Bus encryption method and device of security chip, electronic equipment and medium
The encryption key is generated through linear operations and the plain text data is encrypted using XOR logic operations, which solves the problem of large delay in bus encryption in the prior art and realizes low-latency encryption of high-speed security chips.
Patent Information
- Application Number
- CN202410007722.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-07-11
AI Technical Summary
In the prior art, the bus encryption scheme performs nonlinear transformation based on the S box, resulting in large delays, which is difficult to meet the high-speed security chip's demand for encryption and low delays.
The linear operation method is used to generate encryption keys through random numbers and initial keys, and the plain text data is encrypted using XOR logic operations to reduce the encryption path delay.
While ensuring the encryption strength, the delay in the data encryption process is reduced and the low latency requirement of high-speed security chips for bus encryption is met.
Smart Images

Figure CN120296804A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of digital security chip design, and particularly to a bus encryption method, device, electronic device and medium for a security chip. Background Art
[0002] With the development of high integration of integrated circuits, various devices need to transmit data through a bus, and the security of data transmission on the bus has become the focus of research on digital security chips. In recent years, the development of attack devices has enabled hackers to analyze the plaintext of data transmitted on the bus through attack means such as side-channel attacks, affecting data security. Therefore, data transmission on the bus needs to be encrypted and protected. To enhance the application security of the chip, it is necessary to encrypt the transmission data in the data bus.
[0003] In related technologies, the bus encryption scheme performs a series of non-linear transformations on data based on an S box (Substitution-box, Sbox), and encrypts the bus data through non-linear transformations and operations. The hardware implementation of the S box is usually based on a multi-bit selector or a look-up table (Look Up Table, LUT), which has a large delay. Moreover, compared with paths such as addresses and keys, the data path is usually the critical path. Performing operations such as position swapping and non-linear transformations on the data path will make the critical path longer and the timing difficult to converge. Therefore, the current bus encryption scheme is difficult to meet the requirements of high-speed security chips for low-latency encryption. Summary of the Invention
[0004] Embodiments of this application provide a bus encryption method, device, electronic device and storage medium for a security chip, which can reduce the delay of the encryption path to meet the requirements of high-speed security chips for low-latency bus encryption while ensuring the encryption strength by increasing the key complexity.
[0005] In a first aspect, embodiments of this application provide a bus encryption method for a security chip. The method includes obtaining address data, a random number, and an initial key; performing an exclusive-or logic operation on the address data with the random number to obtain a first array; performing a permutation and an exclusive-or logic operation on each bit of data in the initial key and the first array to obtain an encryption key; and encrypting the plaintext data based on the encryption key to obtain ciphertext data.
[0006] According to the first aspect of the embodiments of this application, before obtaining the address data, the random number, and the initial key, the method further includes: generating the random number and the initial key through a random number module and saving them.
[0007] According to the first aspect of the embodiments of the present application, before obtaining the address data, random number, and initial key, the method further includes: detecting whether an enabling instruction for bus encryption is received; and obtaining the address data, random number, and initial key when the enabling instruction for bus encryption is received.
[0008] According to the first aspect of the embodiments of the present application, encrypting the plaintext data based on the encryption key to obtain ciphertext data includes: sequentially grouping the plaintext data by byte order to obtain a plurality of first segmented arrays, each first segmented array corresponding to four bytes; swapping the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each first segmented array to obtain first permuted data after byte swapping; and encrypting the first permuted data based on the encryption key to obtain ciphertext data.
[0009] According to the first aspect of the embodiments of the present application, performing permutation and exclusive OR logical operations on the data of each bit in the initial key and the first array to obtain an encryption key includes: performing a bit swapping operation on the data of each bit in the first array to obtain a first intermediate array; extracting two groups of data with equal bit numbers from the first intermediate array and performing a logical operation to generate a permutation array; performing a permutation on the data in the first intermediate array based on the permutation array to obtain a second intermediate array; and performing an exclusive OR logical operation on the second intermediate array and the initial key to obtain the encryption key.
[0010] According to the first aspect of the embodiments of the present application, extracting two groups of data with equal bit numbers from the first intermediate array and performing a logical operation to generate a permutation array includes: selecting a marked bit from multiple bits in the first intermediate array; extracting two groups of data with the same number of bits as the marked bit from the first intermediate array as first operation data; and performing a bitwise AND operation on the two groups of first operation data to obtain the permutation array.
[0011] According to the first aspect of the embodiments of the present application, performing permutation and exclusive OR logical operations on the data of each bit in the initial key and the first array to obtain an encryption key includes: performing permutation and exclusive OR logical operations on the data of each bit in the initial key and the first array to obtain a first intermediate key; and concatenating a plurality of first intermediate keys into a key with the same number of bits as the plaintext data to obtain the encryption key.
