2(MX4) to generate a second comparison result CM2. When the multiply-by-two array MX2 is equal to the second result DIV2(MX4), the second comparison result CM2 is at a first logic level.

[0339] The third comparator CMP3 compares the quadruple array MX4 and the third result DIV2(MX8), and generates a third comparison result CM3. When the quadruple array MX4 is equal to the third result DIV2(MX8), the third comparison result CM3 is at a first logic level.

[0340] According to an embodiment of the present application, when the first comparison result CM1, the second comparison result CM2, and the third comparison result CM3 are all at the first logic level, the logic gate LG outputs a first verification signal VF1 at the first logic level. According to other embodiments of the present application, when at least one of the first comparison result CM1, the second comparison result CM2, and the third comparison result CM3 is not at the first logic level, the first verification signal VF1 is not at the first logic level.

[0341] Figure 4 is a schematic diagram showing a division-by-two circuit according to an embodiment of the present application. According to an embodiment of the present application, Figure 4 the division-by-two circuit 400 corresponds to Figure 3 any one of the first division-by-two circuit 301, the second division-by-two circuit 302, and the third division-by-two circuit 303. According to an embodiment of the present application, the division-by-two circuit 400 is used to perform the division-by-two operation shown in Equation 35.

[0342] As Figure 4 shown, the division-by-two circuit 400 is used to perform the division-by-two operation shown in Equation 35 on the input array IN[7:0], and generate an output array OUT[7:0]. The division-by-two circuit 400 uses the first bit IN[0] of the input array (i.e., the least significant bit) as the eighth bit OUT[7] of the output array (i.e., the most significant bit); the division-by-two circuit 400 uses the eighth bit IN[7] of the input array (i.e., the most significant bit) as the seventh bit OUT[6] of the output array; the division-by-two circuit 400 uses the seventh bit IN[6] of the input array as the sixth bit OUT[5] of the above output array.

[0343] The division-by-two circuit 400 uses the sixth bit IN[5] of the input array as the fifth bit OUT[4] of the output array; the first exclusive-OR gate XOR1 of the division-by-two circuit 400 performs an exclusive-OR operation on the fifth bit IN[4] of the input array and the first bit IN[0] of the input array, and uses it as the fourth bit OUT[3] of the output array; the second exclusive-OR gate XOR2 of the division-by-two circuit 400 performs an exclusive-OR operation on the fourth bit IN[3] of the input array and the first bit IN[0] of the input array, and uses it as the third bit OUT[2] of the output array.

[0344] The divide-by-two circuit 400 uses the third bit IN[2] of the input array as the second bit OUT[1] of the output array; the third exclusive-OR gate XOR3 of the divide-by-two circuit 400 performs an exclusive-OR operation on the second bit IN[1] of the input array and the first bit IN[0] of the input array, and serves as the first bit OUT[0] (i.e., the least significant bit) of the output array.

[0345] According to some embodiments of the present application, Formula 4 and Formula 7 can be optimized. The first predetermined value CI[7:0] can be composed of the first value V1 and 0x0, as shown in detail in Formula 41.

[0346] CI[7:0] = {0x0, V1, V1, 0x0, 0x0, 0x0, V1, V1} (Formula 41)

[0347] The second predetermined value CO[7:0] can be composed of the second value V2 and 0x0, as shown in detail in Formula 42, where the second value V2 is the inverse of the first value V1.

[0348] CO[7:0] = {0x0, V2, V2, 0x0, 0x0, 0x0, V2, V2} (Formula 42)

[0349] According to an embodiment of the present application, when Figure 1 the encryption / decryption circuit 140 executes the encryption program, the first value V1 is 0x0 and the second value V2 is 0x1. Therefore, the first predetermined value CI[7:0] is 0x0, and the second predetermined value CO[7:0] is 0x63. According to another embodiment of the present application, when Figure 1 the encryption / decryption circuit 140 executes the decryption program, the first value V1 is 0x1 and the second value V2 is 0x0. Therefore, the first predetermined value CI[7:0] is 0x63, and the second predetermined value CO[7:0] is 0x0.

