Encryption method and device, decryption method and device, electronic equipment, chip and storage medium

Through the encryption method of dividing the data to generate ciphertext blocks and generating authentication codes, the problem of tampering cannot be recognized in the data storage process is solved, and the security and correctness of data storage are achieved. The encryption technology of counting values and key streams ensures efficient parallelism and random access capabilities.

CN120354426APending Publication Date: 2025-07-22BEIJING X RING TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510406476.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing packet password mode fails to effectively ensure the integrity and correctness of the data when ensuring data security, especially in network communication and data storage, it is difficult to identify whether the data has been tampered with.

Method used

An encryption method is adopted to generate a first ciphertext block by dividing the encrypted data, and an authentication code is generated based on these ciphertext blocks, and then the authentication code is encrypted to generate a second ciphertext block to identify whether the data has been modified. This method uses count values and key streams for encryption, ensuring that the generation of authentication codes does not depend on plaintext, and maintains high parallelism and random access capabilities during the encryption process.

Benefits of technology

In the data storage process, it can effectively identify whether the data has been tampered with, improve the security and correctness of the data storage, ensure that the generation of authentication codes does not leak plain text, and improve the security and correctness of the data storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354426A_ABST
    Figure CN120354426A_ABST
Patent Text Reader

Abstract

The invention provides an encryption method and device, a decryption method and device, electronic equipment, a chip and a storage medium, and the method comprises the steps: encrypting to-be-encrypted data, and obtaining at least one first ciphertext block; generating an authentication code corresponding to the to-be-encrypted data according to the at least one first ciphertext block, wherein the authentication code is used for identifying whether the at least one first ciphertext block is modified or not; and encrypting the authentication code to obtain a second ciphertext block of the to-be-encrypted data. Whether the data is tampered or not in the storage process can be identified through the authentication code, and the safety and correctness of data storage can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data processing, and in particular, to an encryption and decryption method, apparatus, electronic device, chip, and storage medium. Background Art

[0002] With the rapid development of the digital age, information security has become a crucial issue, and people have higher and higher requirements for the confidentiality, integrity, and availability of data. Traditional computing technologies have used symmetric cryptography, block ciphers, and public-key cryptography, etc. to provide data protection. Among them, for various modes implemented by block ciphers, usually only the security of data is guaranteed, but the correctness of data is not guaranteed. Summary of the Invention

[0003] The present disclosure provides an encryption and decryption method, apparatus, electronic device, chip, and storage medium to solve the problems in the related art.

[0004] In a first aspect embodiment of the present disclosure, an encryption method is proposed. The method includes: encrypting the data to be encrypted to obtain at least one first ciphertext block; generating an authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block, where the authentication code is used to identify whether the at least one first ciphertext block has been modified; encrypting the authentication code to obtain a second ciphertext block of the data to be encrypted.

[0005] In some embodiments of the present disclosure, encrypting the data to be encrypted to obtain at least one first ciphertext block includes: obtaining a key corresponding to the data to be encrypted; dividing the data to be encrypted into at least one data segment to be encrypted; using the key to encrypt the at least one data segment to be encrypted to obtain at least one first ciphertext block corresponding to the at least one data segment to be encrypted.

[0006] In some embodiments of the present disclosure, using the key to encrypt the at least one data segment to be encrypted to obtain at least one first ciphertext block corresponding to the at least one data segment to be encrypted includes: for any one of the at least one data segment to be encrypted, generating a first count value corresponding to the data segment to be encrypted according to the sequence number of the data segment to be encrypted; using the key corresponding to the data to be encrypted to encrypt the first count value to obtain a first key stream corresponding to the data segment to be encrypted; determining the first ciphertext block corresponding to the data segment to be encrypted according to the first key stream and the data segment to be encrypted.

[0007] In some embodiments of the present disclosure, generating an authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block includes: determining an attribute value of the at least one first ciphertext block; determining a plurality of first ciphertext blocks with the attribute value being a first value among the at least one first ciphertext block, and determining the authentication code corresponding to the data to be encrypted according to the plurality of first ciphertext blocks with the attribute value being the first value.