[0012] According to the first aspect of the embodiments of the present application, performing a permutation and exclusive OR logical operation on the initial key and the data of each bit in the first array to obtain a first intermediate key, including: performing a permutation and exclusive OR logical operation on the initial key and the data of each bit in the first array to obtain a second intermediate key; performing a permutation and exclusive OR logical operation on the second intermediate key and the data of each bit in the first array to obtain a first intermediate key; wherein, the number of times of performing a permutation and exclusive OR logical operation on the data of each bit in the first array corresponding to the first intermediate key is N times, and the number of times of performing a permutation and exclusive OR logical operation on the data of each bit in the first array corresponding to the initial key is N - 2 times, and N is a positive integer greater than 2.
[0013] According to the first aspect of the embodiments of the present application, after encrypting the plaintext data based on the encryption key to obtain the ciphertext data, the method further includes: performing an exclusive OR logical operation on the ciphertext data based on the encryption key to obtain a second permuted data after decryption; sequentially grouping the second permuted data by bytes to obtain a plurality of second segmented arrays corresponding to the first segmented array, and each second segmented array corresponds to four bytes; swapping the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each second segmented array to obtain the plaintext data.
[0014] In a second aspect, an embodiment of the present application provides a bus protection device for a high-speed security chip, and the device includes an acquisition module, an operation module, and an encryption module. Among them, the acquisition module is used to acquire address data, a random number, and an initial key; the operation module is used to perform an exclusive OR logical operation on the address data by using the random number to obtain a first array; the operation module is further used to perform a permutation and exclusive OR logical operation on the initial key and the data of each bit in the first array to obtain an encryption key; the encryption module is used to encrypt the plaintext data based on the encryption key to obtain the ciphertext data.
[0015] In a third aspect, an embodiment of the present application provides an electronic device, and the electronic device includes a processor, a memory, and a program stored in the memory and executable on the processor. When the program is executed by the processor, it implements the bus encryption method of the security chip in the foregoing first aspect.
[0016] In a fourth aspect, an embodiment of the present application provides a readable storage medium, and a program or instruction is stored on the readable storage medium. When the program or instruction is executed by the processor, it implements the steps of the bus encryption method of the security chip in the foregoing first aspect.
[0017] A bus encryption method, device, electronic device, and storage medium for a security chip provided by an embodiment of the present application. The generation process of the encryption key can perform logical operations by combining address data and random numbers, changing the non-linear S-box operation in the related art to a linear transformation and operation. On the premise of meeting the encryption strength, it can reduce the requirement of the chip area for data encryption. Moreover, in this solution, the encryption key and the plaintext data are only XOR-operated once, and the same encryption key is used during the encryption and decryption processes of the data, which can reduce the delay during the data encryption and decryption processes, thereby meeting the requirements of the high-speed security chip for the bus data encryption and decryption speed. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The features, advantages, and technical effects of the exemplary embodiments of the present application will be described below with reference to the accompanying drawings.
[0019] Figure 1 is a flowchart showing a bus encryption method for a security chip provided by an embodiment of the present application;
[0020] Figure 2 is a flowchart showing the process of encrypting plaintext data into ciphertext data based on an encryption key provided by an embodiment of the present application;
[0021] Figure 3 is a flowchart showing the process of performing permutation and XOR logical operations on the data of each bit in the initial key and the first array to obtain an encryption key provided by an embodiment of the present application;
[0022] Figure 4 is a structural diagram of a bus encryption device for a security chip provided by an embodiment of the present application;
[0023] Figure 5 is a structural diagram of another bus encryption device for a security chip provided by an embodiment of the present application;
[0024] Figure 6 is a structural diagram of a bus encryption system for a security chip provided by an embodiment of the present application;
[0025] Figure 7 is a structural diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application and not to limit the present application. For those skilled in the art, the present application can be implemented without some of these specific details. The following description of the embodiments is only intended to provide a better understanding of the present application by showing examples of the present application.
[0027] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0028] In the related art, when encrypting the bus of a security chip, it is necessary to use an S box (Substitution-box, Sbox) for non-linear operation encryption, and at the same time, an inverse S box is required for decryption. The use of two S boxes in the entire chip will increase the area of the chip. The implementation of the S box hardware is usually achieved by using a multi-bit selector or a look-up table (Look Up Table, LUT), which has a relatively large delay. As the complexity of the chip increases, there are more and more master and slave devices connected to the bus. Each device requires a bus encryption module. For each additional bus encryption module, its corresponding area will increase by dozens of times. Secondly, non-linear operation encryption will lead to difficult timing convergence and cannot meet the performance requirements of the encryption module for high-speed security chips. Operations such as permuting the positions of data and non-linear transformation will make it difficult for the data path to converge in terms of timing. Compared with paths such as addresses and keys, the data path is usually the critical path. Operations such as permuting the positions of data and non-linear transformation on the data path will make the critical path longer and the timing more difficult to converge, and cannot meet the performance requirements of high-speed security chips.
