Encryption and decryption method, SM4 algorithm accelerator and BMC chip

By using pipelined key expansion and encryption calculations in the SM4 algorithm accelerator, and introducing multiple sub-S boxes to the S box for nonlinear transformation, the problems of low throughput and poor power-resistant attack effects in the prior art are solved, and efficient encryption and decryption operations and powerful attack resistance are achieved.

CN120238285APending Publication Date: 2025-07-01SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510115839.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-24
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In the encryption and decryption method based on the SM4 algorithm, the throughput is low and the power-resistant attack effect is poor, and key parts such as the S box in the SM4 algorithm are not optimized.

Method used

In the encryption and decryption module of the SM4 algorithm accelerator, the key expansion and encryption calculation are performed using pipelines, and power-resistant attack processing is performed in some pipelines. The S box includes a plurality of sub-S box, each sub-S box corresponds to at least two nonlinear transformations, and the power consumption is random to improve the effect of resisting power consumption attacks.

Benefits of technology

The throughput of the encryption and decryption method based on the SM4 algorithm accelerator is improved, and the effect of resisting power consumption attacks and encryption and decryption security is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238285A_ABST
    Figure CN120238285A_ABST
Patent Text Reader

Abstract

The invention provides an encryption and decryption method, an SM4 algorithm accelerator and a BMC chip, and relates to the technical field of computers. The method is applied to a target SM4 algorithm accelerator, and comprises the following steps: randomly selecting at least one stage of target assembly line from multiple stages of assembly lines corresponding to an encryption and decryption module of the target SM4 algorithm accelerator; performing XOR operation on the round key corresponding to the target assembly line and at least one piece of data in target input corresponding to the target assembly line to obtain a first processing result; performing nonlinear transformation on the first processing result based on an S box in the target assembly line to obtain a second processing result; performing linear transformation on the second processing result to obtain a third processing result; performing XOR operation on the third processing result and data except at least one piece of data in the target input to obtain a fourth processing result; and obtaining target output corresponding to the target pipeline based on the fourth processing result and the at least one piece of data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and in particular, to an encryption and decryption method, an SM4 algorithm accelerator, and a BMC chip. Background Art

[0002] The SM4 algorithm belongs to the symmetric encryption algorithm in the national cryptographic algorithms, and is a block cipher algorithm based on a round function structure. Encryption and decryption operations are implemented by repeatedly executing the same round function structure. When performing data encryption and decryption based on the SM4 algorithm, there is a risk of being attacked. Among various attack methods, the power consumption attack is the easiest to implement and poses the greatest threat. In a power consumption attack, an attacker records the power consumption changes of a cryptographic system device to determine the characteristics that can be used to break the cryptographic system and retrieve the key, which poses a great security risk to the data encryption and decryption process.

[0003] In order to achieve resistance to power consumption attacks, the prior art proposes adding a true random number generator on the basis of an SM4 algorithm accelerator without protective measures. A random state is set in the state machine inside each round, and this random state is controlled by a random signal generated by the true random number generator. Whenever the state machine selects this random state, the normal round transformation will be paused, and a random plaintext and a random key will be selected for encryption operations, that is, pseudo-operations. After adding the random pseudo-operations, when the SM4 algorithm accelerator should perform specific round transformations and round key expansions, other round transformations and round key expansions are randomly executed. Thus, the SM4 algorithm accelerator randomizes both the round function and the key expansion, resulting in a random time for the generation of intermediate values, obscuring the power consumption trajectory at fixed times, and making it impossible for an attacker to infer the key based on the power consumption curve, thereby achieving the purpose of resisting power consumption attacks.

[0004] However, in the above prior art encryption and decryption method based on the SM4 algorithm accelerator, the key expansion and encryption calculations are respectively implemented through iterative calculations, resulting in a low throughput. In addition, the above prior art achieves resistance to power consumption attacks by selecting random plaintexts and random keys for encryption operations, without optimizing key components such as the S-box in the SM4 algorithm, resulting in poor effects of resisting power consumption attacks and low encryption and decryption security. Summary of the Invention

[0005] The present disclosure provides an encryption and decryption method, an SM4 algorithm accelerator, and a BMC chip to at least solve the above technical problems existing in the prior art.

[0006] According to a first aspect of the present disclosure, a method for encryption and decryption is provided, which is applied to a target SM4 algorithm accelerator. The method includes: randomly selecting at least one target pipeline in a multi-stage pipeline corresponding to an encryption and decryption module of the target SM4 algorithm accelerator; performing an exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; performing a non-linear transformation on the first processing result based on an S-box in the target pipeline to obtain a second processing result; the S-box includes a plurality of sub S-boxes, and the plurality of sub S-boxes correspond to at least two non-linear transformations; performing a linear transformation on the second processing result to obtain a third processing result; performing an exclusive OR operation on the third processing result and the data in the target input other than the at least one data to obtain a fourth processing result; obtaining a target output corresponding to the target pipeline based on the fourth processing result and the at least one data.

[0007] In an implementable manner, before performing the exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result, the method further includes: generating a first random number based on a first random number generator array in the target SM4 algorithm accelerator; generating the round key by using the first random number based on a key expansion module in the target SM4 algorithm accelerator; and sending the round key to the encryption and decryption module.

[0008] In an implementable manner, the performing a non-linear transformation on the first processing result based on the S-box in the target pipeline to obtain a second processing result includes: splitting the first processing result to obtain a plurality of first sub-processing results, the number of the first sub-processing results being the same as the number of the sub S-boxes; generating a second random number based on a second random number generator array in the target SM4 algorithm accelerator; determining a target sub S-box based on the second random number; the non-linear transformation corresponding to the target sub S-box being different from the non-linear transformations corresponding to other sub S-boxes; and performing a non-linear transformation on the plurality of first sub-processing results based on the target sub S-box and the other sub S-boxes to obtain the second processing result.

[0009] In an implementable embodiment, the non-linear transformation of a plurality of the first sub-processing results based on the target sub-S box and the other sub-S boxes to obtain the second processing result includes: performing a first non-linear transformation on one of the first sub-processing results based on the target sub-S box to obtain one of the second sub-processing results; the first non-linear transformation is performed based on a composite domain; performing a second non-linear transformation on the other first sub-processing results based on the other sub-S boxes to obtain the other second sub-processing results; the second non-linear transformation is performed based on a look-up table; and splicing all the second sub-processing results to obtain the second processing result.

[0010] In an implementable embodiment, the second random number generator array includes a first random number generator, a second random number generator, and a third random number generator; at least one of the first random number generator, the second random number generator, and the third random number generator is in an enabled state; correspondingly, the random selection of at least one level of target pipeline includes: generating a third random number based on the first random number generator; and selecting at least one level of target pipeline from the multiple levels of pipelines corresponding to the encryption and decryption module based on the third random number.

[0011] In an implementable embodiment, the generation of the second random number based on the second random number generator array in the target SM4 algorithm accelerator includes: generating the second random number based on the second random number generator.

[0012] In an implementable embodiment, an encryption and decryption method further includes: generating a fourth random number based on the third random number generator; and in response to the fourth random number indicating that the target pipeline is in a random state, encrypting and decrypting the fourth random number to obtain an encryption result.

