Coprocessor and computer equipment

By designing a coprocessor that supports multiple encryption algorithms and working modes, the problem that the existing technology cannot support multiple algorithms and modes at the same time is solved, and efficient encryption computing is achieved.

CN120263392APending Publication Date: 2025-07-04CHONGQING XINLIANXIN INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510395728.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing symmetric encryption hardware implementation method cannot support multiple encryption algorithms and multiple working modes at the same time, resulting in the inability to meet diverse performance needs.

Method used

A coprocessor is designed, including an instruction decoding module, a key expansion module and a wheel function calculation module. Through multiple computing units and selection units, it can support a variety of symmetric encryption algorithms and encryption calculations in working modes, including AES and SM4 packet cipher algorithms.

Benefits of technology

It realizes the support of multiple symmetric encryption algorithms and multiple working modes of encryption computing in the case of hardware resource saving, meeting performance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263392A_ABST
    Figure CN120263392A_ABST
Patent Text Reader

Abstract

A coprocessor and computer equipment are applied to symmetric encryption calculation, and the coprocessor comprises an instruction decoding module, a key expansion module and a round function calculation module. The instruction decoding module is used for receiving an instruction sent by the central processing unit and decoding the instruction; the key expansion module comprises a first linear transformation unit, a nonlinear transformation unit and a second linear transformation unit which are connected in sequence, and is used for executing round key calculation operation; the signal provided by the encryption type register represents the type of the symmetric encryption calculation; the round function calculation module comprises a plurality of calculation units, and each calculation unit comprises a plurality of sub-calculation units; and in round function calculation of each round, each calculation unit is used for selecting the sub-calculation units with the required number corresponding to the encryption type according to the signal provided by the encryption type register to perform encryption calculation on the message words participating in the current round so as to obtain the ciphertext of the current round.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of processors, and particularly to a coprocessor and a computer device. Background Art

[0002] Symmetric encryption is an encryption algorithm that uses the same key for both encryption and decryption, and is suitable for scenarios that require fast encryption and decryption and high encryption strength, such as data storage, network communication, etc.

[0003] Some existing hardware implementations of symmetric encryption are designed in a fully pipelined manner for high-speed computing, or the key expansion module, encryption module, and decryption module are combined for low cost. These hardware implementation methods are only applicable to specific symmetric encryption algorithms and specific working modes, and cannot implement encryption calculations for multiple encryption algorithms and multiple working modes.

[0004] Therefore, there is an urgent need for a coprocessor that can support multiple symmetric encryption algorithms, multiple working modes, and meet performance requirements. Summary of the Invention

[0005] This application provides a coprocessor that can support multiple symmetric encryption algorithms, multiple working modes, and meet performance requirements.

[0006] In a first aspect, this application provides a coprocessor for symmetric encryption calculations. The coprocessor includes an instruction decoding module, a key expansion module, and a round function calculation module;

[0007] The instruction decoding module is configured to receive instructions sent by a central processing unit and perform decoding operations on the instructions;

[0008] The key expansion module includes a first linear transformation unit, a non-linear transformation unit, and a second linear transformation unit connected in sequence; in each round of key expansion calculation, the first linear transformation unit is configured to perform a first linear transformation operation of the corresponding encryption type on the key word participating in the current round of key expansion calculation according to the signal provided by the encryption type register; the non-linear transformation unit is configured to perform a non-linear transformation operation on the result of the first linear transformation operation; the second linear transformation unit is configured to perform a second linear transformation operation of the corresponding encryption type on the result of the non-linear transformation operation according to the signal provided by the encryption type register to obtain the expanded key for the current round; the signal provided by the encryption type register represents the type of the symmetric encryption calculation;

[0009] The round function calculation module includes multiple calculation units, and each calculation unit includes multiple sub-calculation units; in each round of round function calculation, each calculation unit is used to select the number of sub-calculation units required for the corresponding encryption type according to the signal provided by the encryption type register, and perform encryption calculation on the message words participating in the current round to obtain the ciphertext of the current round.

[0010] In a possible design, the instruction decoding module includes an instruction decoder and a microprogram memory;

[0011] When the instruction decoding module performs decoding operation on an instruction, it is specifically used for:

[0012] If the instruction is a macro-instruction, call the micro-instruction stream corresponding to the macro-instruction from the microprogram memory, and the instruction decoder performs decoding operation on the micro-instruction stream;

[0013] If the instruction is a micro-instruction, the instruction decoder directly performs decoding operation on the micro-instruction; the micro-instruction is a basic operation instruction.

[0014] In a possible design, the macro-instruction has an instruction characterizing the working mode of the symmetric encryption application; the coprocessor further includes a data download module, a conditional branch module, and a logic calculation module;

[0015] The data download module, the key expansion module, the round function calculation module, the conditional branch module, and the logic calculation module are used to perform calculations corresponding to the specified working mode according to the instructions and the order of the instructions in the decoding result of the micro-instruction stream corresponding to the macro-instruction.