[0008] In some embodiments of the present disclosure, determining the attribute value of at least one first ciphertext block includes: for any one of the at least one first ciphertext blocks, determining the serial number of the first ciphertext block; determining the value of the first bit included in the first ciphertext block as the attribute value of the first ciphertext block, where the serial number of the first bit is equal to the serial number of the ciphertext block.

[0009] In some embodiments of the present disclosure, encrypting the authentication code to obtain the second ciphertext block of the data to be encrypted includes: determining the second count value corresponding to the authentication code according to at least one serial number of at least one data segment to be encrypted; encrypting the second count value with the key corresponding to the data to be encrypted to obtain the second key stream corresponding to the authentication code; determining the second ciphertext block corresponding to the data to be encrypted according to the second key stream and the authentication code.

[0010] An embodiment of the second aspect of the present disclosure provides a decryption method, the method including: decrypting the second ciphertext block to obtain a decryption result; comparing the decryption result with the authentication code corresponding to the data to be encrypted, where the authentication code is used to identify whether at least one first ciphertext block has been modified, and the at least one first ciphertext block is obtained by encrypting the data to be encrypted; in the case of successful comparison, decrypting the at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one first ciphertext block.

[0011] In some embodiments of the present disclosure, decrypting the second ciphertext block to obtain a decryption result includes: determining the second key stream corresponding to the second ciphertext block; determining the decryption result according to the second key stream and the second ciphertext block.

[0012] In some embodiments of the present disclosure, determining the second key stream corresponding to the second ciphertext block includes: determining the second count value corresponding to the second ciphertext block according to at least one serial number of at least one first ciphertext block; obtaining the key corresponding to the data to be encrypted; encrypting the second count value with the key corresponding to the data to be encrypted to obtain the second key stream corresponding to the second ciphertext block.

[0013] In some embodiments of the present disclosure, in the case of successful comparison, decrypting the at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one ciphertext block includes: for any one of the at least one first ciphertext blocks, generating a first count value corresponding to the first ciphertext block according to the serial number of the first ciphertext block; encrypting the first count value with the key corresponding to the data to be encrypted to obtain the first key stream corresponding to the first ciphertext block; determining the data segment to be encrypted corresponding to the first ciphertext block according to the first key stream and the first ciphertext block.

[0014] A third aspect embodiment of the present disclosure provides an encryption device, which includes: a first processing unit, configured to encrypt data to be encrypted to obtain at least one first ciphertext block; a second processing unit, configured to generate an authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block, where the authentication code is used to identify whether the at least one first ciphertext block has been modified; a third processing unit, configured to encrypt the authentication code to obtain a second ciphertext block of the data to be encrypted.

[0015] A fourth aspect embodiment of the present disclosure provides a decryption device, which includes: a first processing unit, configured to decrypt the second ciphertext block to obtain a decryption result; a second processing unit, configured to compare the decryption result with the authentication code corresponding to the data to be encrypted, where the authentication code is used to identify whether the at least one first ciphertext block has been modified, and the at least one first ciphertext block is obtained by encrypting the data to be encrypted; a third processing unit, configured to decrypt the at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one first ciphertext block when the comparison is successful.

[0016] A fifth aspect embodiment of the present disclosure provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described in the first aspect embodiment of the present disclosure or execute the method described in the second aspect embodiment of the present disclosure.

[0017] A fourth aspect embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions, where the computer instructions are used to cause a computer to execute the method described in the first aspect embodiment of the present disclosure or execute the method described in the second aspect embodiment of the present disclosure.

[0018] A fifth aspect embodiment of the present disclosure provides a chip, characterized by including at least one processor and a communication interface; the communication interface is used to receive a signal input to the chip or a signal output from the chip, and the processor communicates with the communication interface and implements the method described in the first aspect embodiment of the present disclosure or executes the method described in the second aspect embodiment of the present disclosure through logic circuits or by executing code instructions.

[0019] In summary, the encryption and decryption methods proposed in the present disclosure can generate an authentication code during the data storage process to identify whether there is any tampering during the storage process, so as to ensure the security and correctness of data storage. The authentication code is generated based on the encrypted data and does not disclose the stored data, which can improve the security of data storage.

[0020] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure, and do not constitute an undue limitation to the present disclosure.