[0013] In an implementable embodiment, before the random selection of at least one level of target pipeline, the method further includes: receiving a target encryption and decryption sub-task, which is allocated by a BMC chip to the target SM4 algorithm accelerator; inputting the data to be encrypted and decrypted in the target encryption and decryption sub-task into the first level of the pipeline of the encryption and decryption module, and outputting the encryption and decryption result corresponding to the data to be encrypted and decrypted based on the last level of the pipeline of the encryption and decryption module.

[0014] In one implementable embodiment, the BMC chip includes at least one SM4 algorithm accelerator. The BMC chip allocates the target encryption / decryption subtask to the target SM4 algorithm accelerator based on the following method: receiving an encryption / decryption task, and splitting the encryption / decryption task into at least one encryption / decryption subtask; the at least one encryption / decryption subtask includes the target encryption / decryption subtask; based on at least one of the task attributes of the at least one encryption / decryption subtask, the pipeline stages of the at least one SM4 algorithm accelerator, the working state of the at least one SM4 algorithm accelerator, and the functional modules corresponding to the at least one SM4 algorithm accelerator, allocating the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator.

[0015] In one implementable embodiment, allocating the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator includes at least one of the following: allocating the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of the at least one encryption / decryption subtask and the functional modules corresponding to the at least one SM4 algorithm accelerator; allocating the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of the at least one encryption / decryption subtask and the working state of the at least one SM4 algorithm accelerator; allocating the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of the at least one encryption / decryption subtask and the pipeline stages of the at least one SM4 algorithm accelerator.

[0016] In one implementable embodiment, an encryption / decryption method further includes: saving the encryption / decryption result corresponding to the data to be encrypted / decrypted to the storage module of the BMC chip.

[0017] In one implementable embodiment, performing a linear transformation on the second processing result to obtain a third processing result includes: performing a cyclic left shift and an exclusive OR operation on the second processing result to obtain the third processing result.

[0018] According to a second aspect of the present disclosure, there is provided an SM4 algorithm accelerator, which includes: an encryption / decryption module for encrypting and decrypting data to be encrypted / decrypted to obtain an encryption / decryption result corresponding to the data to be encrypted / decrypted; a key expansion module for generating round keys required for the encryption / decryption module to perform encryption and decryption; a first random number generator array for generating a first random number required for the encryption / decryption module to perform encryption and decryption, and the first random number is used to generate the round keys; a second random number generator array for generating a second random number, a third random number, and a fourth random number required for the encryption / decryption module to perform encryption and decryption, the second random number is used to determine a target sub-S box in the encryption / decryption module, the third random number is used to select at least one target pipeline in a multi-stage pipeline corresponding to the encryption / decryption module, and the fourth random number is used to determine a random plaintext; and a random number generator control module for controlling the states of the random number generators in the first random number generator array and the second random number generator array.

[0019] In an implementable embodiment, the encryption / decryption module is further configured to: randomly select at least one target pipeline in a multi-stage pipeline corresponding to the encryption / decryption module of the SM4 algorithm accelerator; perform an exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; perform a non-linear transformation on the first processing result based on the S box in the target pipeline to obtain a second processing result; the S box includes a plurality of sub-S boxes, and the plurality of sub-S boxes correspond to at least two non-linear transformations; perform a linear transformation on the second processing result to obtain a third processing result; perform an exclusive OR operation on the third processing result and the data in the target input other than the at least one data to obtain a fourth processing result; and obtain a target output corresponding to the target pipeline based on the fourth processing result and the at least one data.

[0020] In an implementable embodiment, the key expansion module is further configured to: generate the round keys based on the first random number generated by the first random number generator array; and send the round keys to the encryption / decryption module.

[0021] In an implementable embodiment, the encryption / decryption module is further configured to: split the first processing result to obtain a plurality of first sub-processing results, and the number of the first sub-processing results is the same as the number of the sub-S boxes; generate a second random number based on the second random number generator array in the SM4 algorithm accelerator; determine a target sub-S box based on the second random number; the non-linear transformation corresponding to the target sub-S box is different from the non-linear transformations corresponding to other sub-S boxes; and perform non-linear transformations on the plurality of first sub-processing results based on the target sub-S box and the other sub-S boxes to obtain the second processing result.

[0022] In an implementable embodiment, the encryption and decryption module is further configured to: based on the target sub-S box, perform a first non-linear transformation on one of the first sub-processing results to obtain one of the second sub-processing results; the first non-linear transformation is performed based on a composite domain; based on the other sub-S boxes, perform a second non-linear transformation on the other first sub-processing results to obtain the other second sub-processing results; the second non-linear transformation is performed based on a look-up table; concatenate all the second sub-processing results to obtain the second processing result.

[0023] In an implementable embodiment, the second random number generator array includes a first random number generator, a second random number generator, and a third random number generator; at least one of the first random number generator, the second random number generator, and the third random number generator is in an on state; the encryption and decryption module is further configured to: based on the third random number, select at least one target pipeline in the multi-stage pipeline corresponding to the encryption and decryption module.

[0024] In an implementable embodiment, the encryption and decryption module is further configured to: in response to the fourth random number indicating that the target pipeline is in a random state, perform encryption and decryption on the fourth random number to obtain an encryption result.

[0025] According to a third aspect of the present disclosure, there is provided a BMC chip, including: a bus, a processor, a storage module, and a plurality of functional modules, at least one of the functional modules being an encryption and decryption module; the processor, the storage module, and at least one functional module are connected to the bus; the functional module includes a corresponding target SM4 algorithm accelerator; the target SM4 algorithm accelerator is at least configured to: randomly select at least one target pipeline in the multi-stage pipeline corresponding to the encryption and decryption module of the target SM4 algorithm accelerator; perform an exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; based on the S box in the target pipeline, perform a non-linear transformation on the first processing result to obtain a second processing result; the S box includes a plurality of sub-S boxes, and the plurality of sub-S boxes correspond to at least two non-linear transformations; perform a linear transformation on the second processing result to obtain a third processing result; perform an exclusive OR operation on the third processing result and the data in the target input other than the at least one data to obtain a fourth processing result; based on the fourth processing result and the at least one data, obtain the target output corresponding to the target pipeline.

[0026] According to a fourth aspect of the present disclosure, there is provided an electronic device, including: the BMC chip described in the present disclosure.

[0027] A decryption and encryption method, an SM4 algorithm accelerator, and a BMC chip according to the present disclosure. The SM4 algorithm accelerator for performing the decryption and encryption method performs key expansion and encryption calculations in a pipelined manner. Moreover, during the decryption and encryption process, only some of the pipelines are processed against power consumption attacks, improving the throughput of the decryption and encryption method based on the SM4 algorithm accelerator. In addition, the S-box of the SM4 algorithm accelerator of the present disclosure includes multiple sub-S-boxes, and the multiple sub-S-boxes correspond to at least two non-linear transformations. Since the power consumption of each non-linear transformation is different and the data corresponding to the multiple sub-S-boxes during each calculation is random, the power consumption is random, thereby improving the effect of resisting power consumption attacks and the decryption and encryption security.

[0028] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] By referring to the drawings and reading the detailed description below, the above and other objects, features, and advantages of the exemplary embodiments of the present disclosure will become easily understandable. In the drawings, several embodiments of the present disclosure are shown in an exemplary rather than restrictive manner, where:

[0030] In the drawings, the same or corresponding reference numerals represent the same or corresponding parts.