[0350] Next, as Figure 1 shown, since the input state array SBI and the input state array ISBI can both be inputs to the byte substitution / inverse byte substitution unit 145, and the output state array SBO and the output state array ISBO can both be outputs of the byte substitution / inverse byte substitution unit 145, the input of the byte substitution / inverse byte substitution unit 145 is hereinafter defined as the input state array SI and the output of the byte substitution / inverse byte substitution unit 145 is defined as the output state array SO. In other words, when the encryption / decryption circuit 140 executes the encryption program, SI is SBI and SO is SBO. When the encryption / decryption circuit 140 executes the decryption program, SI is ISBI and SO is ISBO.

[0351] As shown in Equation 43, when the second value V2 is 0x1, the first selection array SEL1 is the input state array SI; when the second value V2 is 0x0, the first selection array SEL1 is the output state array SO. In other words, when the encryption / decryption circuit 140 executes the encryption program, the second value V2 is 0x1 and the first selection array SEL1 is the input state array SI; when the encryption / decryption circuit 140 executes the decryption program, the second value V2 is 0x0 and the first selection array SEL1 is the output state array SO.

[0352] SEL1 = V2? SI : SO (Equation 43)

[0353] As shown in Equation 44, when the second value V2 is 0x1, the second selection array SEL2 is the output state array SO; when the second value V2 is 0x0, the second selection array SEL2 is the input state array SI. In other words, when the encryption / decryption circuit 140 executes the encryption program, the second value V2 is 0x1 and the second selection array SEL2 is the output state array SO; when the encryption / decryption circuit 140 executes the decryption program, the second value V2 is 0x0 and the second selection array SEL2 is the input state array SI.

[0354] SEL2 = V2? SO : SI (Equation 44)

[0355] According to Equations 41 to 44, Equation 4 and Equation 7 can be optimized to Equation 45.

[0356] VF2 = (SI[7:0] == CI)? (SO[7:0] == C0) : (SEL1 * AT -1 (SEL2)) == 0x1)

[0357] (Equation 45)

[0358] Comparing Equation 45 with Equation 4 and Equation 7, the encryption program and the decryption program can share the same binary field multiplier and the inverse affine transformation unit, thus saving a binary field multiplier and an inverse affine transformation unit.

[0359] Figure 5 is a schematic diagram showing the first verification unit according to an embodiment of the present application. According to an embodiment of the present application, Figure 5 the first verification unit 500 of

[0360] As Figure 5As shown, the first verification unit 500 includes a first value generator 501, a second value generator 502, a fourth comparator CMP4, a fifth comparator CMP5, a fifth multiplexer MUX4, a sixth multiplexer MUX5, an inverse affine conversion unit 503, a multiplier 504, a sixth comparator CMP6, and a seventh multiplexer MUX6.

[0361] The first value generator 501 is used to execute formula 41 to generate a first predetermined value CI, where the most significant bit to the least significant bit of the first predetermined value CI are sequentially 0x0, a first value V1, a first value V1, 0x0, 0x0, 0x0, a first value V1, and a first value V1. The second value generator 502 is used to execute formula 42 to generate a second predetermined value CO, where the most significant bit to the least significant bit of the second predetermined value CO are sequentially 0x0, a second value V2, a second value V2, 0x0, 0x0, 0x0, a second value V2, and a second value V2.

[0362] The fourth comparator CMP4 compares whether the input status array SI is equal to the first predetermined value CI and generates a fourth comparison result CM4. When the input status array SI is equal to the first predetermined value CI, the fourth comparison result CM4 is a first logic level. The fifth comparator CMP5 compares the output status array SO and the second predetermined value CO and generates a fifth comparison result CM5. When the output status array SO is equal to the second predetermined value CO, the fifth comparison result CM5 is a first logic level.

[0363] The fifth multiplexer MUX4 executes formula 43 and selects the input status array SI or the output status array SO as the first selection array SEL1 based on the second value V2. According to an embodiment of the present application, when Figure 1 the encryption and decryption circuit 140 executes the encryption program, the first selection array SEL1 is the input status array SI. According to another embodiment of the present application, when Figure 1 the encryption and decryption circuit 140 executes the decryption program, the first selection array SEL1 is the output status array SO.