[0016] In a possible design, the first linear transformation unit includes a first cyclic shift unit, a first exclusive OR unit, and a first data selection unit;

[0017] When the first signal provided by the encryption type register indicates that the type of symmetric encryption is the Advanced Encryption Standard AES, the first cyclic shift unit is used to perform a first cyclic shift operation on the key word K participating in the key expansion calculation of the current round i-1 Execute the first cyclic shift operation;

[0018] The first data selection unit is used to input the result of the first cyclic shift operation to the non-linear transformation unit according to the first signal provided by the encryption type register;

[0019] When the second signal provided by the encryption type register indicates that the type of symmetric encryption is the SM4 block cipher algorithm, the first exclusive OR unit is used to perform an exclusive OR operation on the key words K i-3 、K i-2 、K i-1Perform a first exclusive OR operation with the corresponding first key calculation parameter;

[0020] The first data selection unit is further configured to input the result of performing the first exclusive OR operation to the non-linear transformation unit according to the second signal provided by the encryption type register.

[0021] In a possible design, the non-linear transformation unit includes a first SBOX substitution unit;

[0022] The first SBOX substitution unit is configured to perform a first SBOX substitution operation on the result of performing the first circular shift operation or the result of performing the first exclusive OR operation, and input the result of performing the first SBOX substitution operation to the second linear transformation unit.

[0023] In a possible design, the second linear transformation unit includes a second circular shift unit, a second exclusive OR unit, and a second data selection unit;

[0024] When the type of symmetric encryption is the Advanced Encryption Standard AES, the second data selection unit is configured to input the key word K i-Nk and the corresponding second key calculation parameter to the second exclusive OR unit; where Nk is the number of key words included in the key;

[0025] The second exclusive OR unit is configured to perform a second exclusive OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter to obtain the expanded key word K i ;

[0026] When the type of symmetric encryption is the SM4 block cipher algorithm, the second circular shift unit is configured to perform a second circular shift operation on the result of the first SBOX substitution operation;

[0027] The second data selection unit is configured to input the key word K i-4 and the result of the second circular shift operation to the second exclusive OR unit according to the second signal provided by the encryption type register;

[0028] The second exclusive OR unit is further configured to perform a third exclusive OR operation on the key word K i-4 the result of the first SBOX substitution operation and the result of the second circular shift operation to obtain the expanded key word Ki.

[0029] In a possible design, the multiple computing units of the round function computing module include a second SBOX substitution unit, a third cyclic shift unit, a column transformation unit, a third XOR unit, and a fourth XOR unit; each computing unit includes four sub-computing units; the round function computing module further includes multiple data selection units;

[0030] When the type of symmetric encryption is the Advanced Encryption Standard AES, the third data selection unit is used to input the message words X i 、X i+1 、X i+2 、X i+3 participating in the round function calculation of the current round to the four sub-computing units of the second SBOX substitution unit;

[0031] The four sub-computing units of the second SBOX substitution unit are used to perform a third SBOX substitution operation on the message words X i 、X i+1 、X i+2 、X i+3 ;

[0032] The fourth data selection unit is used to input the result of the third SBOX substitution operation to the four sub-computing units of the third cyclic shift unit according to the first selection signal;

[0033] The four sub-computing units of the third cyclic shift unit are used to perform a third cyclic shift operation on the result of the third SBOX substitution operation;

[0034] The four sub-computing units of the column transformation unit and the four sub-computing units of the third XOR unit are used to perform a column transformation operation on the result of the third cyclic shift operation;

[0035] The fifth data selection unit is used to input the extended key block participating in the round function calculation of the current round to the four sub-computing units of the fourth XOR unit; the extended key block includes 4 extended key words;

[0036] The four sub-computing units of the fourth XOR unit are used to perform a fourth XOR operation on the result of the column transformation operation and the extended key block to obtain the ciphertext of the current round.

[0037] In a possible design, the round function computing module further includes a fifth XOR unit;

[0038] When the type of symmetric encryption is the SM4 block cipher algorithm, the fifth XOR unit is used to perform an XOR operation on the message words X i+1 、X i+2 、X i+3 and the extended key word K participating in the round function calculation of the current roundi Perform the fifth XOR operation;

[0039] The third data selection unit is configured to input the result of the fifth XOR operation into a sub-computation unit of the second SBOX substitution unit according to the second selection signal;

[0040] A sub-computation unit of the second SBOX substitution unit is configured to perform a fourth SBOX substitution operation on the result of the fifth XOR operation;

[0041] The fourth data selection unit is configured to input the result of the fourth SBOX substitution operation into four sub-computation units of the third circular shift unit according to the second selection signal;

[0042] The four sub-computation units of the third circular shift unit are configured to perform a fourth circular shift operation based on words on the result of the fourth SBOX substitution operation;

[0043] The fifth data selection unit is configured to input the result of the fourth circular shift operation into a sub-computation unit of the fourth XOR unit according to the second selection signal;

[0044] A sub-computation unit of the fourth XOR unit is configured to perform a sixth XOR operation on the result of the fourth circular shift operation, and input the execution result of the sixth XOR operation into a sub-computation unit of the fifth XOR unit;

[0045] The sixth data selection unit is configured to input the result of the fourth SBOX substitution operation and the message word X i into a sub-computation unit of the fifth XOR unit;

[0046] A sub-computation unit of the fifth XOR unit is configured to perform a seventh XOR operation on the result of the fourth SBOX substitution operation, the result of the sixth XOR operation, and the message word X i to obtain the ciphertext X i+4 .