[0031] Figure 1 The flowchart of a decryption and encryption method according to an embodiment of the present disclosure is shown Figure 1 ;

[0032] Figure 2 The flowchart of a decryption and encryption method according to an embodiment of the present disclosure is shown Figure 2 ;

[0033] Figure 3 The flowchart of a decryption and encryption method according to an embodiment of the present disclosure is shown Figure 3 ;

[0034] Figure 4 The scenario diagram of a decryption and encryption method according to an embodiment of the present disclosure is shown Figure 1 ;

[0035] Figure 5 The scenario diagram of a decryption and encryption method according to an embodiment of the present disclosure is shown Figure 2 ;

[0036] Figure 6 The scenario diagram of the SM4 algorithm in the prior art is shown Figure 1 ; wherein,

[0037] Figure 6Figure (a) in [the reference] shows the flow chart of the SM4 algorithm in the prior art;

[0038] Figure 6 Figure (b) in [the reference] shows the schematic diagram of the T transformation of the round function of the SM4 algorithm in the prior art;

[0039] Figure 7 shows the schematic scenario of the SM4 algorithm in the prior art Figure 2 ; where

[0040] Figure 7 Figure (a) in [the reference] shows the schematic diagram of the key expansion of the SM4 algorithm in the prior art;

[0041] Figure 7 Figure (b) in [the reference] shows the schematic diagram of the round function of the key expansion of the SM4 algorithm in the prior art;

[0042] Figure 8 shows the schematic diagram of the anti-power consumption attack SM4 algorithm accelerator in the prior art;

[0043] Figure 9 shows the schematic diagram of the structure of an SM4 algorithm accelerator according to an embodiment of the present disclosure;

[0044] Figure 10 shows the schematic diagram of the structure of a BMC chip according to an embodiment of the present disclosure. Detailed implementation manners

[0045] To make the objectives, features, and advantages of the present disclosure more obvious and understandable, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present disclosure.

[0046] For the convenience of understanding the present disclosure, the following terms related to the present disclosure are explained:

[0047] 1. SM4 algorithm: The SM4 algorithm belongs to the symmetric encryption algorithm in the national cryptographic algorithms and is a block cipher algorithm based on the round function structure. The encryption and decryption operations are realized by repeatedly executing the same round function structure. Figure 6 shows the schematic scenario of the SM4 algorithm in the prior art Figure 1 ; where Figure 6 Figure (a) in [the reference] shows the flow chart of the SM4 algorithm in the prior art; Figure 6 Figure (b) in [the reference] shows the schematic diagram of the T transformation of the round function of the SM4 algorithm in the prior art, as Figure 6As shown in Figure (a) therein, the SM4 algorithm uses a 128-bit key and block size. Assuming the input 128-bit plaintext is (X0, X1, X2, X3), where X0, X1, X2, and X3 are all 32-bit data, also known as words. After the first round of operations, the 5th word X4 = F(X0, X1, X2, X3, rk0) is generated, where rk0 is the round key for the first round of encryption. Continuing with the second round of operations, the 6th word X5 = F(X1, X2, X3, X4, rk1) is obtained, and so on, for a total of 32 rounds. Eventually, 36 words are obtained. The last four words (X32, X33, X34, X35) obtained in the last round are sorted in reverse order to obtain the output ciphertext (Y0, Y1, Y2, Y3); as Figure 6 As shown in Figure (b) therein, the T transformation of the SM4 algorithm round function consists of a non-linear transformation τ and a linear transformation L. The non-linear transformation τ consists of 4 parallel S-boxes, and the linear transformation includes cyclic shift and XOR calculations. Figure 7 shows a schematic diagram of the scenario of the SM4 algorithm in the prior art Figure 2 ; among them, Figure 7 Figure (a) therein shows a schematic diagram of the key expansion of the SM4 algorithm in the prior art; Figure 7 Figure (b) therein shows a schematic diagram of the round function of the key expansion of the SM4 algorithm in the prior art, as Figure 7 As shown in Figure (a) therein, the key expansion of the SM4 algorithm generates round keys for 32 rounds for encryption or decryption. The round function of the key expansion and the round function in the encryption process have the same structure, both including the non-linear transformation τ and the linear transformation L.

[0048] 2. BMC (Baseboard Management Controller) chip: The BMC chip is an important management chip in the server, responsible for functions such as hardware monitoring of the server (the BMC chip can monitor various hardware parameters of the server, including voltage, temperature, fan speed, power status, etc.), fault management (the BMC chip can detect and record faults occurring in the server), and remote control (the BMC chip allows administrators to remotely control the server, including power on, power off, restart, etc.). The encryption and decryption module of the BMC chip is an important security component. It can protect the data communicated between the BMC and other devices (such as server management data, firmware update data), protect the sensitive data stored in the BMC (such as passwords, certificates), and provide a secure boot function for the BMC. The encryption and decryption module of the BMC chip usually supports multiple encryption algorithms, including symmetric encryption algorithms, asymmetric encryption algorithms, cryptographic hash algorithms, etc.

[0049] 3. Power Consumption Attack: A power consumption attack exploits the strong correlation between the power consumption information of a device and the data processed by the logic units in the circuit. In a power consumption attack, the attacker records the power consumption changes of a cryptographic system device to identify characteristics that can be used to break the cryptographic system and retrieve the key. Common power consumption attack methods include Simple Power Analysis (SPA), Differential Power Analysis (DPA), etc.

[0050] 4. Resistance to Differential Power Analysis: There are two categories of ideas for defenses against DPA. The first category of ideas is to remove the data dependence of the power consumption information and equalize the power consumption information, such as constant power consumption technology. The second category of ideas is to mask the power consumption information, randomize the power consumption information, add noise, etc., making it difficult for the attacker to distinguish and utilize, such as masking technology.

[0051] 5. SM4 Algorithm Accelerator Against Power Consumption Attacks in the Prior Art: Figure 8 The schematic diagram of an SM4 algorithm accelerator against power consumption attacks in the prior art is shown. As Figure 8 shown, a DPA-resistant SM4 algorithm accelerator based on a true random number generator is provided in the prior art. On the basis of an SM4 algorithm accelerator without protection measures, a true random number generator is added. A random state is set in each round of the internal state machine. This random state is controlled by a random signal generated by the random number generator. Whenever the state machine selects this random state, the normal round transformation will be paused, and random plaintext and random keys will be selected for encryption operations, that is, pseudo-operations. After adding random pseudo-operations, when the SM4 algorithm accelerator should perform specific round transformations and round key expansions, other round transformations and round key expansions are randomly executed. Thus, the SM4 algorithm accelerator randomizes both the round function and the key expansion, resulting in the moment when the intermediate value is generated not being fixed, obscuring the power consumption trajectory at a fixed moment, making it impossible for the attacker to infer the key based on the differential power consumption curve, thereby achieving the purpose of resisting DPA.

[0052] Figure 1 The flowchart of an encryption and decryption method according to an embodiment of the present disclosure is shown Figure 1 as Figure 1 shown. An encryption and decryption method is applied to a target SM4 algorithm accelerator. The method includes:

[0053] Step S101, randomly select at least one target pipeline in the multi-stage pipeline corresponding to the encryption and decryption module of the target SM4 algorithm accelerator.

[0054] In this embodiment, the target SM4 algorithm accelerator has at least an encryption / decryption module. The encryption / decryption module performs encryption and decryption in a pipelined manner. First, at least one target pipeline needs to be randomly selected from the multi-stage pipelines corresponding to the encryption / decryption module of the target SM4 algorithm accelerator.