[0022] Figure 1 Flow diagram of an encryption method provided by an embodiment of the present disclosure Figure 1 ;

[0023] Figure 2 Flow diagram of an encryption method provided by an embodiment of the present disclosure Figure 2 ;

[0024] Figure 3 Flow diagram of a decryption method provided by an embodiment of the present disclosure;

[0025] Figure 4A System block diagram of an authenticatable CTR encryption device provided by an embodiment of the present disclosure;

[0026] Figure 4B Authenticatable CTR encryption method based on a random sequence provided by an embodiment of the present disclosure;

[0027] Figure 4C Authenticatable CTR decryption method based on a random sequence provided by an embodiment of the present disclosure;

[0028] Figure 5 Structural diagram of an encryption device provided by an embodiment of the present disclosure;

[0029] Figure 6 Structural diagram of a decryption device provided by an embodiment of the present disclosure;

[0030] Figure 7 Structural diagram of an electronic device provided by an embodiment of the present disclosure;

[0031] Figure 8 Structural diagram of a chip provided by an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] Embodiments of the present disclosure will be described in detail below. Examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described by referring to the drawings below are exemplary and are intended to explain the present disclosure, and should not be construed as limiting the present disclosure.

[0033] With the rapid development of the digital age, information security has become a crucial issue. People have increasingly higher requirements for the confidentiality, integrity, and availability of data.

[0034] Current computing technologies have used symmetric ciphers, block ciphers, and public-key ciphers, etc. to provide data protection. Among them, block ciphers, as an important encryption technology, play a key role in protecting information security. Block ciphers achieve data encryption by dividing the plaintext into fixed-length blocks and performing encryption operations on each block. However, relying solely on basic block cipher algorithms is not sufficient to meet the requirements of various complex application scenarios. To better adapt to different application environments, various block cipher modes have been proposed.

[0035] Among them, the Electronic Codebook (ECB) mode, Cipher Block Chaining (CBC) mode, Cipher FeedBack (CFB) mode, and Output Feedback (OFB) mode, etc. have been widely studied and applied. And the Counter Mode (CTR), as a relatively novel block cipher mode, has gradually received attention in recent years. The CTR mode has unique advantages such as high parallelism and fast encryption speed. However, when the network communication is attacked, it is not easy to identify the tampering of messages in a timely manner. Therefore, on the basis of providing data security for the computing system, it is also necessary to ensure the correctness of the data without causing a significant negative impact on performance.

[0036] In one implementation, first, the chaotic iterative initial key Kc is sent into the Logistic pseudo-random sequence generator. Each iteration of the chaotic map can generate 32 bits of binary numbers. After 4 iterations, the results are respectively XORed with the Counter value and then subjected to the Advanced Encryption Standard (AES) block encryption process. The AES key is Key; after encryption, it is XORed with the first 128-bit plaintext block to obtain the ciphertext block; and so on. All the key frames of the H.264 video stream are encrypted using parallel operations to ensure high data security. This implementation proposes a video stream security monitoring system based on chaos theory and the AES-CTR encryption algorithm, which solves the problem of poor randomness of the Counter value of the AES-CTR algorithm, but it only ensures the security of the data and does not guarantee the correctness of the data.

[0037] In another implementation, the protected master key can be generated in the security module, and the plaintext of the protected master key does not appear outside the security module; the hardware random number generator is used to generate a group of protected keys (including multiple protected keys); the protected master key encrypts and stores the protected keys through the CTR (Counter) mode; the protected key (group) encrypts and stores multiple working keys through the CTR mode. The working keys include encryption keys, MAC keys, asymmetric keys, etc., and can be generated by random numbers or according to certain operation rules. This method can effectively improve the security of key storage, but it only ensures the security of key storage and does not guarantee the correctness of key storage.

[0038] Therefore, to solve the above problems, the present disclosure proposes an encryption and decryption method, which is mainly used to identify whether there are problems of data being "attacked" and "tampered" during network communication and data storage processes, so as to ensure that the data is correctly transmitted.

[0039] The specific content of this method is as follows.

[0040] Figure 1 Flow schematic of an encryption method provided by an embodiment of the present disclosure Figure 1 As Figure 1 shown, this method may include the following steps.