[0029] To solve the problems of the prior art, the embodiments of the present application provide a bus encryption method, device, electronic device, and medium for a security chip.
[0030] First, the bus encryption method for a security chip provided by the embodiments of the present application will be introduced below.
[0031] The flowchart of a bus encryption method for a security chip provided by an embodiment of the present application is as follows Figure 1 shown. The bus encryption method for the security chip may include the following steps S110 - S140.
[0032] S110. Obtain address data, a random number, and an initial key.
[0033] In the embodiment of the present application, when encrypting the plaintext data of the security chip, address data is obtained, and a linear operation is performed based on the address data, a random number (Number Once, Nonce), and the initial key, so as to quickly obtain a key with a certain encryption strength.
[0034] S120. Perform an exclusive - OR logical operation on the address data with the random number to obtain a first array.
[0035] In the embodiment of the present application, an exclusive - OR operation is performed on the random number (Number Once, Nonce) and the address data, and the address data is scrambled with the random number to obtain a first array. Using the first array to participate in the generation of a new key can improve the strength of bus encryption. It can be understood that the address data participating in the address scrambling can be based on byte operations or word operations, and the scrambling bit width is determined by the addressing space of the smallest device. In one example, when the scrambling bit width is 12, the smallest addressing space cannot be less than 4KB, otherwise the address scrambling will access the addresses of other devices.
[0036] S130. Perform permutation and exclusive - OR logical operations on the data of each bit in the initial key and the first array to obtain an encryption key.
[0037] In the embodiment of the present application, a logical operation is performed on the first array obtained by address scrambling processing and the initial key, which can increase the strength of the initial key. The encryption key has a higher strength compared to the initial key. The present application can fully ensure the data security of the chip bus by increasing the encryption strength of the key.
[0038] S140. Encrypt the plaintext data based on the encryption key to obtain ciphertext data.
[0039] In the embodiment of the present application, the exclusive - OR logical operation between the encryption key and the plaintext data is only performed once, which can reduce the delay of the data encryption path and meet the requirement of low - delay bus encryption for high - speed security chips.
[0040] The above is the specific implementation of the bus encryption method for the security chip provided by the embodiments of the present application. The generation process of the encryption key performs a logical operation by combining the address data and the random number, changing the non-linear S-box operation in the related technology to a linear transformation and operation, which can reduce the requirement for the chip area for data encryption on the premise of meeting the encryption strength. Since the encryption key and the plaintext data only perform an exclusive OR logical operation once, and the same encryption key is used during both the encryption and decryption processes of the data, it can reduce the delay of data encryption, thereby meeting the requirements of the high-speed security chip for the data encryption and decryption speed. Moreover, since the determination of the encryption key needs to be based on the random number inside the chip, the random number will not be made public, different chips have different encryption keys, and the encryption keys corresponding to the same chip at different power-on and power-off times are also different.
[0041] In some embodiments, based on the aforementioned bus encryption method for the security chip, the present application also provides another implementation of the bus encryption method for the security chip. Before S110, this implementation further includes: generating a random number and an initial key through a random number module and saving them.
[0042] In the embodiments of the present application, a random number module is provided inside the chip. The random data module can automatically generate a random data group and determine a random number and an initial key based on the random data group. The initial key is directly generated by the random number module of the chip. Based on this, the random number and the initial key occur inside the chip during both the generation stage and the stage of participating in the logical operation and will not be made public, thereby ensuring the security of encryption.
[0043] In some embodiments, based on the aforementioned bus encryption method for the security chip, the present application also provides yet another implementation of the bus encryption method for the security chip. Before S110, this implementation further includes: detecting whether an enable instruction for bus encryption is received; and when the enable instruction for bus encryption is received, obtaining the address data, the random number, and the initial key.
[0044] In the embodiments of the present application, before the enable instruction for bus encryption is received, the random number and the initial key are latched inside the encryption module. After the enable instruction is received, the encryption module performs a logical operation based on the address data, the random number, and the initial key and determines the encryption key capable of encrypting the plaintext data. Based on this, this security chip encrypts the plaintext data using the encryption key based on the enable instruction for bus encryption.
[0045] In some embodiments, as Figure 2 shown, S140 (encrypting the plaintext data based on the encryption key to obtain the ciphertext data) may include the following steps:
[0046] S210. Group the plaintext data in sequence by byte to obtain a plurality of first segmented arrays, and each first segmented array corresponds to four bytes.