[0364] The sixth multiplexer MUX5 executes formula 44 and selects the input status array SI or the output status array SO as the second selection array SEL2 based on the second value V2. According to an embodiment of the present application, when Figure 1 the encryption and decryption circuit 140 executes the encryption program, the second selection array SEL2 is the output status array SO. According to another embodiment of the present application, when Figure 1 the encryption and decryption circuit 140 executes the decryption program, the second selection array SEL2 is the input status array SI.

[0365] The inverse affine transformation unit 503 performs an inverse affine transformation (i.e., AT -1 ) on the second selection array SEL2, generating a fourth result R4. The multiplier 504 multiplies the first selection array SEL1 by the fourth result R4, generating a fifth result R5. The sixth comparator CMP6 compares the fifth result R5 with 0x1, generating a sixth comparison result CM6. When the fifth result R5 is equal to 0x1, the sixth comparison result CM6 is the first logic level.

[0366] The seventh multiplexer MUX6 outputs the fifth comparison result CM5 or the sixth comparison result CM6 as the second verification signal VF2 based on the fourth comparison result CM4. According to an embodiment of the present application, when the second verification signal VF2 is at the first logic level, it represents that Figure 1 the byte substitution / anti-byte substitution conversion performed by the byte substitution / anti-byte substitution unit 145 is correct. According to another embodiment of the present application, when the second verification signal VF2 is not at the first logic level, it represents that Figure 1 the byte substitution / anti-byte substitution conversion performed by the byte substitution / anti-byte substitution unit 145 is incorrect.

[0367] Equation 24 can detect errors in the mix column transformation performed by the mix column / inverse mix column unit 146 and the transformation performed by the round key addition unit 147. Equation 28 can detect errors in the inverse mix column transformation performed by the mix column / inverse mix column unit 146 and the transformation performed by the round key addition unit 147, where Equation 24 and Equation 28 can be optimized to Equation 46.

[0368] VF3 = (ARKXi == (ISBOXi[7:0] ⊕ RKXi)) == (ARKXi == (SBOXi[7:0] ⊕ RKXi))

[0369] == (ARKXi == (SOXi[7:0] ⊕ RKXi)), where 0 ≤ i ≤ 3

[0370] (Equation 46)

[0371] Figure 6 is a schematic diagram showing a third verification unit according to an embodiment of the present application. According to an embodiment of the present application, Figure 6 the third verification unit 600 is used to execute Equation 46 to detect whether Figure 1 the transformations performed by the mix column / inverse mix column unit 146 and the round key addition unit 147 are correct.

[0372] As Figure 6As shown, the third verification unit 600 includes a first byte division device 601, a second byte division device 602, a third byte division device 603, a first logic operation unit 604, a second logic operation unit 605, a third logic operation unit 606, a fourth logic operation unit 607, and a seventh comparator CMP7.

[0373] The first byte division device 601 divides the output status array SO (including SBO and ISBO) by bytes to generate divided output status arrays SO[7:0], SO[15:8], SO[23:16], SO[31:24]. The second byte division device 602 divides the recovery key RK by bytes to generate divided recovery keys RK[7:0], RK[15:8], RK[23:16], RK[31:24]. The third byte division device 603 divides the result data ARK by bytes to generate divided result data ARK[7:0], ARK[15:8], ARK[23:16], ARK[31:24].

[0374] The first logic operation unit 604 performs an exclusive OR operation on the divided output status arrays SO[7:0], SO[15:8], SO[23:16], SO[31:24] to generate a simplified output status array SBOXi[7:0]. The second logic operation unit 605 performs an exclusive OR operation on the divided recovery keys RK[7:0], RK[15:8], RK[23:16], RK[31:24] to generate a simplified recovery key RKXi[7:0]. The third logic operation unit 606 performs an exclusive OR operation on the divided result data ARK[7:0], ARK[15:8], ARK[23:16], ARK[31:24] to generate a simplified result data ARKXi[7:0].

[0375] The fourth logic operation unit 607 performs an exclusive OR operation on the simplified output status array SBOXi[7:0] and the simplified recovery key RKXi[7:0] to generate a sixth result R6. The seventh comparator CMP7 compares the sixth result R6 and the simplified result data ARKXi[7:0] to generate a third verification signal VF3.