[0041] Step 101, encrypt the data to be encrypted to obtain at least one first ciphertext block.

[0042] In some embodiments, the data to be encrypted is the data that needs to be encrypted, and the name of the data to be encrypted may also be plaintext, plaintext data, etc.

[0043] In some embodiments, encrypting the data to be encrypted to obtain at least one first ciphertext block includes: obtaining the key corresponding to the data to be encrypted; dividing the data to be encrypted into at least one data segment to be encrypted; using the key to encrypt at least one data segment to be encrypted to obtain at least one first ciphertext block corresponding to at least one data segment to be encrypted.

[0044] In some embodiments, the encrypted data can be divided, that is, the plaintext can be grouped. Dividing a data to be encrypted can obtain at least one data segment to be encrypted. When encrypting the data to be encrypted, each data segment to be encrypted can be encrypted separately. After each data segment to be encrypted is encrypted, the corresponding first ciphertext block can be obtained. In other words, the first ciphertext block is obtained by encrypting the plaintext content. Optionally, one data to be encrypted can correspond to one key, that is, the key corresponding to the plaintext can be determined.

[0045] In some embodiments, encrypting at least one data segment to be encrypted using a key to obtain at least one first ciphertext block corresponding to the at least one data segment to be encrypted includes: for any one of the at least one data segment to be encrypted, generating a first count value corresponding to the data segment to be encrypted according to the serial number of the data segment to be encrypted; encrypting the first count value using the key corresponding to the data to be encrypted to obtain a first key stream corresponding to the data segment to be encrypted; and determining a first ciphertext block corresponding to the data segment to be encrypted according to the first key stream and the data segment to be encrypted.

[0046] Optionally, encrypting at least one data segment to be encrypted using a key to obtain at least one first ciphertext block corresponding to the at least one data segment to be encrypted includes: for any one of the at least one data segment to be encrypted, generating a first count value corresponding to the data segment to be encrypted according to the serial number of the data segment to be encrypted; encrypting the first count value using the key corresponding to the data to be encrypted to obtain a first key stream corresponding to the data segment to be encrypted; and performing a first operation on the first key stream and the data segment to be encrypted to obtain a first ciphertext block corresponding to the data segment to be encrypted.

[0047] In some embodiments, when dividing the data to be encrypted, the serial number of each data segment to be encrypted can be determined. For example, the serial number can be determined according to the position of the data segment to be encrypted in the original plaintext. For example, the serial number of the first data segment at the beginning of the original plaintext is 1, and the serial number of the last data segment at the end of the original plaintext is N, where N is greater than 0 and N is a positive integer, that is, the serial number of the data segment to be encrypted can be determined according to the front-back order of the data segments to be encrypted in the data to be encrypted.

[0048] In some embodiments, after determining the serial number of the data segment to be encrypted, the first count value corresponding to each data segment to be encrypted in the at least one data segment to be encrypted can be determined respectively. Optionally, the first count value can include a pseudo-random number and the serial number of the data segment to be encrypted, where the pseudo-random number is the same in one encryption task. One encryption task can refer to the process of encrypting a data segment to be encrypted, that is, the process of encrypting a plaintext. Optionally, one encryption task can encrypt the plaintext input once, that is, inputting the plaintext once can perform one encryption task.

[0049] For example, when the length of a data segment to be encrypted is 128 bits, the initial value of the counter is as follows: 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0001, where the first 64 bits are the externally input pseudo-random number, which must be different in different encryption tasks and the same in multiple data segments to be encrypted in the same encryption task. The last 64 bits are the block sequence number, which will be incremented successively in multiple data segments to be encrypted in the same encryption task. For example, the first count value of the first data segment to be encrypted can be represented as 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0001, and the first count value of the second data segment to be encrypted can be represented as 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0002, and so on.

[0050] In some embodiments, after determining the first count value of the data segment to be encrypted, the first count value can be encrypted using a key. Optionally, the first count value can be encrypted using the AES encryption algorithm to obtain a first key stream, that is, the first key stream is the key stream corresponding to the data segment to be encrypted. One data segment to be encrypted can correspond to one first key stream, that is, at least one first key stream corresponding to each of at least one data segment to be encrypted can be determined.