[0055] Figure 4 Fig. shows a schematic scenario of an encryption / decryption method according to an embodiment of the present disclosure Figure 1 , as Figure 4 shown, there are 32 levels of round function pipelines in total in the encryption / decryption module. In the encryption scenario, the plaintext is input into the 1st level of pipeline, and after 32 levels of pipelines, the ciphertext corresponding to the plaintext is output. One of the 32 levels of pipelines can be determined as the target pipeline. For example, the 3rd level of pipeline is determined as the target pipeline. It should be emphasized that the target pipeline can be unique or not unique.

[0056] Step S102: Perform an exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result.

[0057] In this embodiment, each level of pipeline corresponding to the encryption / decryption module has a corresponding round key. As Figure 4 shown, the 1st level of pipeline corresponds to round key 1, the 2nd level of pipeline corresponds to round key 2, the 3rd level of pipeline corresponds to round key 3, and so on; each level of pipeline has a corresponding target input, and the target input includes multiple data. For the target pipeline, it is necessary to perform an exclusive OR operation on the round key corresponding to the target pipeline and some of the data in the target input corresponding to the target pipeline to obtain a first processing result.

[0058] Figure 5 Fig. shows a schematic scenario of an encryption / decryption method according to an embodiment of the present disclosure Figure 2 , the process of data processing for each level of pipeline is as Figure 5 shown, where X i , X i+1 , X i+2 , X i+3 are the inputs of the round function corresponding to this level of pipeline, rk i is the round key corresponding to this level of pipeline. The exclusive OR operation can be performed on X i+1 , X i+2 , X i+3 and the round key rk i to obtain a first processing result A, that is where is the exclusive OR calculation.

[0059] Step S103: Based on the S-box in the target pipeline, perform a non-linear transformation on the first processing result to obtain a second processing result.

[0060] In this embodiment, the S-box includes a plurality of sub S-boxes. The plurality of sub S-boxes correspond to at least two non-linear transformations. Based on the S-box in the target pipeline, a non-linear transformation can be performed on the first processing result to obtain a second processing result. In an implementable manner, the first processing result can be split into a plurality of sub-processing results, and the plurality of sub-processing results are sent to different sub S-boxes for non-linear transformation. The plurality of sub-processing results correspond to at least two non-linear transformations, and the power consumption corresponding to each non-linear transformation is different.

[0061] As Figure 5 shown, the S-box includes 4 sub S-boxes, namely S-box 1, S-box 2, S-box 3, and S-box 4. The 4 sub S-boxes correspond to at least two non-linear transformations. For example, S-box 1 corresponds to a non-linear transformation based on a lookup table, and S-box 2, S-box 3, and S-box 4 correspond to non-linear transformations based on a composite domain. The first processing result can be split into 4 sub-processing results and sent to the 4 sub S-boxes respectively, and the results output by the 4 sub S-boxes are spliced to obtain the second processing result B.

[0062] Step S104: Perform a linear transformation on the second processing result to obtain a third processing result.

[0063] In this embodiment, the linear transformation includes a cyclic left shift and an exclusive OR operation. That is, a cyclic left shift and an exclusive OR operation need to be performed on the second processing result to obtain a third processing result. As Figure 5 shown, the formula for performing a linear transformation on the second processing result B to obtain a third processing result C is: wherein, <<< is a cyclic left shift.

[0064] Step S105: Perform an exclusive OR operation on the third processing result and the data in the target input except for at least one piece of data to obtain a fourth processing result.

[0065] In this embodiment, it is also necessary to perform an exclusive OR operation on the third processing result and the data in the target input except for at least one piece of data to obtain a fourth processing result. As Figure 5 shown, if at least one piece of data is X i+1 , X i+2 , X i+3 , then the data except for at least one piece of data is X i . The third processing result C can be exclusive ORed with X i to obtain a fourth processing result X i+4 .

[0066] Step S106: Based on the fourth processing result and at least one piece of data, obtain the target output corresponding to the target pipeline.

[0067] In this embodiment, it is also necessary to splice the fourth processing result and at least one piece of data to obtain the target output corresponding to the target pipeline. As Figure 5 shown, if at least one piece of data is X i+1 、X i+2 、X i+3 , and the fourth processing result is X i+4 , then the target output corresponding to the target pipeline is (X i+1 、X i+2 、X i+3 、X i+4 ).

[0068] In the present disclosure, the target SM4 algorithm accelerator performs key expansion and encryption calculations in a pipeline manner. Moreover, during the encryption and decryption processes, only some of the pipelines are processed against power consumption attacks, which improves the throughput of the encryption and decryption method based on the target SM4 algorithm accelerator. Furthermore, the S-box of the target SM4 algorithm accelerator in the present disclosure includes multiple sub S-boxes, and the multiple sub S-boxes correspond to at least two non-linear transformations. Since the power consumption of each non-linear transformation is different, and the data corresponding to the calculation of the multiple sub S-boxes each time is random, the power consumption is random, thereby being able to improve the effect of resisting power consumption attacks and the security of encryption and decryption.

[0069] In another embodiment, before step S102 "perform an exclusive OR operation on the round key corresponding to the target pipeline and at least one piece of data in the target input corresponding to the target pipeline to obtain a first processing result", the method further includes:

[0070] Generate a first random number based on the first random number generator array in the target SM4 algorithm accelerator; generate a round key using the first random number based on the key expansion module in the target SM4 algorithm accelerator; and send the round key to the encryption and decryption module.

[0071] In this embodiment, the target SM4 algorithm accelerator further includes a first random number generator array and a key expansion module. The key expansion module is used to generate the round key corresponding to each stage of the pipeline in the encryption and decryption module. A first random number can be generated based on the first random number generator array, and then a round key can be generated using the first random number based on the key expansion module and sent to the encryption and decryption module. Among them, the first random number generator array may include a true random number generator and / or a pseudo-random number generator.

[0072] Figure 2 shows the flowchart of an encryption and decryption method according to an embodiment of the present disclosure Figure 2 , as Figure 2 shown, step S103 "perform a non-linear transformation on the first processing result based on the S-box in the target pipeline to obtain a second processing result" includes:

[0073] Step S201: Split the first processing result to obtain multiple first sub - processing results.

[0074] In this embodiment, the number of first sub - processing results is the same as the number of sub - S - boxes. As Figure 5 shown, if the first processing result A is 32 - bit and there are 4 sub - S - boxes in the S - box, then the first processing result A can be split into 4 first sub - processing results, and each first sub - processing result is 8 - bit.

[0075] Step S202: Generate a second random number based on the second random number generator array in the target SM4 algorithm accelerator.

[0076] Step S203: Determine the target sub - S - box based on the second random number.

[0077] In this embodiment, the target SM4 algorithm accelerator also includes a second random number generator array. The second random number generator array may include multiple true random number generators and / or pseudo - random number generators. A second random number can be generated based on the second random number generator array, and then the target sub - S - box is determined based on the second random number. The non - linear transformation corresponding to the target sub - S - box is different from the non - linear transformations corresponding to other sub - S - boxes.

[0078] As Figure 5 shown, the random number generator connected to the S - box can be one of the random number generators in the second random number generator array. The random number generator generates a second random number, and the corresponding target sub - S - box can be determined based on the second random number. If the target sub - S - box is S - box 4, then the non - linear transformation corresponding to S - box 4 is different from the non - linear transformations corresponding to S - box 1, S - box 2, and S - box 3.

[0079] Step S204: Perform non - linear transformations on the multiple first sub - processing results based on the target sub - S - box and other sub - S - boxes to obtain a second processing result.