[0047] In the embodiments of the present application, during the process of encrypting the bus plaintext data, in order to fully ensure the encryption strength, before performing logical operation encryption on the plaintext data using the encryption key, the plaintext data is first preprocessed based on bytes to further ensure the encryption strength of the bus data. Based on this, in order to perform a transposition operation on the plaintext data according to a preset rule, the plaintext data can be grouped first according to the byte order.
[0048] S220. Exchange the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each first segmented array to obtain the first permutation data after byte exchange.
[0049] In the embodiments of the present application, exchanging the high 2 bytes and the low 2 bytes in the first segmented array can perform the first encryption on the plaintext data by bytes.
[0050] S230. Encrypt the first permutation data based on the encryption key to obtain the ciphertext data.
[0051] In the embodiments of the present application, after the first encryption to obtain the first permutation data, the second encryption of the data is performed using the encryption key, which can fully ensure the security of the ciphertext data.
[0052] In some embodiments, as Figure 3 shown, S130 (performing permutation and exclusive OR logical operations on the initial key and the data of each bit in the first array to obtain the encryption key) may include the following steps:
[0053] S310. Perform a bit exchange operation on the data of each bit in the first array to obtain the first intermediate array.
[0054] In the embodiments of the present application, before performing logical operation on the initial key, the data in the first data is first processed according to a preset rule to improve the encryption complexity of the first array. The first intermediate array has a higher encryption complexity than the first array.
[0055] S320. Extract two groups of data with equal number of bits from the first intermediate array and perform logical operations to generate a permutation array.
[0056] In the embodiments of the present application, in order to further improve the encryption complexity of the first intermediate data and increase the encryption strength, logical operation processing is performed on the data of some bits in the first intermediate array to determine the permutation array, and the permutation array is used to permute the data of the selected part of the bits in the first intermediate array.
[0057] S330. Perform a permutation on the data in the first intermediate array based on the permutation array to obtain the second intermediate array.
[0058] In the embodiments of the present application, it can be understood that the permutation array is obtained by performing a logical operation on the data of the selected partial bit positions. The bit width of the permutation array is the same as the bit width of the selected partial bit positions. Therefore, the permutation array can be used to permute the data corresponding to the selected partial bit positions. The obtained second intermediate array has a higher encryption strength than the first intermediate array.
[0059] S340. Perform an exclusive OR logical operation on the second intermediate array and the initial key to obtain the encryption key. In the embodiments of the present application, after further operation on the first array determined based on the random number and the address data to obtain the second intermediate data, by performing an exclusive OR process on the initial key using the second intermediate data, an encryption key with a higher strength than the initial key can be obtained. It can be understood that in the process from the first array to the first intermediate array, from the first intermediate array to the second intermediate array, and from the second intermediate array and the initial key to the encryption key, simple and linear logical operation processes are performed, which have the characteristics of fast speed and low latency compared with the operation using a non-linear S box.
[0060] In some embodiments, S320 (extracting two groups of data with equal bit numbers from the first intermediate array and performing a logical operation to generate a permutation array) may include the following steps:
[0061] S321. Select the marked bit positions from multiple bit positions in the first intermediate array.
[0062] In the embodiments of the present application, it can be understood that in order to perform further logical operations on the first intermediate array to improve the encryption complexity, the data corresponding to the partial bit positions of the first intermediate array can be processed. Thus, the marked bit positions can be randomly selected from the first intermediate array, and the data with the corresponding bit width can be selected for further processing according to the bit width of the marked bit positions.
[0063] S322. Extract two groups of data with the same number of bits as the marked bit positions from the first intermediate array as the first operation data.
[0064] In the embodiments of the present application, after determining the bit width of the marked bit positions, based on this bit width, the data with the corresponding number of bit positions is selected from the first intermediate data to obtain two groups of first operation data. The two groups of first operation data can have the data corresponding to the same bit positions in the first intermediate data, and there is no limitation on the selection of the two groups of first operation data.
[0065] S323. Perform a bitwise AND operation on the two groups of first operation data to obtain the permutation array.
[0066] In the embodiments of the present application, it can be understood that in Verilog, the process of performing a bitwise AND logical operation on two sets of first operation data does not change the bit width, and the permutation array has the same bit width as the first operation data. Based on this, the data in the first intermediate array can be permuted using the permutation array.