[0047] In a possible design, the key expansion module further includes a first counter for counting the number of rounds of key expansion calculation;

[0048] When the value in the first counter is divisible by Nk, the first circular shift unit performs a first circular shift operation on the key word K i-1 participating in the key expansion calculation of the current round; Nk is the number of key words included in the key;

[0049] When the value in the first counter is other values, the first circular shift unit does not process the key word K i-1 .

[0050] In a possible design, the key expansion module further includes a first counter for counting the number of rounds of key expansion calculation;

[0051] When the value in the first counter is divisible by Nk, or when Nk is greater than 6 and the remainder of the value in the first counter divided by Nk is 4, the first SBOX substitution unit performs a first SBOX substitution operation on the result of the first circular shift operation;

[0052] When the value in the first counter is in other cases, the first SBOX substitution unit does not process the key word K i-1 and directly inputs the key word K i-1 to the second exclusive OR unit.

[0053] In a possible design, the key expansion module further includes a first counter for counting the number of rounds of key expansion calculation;

[0054] When the value in the first counter is divisible by Nk, the second data selection unit inputs the key word K i-Nk and the corresponding second key calculation parameter to the second exclusive OR unit according to the first signal provided by the encryption type register;

[0055] When the value in the first counter is not divisible by Nk, the second data selection unit inputs the key word K i-Nk to the second exclusive OR unit according to the first signal provided by the encryption type register;

[0056] The second exclusive OR unit is used to perform a second exclusive OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter, including:

[0057] When the value in the first counter is divisible by Nk, the second exclusive OR unit performs a second exclusive OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter;

[0058] When Nk is greater than 6 and the remainder of the value in the first counter divided by Nk is 4, the second exclusive OR unit performs a second exclusive OR operation on the result of the first SBOX substitution operation and the key word K i-Nk ;

[0059] When the value in the first counter is in other cases, the second exclusive OR unit performs a second exclusive OR operation on the key word K i-1 and the key word K i-Nk .

[0060] In a possible design, the round function calculation module further includes a second counter for counting the number of rounds of round function calculation;

[0061] When the value in the second counter is equal to 0, the four sub-calculation units of the fourth XOR unit perform a fourth XOR operation on the plaintext and the key block of the 0th round to obtain the ciphertext of the 0th round;

[0062] The four sub-calculation units of the column transformation unit and the four sub-calculation units of the third XOR unit are used to perform a column transformation operation on the result of the third circular shift operation, including:

[0063] The four sub-calculation units of the column transformation unit and the four sub-calculation units of the third XOR unit perform a column transformation operation on the result of the third circular shift operation when the value in the second counter is greater than or equal to 1 and less than or equal to Nr - 1; when the value in the second counter is equal to Nr, the result of the third circular shift operation is not processed.

[0064] In a second aspect, an embodiment of the present application provides a computer device, including the coprocessor according to any one of the first aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0066] Figure 1 Structural schematic diagram of a coprocessor provided by an embodiment of the present application Figure 1 ;

[0067] Figure 2 Structural schematic diagram of a coprocessor provided by an embodiment of the present application Figure 2 ;

[0068] Figure 3 Structural schematic diagram of a coprocessor provided by an embodiment of the present application Figure 3 ;

[0069] Figure 4 Structural schematic diagram of a key expansion module provided by an embodiment of the present application;

[0070] Figure 5 Structural schematic diagram of a round function calculation module provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0071] To make the objectives, technical solutions, and advantages of this application clearer, the following will further describe this application in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of them. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.

[0072] In the embodiments of this application, "a plurality of" means two or more. Terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.

[0073] Figure 1 FIG. is a schematic structural diagram of a co-processor provided by an embodiment of this application, which is applied to symmetric encryption calculations, such as Figure 1 As shown, the co-processor 100 includes an instruction decoding module 110, a key expansion module 120, and a round function calculation module 130.

[0074] The instruction decoding module 110 is configured to receive instructions sent by a central processing unit and perform decoding operations on the instructions.

[0075] The key expansion module 120 includes a first linear transformation unit 121, a non-linear transformation unit 122, and a second linear transformation unit 123 connected in sequence. In each round of key expansion calculation, the first linear transformation unit 121 is configured to perform a first linear transformation operation of the corresponding encryption type on the key words participating in the current round of key expansion calculation according to the signal provided by the encryption type register; the non-linear transformation unit 122 is configured to perform a non-linear transformation operation on the result of the first linear transformation operation; the second linear transformation unit 123 is configured to perform a second linear transformation operation of the corresponding encryption type on the result of the non-linear transformation operation according to the signal provided by the encryption type register to obtain the expanded key of the current round. Among them, the signal provided by the encryption type register represents the type of symmetric encryption calculation, such as the advanced encryption standard (AES), the SM4 block cipher algorithm.