[0080] In this embodiment, different non - linear transformations can be performed on the multiple first sub - processing results based on the target sub - S - box and other sub - S - boxes to obtain a second processing result.

[0081] In this embodiment, a first non - linear transformation can be performed on one of the first sub - processing results based on the target sub - S - box to obtain one of the second sub - processing results. The first non - linear transformation is based on a composite domain transformation. And a second non - linear transformation is performed on the other first sub - processing results based on other sub - S - boxes to obtain the other second sub - processing results. The second non - linear transformation is based on a lookup table transformation. Then all the second sub - processing results are concatenated to obtain the second processing result.

[0082] As Figure 5As shown, if it is determined that S-box 4 is the target sub S-box based on the second random number, then it is determined that the non-linear transformation corresponding to S-box 4 is a non-linear transformation based on a composite field, and the non-linear transformations corresponding to S-box 1, S-box 2, and S-box 3 are non-linear transformations based on a look-up table. Among them, the look-up table of the S-box is usually a storage structure of a fixed size, which directly maps the input value to the output value; the composite field calculation of the S-box usually maps the elements on GF(2 8 ) to GF((2 4 )) through an isomorphic mapping matrix, and then performs an inverse calculation on GF((2 2 )) 4 ), and then maps the result of the inverse calculation through the inverse matrix of the isomorphic mapping matrix to obtain the calculation result. 2

[0083] In the present disclosure, multiple sub S-boxes correspond to at least two non-linear transformations. Since the power consumption of each non-linear transformation is different, and the data corresponding to the calculation of multiple sub S-boxes each time is random, the power consumption is random, thereby being able to improve the effect of anti-power consumption attacks and the security of encryption and decryption.

[0084] In another embodiment, the second random number generator array includes a first random number generator, a second random number generator, and a third random number generator; at least one of the first random number generator, the second random number generator, and the third random number generator is in an on state;

[0085] Correspondingly, "randomly select at least one level of target pipeline" in step S101 includes:

[0086] Generate a third random number based on the first random number generator; select at least one level of target pipeline from the multiple levels of pipelines corresponding to the encryption and decryption module based on the third random number.

[0087] ​In this embodiment, the second random number generator array of the target SM4 algorithm accelerator includes three random number generators, namely the first random number generator, the second random number generator, and the third random number generator. Each random number generator generates random numbers for different purposes. Among them, the first random number generator is used to generate a third random number, and based on the third random number, at least one target pipeline can be randomly selected in the multi-stage pipeline corresponding to the encryption and decryption module; the second random number generator is used to generate a second random number, and the target sub-S box can be determined based on the second random number; the third random number generator is used to generate a fourth random number, and the fourth random number can determine whether the pipeline is in a random state. At least one of the first random number generator, the second random number generator, and the third random number generator is in an enabled state. For example, when only the first random number generator is in an enabled state, the target pipeline has randomness, while the target sub-S box is fixed and the pipeline does not distinguish whether it is random; when the first random number generator and the second random number generator are in an enabled state, the target pipeline and the target sub-S box have randomness, while the pipeline does not distinguish whether it is random. The enabled states of the random number generators in the second random number generator array can be arbitrarily arranged and combined.

[0088] In this embodiment, the fourth random number can characterize whether the target pipeline is in a random state. If the fourth random number characterizes that the target pipeline is in a random state, the fourth random number is encrypted and decrypted to obtain an encryption result. That is, whenever the pipeline enters a random state determined by the random number generator, the normal round transformation is paused, and a random plaintext and a random key are selected for an encryption operation, that is, a pseudo-operation. This pseudo-operation does not affect the final output result because it is only used to confuse the power consumption mode and other side-channel characteristics. After completing the pseudo-operation, the pipeline will resume to the normal processing path and continue to process the original data, so as to achieve a better anti-power consumption attack effect.

[0089] In another embodiment, before "randomly selecting at least one target pipeline" in step S101, an encryption and decryption method further includes:

[0090] Receiving a target encryption and decryption subtask, where the target encryption and decryption subtask is assigned by the BMC chip to the target SM4 algorithm accelerator; inputting the data to be encrypted and decrypted in the target encryption and decryption subtask into the first stage of the pipeline of the encryption and decryption module, and outputting the encryption and decryption result corresponding to the data to be encrypted and decrypted based on the output of the last stage of the pipeline of the encryption and decryption module.

[0091] In this embodiment, before randomly selecting at least one level of target pipeline, the target SM4 algorithm accelerator also needs to receive the target encryption / decryption subtask allocated by the BMC chip. The target encryption / decryption subtask includes the data to be encrypted / decrypted. The data to be encrypted / decrypted can be input into the first-level pipeline of the encryption / decryption module, and the encryption / decryption result corresponding to the data to be encrypted / decrypted is output based on the last-level pipeline of the encryption / decryption module. As Figure 4 shown, the plaintext is the data to be encrypted. The data to be encrypted is input into the 1-level pipeline of the encryption / decryption module, and then the ciphertext output by the last-level pipeline (32-level pipeline) of the encryption / decryption module is determined as the encryption result corresponding to the data to be encrypted.

[0092] In an implementable manner, the BMC chip includes a storage module. After the encryption / decryption module obtains the encryption / decryption result corresponding to the data to be encrypted / decrypted, the encryption / decryption result can be saved to the storage module of the BMC chip.

[0093] Figure 3 shows the flowchart of an encryption / decryption method according to an embodiment of the present disclosure Figure 3 As Figure 3 shown, the BMC chip includes at least one SM4 algorithm accelerator. The BMC chip allocates the target encryption / decryption subtask to the target SM4 algorithm accelerator based on the following method:

[0094] Step S301: Receive the encryption / decryption task.

[0095] Step S302: Split the encryption / decryption task into at least one encryption / decryption subtask.

[0096] In this embodiment, the encryption / decryption task can be a task of encrypting unencrypted data such as text, image, or video, or a task of decrypting encrypted data. Based on the attributes of the encryption / decryption task, etc., the encryption / decryption task can be split into at least one encryption / decryption subtask, and at least one of the encryption / decryption subtasks includes the target encryption / decryption subtask. For example, if the encryption / decryption task is the encryption / decryption of video data, the task of encrypting / decrypting the video frame can be used as the first encryption subtask, the task of encrypting / decrypting the video subtitle can be used as the second encryption subtask, and the task of encrypting / decrypting the video audio can be used as the third encryption subtask.

[0097] Step S303: Allocate at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on at least one of the task attributes of at least one encryption / decryption subtask, the number of pipeline levels of at least one SM4 algorithm accelerator, the working state of at least one SM4 algorithm accelerator, and the functional modules corresponding to at least one SM4 algorithm accelerator.

[0098] In this embodiment, the task attributes of the encryption / decryption subtasks are the types and contents of the data to be encrypted included in the encryption / decryption subtasks. The types are such as text, audio, and video, etc., and the contents are such as media data, operation logs, etc. The working states of the SM4 algorithm accelerators can include the working state and the idle state. The function modules corresponding to at least one SM4 algorithm accelerator can include a video module, an encryption / decryption module, a fault management module, and other function modules. At least one encryption / decryption subtask is allocated to the corresponding target SM4 algorithm accelerator based on the task attributes of at least one encryption / decryption subtask, the pipeline stages, the working state, and the corresponding function modules of the SM4 algorithm accelerator.