[0067] In one example, assume that the bit width of the first array obtained by the exclusive OR operation of the address data and the random number is 8, and the first array is denoted as a[7:0]. Assume that the bit width of the initial key is 4 and is denoted as key[3:0]. In Verilog, performing a permutation and exclusive OR logical operation on the data of each bit in the initial key and the first array to obtain the encryption key may include the following steps:
[0068] (1) First, perform a bit swap operation on the data of each bit in the first array to obtain the first intermediate array A1, which can be: A1 = {a[4:3], a[0], a[7], a[2:1], a[5], a[6]};
[0069] (2) Second, extract two sets of data with equal number of bits from the first intermediate array, perform a logical operation to generate a permutation array, and based on the permutation array, permute the data in the first intermediate array to obtain the second intermediate array. The second intermediate array is denoted as A2. The arrays corresponding to the fifth bit, fourth bit, third bit, and second bit in the second intermediate array A2 can be:
[0070] A2[5:2] = {A1[6], A1[4], A1[3], A1[0]} & {A1[4], A1[5], A1[1], A1[2]};
[0071] It can be understood that when selecting two sets of data corresponding to 4 bits from the first intermediate array and performing a bitwise AND operation, an array with a bit width of 4 is obtained, and this array is used as the array corresponding to the fifth bit, fourth bit, third bit, and second bit of the second intermediate array A2. The arrays of the seventh bit, sixth bit, first bit, and 0th bit of the second intermediate array A2 are equal to the corresponding ones in the first intermediate array, that is:
[0072] A2[7:6] = A1[7:6]; A2[1:0] = A1[1:0];
[0073] Therefore, after obtaining the permutation array, the data with the corresponding bit width can be directly selected from the first intermediate array and permuted with the permutation array to obtain the second intermediate data. Based on this, the data of some bits in the second intermediate data is replaced relative to the first intermediate data, thereby improving the encryption strength.
[0074] (3)Finally, perform an exclusive OR logical operation on the second intermediate array and the initial key to obtain the encryption key, which is denoted as Key-new;
[0075] Key_new = {key[3:0], key[3:0]} ^ A2; where key[3:0] is the initial key, A2 is the second intermediate array, and {key[3:0], key[3:0]} represents juxtaposing two key[3:0]s to obtain a key with a bit width of 8. It can be understood that since the bit width of the initial key key[3:0] is 4 and the bit width of the second intermediate array A2 is 8, in order to enable the initial key key[3:0] to perform an exclusive OR logical operation with the second intermediate array A2, two initial keys key[3:0] can be arranged into a key with a bit width of 8.
[0076] In some embodiments, S130 (performing permutation and exclusive OR logical operations on the initial key and the data of each bit in the first array to obtain the encryption key) may further include the following steps:
[0077] S131. Perform permutation and exclusive OR logical operations on the initial key and the data of each bit in the first array to obtain the first intermediate key.
[0078] In the embodiments of the present application, it can be understood that the bit width of the first intermediate key corresponds to and is equal to the bit width of the initial key. Before encrypting the plaintext data based on the first intermediate key, it is necessary to verify whether the bit widths corresponding to the first intermediate key and the plaintext data are the same.
[0079] S132. Concatenate multiple first intermediate keys into a key equal to the bit width of the plaintext data to obtain the encryption key.
[0080] In the embodiments of the present application, it can be understood that in the case where the bit width of the first intermediate key is less than the bit width of the plaintext data, it is necessary to concatenate the first intermediate keys into an encryption key equal to the bit width of the plaintext data. Based on this, the encryption key can be used to perform an exclusive OR logical operation with the plaintext data to encrypt the plaintext data.
[0081] In some embodiments, S131 (performing permutation and exclusive OR logical operations on the initial key and the data of each bit in the first array to obtain the first intermediate key) may include the following steps:
[0082] S1311. Perform permutation and exclusive OR logical operations on the initial key and the data of each bit in the first array to obtain the second intermediate key, where the number of times of performing permutation and exclusive OR logical operations on the data of each bit in the first array corresponding to the initial key is N - 2 times, and N is a positive integer greater than 2.
[0083] In the embodiments of the present application, it can be understood that the obtained initial key may be an initial string directly generated by a random number module, or an intermediate string obtained after multiple rounds of data permutation and exclusive OR logical operations on the initial string, address data, and random numbers.
[0084] S1312. Perform permutation and exclusive OR logical operations on the data of each bit in the second intermediate key and the first array to obtain a first intermediate key, where the number of times of performing permutation and exclusive OR logical operations on the data of each bit in the first array corresponding to the first intermediate key is N times.
[0085] In the embodiments of the present application, it can be understood that when it is determined that the number of times of performing permutation and exclusive OR logical operations on the data of each bit in the first array is N times, the number of operation rounds that the second intermediate key goes through is N - 1 times.