[0076] The round function calculation module 130 includes a plurality of calculation units, and each calculation unit includes a plurality of sub-calculation units; in each round of round function calculation, each calculation unit is configured to select the number of sub-calculation units required for the corresponding encryption type according to the signal provided by the encryption type register to perform encryption calculation on the message words participating in the current round to obtain the ciphertext of the current round.

[0077] In a possible design, such as Figure 2As shown in the figure, the instruction decoding module 110 includes an instruction decoder 111 and a microprogram memory 112. When the instruction decoding module 110 performs decoding operations on instructions, it is specifically used for: if the instruction is a macro instruction, it calls the micro-instruction stream corresponding to the macro instruction from the microprogram memory 112, and the instruction decoder 111 performs decoding operations on the micro-instruction stream; if the instruction is a micro-instruction, the instruction decoder 111 directly performs decoding operations on the micro-instruction.

[0078] Among them, the micro-instruction is a basic operation instruction; the macro instruction is an instruction that characterizes the working mode of symmetric encryption applications. The working modes of symmetric encryption include Electronic Codebook (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), Output Feedback (OFB), Counter Mode (CTR), etc. Exemplarily, Table 1 shows the macro instructions and micro instructions of the coprocessor for symmetric encryption calculations provided by the embodiments of the present application.

[0079] Table 1

[0080]

[0081]

[0082]

[0083]

[0084]

[0085] In a possible design, as Figure 3 shown, the coprocessor further includes a data download module 140, a conditional branch module 150, and a logic calculation module 160.

[0086] Among them, the data download module 140 is used to download data to the corresponding storage unit according to the download micro-instruction. The conditional branch module 150 is used to jump the instruction pointer to the position indicated by the conditional branch micro-instruction when the condition in the conditional branch micro-instruction is satisfied. The logic calculation module is used to perform corresponding logic calculations according to the logic calculation micro-instruction.

[0087] The data download module 140, the key expansion module 120, the round function calculation module 130, the conditional branch module 150, and the logic calculation module 160 are used to perform calculations corresponding to the specified working mode according to the instructions and the order of the instructions in the decoding result of the micro-instruction stream corresponding to the macro instruction.

[0088] The operation processes of the key expansion calculations of AES and SM4 both include SBOX byte substitution of key words, word-based circular shift, and exclusive OR operations. Therefore, the pseudo-code for the general key expansion calculation is abstracted as follows in this application:

[0089] For(i = 0; i < N k ; i++) K i = ExpPreLoop(MK i );

[0090] For(i = N k ; i < N exp ; i++) / / N exp = sm4_enable? 36 : 4 * (N r + 1);

[0091] If(sm4_enable) K = ExpPreXor(K i-3 , K i-2 , K i-1 , RCON[i - N k );

[0092] If(aes_enable) K = ExpPreRotW(Ki -1 );

[0093] K = ExpSubW(K);

[0094] KS0 = sm4_enable? ExpRotW0(K) : 0;

[0095] KS1 = sm4_enable? ExpRotW1(K) : RCON[i / Nk];

[0096] KS2 = sm4_enable? K i-4 : K i-Nk ;

[0097] K i = ExpFnlXor(K, KS0, KS1, KS2);

[0098] endfor

[0099] Based on the above pseudo-code of the key expansion calculation, the hardware structures of the first linear transformation unit 121, the non-linear transformation unit 122, and the second linear transformation unit 123 of the key expansion module 120 are designed.

[0100] In a possible design, referring to Figure 4, the first linear transformation unit 121 includes a first cyclic shift unit 1211, a first exclusive OR unit 1212, and a first data selection unit 1213.

[0101] When the first signal provided by the encryption type register indicates that the type of symmetric encryption is the Advanced Encryption Standard (AES), the first cyclic shift unit 1211 is used to perform a first cyclic shift operation on the key word K participating in the key expansion calculation of the current round. i-1 The first data selection unit 1213 is used to input the result of the first cyclic shift operation to the non-linear transformation unit according to the first signal provided by the encryption type register.

[0102] When the second signal provided by the encryption type register indicates that the type of symmetric encryption is the SM4 block cipher algorithm, the first exclusive OR unit 1212 is used to perform a first exclusive OR operation on the key word K participating in the key expansion calculation of the current round, i-3 K i-2 K i-1 and the corresponding first key calculation parameter. The first data selection unit 1213 is also used to input the result of the first exclusive OR operation to the non-linear transformation unit according to the second signal provided by the encryption type register.

[0103] In a possible design, referring to Figure 4 , the non-linear transformation unit 122 includes a first SBOX substitution unit 1221. The first SBOX substitution unit 1221 is used to perform a first SBOX substitution operation on the result of the first cyclic shift operation or the result of the first exclusive OR operation, and input the result of the first SBOX substitution operation to the second linear transformation unit 123.

[0104] In a possible design, referring to Figure 4 , the second linear transformation unit 123 includes a second cyclic shift unit 1231, a second exclusive OR unit 1232, and a second data selection unit 1233.