[0376] Figure 7 is a block diagram showing an encryption / decryption device according to another embodiment of the present application. Figure 7 The encryption / decryption device 700 and Figure 1 Compared with the encryption / decryption device 100, the encryption / decryption device 700 further includes a second verification unit 701, a first verification unit 702, and a third verification unit 703.

[0377] According to an embodiment of the present application, the second verification unit 701 corresponds to Figure 3 the second verification unit 300, and is used to execute formula 40. When the first verification signal VF1 is at the first logic level, the controller 130 determines that the binary field multiplication by two, multiplication by four, and multiplication by eight operations performed by the mix column / inverse mix column unit 146 are correct.

[0378] According to an embodiment of the present application, the first verification unit 702 corresponds to Figure 5 the first verification unit 500, and is used to execute formula 45. When the second verification signal VF2 is at the first logic level, the controller 130 determines that the byte substitution / inverse byte substitution conversion performed by the byte substitution / inverse byte substitution unit 145 is correct.

[0379] According to an embodiment of the present application, the third verification unit 703 corresponds to Figure 6 the third verification unit 600, and is used to execute formula 46. When the third verification signal VF3 is at the first logic level, the controller 130 determines that the mix column conversion or inverse mix column conversion performed by the mix column / inverse mix column unit 146 and the conversion performed by the round key addition unit 147 are correct.

[0380] Figure 8 is a block diagram showing an encryption / decryption device according to another embodiment of the present application. Compared with the encryption / decryption device 700, the encryption / decryption device 800 further includes a dual round key addition unit 801, a dual row shift / inverse row shift unit 802, an encoder 803, a dual register 804, and a decoder 805, which are used to check whether the transmission between the register 144 and each conversion is correct.

[0381] The circuit structure of the dual round key addition unit 801 is the same as that of the round key addition unit 147, and is used to execute the operation of the round key addition unit 147 again to generate dual result data DARK. The circuit structure of the dual row shift / inverse row shift unit 802 is the same as that of the row shift / inverse row shift unit 143. Therefore, the dual row shift / inverse row shift unit 802 cyclically shifts each horizontal row in the dual result data DARK to generate dual shifted data DSR. According to some embodiments of the present application, the row shift / inverse row shift operation performed by the dual row shift / inverse row shift unit 802 is the same as the row shift / inverse row shift operation performed by the row shift / inverse row shift unit 143.

[0382] The encoder 803 performs an encoding operation on the dual-shifted data DSR to generate encoded data ENC. The dual register 804 is used to store the encoded data ENC, where the register 144 stores the shifted data SR as status data ST. The decoder 805 performs a decoding operation on the encoded data ENC stored in the dual register 804 to generate decoded data DEC. According to some embodiments of the present application, the encoding operation performed by the encoder 803 is the inverse function of the decoding operation performed by the decoder 805. According to some embodiments of the present application, the encoding operation performed by the encoder 803 can be any known or unknown encoding method.

[0383] According to some embodiments of the present application, when the operations of the row shift / inverse row shift unit 143, the register 144, and the add round key unit 147 are all correct, the decoded data DEC should be equal to the input state array SI.

[0384] Compared with Figure 7 the first verification unit 702 of Figure 8 verifies whether the byte substitution / inverse byte substitution conversion performed by the byte substitution / inverse byte substitution unit 145 is correct according to the input state array SI and the output state array SO.

[0385] According to some embodiments of the present application, it can be determined whether the conversion performed by the add round key unit 147 is correct by comparing whether the dual result data DARK and the result data ARK are consistent or whether the dual-shifted data DSR and the shifted data SR are consistent. At the same time, it can also be determined whether the shift operation performed by the row shift / inverse row shift unit 143 is correct. According to some embodiments of the present application, it can be determined whether the status data ST stored in the register 144 is correct by comparing the decoded data DEC and the status data ST stored in the register 144.