[0086] Based on this, as the number of rounds of data permutation and exclusive OR logical operations that the initial string goes through increases, the encryption delay will increase, and the encryption strength will also increase. The number of rounds of the foregoing data permutation and exclusive OR logical operations can be set according to the requirements of the bus data encryption strength and timing required by the security chip.
[0087] In some embodiments, based on the foregoing bus encryption method of the security chip, the present application further provides another implementation manner of the bus encryption method of the security chip. After S140, this implementation manner further includes:
[0088] S150. Perform exclusive OR logical operation on the ciphertext data based on the encryption key to obtain the decrypted second permutation data;
[0089] In the embodiments of the present application, it can be understood that when decrypting the encrypted bus ciphertext data, the same encryption key as that used during encryption needs to be used to perform the same exclusive OR operation on the ciphertext data to obtain the second permutation data.
[0090] It should be emphasized that in the case where the plaintext data undergoes two - stage encryption, that is, before encrypting the plaintext data with the encryption key, byte permutation is first performed on the plaintext data. Then, after obtaining the second permutation data, a second - stage decryption procedure is required to obtain the original plaintext data.
[0091] S160. Group the second permutation data byte - by - byte in sequence to obtain a plurality of second segmented arrays corresponding to the first segmented array, and each second segmented array corresponds to four bytes;
[0092] In the embodiments of the present application, it can be understood that when performing the second - stage decryption procedure on the second permutation data, grouping of the second permutation data needs to be performed based on the same rules as those during encryption.
[0093] S170. Swap the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each second segmented array to obtain the plaintext data.
[0094] In the embodiments of the present application, it can be understood that since the high 2 bytes and the low 2 bytes in the plaintext data are swapped during encryption, when decrypting and restoring the plaintext data, byte transposition needs to be performed based on the same rule to obtain the plaintext data.
[0095] The embodiments of the present application also provide a bus encryption device 400 for a security chip, as Figure 4 shown. The device 400 may include the following modules:
[0096] An acquisition module 410, configured to acquire address data, a random number, and an initial key.
[0097] An operation module 420, configured to perform an exclusive OR logic operation on the address data using the random number to obtain a first array.
[0098] The operation module 420 is further configured to perform permutation and exclusive OR logic operations on the initial key and the data of each bit in the first array to obtain an encryption key.
[0099] An encryption module 430, configured to encrypt the plaintext data based on the encryption key to obtain ciphertext data.
[0100] According to the embodiments of the present application, any multiple of the acquisition module 410, the operation module 420, and the encryption module 430 may be combined and implemented in one module, or any one of them may be split into multiple modules. Or, at least part of the functions of one or more of these modules may be combined with at least part of the functions of other modules and implemented in one module.
[0101] In some embodiments, please refer to Figure 5 , the bus encryption device 400 for a security chip may further include a generation module 440. Specifically, the generation module 440 may be configured to: before acquiring the address data, the random number, and the initial key, generate the random number and the initial key through a random number module and save them.
[0102] In some embodiments, please refer to Figure 5 , the bus encryption device 400 for a security chip may further include a detection module 450. Specifically, the detection module 450 may be configured to: before acquiring the address data, the random number, and the initial key, detect whether an enable instruction for bus encryption is received; and in the case of receiving the enable instruction for bus encryption, acquire the address data, the random number, and the initial key.
[0103] In some embodiments, please refer to Figure 5, the bus encryption device 400 of the security chip may further include a decryption module 460, and the decryption module 460 may specifically be configured to: after encrypting the plaintext data based on the encryption key to obtain the ciphertext data,
[0104] perform an exclusive OR logical operation on the ciphertext data based on the encryption key to obtain the decrypted second permutation data.
[0105] Group the second permutation data byte by byte in sequence to obtain a plurality of second segmented arrays corresponding to the first segmented array, and each second segmented array corresponds to four bytes.
[0106] Exchange the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each second segmented array to obtain the plaintext data.
[0107] In some embodiments, the operation module 420 may specifically be configured to:
[0108] Perform a bit swapping operation on the data of each bit position in the first array to obtain a first intermediate array.
[0109] Extract two groups of data with equal number of bits from the first intermediate array and perform a logical operation to generate a permutation array.
[0110] Perform a permutation on the data in the first intermediate array based on the permutation array to obtain a second intermediate array.
[0111] Perform an exclusive OR logical operation on the second intermediate array and the initial key to obtain the encryption key.
[0112] In some other embodiments, the operation module 420 may further specifically be configured to:
[0113] Select a marked bit position from multiple bit positions in the first intermediate array.
[0114] Extract two groups of data with the same number of bits as the marked bit position from the first intermediate array as the first operation data.
[0115] Perform a bitwise AND operation on the two groups of first operation data to obtain a permutation array.