[0105] When the type of symmetric encryption is the Advanced Encryption Standard (AES), the second data selection unit 1233 is used to input the key word K i-Nk and the corresponding second key calculation parameter to the second exclusive OR unit 1232; where Nk is the number of key words included in the key. The second exclusive OR unit 1232 is used to perform a second exclusive OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter to obtain the expanded key word K i of the key expansion calculation of the current round.

[0106] When the type of symmetric encryption is the SM4 block cipher algorithm, the second cyclic shift unit 1231 is used to perform a second cyclic shift operation on the result of the first SBOX substitution operation. The second data selection unit 1233 is used to input the key word K i-4 , and the result of the second cyclic shift operation into the second exclusive-OR unit 1232 according to the second signal provided by the encryption type register. The second exclusive-OR unit 1232 is also used to perform a third exclusive-OR operation on the key word K i-4 , the result of the first SBOX substitution operation, and the result of the second cyclic shift operation to obtain the expanded key word Ki.

[0107] The operation processes of the round function iterative transformation of AES and SM4 both contain byte substitution of SBOX, word-based cyclic shift, and the AddRndKey function (exclusive-OR calculation of state data and key word). Therefore, the pseudo-code for the general round function calculation abstracted in this application is as follows:

[0108] {S0,S1,S2,S3} = preloop(IN); / /

[0109] For(r = 1; r < N; r++)

[0110] If(sub_enable)

[0111] {S0,S1,S2,S3} = RndSubOp(S0,S1,S2,S3);

[0112] {S0,S1,S2,S3} = {SubW0(S0),SubW1(S1),SubW1(S2),SubW1(S3)};

[0113] Endif

[0114] If(rot_enable)

[0115] {R0,R1,R2,R3} = RndRotOp(S0,S1,S2,S3);

[0116] {R0,R1,R2,R3} = {RotW0(R0),RotW1(R1),RotW1(R2),RotW1(R3)};

[0117] Endif

[0118] If(mxor_enable)

[0119] {C0,C1,C2,C3} = RndMxorOp(R0,R1,R2,R3);

[0120] {C0, C1, C2, C3} = {MidXOR(C0), MidXOR(C1), MidXOR(C2), MidXOR(C3)};

[0121] endif

[0122] {S0, S1, S2, S3} = {FnlXOR0(C0), FnlXOR1(C1), FnlXOR1(C2), FnlXOR1(C3)};

[0123] endfor

[0124] Design the hardware structure of the round function calculation module 130 based on the above pseudocode of the round function calculation.

[0125] In a possible design, refer to Figure 5 , the multiple calculation units of the round function calculation module 130 include a second SBOX substitution unit, a third cyclic shift unit, a column transformation unit, a third XOR unit, and a fourth XOR unit; each calculation unit includes four sub-calculation units; the round function calculation module also includes multiple data selection units.

[0126] When the type of symmetric encryption is the Advanced Encryption Standard AES, the third data selection unit is used to input the message words X i , X i+1 , X i+2 , X i+3 involved in the round function calculation of the current round to the four sub-calculation units of the second SBOX substitution unit. The four sub-calculation units of the second SBOX substitution unit are used to perform the third SBOX substitution operation on the message words X i , X i+1 , X i+2 , X i+3 . The fourth data selection unit is used to input the result of the third SBOX substitution operation to the four sub-calculation units of the third cyclic shift unit according to the first selection signal. The four sub-calculation units of the third cyclic shift unit are used to perform the third cyclic shift operation on the result of the third SBOX substitution operation. The four sub-calculation units of the column transformation unit and the four sub-calculation units of the third XOR unit are used to perform the column transformation operation on the result of the third cyclic shift operation. The fifth data selection unit is used to input the expanded key block involved in the round function calculation of the current round to the four sub-calculation units of the fourth XOR unit; the expanded key block includes 4 expanded key words. The four sub-calculation units of the fourth XOR unit are used to perform the fourth XOR operation on the result of the column transformation operation and the expanded key block to obtain the ciphertext of the current round.

[0127] In a possible design, the round function calculation module also includes a fifth XOR unit.

[0128] When the type of symmetric encryption is the SM4 block cipher algorithm, the fifth XOR unit is used to perform an XOR operation on the message words X i+1 , X i+2 , X i+3 and the extended key word K i participating in the round function calculation of the current round.

[0129] The third data selection unit is used to input the result of the fifth XOR operation to a sub-computation unit of the second SBOX substitution unit according to the second selection signal.

[0130] A sub-computation unit of the second SBOX substitution unit is used to perform a fourth SBOX substitution operation on the result of the fifth XOR operation.

[0131] The fourth data selection unit is used to input the result of the fourth SBOX substitution operation to four sub-computation units of the third circular shift unit according to the second selection signal.

[0132] The four sub-computation units of the third circular shift unit are used to perform a word-based fourth circular shift operation on the result of the fourth SBOX substitution operation.

[0133] The fifth data selection unit is used to input the result of the fourth circular shift operation to a sub-computation unit of the fourth XOR unit according to the second selection signal.

[0134] A sub-computation unit of the fourth XOR unit is used to perform a sixth XOR operation on the result of the fourth circular shift operation and input the execution result of the sixth XOR operation to a sub-computation unit of the fifth XOR unit.