[0386] In addition, as shown in Equation 40, the second verification unit 701 performs a division-by-two operation on the multiply-by-two array MX2 to generate a multiply-by-two and divide-by-two array MX2D2, and determines whether the multiply-by-two and divide-by-two array MX2D2 is equal to the binary field multiplicand array M. In other words, when the operations of the row shift / inverse row shift unit 143, the register 144, the byte substitution / inverse byte substitution unit 145, the second multiplexer MUX1, and the round key addition unit 147 and the binary field multiply-by-two operation of the mix column / inverse mix column unit 146 are all correct, the multiply-by-two and divide-by-two array MX2D2 is equivalent to the multiplicand array M, where the multiplicand array M is equal to the output state array SO. In other words, the multiply-by-two and divide-by-two array MX2D2 can be used to replace the output state array SO.

[0387] Figure 9 is a block diagram showing an encryption / decryption device according to another embodiment of the present application. Compared with Figure 8 the encryption / decryption device 800, the first verification unit 910 of the encryption / decryption device 900 verifies whether the byte substitution transformation or the inverse byte substitution transformation performed by the byte substitution / inverse byte substitution unit 145 is correct according to the decoded data DEC and the multiply-by-two and divide-by-two array MX2D2 generated by the second verification unit 701.

[0388] Since the decoded data DEC is the input state array SI generated by another set of hardware, and the multiply-by-two and divide-by-two array MX2D2 is generated by performing a multiply-by-two operation and a division-by-two operation on the output state array SO, the second verification signal VF2 can not only determine whether the byte substitution transformation or the inverse byte substitution transformation performed by the byte substitution / inverse byte substitution unit 145 is correct, but also be used to confirm whether the transmission between the row shift / inverse row shift unit 143, the byte substitution / inverse byte substitution unit 145, the mix column / inverse mix column unit 146, and the round key addition unit 147 is correct, and at the same time confirm whether the state data ST stored in the register 144 is correct.

[0389] Figure 10 is a schematic diagram showing an encoding operation and a decoding operation according to an embodiment of the present application. As Figure 10 shown, the encoder 1010 includes a first transposition unit 1011 and a first binary field addition unit 1012, and the decoder 1020 includes a second binary field addition unit 1021 and a second transposition unit 1022, where the encoder 1010 and the decoder 1020 respectively correspond to Figures 8 - 9 the encoder 803 and the decoder 805 of

[0390] As Figure 10As shown, when the encoder 1010 receives the dual-shift data DSR, it divides the dual-shift data DSR into the first encoded data A, the second encoded data B, the third encoded data C, and the fourth encoded data D. The first transposition unit 1011 performs a transposition operation on the first encoded data A, the second encoded data B, the third encoded data C, and the fourth encoded data D, and generates the first transposed data X0, the second transposed data X1, the third transposed data X2, and the fourth transposed data X3. The first binary field addition unit 1012 includes a plurality of exclusive-OR gates for performing an exclusive-OR operation on any three of the first transposed data X0, the second transposed data X1, the third transposed data X2, and the fourth transposed data X3, and generates the encoded data ENC, where the encoded data ENC includes the first encoded data O0, the second encoded data O1, the third encoded data O2, and the fourth encoded data O3.

[0391] When the decoder 1020 receives the encoded data ENC, the second binary field addition unit 1021 performs an exclusive-OR operation on any three of the first encoded data O0, the second encoded data O1, the third encoded data O2, and the fourth encoded data O3, and generates the first exclusive-OR data Y0, the second exclusive-OR data Y1, the third exclusive-OR data Y2, and the fourth exclusive-OR data Y3. The second transposition unit 1022 performs an inverse transposition operation on the first exclusive-OR data Y0, the second exclusive-OR data Y1, the third exclusive-OR data Y2, and the fourth exclusive-OR data Y3, and generates the first decoded data A', the second decoded data B', the third decoded data C', and the fourth decoded data D', where the first decoded data A', the second decoded data B', the third decoded data C', and the fourth decoded data D' are combined into the decoded data DEC. According to some embodiments of the present application, the transposition operation performed by the first transposition unit 1011 is the inverse function of the inverse transposition operation performed by the second transposition unit 1022.