[0051] In some embodiments, after determining the first key stream, a first operation can be performed on the first key stream and the data segment to be encrypted to obtain a first ciphertext block, thereby encrypting the data segment to be encrypted. Optionally, after a first operation is performed on one data segment to be encrypted and one first key stream, a first ciphertext block corresponding to the data segment to be encrypted can be obtained. Optionally, the first operation can be an exclusive OR operation, that is, an exclusive OR operation can be performed on the first key stream and the data to be encrypted to obtain the first ciphertext block.

[0052] Step 102, generate an authentication code corresponding to the data to be encrypted according to at least one first ciphertext block.

[0053] In some embodiments, the authentication code is used to identify whether at least one first ciphertext block has been modified. Optionally, after obtaining the first ciphertext block according to step 101, the first ciphertext block can be stored. When the stored first ciphertext block is attacked / tampered with during or after storage, the data of the stored first ciphertext block is modified, resulting in data damage. Similarly, when attacked / tampered with, the authentication code corresponding to the data to be encrypted will change. Therefore, when it is determined that the authentication code has changed, it can be determined that the stored ciphertext block has been modified.

[0054] In some embodiments, after generating the first ciphertext block of the data segment to be encrypted, an authentication code can be generated based on at least one first ciphertext block corresponding to one data to be encrypted. Among them, generating the authentication code corresponding to the data to be encrypted based on at least one first ciphertext block includes: determining the attribute values of at least one first ciphertext block; determining multiple first ciphertext blocks among at least one first ciphertext block whose attribute values are the first value, and determining the authentication code corresponding to the data to be encrypted based on the multiple first ciphertext blocks whose attribute values are the first value.

[0055] Optionally, generating the authentication code corresponding to the data to be encrypted based on at least one first ciphertext block includes: determining the attribute values of at least one first ciphertext block; performing a first operation on multiple first ciphertext blocks among at least one first ciphertext block whose attribute values are the first value to obtain the authentication code corresponding to the data to be encrypted. In other words, the authentication code is generated based on some first ciphertext blocks without the participation of plaintext, and better security can be obtained.

[0056] Step 103, encrypt the authentication code to obtain the second ciphertext block of the data to be encrypted.

[0057] In some embodiments, after generating the authentication code, the authentication code can be encrypted to obtain the second ciphertext block, and then the first ciphertext block and the second ciphertext block can be stored to implement the encryption of the data to be encrypted.

[0058] In some embodiments, encrypting the authentication code to obtain the second ciphertext block of the data to be encrypted includes: determining a second count value corresponding to the authentication code according to at least one serial number of at least one data segment to be encrypted; encrypting the second count value with the key corresponding to the data to be encrypted to obtain a second key stream corresponding to the authentication code; determining the second ciphertext block corresponding to the data to be encrypted according to the second key stream and the authentication code.

[0059] Optionally, encrypting the authentication code to obtain the second ciphertext block of the data to be encrypted includes: determining a second count value corresponding to the authentication code according to at least one serial number of at least one data segment to be encrypted; encrypting the second count value with the key corresponding to the data to be encrypted to obtain a second key stream corresponding to the authentication code; performing a first operation on the second key stream and the authentication code to obtain the second ciphertext block corresponding to the data to be encrypted.

[0060] In some embodiments, when encrypting at least one first ciphertext block, the encryption operation of each first ciphertext block is independent and does not depend on the data of other first ciphertext blocks. Therefore, this encryption method has high parallelism and can achieve efficient encryption when processing a large amount of data.

[0061] In summary, in the above embodiments of the present disclosure, it is possible to generate an authentication code during the data storage process to identify whether there is any tampering during the storage process, so as to ensure the security and correctness of data storage. The authentication code is generated based on the encrypted data and will not disclose the stored data, which can improve the security of data storage.

[0062] Figure 2 Schematic flow of an encryption method provided by an embodiment of the present disclosure Figure 2 As Figure 2 shown, based on Figure 1 the embodiments shown, the method includes the following steps.

[0063] Step 201, determine the attribute values of at least one first ciphertext block.