[0116] In some embodiments, the encryption module 430 may specifically be configured to:
[0117] Group the plaintext data byte by byte in sequence to obtain a plurality of first segmented arrays, and each first segmented array corresponds to four bytes.
[0118] Exchange the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each first segmented array to obtain the first permutation data after byte swapping.
[0119] Encrypt the first permutation data based on the encryption key to obtain ciphertext data.
[0120] Figure 5 Each module in the device shown has the function of implementing each step in the bus encryption method of the aforementioned security chip and can achieve its corresponding technical effects. For the sake of brevity, it will not be described in detail here.
[0121] In some embodiments, the present application also provides a schematic structural diagram of a bus encryption system for a security chip, as Figure 6 shown. The bus encryption system includes an address scrambling module 510, a random number module 520, a write data bus byte permutation module 530, a read data bus byte permutation module 540, a new Key generation module 550, and an encryption / decryption module 560.
[0122] The random number module 520 is used to generate a random string, which is used as the random number Nonce and the key Key. The random number Nonce can be used to scramble the address data in the address scrambling module 510 to obtain a first array. The key Key and the first array perform a permutation and exclusive OR logic operation on the data of each bit in the new Key generation module 550 to obtain an encryption key.
[0123] The plaintext data of the data bus is grouped in sequence by byte order in the write data bus byte permutation module 530 to obtain a plurality of first segmented arrays, and each first segmented array corresponds to four bytes; then, the data corresponding to the two high-order bytes in each first segmented array is exchanged with the data corresponding to the two low-order bytes to obtain the first permutation data after byte exchange. The first permutation data and the encryption key are encrypted in the encryption / decryption module 560 to obtain ciphertext data.
[0124] The encryption / decryption module 560 can also decrypt the ciphertext data. During the decryption process, the ciphertext data uses the same encryption key as in encryption to perform the same exclusive OR operation to obtain the second permutation data. The second permutation data can obtain the plaintext data by performing byte transposition on the second permutation data in the read data bus byte permutation module 540 based on the same rule as the write data bus byte permutation module 530.
[0125] In some embodiments, the present application provides an electronic device, and the schematic structural diagram of the electronic device is as Figure 7 shown.
[0126] The electronic device may include a processor 610 and a memory 620 storing computer program instructions.
[0127] Specifically, the above-mentioned processor 610 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured as one or more integrated circuits for implementing the embodiments of the present application.
[0128] The memory 620 may include a mass storage for data or instructions. By way of example and not limitation, the memory 620 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In a suitable case, the memory 620 may include a removable or non-removable (or fixed) medium. In a suitable case, the memory 620 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 620 is a non-volatile solid-state memory.
[0129] The memory 620 may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, generally, the memory 620 includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it can perform the operations described in any of the bus encryption methods of the security chips in the above embodiments.
[0130] The processor 610 reads and executes the computer program instructions stored in the memory 620 to implement any of the bus encryption methods of the security chips in the above embodiments.
[0131] In one example, the electronic device may further include a communication interface 630 and a bus 600. Among them, as Figure 6 shown, the processor 610, the memory 620, and the communication interface 630 are connected through the bus 600 and complete communication with each other.
[0132] The communication interface 630 is mainly used to implement communication between the various modules, devices, units, and / or devices in the embodiments of the present application.
[0133] The bus 600 includes hardware, software, or both, and couples the components of the online data flow metering device to each other. By way of example and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 600 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.
[0134] In addition, in combination with the bus encryption method of the security chip in the above embodiments, the embodiments of the present application can be implemented by providing a computer-readable storage medium. Computer program instructions are stored on the computer-readable storage medium; when the computer program instructions are executed by a processor, any one of the bus encryption methods of the security chip in the above embodiments is implemented.
[0135] It should be clear that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated, and those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present application.
[0136] The functional blocks shown in the above block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an Application Specific Integrated Circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present application are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave on a transmission medium or a communication link. A "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, Erasable ROMs (EROMs), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.
[0137] It should also be noted that in the exemplary embodiments mentioned in this application, some methods or systems are described based on a series of steps or devices. However, this application is not limited to the order of the above steps. That is to say, the steps can be executed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps can be executed simultaneously.
[0138] As described above with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems) and computer program products according to embodiments of the present disclosure. It should be understood that each block in the flowchart and / or block diagram, and the combination of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the functions / actions specified in one or more blocks of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It is also understood that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can also be implemented by dedicated hardware that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0139] The above are only the specific embodiments of this application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, modules, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered by the protection scope of this application.