[0392] To enhance the protection of the AES redundancy-based fault attack countermeasure, Figure 10 a binary field addition coding mechanism for fault space conversion is proposed for the encoder 1010 and the decoder 1020. The fault space transformation method mainly implements different coding methods for the encryption / decryption states of the normal run and the redundant run of the redundancy mechanism. Even if an attacker can insert the same fault at the corresponding time points in the normal run and the redundant run operations into the encryption state or the decryption state, the two runs will produce very different incorrect encryption states or decryption states due to different coding methods, resulting in the fault space transformation method being able to greatly reduce the probability of fault collision.

[0393] To reduce costs, the fault space transformation method in normal rounds generally does not use any encoding. Under the limitation of the lowest security requirements, Figure 8 the encryption / decryption device 800 and Figure 9 the redundant rounds of the encryption / decryption device 900 can adopt the encoding operation and decoding operation of binary field addition, which can greatly reduce the area and latency.

[0394] Figure 11 is a flowchart showing the encryption / decryption method according to an embodiment of the present application. The following description of Figure 11 the encryption / decryption method 1100 will be paired with Figure 8 the encryption / decryption device 800 for detailed description.

[0395] First, using the row shift / inverse row shift unit 143, perform a row shift / inverse row shift operation on the result data ARK to generate the shifted data SR (step S1101), where the shifted data SR is stored in the register 144 and is the input state array SI. Then, using the byte substitution / inverse byte substitution unit 145, perform a byte substitution / inverse byte substitution conversion on the input state array SI to generate the output state array SO (step S1102).

[0396] Using the dual row shift / inverse row shift unit 802, perform a row shift / inverse row shift operation on the dual result data DARK to generate the dual shifted data DSR (also called the dual input state array) (step S1103). Encode the dual shifted data DSR (also called the dual input state array) to generate the encoded data ENC (step S1104). Decode the encoded data ENC to generate a decoded data DEC (step S1105).

[0397] Finally, according to the correspondence between the decoded data DEC and the output state array SO, determine whether the byte substitution / inverse byte substitution conversion performed by the byte substitution / inverse byte substitution unit 145 is correct (step S1106). According to some embodiments of the present application, in step S1106, the input state array SI in Formulas 43 to 45 is replaced with the decoded data DEC to generate a second verification signal VF2 to determine whether the byte substitution / inverse byte substitution conversion performed by the byte substitution / inverse byte substitution unit 145 is correct.

[0398] Figure 12 is a flowchart showing the encryption / decryption method according to an embodiment of the present application. The following description of Figure 12 the encryption / decryption method 1200 will be paired with Figure 8 the encryption / decryption device 900 for detailed description. Compared with Figure 11The encryption / decryption method 1100. Steps S1201 to S1205 of the encryption / decryption method 1200 are the same as steps S1101 to S1105 of the encryption / decryption method 1100, and will not be repeated here.

[0399] In step S1206, the output state array SO is multiplied by two using the MixColumn / InvMixColumn unit 146 to generate the multiply-by-two array MX2. Then, the multiply-by-two array MX2 is divided by two using the second verification unit 701 to generate the multiply-by-two divided-by-two array MX2D2 (step S1207). Finally, according to the correspondence between the decoded data DEC and the multiply-by-two divided-by-two array MX2D2, it is determined whether the byte substitution / InvByteSubstitution transformation performed by the byte substitution / InvByteSubstitution unit 145 is correct (step S1208).

[0400] According to some embodiments of the present application, in step S1208, the input state array SI in Formulas 43 to 45 is replaced with the decoded data DEC and the output state array SO is replaced with the multiply-by-two divided-by-two array MX2D2 to generate the second verification signal VF2, so as to determine whether the byte substitution / InvByteSubstitution transformation performed by the byte substitution / InvByteSubstitution unit 145 is correct.

[0401] The present application proposes an encryption / decryption device with a verification mechanism, which is applicable to any implementation manner of byte substitution transformation. Although there are many implementation manners of byte substitution transformation or InvByteSubstitution transformation, the verification mechanism of the encryption / decryption device of the present application can detect whether an error occurs in the operation when the input value of the multiplicative inverse is 0x0, and can detect whether an error occurs in the binary field multiplication operation in the MixColumn operation and the InvMixColumn operation. In addition, the verification mechanism proposed by the present application can also protect the decryption program to ensure the security of the encrypted or decrypted data. Furthermore, the verification mechanism proposed by the present application can also determine whether an error occurs during the data transmission process, thereby improving the security during the encryption and decryption processes.