[0135] The sixth data selection unit is used to input the result of the fourth SBOX substitution operation and the message word X i to a sub-computation unit of the fifth XOR unit according to the second selection signal.

[0136] A sub-computation unit of the fifth XOR unit is used to perform a seventh XOR operation on the result of the fourth SBOX substitution operation, the result of the sixth XOR operation, and the message word X i to obtain the ciphertext X i+4 .

[0137] In a possible design, the key expansion module further includes a first counter for counting the number of rounds of key expansion calculation.

[0138] When the value in the first counter is divisible by Nk, the first circular shift unit performs a circular shift on the key word K i-1Perform the first cyclic shift operation; Nk is the number of key words included in the key. When the value in the first counter is other values, the first cyclic shift unit does not process the key word K i-1 for processing.

[0139] In a possible design, the key expansion module further includes a first counter for counting the number of rounds of key expansion calculation; when the value in the first counter is divisible by Nk, or when Nk is greater than 6 and the remainder of the value in the first counter divided by Nk is 4, the first SBOX substitution unit performs the first SBOX substitution operation on the result of the first cyclic shift operation; when the value in the first counter is in other cases, the first SBOX substitution unit does not process the key word K i-1 for processing, and directly inputs the key word K i-1 to the second exclusive OR unit.

[0140] In a possible design, the key expansion module further includes a first counter for counting the number of rounds of key expansion calculation;

[0141] When the value in the first counter is divisible by Nk, the second data selection unit, according to the first signal provided by the encryption type register, inputs the key word K i-Nk and the corresponding second key calculation parameter to the second exclusive OR unit; when the value in the first counter is not divisible by Nk, the second data selection unit, according to the first signal provided by the encryption type register, inputs the key word K i-Nk to the second exclusive OR unit.

[0142] The second exclusive OR unit is used to perform a second exclusive OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter, including: when the value in the first counter is divisible by Nk, the second exclusive OR unit performs a second exclusive OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter; when Nk is greater than 6 and the remainder of the value in the first counter divided by Nk is 4, the second exclusive OR unit performs a second exclusive OR operation on the result of the first SBOX substitution operation and the key word K i-Nk to perform a second exclusive OR operation; when the value in the first counter is in other cases, the second exclusive OR unit performs a second exclusive OR operation on the key word K i-1 and the key word K i-Nk to perform a second exclusive OR operation.

[0143] In a possible design, the round function calculation module further includes a second counter for counting the number of rounds of round function calculation; when the value in the second counter is equal to 0, the four sub-calculation units of the fourth exclusive OR unit perform a fourth exclusive OR operation on the plaintext and the key block of the 0th round to obtain the ciphertext of the 0th round;

[0144] The four sub-computation units of the column transformation unit and the four sub-computation units of the third exclusive OR unit are used to perform a column transformation operation on the result of the third cyclic shift operation, including: when the value in the second counter is greater than or equal to 1 and less than or equal to Nr - 1, the four sub-computation units of the column transformation unit and the four sub-computation units of the third exclusive OR unit perform a column transformation operation on the result of the third cyclic shift operation; when the value in the second counter is equal to Nr, no processing is performed on the result of the third cyclic shift operation.

[0145] The embodiments of the present application provide a symmetric encryption coprocessor that can support different symmetric encryption algorithms and their different working modes, and can support symmetric encryption algorithms and CMAC authentication in modes such as CBC, CFB, OFB, and CTR of AES and SM4: (a) A dedicated instruction set that can process multiple symmetric encryption algorithms and multiple working modes is customized, including microinstructions for processing basic operations and macroinstructions for implementing encryption or decryption algorithms of symmetric algorithms; if the decoder confirms that the current instruction is a macroinstruction, directly read the built-in decomposition program related to the macroinstruction, and perform the calculation of the specified round function according to the signals decoded from the instructions of the built-in decomposition program; (b) A dedicated control register is set, and the calculation of the key expansion function is completed according to the relevant signals of the dedicated control register. This design method saves the consumption of hardware resources, and only uses the resources of a set of circuits to support the hardware processing of multiple symmetric encryption algorithms and multiple working modes.

[0146] Based on the same inventive concept, the embodiments of the present application further provide a computer device, including the coprocessor listed in any of the above manners.

[0147] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0148] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A coprocessor, applied to symmetric encryption calculations, characterized in that It includes an instruction decoding module, a key expansion module, and a round function calculation module; The instruction decoding module is used to receive instructions sent by the central processing unit and perform decoding operations on the instructions; The key expansion module includes a first linear transformation unit, a non-linear transformation unit, and a second linear transformation unit connected in sequence; in each round of key expansion calculation, the first linear transformation unit is used to perform a first linear transformation operation of the corresponding encryption type on the key word participating in the current round of key expansion calculation according to the signal provided by the encryption type register; the non-linear transformation unit is used to perform a non-linear transformation operation on the result of the first linear transformation operation; the second linear transformation unit is used to perform a second linear transformation operation of the corresponding encryption type on the result of the non-linear transformation operation according to the signal provided by the encryption type register to obtain the expanded key of the current round; the signal provided by the encryption type register represents the type of the symmetric encryption calculation; The round function calculation module includes a plurality of calculation units, and each calculation unit includes a plurality of sub-calculation units; in each round of round function calculation, each calculation unit is used to select the number of sub-calculation units required for the corresponding encryption type according to the signal provided by the encryption type register to perform encryption calculation on the message word participating in the current round to obtain the ciphertext of the current round.