[0064] In some embodiments, determining the attribute values of at least one first ciphertext block includes: for any one of the at least one first ciphertext block, determine the serial number of the first ciphertext block; determine the value of the first bit included in the first ciphertext block as the attribute value of the first ciphertext block, and the serial number of the first bit is equal to the serial number of the first ciphertext block.

[0065] Optionally, a first ciphertext block may include multiple bits, and the value of each bit may be 0 or 1. When determining the attribute value of the first ciphertext block, the serial number of the first ciphertext block may be determined. For example, when the first ciphertext block is the third ciphertext block among the at least one first ciphertext block, the serial number of the first ciphertext block is 3. At this time, from the multiple bits included in the ciphertext block, the value corresponding to the bit with the serial number 3 may be determined. When the value corresponding to the bit with the serial number 3 is 1, the attribute value of the first ciphertext block is 1. When the value corresponding to the bit with the serial number 3 is 0, the attribute value of the first ciphertext block may be determined to be 0.

[0066] Optionally, for different first ciphertext blocks, the attribute values of each first ciphertext block may be determined according to the serial numbers of different ciphertext blocks and the bits included in different ciphertext blocks.

[0067] Step 202, determine multiple first ciphertext blocks with the attribute value being the first value among the at least one first ciphertext block, and determine the authentication code corresponding to the data to be encrypted according to the multiple first ciphertext blocks with the attribute value being the first value.

[0068] In some embodiments, a first operation may be performed on the multiple first ciphertext blocks with the attribute value being the first value to obtain the authentication code corresponding to the data to be encrypted, where the first value may be 1. In other words, multiple first ciphertext blocks with the attribute value of 1 may be selected for exclusive OR operation to obtain the authentication code. Optionally, the first value may also be other values, and the present disclosure does not limit this.

[0069] In some embodiments, encrypting the authentication code to obtain a second ciphertext block of the data to be encrypted includes: determining a second count value corresponding to the authentication code according to at least one sequence number of at least one data segment to be encrypted; encrypting the second count value with the key corresponding to the data to be encrypted to obtain a second key stream corresponding to the authentication code; performing a first operation on the second key stream and the authentication code to obtain a second ciphertext block corresponding to the data to be encrypted.

[0070] Optionally, a second count value corresponding to the authentication code may be determined according to at least one sequence number of at least one data segment to be encrypted, where the second count value is greater than at least one first count value. For example, if the value of the sequence number part of at least one first count value ranges from 1 to N, then the value of the sequence number part of the second count value may be n + 1. Optionally, in the same encryption task, the pseudo-random parts of the first count value and the second count value are the same.

[0071] Optionally, when encrypting the second count value, the key used is the same as the key used when encrypting the first count value, both being the key corresponding to the data to be encrypted. After encrypting the second count value with the key, a second key stream corresponding to the authentication code can be obtained. Similarly, the second count value can be encrypted using the AES algorithm.

[0072] In some embodiments, after obtaining the second key stream, a first operation may be performed on the second key stream and the authentication code. The first operation may be an exclusive OR operation. After performing the first operation, a second ciphertext block corresponding to the authentication code can be obtained.

[0073] In summary, in the above embodiments of the present application, an authentication code can be generated according to at least one first ciphertext block and the authentication code can be encrypted. The selection of the authentication code does not depend on the plaintext, and the random sequence required for generating the authentication code is not disclosed, which will not cause the plaintext to be leaked. On the basis of ensuring security, the correctness of data storage is enhanced.

[0074] Figure 3 It is a schematic flowchart of a decryption method provided by an embodiment of the present disclosure. As Figure 3 shown, based on Figure 1 the embodiment shown, the method includes the following steps.

[0075] Step 301, decrypt the second ciphertext block to obtain a decryption result.

[0076] In some embodiments, when storing data and authentication codes, both the data to be stored and the authentication codes are encrypted. The authentication code is used to identify whether at least one first ciphertext block has been modified. The at least one first ciphertext block is obtained by encrypting the data to be encrypted. When decrypting, the second ciphertext block needs to be retrieved from the memory. Since the stored second ciphertext block may be tampered with during storage, the information of the retrieved second ciphertext block may be different from that of the second ciphertext block obtained after encrypting with the authentication code corresponding to the data to be encrypted before. Therefore, before decrypting the encrypted data, that is, before decrypting at least one first ciphertext block, it is necessary to verify whether the authentication code is correct to determine whether at least one stored first ciphertext block has been modified. Therefore, before decrypting at least one first ciphertext block, it is necessary to first decrypt the second ciphertext block corresponding to the authentication code and determine whether the decryption result is the same as the authentication code to determine whether at least one first ciphertext block has been modified.