[0402] Although the embodiments of the present application and their advantages have been disclosed as above, it should be understood that any person skilled in the art can make changes, substitutions, and modifications without departing from the spirit and scope of the present application. In addition, the protection scope of the present application is not limited to the processes, machines, manufactures, compositions of matter, devices, methods, and steps in the specific embodiments described in the specification. Any person skilled in the art can understand the processes, machines, manufactures, compositions of matter, devices, methods, and steps developed currently or in the future from the disclosure content of some embodiments of the present application. As long as they can perform substantially the same functions or obtain substantially the same results in the embodiments described herein, they can be used according to some embodiments of the present application. Therefore, the protection scope of the present application includes the above-mentioned processes, machines, manufactures, compositions of matter, devices, methods, and steps. In addition, each claim constitutes an individual embodiment, and the protection scope of the present application also includes the combination of each claim and embodiment.

Claims

1. An encryption / decryption device, characterized in that: include: A row shift / reverse shift unit performs a row shift / reverse shift operation on a result data to generate an input state array; A byte substitution / inverse byte substitution unit converts the input state array to generate an output state array; A pair of even row shift / inverse row shift units, performing the row shift / inverse row shift operation on a pair of even result data to generate a pair of even input state arrays; an encoder, encoding the dual input state array to generate a coded data; a decoder, decoding the encoded data to generate decoded data; a first verification unit, verifying the correspondence between the decoded data and the output state array, and generating a first verification signal; as well as A controller determines whether the conversion performed by the byte substitution / de-byte substitution unit is correct according to the first verification signal.

2. The encryption / decryption device according to claim 1, wherein: Also includes: a mix-row / anti-mix-row unit, which performs a mix-row / anti-mix-row operation on the output state array to generate a mix / anti-mix array, wherein the mix-row / anti-mix-row operation includes a binary field multiplication operation; and A round key addition unit performs a binary field addition operation on the mixing / demixing array and a round key to generate the result data.

3. The encryption / decryption device according to claim 2, wherein: The mixing column / demixing column unit performs a one-by-two operation on the output state array to generate a one-by-two array; The encryption / decryption device further comprises: a second verification unit, performing a one-to-two division operation on the multiplication-two array to generate a one-to-two-to-two array, and determining whether the output state array and the multiplication-two-to-two array conform to a corresponding relationship, and generating a second verification signal; wherein the controller determines whether the binary field multiplication operation performed by the mixing column / demixing column unit is correct according to the second verification signal; wherein when the binary field multiplication operation and the division by two operation are correct, the multiplication by two and division by two arrays are equal to the output state array; The first verification unit regards the multiplication and division array as the output state array, so that the first verification unit verifies the corresponding relationship between the decoded data and the multiplication and division array to generate the first verification signal.

4. The encryption / decryption device according to claim 1, wherein: The first verification unit comprises: a first value generator for generating a first predetermined value, wherein the first predetermined value is 0x0, a first value, the first value, 0x0, 0x0, 0x0, the first value, and the first value in order from the most significant bit to the least significant bit; a second value generator for generating a second predetermined value, wherein the second predetermined value is 0x0, a second value, the second value, 0x0, 0x0, 0x0, the second value, and the second value in order from the most significant bit to the least significant bit; a first comparator, comparing the decoded data and the first predetermined value to generate a first result, wherein when the decoded data is equal to the first predetermined value, the first result is a first logic level; a second comparator, comparing the output state array and the second predetermined value to generate a second result, wherein when the output state array is equal to the second predetermined value, the second result is the first logic level; a first multiplexer, selecting the decoded data or the output state array to form a first selection array; a second multiplexer, selecting the decoded data or the output state array to form a second selection array; an inverse affine transformation unit, performing an inverse affine transformation on the second selection array to generate a third result; a multiplier, multiplying the first selection array by the third result to generate a fourth result; a third comparator, comparing the fourth result and 0x1 to generate a fifth result, wherein when the fourth result is equal to 0x1, the fifth result is the first logic level; and a third multiplexer, based on the first result, outputting the second result or the fifth result as the first verification signal; When the first verification signal is at the first logic level, it indicates that the conversion is correct.