[0099] In another embodiment, "allocating at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator" in step S303 includes at least one of the following:

[0100] Allocating at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of at least one encryption / decryption subtask and the function modules corresponding to at least one SM4 algorithm accelerator. For example, if the type of the data to be encrypted shown in the task attributes of the encryption / decryption subtask is video, then the encryption / decryption subtask is allocated to the SM4 algorithm accelerator in the video module.

[0101] Allocating at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of at least one encryption / decryption subtask and the working state of at least one SM4 algorithm accelerator. For example, if the content of the data to be encrypted shown in the task attributes of the encryption / decryption subtask is the subtitle of a video, then the encryption / decryption subtask is allocated to the SM4 algorithm accelerator in the idle state to perform auxiliary calculations for video data encryption.

[0102] Allocating at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of at least one encryption / decryption subtask and the pipeline stages of at least one SM4 algorithm accelerator. For example, if the content of the data to be encrypted shown in the task attributes of the encryption / decryption subtask is the video picture, then the encryption / decryption subtask is allocated to the SM4 algorithm accelerator with the pipeline stages greater than a certain threshold. The SM4 algorithm accelerator with more pipeline stages has a greater throughput.

[0103] It should be emphasized that at least one encryption / decryption subtask can also be allocated to the corresponding target SM4 algorithm accelerator based on other combinations of the task attributes of at least one encryption / decryption subtask, the pipeline stages, the working state, and the corresponding function modules of the SM4 algorithm accelerator.

[0104] In this embodiment, the pipeline stage number of the SM4 algorithm accelerator can be determined according to its specific module in the BMC chip. For example, the SM4 algorithm accelerator in the encryption / decryption module is used for data encryption / decryption in various application scenarios of the BMC chip, and has high throughput requirements; the SM4 algorithm accelerator in the video module is used for encryption / decryption of video data, and has relatively high throughput requirements; the SM4 algorithm accelerator in the fault management module is used for encryption / decryption of server fault data, and has low throughput requirements. Therefore, the encryption / decryption calculation module and the key expansion module of the SM4 algorithm accelerator in the encryption / decryption module and the video module have 32 pipeline stages; the encryption / decryption calculation module and the key expansion module of the SM4 algorithm accelerator in the fault management module have fewer 8 pipeline stages. In addition, the pipeline stage numbers of the encryption / decryption calculation module and the key expansion module can also be different.

[0105] When processing the encryption / decryption subtask, the processor configures multiple SM4 algorithm accelerators in the BMC chip according to the computing power requirements of the encryption / decryption subtask, and preferentially uses the SM4 algorithm accelerator in the functional module corresponding to the computing task. For example, when encrypting video data, the SM4 algorithm accelerator in the video module is preferentially used; then the SM4 algorithm accelerators in other modules in the idle state are used for auxiliary calculation to improve the overall computing power. For example, if the SM4 algorithm accelerator in the encryption / decryption module is used for other task calculations and the SM4 algorithm accelerator in the fault management module is in the idle state, the SM4 algorithm accelerator in the fault management module is configured for auxiliary calculation of video data encryption. If there is no SM4 algorithm accelerator in the functional module corresponding to the encryption / decryption subtask, the SM4 algorithm accelerator in the encryption / decryption module is preferentially used for calculation, and then the idle SM4 algorithm accelerators in other modules are used for auxiliary calculation.

[0106] In the present disclosure, the BMC chip can allocate the encryption / decryption subtask to the corresponding SM4 algorithm accelerator based on at least one of the task attributes of the at least one encryption / decryption subtask, the pipeline stage number, the working state of the SM4 algorithm accelerator, and the corresponding functional module, improving the flexibility of the allocation of the encryption / decryption subtask and being applicable to various scenarios.

[0107] Figure 9 FIG. shows a schematic structural diagram of an SM4 algorithm accelerator according to an embodiment of the present disclosure, as Figure 9 shown, an SM4 algorithm accelerator 100 includes:

[0108] The encryption / decryption module 13 is used to encrypt and decrypt the data to be encrypted / decrypted, and obtain the encryption / decryption result corresponding to the data to be encrypted / decrypted; the key expansion module 14 is used to generate the round keys required for the encryption / decryption module to perform encryption and decryption; the first random number generator array 11 is used to generate the first random number required for the encryption / decryption module to perform encryption and decryption, and the first random number is used to generate the round keys; the second random number generator array 12 is used to generate the second random number, the third random number and the fourth random number required for the encryption / decryption module to perform encryption and decryption. The second random number is used to determine the target sub-S box in the encryption / decryption module, the third random number is used to select at least one target pipeline in the multi-stage pipeline corresponding to the encryption / decryption module, and the fourth random number is used to determine the random plaintext; the random number generator control module 10 is used to control the states of the random number generators in the first random number generator array and the second random number generator array.

[0109] In an implementable manner, the encryption / decryption module 13 is further used to: randomly select at least one target pipeline in the multi-stage pipeline corresponding to the encryption / decryption module of the SM4 algorithm accelerator; perform an exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; perform a non-linear transformation on the first processing result based on the S box in the target pipeline to obtain a second processing result; the S box includes multiple sub-S boxes, and the multiple sub-S boxes correspond to at least two non-linear transformations; perform a linear transformation on the second processing result to obtain a third processing result; perform an exclusive OR operation on the third processing result and the data other than at least one data in the target input to obtain a fourth processing result; based on the fourth processing result and at least one data, obtain the target output corresponding to the target pipeline.

[0110] In an implementable manner, the key expansion module 14 is further used to: generate round keys based on the first random number generated by the first random number generator array; send the round keys to the encryption / decryption module.

[0111] In an implementable manner, the encryption / decryption module 13 is further used to: split the first processing result to obtain multiple first sub-processing results, and the number of the first sub-processing results is the same as the number of the sub-S boxes; generate a second random number based on the second random number generator array in the SM4 algorithm accelerator; determine the target sub-S box based on the second random number; the non-linear transformation corresponding to the target sub-S box is different from the non-linear transformations corresponding to other sub-S boxes; perform non-linear transformations on the multiple first sub-processing results based on the target sub-S box and other sub-S boxes to obtain a second processing result.

[0112] In one implementable embodiment, the encryption and decryption module 13 is further configured to: perform a first non-linear transformation on one of the first sub-processing results based on a target sub S-box to obtain one of the second sub-processing results; the first non-linear transformation is performed based on a composite domain; perform a second non-linear transformation on the other first sub-processing results based on other sub S-boxes to obtain the other second sub-processing results; the second non-linear transformation is performed based on a look-up table; splice all the second sub-processing results to obtain a second processing result.

[0113] In one implementable embodiment, the second random number generator array 12 includes a first random number generator, a second random number generator, and a third random number generator; at least one of the first random number generator, the second random number generator, and the third random number generator is in an enabled state; the encryption and decryption module 13 is further configured to: select at least one target pipeline in the multi-stage pipeline corresponding to the encryption and decryption module based on the third random number.

[0114] In one implementable embodiment, the encryption and decryption module 13 is further configured to:

[0115] In response to the fourth random number indicating that the target pipeline is in a random state, encrypt and decrypt the fourth random number to obtain an encryption result.

[0116] In one implementable embodiment, the encryption and decryption module 13 is further configured to: receive a target encryption and decryption sub-task, where the target encryption and decryption sub-task is assigned by the BMC chip to the target SM4 algorithm accelerator; input the data to be encrypted and decrypted in the target encryption and decryption sub-task into the first stage of the pipeline of the encryption and decryption module, and output the encryption and decryption result corresponding to the data to be encrypted and decrypted based on the last stage of the pipeline of the encryption and decryption module.