2. The coprocessor according to claim 1, wherein The instruction decoding module includes an instruction decoder and a microprogram memory; When the instruction decoding module performs a decoding operation on an instruction, it specifically is used for: If the instruction is a macro instruction, call the micro-instruction stream corresponding to the macro instruction from the microprogram memory, and the instruction decoder performs a decoding operation on the micro-instruction stream; If the instruction is a micro-instruction, the instruction decoder directly performs a decoding operation on the micro-instruction; the micro-instruction is a basic operation instruction.

3. The coprocessor according to claim 2, wherein The macro instruction has an instruction characterizing the working mode of the symmetric encryption application; the coprocessor further includes a data download module, a conditional branch module, and a logic calculation module; The data download module, the key expansion module, the round function calculation module, the conditional branch module, and the logic calculation module are used to perform calculations corresponding to the specified working mode according to the instructions and the order of the instructions in the decoding result of the micro-instruction stream corresponding to the macro instruction.

4. The coprocessor according to claim 1, wherein The first linear transformation unit includes a first cyclic shift unit, a first exclusive OR unit, and a first data selection unit; When the first signal provided by the encryption type register indicates that the type of symmetric encryption is the Advanced Encryption Standard (AES), the first cyclic shift unit is used to perform a first cyclic shift operation on the key word K participating in the key expansion calculation of the current round. i-1 Perform the first cyclic shift operation; The first data selection unit is used to input the result of performing the first cyclic shift operation to the non-linear transformation unit according to the first signal provided by the encryption type register; When the second signal provided by the encryption type register indicates that the type of symmetric encryption is the SM4 block cipher algorithm, the first XOR unit is used to perform a first XOR operation on the key words K i-3 , K i-2 , K i-1 and the corresponding first key calculation parameters; The first data selection unit is further used to input the result of performing the first exclusive OR operation to the non-linear transformation unit according to the second signal provided by the encryption type register.

5. The coprocessor according to claim 4, wherein The non-linear transformation unit includes a first SBOX substitution unit; The first SBOX substitution unit is used to perform a first SBOX substitution operation on the result of performing the first cyclic shift operation or the result of performing the first exclusive OR operation, and input the result of performing the first SBOX substitution operation to the second linear transformation unit.

6. The coprocessor according to claim 5, wherein The second linear transformation unit includes a second cyclic shift unit, a second exclusive-OR unit, and a second data selection unit; When the type of symmetric encryption is the Advanced Encryption Standard (AES), the second data selection unit is configured to input the key word K i-Nk and the corresponding second key calculation parameter into the second exclusive-OR unit; where Nk is the number of key words included in the key The second exclusive-OR unit is used to perform a second exclusive-OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter to obtain an expanded key word K i ; When the type of symmetric encryption is the SM4 block cipher algorithm, the second cyclic shift unit is used to perform a second cyclic shift operation on the result of the first SBOX substitution operation; The second data selection unit is configured to input the key word K according to a second signal provided by the encryption type register i-4 , and the result of the second cyclic shift operation, into the second exclusive OR unit; The second exclusive OR unit is further configured to perform a third exclusive OR operation on the key word K i-4 , the result of the first SBOX substitution operation, and the result of the second cyclic shift operation to obtain an extended key word Ki.

7. The coprocessor according to claim 6, wherein The multiple calculation units of the round function calculation module include a second SBOX substitution unit, a third cyclic shift unit, a column transformation unit, a third exclusive-OR unit, and a fourth exclusive-OR unit; each calculation unit includes four sub-calculation units; the round function calculation module further includes multiple data selection units; When the type of symmetric encryption is the Advanced Encryption Standard (AES), the third data selection unit is used to, according to the first selection signal, input the message words X i , X i+1 , X i+2 , X i+3 into the four sub-computation units of the second SBOX substitution unit; The four sub-computation units of the second SBOX replacement unit are used to perform a third SBOX replacement operation on the message words X i , X i+1 , X i+2 , X i+3 ; The fourth data selection unit is used to input the result of performing the third SBOX substitution operation to the four sub-calculation units of the third cyclic shift unit according to the first selection signal; The four sub-calculation units of the third cyclic shift unit are used to perform a third cyclic shift operation on the result of performing the third SBOX substitution operation; The four sub-calculation units of the column transformation unit and the four sub-calculation units of the third exclusive-OR unit are used to perform a column transformation operation on the result of performing the third cyclic shift operation; The fifth data selection unit is used to input the extended key block participating in the round function calculation of the current round to the four sub-calculation units of the fourth exclusive-OR unit; the extended key block includes 4 extended key words; The four sub-calculation units of the fourth exclusive-OR unit are used to perform a fourth exclusive-OR operation on the result of the column transformation operation and the extended key block to obtain the ciphertext of the current round.