5. The encryption / decryption device according to claim 4, characterized in that: When the encryption / decryption device executes an encryption program, the first selection array is the decoded data; wherein when the encryption / decryption device executes a decryption procedure, the first selection array is the output state array; wherein when the encryption / decryption device executes the encryption program, the second selection array is the output state array; wherein when the encryption / decryption device executes the decryption program, the second selection array is the decoded data; The second value is the inverse of the first value.

6. The encryption / decryption device according to claim 3, characterized in that: When the mix column / unmix column unit performs the binary field multiplication operation on a multiplicand array to multiply the multiplicand array by two, the multiplicand array is shifted left by one bit to generate a left-shifted array; wherein a most significant bit of the multiplicand array replicates a first bit number to generate a first value, wherein the number of bits of the multiplicand array is the first bit number minus 1; A first predetermined value is subjected to an AND operation with the first value to generate a second value; The left shift array and the second value perform an exclusive OR operation to generate a one-by-two array.

7. The encryption / decryption device according to claim 3, characterized in that: The second verification unit comprises: a first divide-by-two circuit for performing the divide-by-two operation on the one-by-two array to generate the multiply-by-two divide-by-two array; a second divide-by-two circuit for performing the divide-by-two operation on the one-by-four array to generate a one-by-four divided by two array; a third divide-by-two circuit for performing the divide-by-two operation on the one-by-eight array to generate a one-by-eight divide-by-two array; a first comparator, comparing the multiplicand array and the multiplication and division array to generate a first result, wherein when the multiplicand array and the multiplication and division array are equal, the first result is a first logic level; a second comparator, comparing the multiply-by-two array and the multiply-by-four-divide-by-two array to generate a second result, wherein when the multiply-by-two array is equal to the multiply-by-four-divide-by-two array, the second result is the first logic level; a third comparator, comparing the multiply-by-four array and the multiply-by-eight-divide-by-two array to generate a third result, wherein when the multiply-by-four array is equal to the multiply-by-eight-divide-by-two array, the third result is the first logic level; and a logic gate, wherein when the first result, the second result, and the third result are all at the first logic level, the logic gate outputs the second verification signal at the first logic level; The controller determines whether the binary field multiplication operation performed by the mix column / anti-mix column unit is correct based on the second verification signal at the first logic level.

8. The encryption / decryption device according to claim 1, wherein: Also includes: a pair of dual round key addition units, performing a binary field addition operation on the mixing / demixing array and a round key to generate the dual result data; wherein when the result data is equal to the dual result data, the controller determines that the binary field addition operation performed by the round key addition unit is correct; When the input state array is equal to the dual input state array, the controller determines that the row shift / reverse row shift operation performed by the row shift / reverse row shift unit is correct.

9. An encryption / decryption method, characterized in that: include: Perform a row shift / reverse row shift operation on a result data to generate an input state array; Performing a byte substitution / inverse byte substitution conversion on the input state array to generate an output state array; Using a pair of even row shift / inverse row shift units, a pair of even result data is subjected to the row shift / inverse row shift operation to generate a pair of even input state arrays; Encoding the dual input state array to generate a coded data; Decoding the encoded data to generate decoded data; and Whether the byte substitution / de-byte substitution conversion is correct is determined according to the correspondence between the decoded data and the output state array.

10. An encryption / decryption method, characterized in that: include: Perform a row shift / reverse row shift operation on a result data to generate an input state array; Performing a byte substitution / inverse byte substitution conversion on the input state array to generate an output state array; Using a pair of even row shift / inverse row shift units, a pair of even result data is subjected to the row shift / inverse row shift operation to generate a pair of even input state arrays; Encoding the dual input state array to generate a coded data; Decoding the encoded data to generate decoded data; Performing a one-by-two operation on the output state array to generate a one-by-two array; Performing a one-to-two division operation on the multiplied-by-two array to generate a one-to-two-to-two division-by-two array; and Whether the byte substitution / inverse byte substitution conversion is correct is determined according to the correspondence between the decoded data and the multiplication-by-two and division-by-two arrays.