[0117] In one implementable embodiment, the encryption and decryption module 13 is further configured to: save the encryption and decryption result corresponding to the data to be encrypted and decrypted to the storage module of the BMC chip.

[0118] In one implementable embodiment, the encryption and decryption module 13 is further configured to: perform a circular left shift and an exclusive OR operation on the second processing result to obtain a third processing result.

[0119] Figure 10 FIG. shows a schematic structural diagram of a BMC chip according to an embodiment of the present disclosure, as Figure 10 shown, a BMC chip 200 includes:

[0120] A bus 20, a processor 21, a storage module 22, and a plurality of functional modules, at least one functional module being an encryption and decryption module 23, and the functional modules may further include a video module 24, a fault management module 25, and other functional modules 26; the processor 21, the storage module 22, and at least one functional module are connected to the bus 20;

[0121] The functional module includes corresponding target SM4 algorithm accelerators, and all the target SM4 algorithm accelerators can be the same or different; the target SM4 algorithm accelerator can execute an encryption and decryption method in the present disclosure;

[0122] The target SM4 algorithm accelerator is at least used for: randomly selecting at least one target pipeline in the multi-stage pipeline corresponding to the encryption and decryption module of the target SM4 algorithm accelerator; performing an exclusive OR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; performing a non-linear transformation on the first processing result based on the S box in the target pipeline to obtain a second processing result; the S box includes a plurality of sub-S boxes, and the plurality of sub-S boxes correspond to at least two non-linear transformations; performing a linear transformation on the second processing result to obtain a third processing result; performing an exclusive OR operation on the third processing result and the data other than at least one data in the target input to obtain a fourth processing result; obtaining the target output corresponding to the target pipeline based on the fourth processing result and at least one data.

[0123] In an implementable manner, the processor 21 is the control and computing core module of the BMC chip, the processor is an Arm processor or a RISC-V processor, and the processor 21 can be a single-core processor or a multi-core processor. The storage module 22 is used for data storage of the BMC chip, including SRAM, DDR SDRAM, ROM, FLASH, etc. The encryption and decryption module 23 is used to implement the calculation of various encryption and decryption algorithms, such as the AES algorithm, the ECC algorithm, and the SHA algorithm. The video module 24 is used to obtain the original video data of the server, compress it and send it to the remote end through the network. The fault management module 25 is used to implement the detection, diagnosis, and recording of server faults by the BMC chip. The other functional module 26 includes a clock module, a power module, a hardware monitoring module, etc., and is used to implement functions such as hardware monitoring and remote control of the BMC chip. The processor 21, the storage module 22, the encryption and decryption module 23, the video module 24, the fault management module 25, and the other functional module 26 are connected through the bus 20, including the AXI bus, the AHB bus, the APB bus, etc.

[0124] In an implementable manner, the BMC chip contains 3 SM4 algorithm accelerators, which are respectively located in the encryption and decryption module 23, the video module 24, and the fault management module 25. The 3 SM4 algorithm accelerators can be exactly the same or have different structures according to the different functional modules they are in.

[0125] In one implementable manner, the processor 21 is at least configured to: receive an encryption / decryption task, and split the encryption / decryption task into at least one encryption / decryption subtask; at least one of the encryption / decryption subtasks includes a target encryption / decryption subtask; based on at least one of the task attributes of the at least one encryption / decryption subtask, the pipeline stages of the at least one SM4 algorithm accelerator, the working states of the at least one SM4 algorithm accelerator, and the function modules corresponding to the at least one SM4 algorithm accelerator, allocate the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator.

[0126] In one implementable manner, the processor 21 is at least configured to perform at least one of the following: allocate the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of the at least one encryption / decryption subtask and the function modules corresponding to the at least one SM4 algorithm accelerator; allocate the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of the at least one encryption / decryption subtask and the working states of the at least one SM4 algorithm accelerator; allocate the at least one encryption / decryption subtask to the corresponding target SM4 algorithm accelerator based on the task attributes of the at least one encryption / decryption subtask and the pipeline stages of the at least one SM4 algorithm accelerator.

[0127] The present disclosure also provides an electronic device, which includes the BMC chip of the present disclosure.

[0128] It should be understood that the various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps described in the present disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved. No limitation is made herein.

[0129] In addition, the terms "first" and "second" are only used for descriptive purposes, and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of the present disclosure, "a plurality" means two or more, unless otherwise specifically defined.

[0130] The above are only the specific implementation manners of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present disclosure can easily think of changes or substitutions, which should all be covered within the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.

Claims

1. An encryption and decryption method, characterized in that: Applied to a target SM4 algorithm accelerator, the method comprises: Randomly select at least one target pipeline from the multi-stage pipelines corresponding to the encryption and decryption modules of the target SM4 algorithm accelerator; Performing an XOR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; Based on the S-box in the target pipeline, performing a nonlinear transformation on the first processing result to obtain a second processing result; the S-box includes a plurality of sub-S-boxes, and the plurality of sub-S-boxes correspond to at least two nonlinear transformations; Performing a linear transformation on the second processing result to obtain a third processing result; Performing an XOR operation on the third processing result and the data in the target input except the at least one data to obtain a fourth processing result; Based on the fourth processing result and the at least one data, a target output corresponding to the target pipeline is obtained.

2. The method according to claim 1, characterized in that Before performing an XOR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain the first processing result, the method further includes: Generate a first random number based on a first random number generator array in the target SM4 algorithm accelerator; Generate the round key using the first random number based on the key expansion module in the target SM4 algorithm accelerator; The round key is sent to the encryption and decryption module.

3. The method according to claim 1, characterized in that The step of performing a nonlinear transformation on the first processing result based on the S-box in the target pipeline to obtain a second processing result includes: Splitting the first processing result to obtain a plurality of first sub-processing results, wherein the number of the first sub-processing results is the same as the number of the sub-S boxes; Generate a second random number based on a second random number generator array in the target SM4 algorithm accelerator; Determine a target sub-S-box based on the second random number; the nonlinear transformation corresponding to the target sub-S-box is different from the nonlinear transformations corresponding to other sub-S-boxes; Based on the target sub-S-box and the other sub-S-boxes, a plurality of the first sub-processing results are nonlinearly transformed to obtain the second processing results.

4. The method according to claim 3, characterized in that The performing nonlinear transformation on the plurality of the first sub-processing results based on the target sub-S-box and the other sub-S-boxes to obtain the second processing result includes: Based on the target sub-S-box, a first nonlinear transformation is performed on one of the first sub-processing results to obtain one of the second sub-processing results; the first nonlinear transformation is performed based on a composite domain; Based on the other sub-S-boxes, performing a second nonlinear transformation on the other first sub-processing results to obtain other second sub-processing results; the second nonlinear transformation is performed based on a lookup table; All second sub-processing results are concatenated to obtain the second processing result.

5. The method according to claim 3, characterized in that: The second random number generator array includes a first random number generator, a second random number generator and a third random number generator; at least one of the first random number generator, the second random number generator and the third random number generator is in an on state; Accordingly, the randomly selecting at least one target pipeline includes: Based on the first random number generator, generate a third random number; Based on the third random number, at least one target pipeline is selected from the multi-stage pipelines corresponding to the encryption and decryption module.