8. The coprocessor according to claim 7, wherein The round function calculation module further includes a fifth exclusive-OR unit; When the type of symmetric encryption is the SM4 block cipher algorithm, the fifth exclusive-OR unit is used to perform an exclusive-OR operation on the message words X i+1 , X i+2 , X i+3 and the extended key word K i participating in the round function calculation of the current round; The third data selection unit is used to input the result of the fifth exclusive-OR operation to a sub-calculation unit of the second SBOX substitution unit according to the second selection signal; A sub-calculation unit of the second SBOX substitution unit is used to perform a fourth SBOX substitution operation on the result of the fifth exclusive-OR operation; The fourth data selection unit is used to input the result of the fourth SBOX substitution operation to the four sub-calculation units of the third cyclic shift unit according to the second selection signal; The four sub-calculation units of the third cyclic shift unit are used to perform a word-based fourth cyclic shift operation on the result of the fourth SBOX substitution operation; The fifth data selection unit is used to input the result of the fourth cyclic shift operation to a sub-calculation unit of the fourth exclusive-OR unit according to the second selection signal; A sub-calculation unit of the fourth exclusive-OR unit is used to perform a sixth exclusive-OR operation on the result of the fourth cyclic shift operation and input the execution result of the sixth exclusive-OR operation to a sub-calculation unit of the fifth exclusive-OR unit; The sixth data selection unit is configured to input, according to the second selection signal, the result of the fourth SBOX replacement operation and the message word X i to a sub-computation unit of the fifth exclusive-OR unit; One sub-computation unit of the fifth exclusive-OR unit is used to perform a seventh exclusive-OR operation on the result of the fourth SBOX substitution operation, the result of the sixth exclusive-OR operation, and the message word X i to obtain the ciphertext X i+4 .

9. The coprocessor according to claim 4, wherein The key expansion module further includes a first counter for counting the number of rounds of key expansion calculation; When the value in the first counter is divisible by Nk, the first cyclic shift unit performs a first cyclic shift operation on the key word K participating in the current round of key expansion calculation; Nk is the number of key words included in the key; i-1 When the value in the first counter is divisible by Nk, the first cyclic shift unit performs a first cyclic shift operation on the key word K participating in the current round of key expansion calculation; Nk is the number of key words included in the key; When the value in the first counter is other values, the first cyclic shift unit does not process the key word K i-1 thereby 10. The coprocessor according to claim 5, wherein The key expansion module further includes a first counter for counting the number of rounds of key expansion calculation; When the value in the first counter is divisible by Nk, or when Nk is greater than 6 and the remainder of the value in the first counter divided by Nk is 4, the first SBOX substitution unit performs a first SBOX substitution operation on the result of performing the first cyclic shift operation; When the value in the first counter is in other cases, the first SBOX replacement unit does not process the key word K i-1 and directly inputs the key word K i-1 to the second XOR unit.

11. The coprocessor according to claim 6, wherein The key expansion module further includes a first counter for counting the number of rounds of key expansion calculation; When the value in the first counter is divisible by Nk, the second data selection unit inputs the key word K i-Nk and the corresponding second key calculation parameter to the second exclusive OR unit according to the first signal provided by the encryption type register; When the value in the first counter cannot be divided evenly by Nk, the second data selection unit inputs the key word K to the second exclusive-OR unit according to the first signal provided by the encryption type register. i-Nk ​ The second exclusive-OR unit is used to perform a second exclusive-OR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter, and includes: When the value in the first counter is divisible by Nk, the second XOR unit performs a second XOR operation on the result of the first SBOX substitution operation, the key word K i-Nk and the second key calculation parameter; When Nk is greater than 6 and the remainder of the value in the first counter divided by Nk is 4, the second XOR unit performs a second XOR operation on the result of the first SBOX substitution operation and the key word K i-Nk ; When the value in the first counter is in other cases, the second exclusive-OR unit performs an exclusive-OR operation on the key word K i-1 and the key word K i-Nk to perform a second exclusive-OR operation.

12. The coprocessor according to claim 7, wherein The round function calculation module further includes a second counter for counting the number of rounds of round function calculation; When the value in the second counter is equal to 0, the four sub-calculation units of the fourth exclusive OR unit perform a fourth exclusive OR operation on the plaintext and the key block of the 0th round to obtain the ciphertext of the 0th round; The four sub-calculation units of the column transformation unit and the four sub-calculation units of the third exclusive OR unit are used to perform a column transformation operation on the result of the third cyclic shift operation, including: The four sub-calculation units of the column transformation unit and the four sub-calculation units of the third exclusive OR unit perform a column transformation operation on the result of the third cyclic shift operation when the value in the second counter is greater than or equal to 1 and less than or equal to Nr - 1; when the value in the second counter is equal to Nr, no processing is performed on the result of the third cyclic shift operation.

13. The coprocessor according to any one of claims 1 to 12, characterized in that, The functions or pseudo-codes of the micro-instructions and the macro-instructions are as follows.

14. A computer device, characterized in that, It includes the coprocessor according to any one of claims 1 to 12.