[0077] In some embodiments, decrypting the second ciphertext block to obtain a decryption result includes: determining a second key stream corresponding to the second ciphertext block; and determining the decryption result according to the second key stream and the second ciphertext block.

[0078] Optionally, decrypting the second ciphertext block to obtain a decryption result includes: determining a second key stream corresponding to the second ciphertext block; performing a second operation on the second key stream and the second ciphertext block to obtain the decryption result, where the second operation is the inverse operation of the first operation.

[0079] In some embodiments, when decrypting the second ciphertext block, it is necessary to first determine the second key stream. Determining the second key stream corresponding to the second ciphertext block includes: determining a second count value corresponding to the second ciphertext block according to at least one serial number of at least one first ciphertext block; obtaining the key corresponding to the data to be encrypted; and encrypting the second count value with the key corresponding to the data to be encrypted to obtain the second key stream corresponding to the second ciphertext block.

[0080] In other words, the key corresponding to the data to be processed can be determined, and the second count value corresponding to the second ciphertext block is encrypted with the key to obtain the second key stream. Since the original second ciphertext block is obtained by encrypting the authentication code, during decryption, the count value of the second ciphertext block is the same as that of the authentication code, both being the second count value, and the key used during decryption is the same as the key used during encryption. Therefore, the second key stream used for decryption is the same as the second key stream used for encrypting the authentication code.

[0081] In some embodiments, after determining the second key stream, a second operation can be performed on the second key stream and the second ciphertext block. The second operation is the inverse operation of the first operation. The first operation is the exclusive OR operation, and the second operation is processed in the reverse order of the exclusive OR operation to decrypt the second ciphertext block.

[0082] Step 302: Compare the decryption result with the authentication code corresponding to the data to be encrypted.

[0083] In some embodiments, after decrypting the second ciphertext block, a decryption result can be obtained. It is necessary to compare the decryption result with the authentication code, that is, to determine whether the decryption result is the same as the authentication code. If the decryption result is the same as the authentication code, it is determined that the stored first ciphertext block and the second ciphertext block have not been tampered with. When the comparison is successful, the decryption of at least one first ciphertext block can be continued.

[0084] Step 303: In the case where the comparison is successful, decrypt at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one first ciphertext block.

[0085] In some embodiments, when the decryption result and the authentication code are successfully compared, the decryption of at least one first ciphertext block can be continued. An exception message is used to prompt that at least one first ciphertext block has been modified. If the comparison fails, that is, there is a difference between the decryption result and the authentication code, the decryption of at least one first ciphertext block is not allowed. At this time, an exception message can be generated, and the exception message is used to prompt that the stored ciphertext block has been modified.

[0086] In some embodiments, in the case where the comparison is successful, decrypting at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one ciphertext block includes: for any one of the at least one first ciphertext blocks, generating a first count value corresponding to the first ciphertext block according to the serial number of the first ciphertext block; encrypting the first count value with the key corresponding to the data to be encrypted to obtain a first key stream corresponding to the first ciphertext block; determining the data segment to be encrypted corresponding to the first ciphertext block according to the first key stream and the first ciphertext block.

[0087] Optionally, in the case where the comparison is successful, decrypting at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one ciphertext block includes: for any one of the at least one first ciphertext blocks, generating a first count value corresponding to the first ciphertext block according to the serial number of the first ciphertext block; encrypting the first count value with the key corresponding to the data to be encrypted to obtain a first key stream corresponding to the first ciphertext block; performing a second operation on the first key stream and the first ciphertext block to obtain the data segment to be encrypted corresponding to the first ciphertext block.

[0088] Similarly, the first ciphertext block is obtained by encrypting at least one data segment to be encrypted. The count value of the first ciphertext block and the count value of the corresponding data segment to be encrypted are both the first count value. The key used to decrypt the first ciphertext block is the same as the key used to encrypt the corresponding data segment to be encrypted.