6. The method according to claim 5, wherein generating a second random number based on a second random number generator array in the target SM4 algorithm accelerator comprises: Based on the second random number generator, the second random number is generated.

7. The method according to claim 5, further comprising: Based on the third random number generator, generate a fourth random number; In response to the fourth random number indicating that the target pipeline is in a random state, the fourth random number is encrypted and decrypted to obtain an encryption result.

8. The method according to claim 1, before randomly selecting at least one target pipeline, the method further comprises: Receive a target encryption and decryption subtask, where the target encryption and decryption subtask is assigned by the BMC chip to the target SM4 algorithm accelerator; The data to be encrypted and decrypted in the target encryption and decryption subtask is input into the first-stage pipeline of the encryption and decryption module, and the encryption and decryption result corresponding to the data to be encrypted and decrypted is output based on the last-stage pipeline of the encryption and decryption module.

9. The method according to claim 8, wherein the BMC chip includes at least one SM4 algorithm accelerator, and the BMC chip allocates the target encryption and decryption subtask to the target SM4 algorithm accelerator based on the following method: Receiving an encryption and decryption task, and splitting the encryption and decryption task into at least one encryption and decryption subtask; At least one encryption and decryption subtask includes the target encryption and decryption subtask; Based on the task attributes of at least one of the encryption and decryption subtasks, the pipeline level of at least one of the SM4 algorithm accelerators, the working status of at least one of the SM4 algorithm accelerators, and at least one of the functional modules corresponding to at least one of the SM4 algorithm accelerators, at least one encryption and decryption subtask is assigned to the corresponding target SM4 algorithm accelerator.

10. The method according to claim 9, wherein allocating at least one encryption and decryption subtask to a corresponding target SM4 algorithm accelerator comprises at least one of the following: Based on the task attributes of at least one of the encryption and decryption subtasks and the functional module corresponding to at least one of the SM4 algorithm accelerators, allocating at least one encryption and decryption subtask to a corresponding target SM4 algorithm accelerator; Based on the task attribute of at least one of the encryption and decryption subtasks and the working state of at least one of the SM4 algorithm accelerators, allocating at least one encryption and decryption subtask to a corresponding target SM4 algorithm accelerator; Based on the task attributes of at least one of the encryption and decryption subtasks and the pipeline level of at least one of the SM4 algorithm accelerators, at least one encryption and decryption subtask is allocated to the corresponding target SM4 algorithm accelerator.

11. The method according to claim 8, further comprising: The encryption and decryption results corresponding to the data to be encrypted and decrypted are stored in the storage module of the BMC chip.

12. The method according to claim 1, wherein performing a linear transformation on the second processing result to obtain a third processing result comprises: Perform a circular left shift and an XOR operation on the second processing result to obtain the third processing result.

13. An SM4 algorithm accelerator, characterized in that: The SM4 algorithm accelerator includes: An encryption and decryption module, used to encrypt and decrypt the data to be encrypted and decrypted, and obtain the encryption and decryption results corresponding to the data to be encrypted and decrypted; A key expansion module, used to generate round keys required by the encryption and decryption module for encryption and decryption; A first random number generator array, used to generate a first random number required by the encryption and decryption module for encryption and decryption, wherein the first random number is used to generate the round key; A second random number generator array is used to generate a second random number, a third random number and a fourth random number required for the encryption and decryption module to perform encryption and decryption, wherein the second random number is used to determine a target sub-S-box in the encryption and decryption module, the third random number is used to select at least one target pipeline from the multi-stage pipelines corresponding to the encryption and decryption module, and the fourth random number is used to determine a random plaintext; A random number generator control module is used to control the states of the random number generators in the first random number generator array and the second random number generator array.

14. The SM4 algorithm accelerator according to claim 13, characterized in that: The encryption and decryption module is also used for: Randomly select at least one target pipeline from the multi-stage pipelines corresponding to the encryption and decryption modules of the SM4 algorithm accelerator; Performing an XOR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; Based on the S-box in the target pipeline, performing a nonlinear transformation on the first processing result to obtain a second processing result; the S-box includes a plurality of sub-S-boxes, and the plurality of sub-S-boxes correspond to at least two nonlinear transformations; Performing a linear transformation on the second processing result to obtain a third processing result; Performing an XOR operation on the third processing result and the data in the target input except the at least one data to obtain a fourth processing result; Based on the fourth processing result and the at least one data, a target output corresponding to the target pipeline is obtained.

15. The SM4 algorithm accelerator according to claim 13, characterized in that: The key expansion module is further used for: generating the round key based on the first random number generated by the first random number generator array; The round key is sent to the encryption and decryption module.

16. The SM4 algorithm accelerator according to claim 13, characterized in that: The encryption and decryption module is also used for: Splitting the first processing result to obtain a plurality of first sub-processing results, wherein the number of the first sub-processing results is the same as the number of the sub-S boxes; Generate a second random number based on a second random number generator array in the SM4 algorithm accelerator; Determine a target sub-S-box based on the second random number; the nonlinear transformation corresponding to the target sub-S-box is different from the nonlinear transformations corresponding to other sub-S-boxes; Based on the target sub-S-box and the other sub-S-boxes, a plurality of the first sub-processing results are nonlinearly transformed to obtain the second processing results.

17. The SM4 algorithm accelerator according to claim 13, characterized in that: The encryption and decryption module is also used for: Based on the target sub-S-box, a first nonlinear transformation is performed on one of the first sub-processing results to obtain one of the second sub-processing results; the first nonlinear transformation is performed based on a composite domain; Based on the other sub-S-boxes, performing a second nonlinear transformation on the other first sub-processing results to obtain other second sub-processing results; the second nonlinear transformation is performed based on a lookup table; All second sub-processing results are concatenated to obtain the second processing result.

18. The SM4 algorithm accelerator according to claim 13, characterized in that: The second random number generator array includes a first random number generator, a second random number generator and a third random number generator; at least one of the first random number generator, the second random number generator and the third random number generator is in an on state; The encryption and decryption module is also used for: Based on the third random number, at least one target pipeline is selected from the multi-stage pipelines corresponding to the encryption and decryption module.

19. The SM4 algorithm accelerator according to claim 13, characterized in that: The encryption and decryption module is also used for: In response to the fourth random number indicating that the target pipeline is in a random state, the fourth random number is encrypted and decrypted to obtain an encryption result.

20. A BMC chip, characterized in that: The BMC chip includes: A bus, a processor, a storage module and a plurality of functional modules, at least one of which is an encryption and decryption module; the processor, the storage module and the at least one functional module are connected to the bus; The functional module includes a corresponding target SM4 algorithm accelerator; The target SM4 algorithm accelerator is at least used for: Randomly select at least one target pipeline from the multi-stage pipelines corresponding to the encryption and decryption modules of the target SM4 algorithm accelerator; Performing an XOR operation on the round key corresponding to the target pipeline and at least one data in the target input corresponding to the target pipeline to obtain a first processing result; Based on the S-box in the target pipeline, performing a nonlinear transformation on the first processing result to obtain a second processing result; the S-box includes a plurality of sub-S-boxes, and the plurality of sub-S-boxes correspond to at least two nonlinear transformations; Performing a linear transformation on the second processing result to obtain a third processing result; Performing an XOR operation on the third processing result and the data in the target input except the at least one data to obtain a fourth processing result; Based on the fourth processing result and the at least one data, a target output corresponding to the target pipeline is obtained.