Claims
1. A bus encryption method for a security chip, characterized in that, Including: Obtain address data, a random number, and an initial key; Perform an exclusive - OR logic operation on the address data using the random number to obtain a first array; Perform permutation and exclusive - OR logic operations on the data of each bit position in the initial key and the first array to obtain an encryption key; Encrypt the plaintext data based on the encryption key to obtain ciphertext data.
2. The bus encryption method of the security chip according to claim 1, characterized in that, Before obtaining the address data, random number, and initial key, the method further includes: Generate the random number and initial key through a random number module and save them.
3. The bus encryption method of the security chip according to claim 1, characterized in that, Before obtaining the address data, random number, and initial key, the method further includes: Detect whether an enable instruction for bus encryption is received; When an enable instruction for bus encryption is received, obtain the address data, random number, and initial key.
4. The bus encryption method of the security chip according to claim 1, characterized in that, The encrypting the plaintext data based on the encryption key to obtain ciphertext data includes: Group the plaintext data in sequence by byte order to obtain a plurality of first segmented arrays, and each of the first segmented arrays corresponds to four bytes; Exchange the data corresponding to the two high - order bytes and the data corresponding to the two low - order bytes in each of the first segmented arrays to obtain first permuted data after byte exchange; Encrypt the first permuted data based on the encryption key to obtain ciphertext data.
5. The bus encryption method of the security chip according to claim 1, characterized in that The performing permutation and exclusive - OR logic operations on the data of each bit position in the initial key and the first array to obtain an encryption key includes: Perform a bit - swapping operation on the data of each bit position in the first array to obtain a first intermediate array; Extract two groups of data with equal number of bits from the first intermediate array and perform a logical operation to generate a permutation array; Perform permutation on the data in the first intermediate array based on the permutation array to obtain a second intermediate array; Perform an exclusive - OR logic operation on the second intermediate array and the initial key to obtain an encryption key.
6. The bus encryption method of the security chip according to claim 5, characterized in that, The extracting two groups of data with equal number of bits from the first intermediate array and performing a logical operation to generate a permutation array includes: Select marker bit positions from multiple bit positions in the first intermediate array; Extract two groups of data with the same number of bits as the marker bit positions from the first intermediate array as first operation data; Perform a bit - wise AND operation on the two groups of first operation data to obtain a permutation array.
7. The bus encryption method of the security chip according to claim 1, characterized in that The performing permutation and exclusive - OR logic operations on the data of each bit position in the initial key and the first array to obtain an encryption key includes: Perform permutation and exclusive - OR logic operations on the data of each bit position in the initial key and the first array to obtain a first intermediate key; Concatenate multiple first intermediate keys into a key with the same number of bit positions as the plaintext data to obtain the encryption key.
8. The bus encryption method of the security chip according to claim 7, characterized in that, The performing permutation and exclusive - OR logic operations on the data of each bit position in the initial key and the first array to obtain a first intermediate key includes: Perform permutation and exclusive - OR logic operations on the data of each bit position in the initial key and the first array to obtain a second intermediate key; Perform permutation and exclusive - OR logic operations on the second intermediate key and the data of each bit position in the first array to obtain the first intermediate key; Among them, the number of times of permutation and exclusive OR logical operations performed on the data of each bit in the first array corresponding to the first intermediate key is N times, and the number of times of permutation and exclusive OR logical operations performed on the data of each bit in the first array corresponding to the initial key is N - 2 times, where N is a positive integer greater than 2.
9. The bus encryption method of the security chip according to claim 4, characterized in that, After encrypting the plaintext data with the encryption key to obtain ciphertext data, the method further includes: Performing an exclusive OR logical operation on the ciphertext data with the encryption key to obtain a second permuted data after decryption; Grouping the second permuted data byte by byte in sequence to obtain a plurality of second segmented arrays corresponding to the first segmented arrays, and each of the second segmented arrays corresponds to four bytes; Exchanging the data corresponding to the two high-order bytes and the data corresponding to the two low-order bytes in each of the second segmented arrays to obtain the plaintext data.
10. A bus encryption device for a security chip, characterized in that, It includes: An acquisition module: used to acquire address data, a random number, and an initial key; An operation module, configured to perform an exclusive OR logical operation on the address data with the random number to obtain a first array; The operation module is further configured to perform permutation and exclusive OR logical operations on the data of each bit in the initial key and the first array to obtain an encryption key; An encryption module, configured to encrypt the plaintext data with the encryption key to obtain ciphertext data.
11. An electronic device, characterized in that, It includes: A processor, a memory, and a program stored on the memory and executable on the processor, and when the program is executed by the processor, it implements the bus encryption method of the security chip according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that, A program or instruction is stored on the computer-readable storage medium, and when the program or instruction is executed by the processor, it implements the bus encryption method of the security chip according to any one of claims 1 to 9.