[0089] In some embodiments, when decrypting the first ciphertext block, a first key stream may be generated according to the key and the first count value. Then, a second operation may be performed on the first key stream and the first ciphertext block to decrypt the first ciphertext block and obtain the data segment to be encrypted corresponding to the first ciphertext block.

[0090] In some embodiments, when decrypting, since the decryption of each first ciphertext block does not depend on the decryption result of other first ciphertext blocks, according to needs, some ciphertext blocks may be selected from at least one first ciphertext block for decryption, that is, only some first ciphertext blocks may be decrypted, which can achieve random access to any block in the ciphertext without decrypting the previous blocks, providing a high random access ability.

[0091] In some embodiments, in the solution of the present disclosure, since the process of encrypting to obtain the first ciphertext block and encrypting the first ciphertext block does not depend on the input of the plaintext or ciphertext, only the key and the count value are required. Therefore, before receiving the encryption and decryption command, pre-computation of generating the key stream may be performed. After inputting the data to be encrypted or decrypted, the first operation or the second operation may be directly performed, which can improve the operation throughput.

[0092] In summary, in the above embodiments of the present disclosure, when decrypting, first decrypt the second ciphertext block, and compare the decryption result with the authentication code. When the comparison is successful, decrypt the first ciphertext block. When the comparison fails, do not decrypt and generate an exception message, which can make the stored data be recognized when it is tampered with, and the selection of the authentication code does not depend on the plaintext, and the random sequence required for generating the authentication code is not made public, which will not cause plaintext leakage, enhancing the correctness of data storage while ensuring security.

[0093] The technical solution of the present disclosure will be further described in detail below in combination with specific application embodiments.

[0094] The following is a random-sequence-based authenticated CTR encryption and decryption method provided by an embodiment of the present disclosure. This method is applicable to encryption and decryption in the data access process. Optionally, an authenticated CTR encryption device proposed by the present disclosure may be used to implement the above method.

[0095] As Figure 4AAs shown in the figure, it is a system block diagram of an authenticated CTR encryption device. When implementing the above method using this encryption device, the host sends information such as the address and data to be stored. After passing through the parallel encryption module and the authentication code generation module, the encrypted data and the corresponding authentication code are sent to the storage unit together. When the host needs to read the data in the storage unit, the data is taken out from the storage unit, and then its corresponding authentication code is sent to the authentication module for authentication. After successful authentication, the data is sent to the parallel decryption module for decryption, and the decrypted data is transmitted to the host; if the authentication fails, it is considered that the data has been tampered with, so decryption and data transmission are not performed, and a system exception is reported.

[0096] Among them, the keys required by the encryption module, decryption module, authentication code generation module, and authentication module are managed and distributed by an external key manager; the random numbers required by the encryption module, decryption module, and authentication code generation module are provided by an external pseudo-random number generator.

[0097] As Figure 4B and 4C shown, the encryption and decryption using the above encryption device includes: dividing the plaintext into groups P1~P N , each group corresponding to a counter value (Counter1~Counter N). The same key K is used to encrypt the counter value to generate a series of key streams. The plaintexts P1~P N are respectively XORed with the corresponding key streams to obtain ciphertext groups C1~C N . P N+1 is the XOR of the first N C i corresponding to the N-bit random 0 / 1 bit string vector, and P N+1 serves as the authentication code, and the last ciphertext C N+1 is generated by encrypting CounterN+1 with the key K. During decryption, first decrypt C N+1 and compare it with the authentication code P N+1 . After successful comparison, decrypt the ciphertext groups C1~C N , otherwise do not decrypt and report a system exception.

[0098] Among them, determining the counter value corresponding to each group includes: each time encryption is performed, a different value is generated as the initial value of the counter. For example, when the group length is 128 bits, the initial value of the counter is as follows: 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0001, where the first 64 bits are the pseudo-random numbers input externally, and this part must be different each time encryption is performed and the same in the same series of plaintext groups; the last 64 bits are the group serial number, and this part will be incremented sequentially in the same series of plaintext groups. During the encryption process, the counter values of different plaintext groups are as follows:

[0099] 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0001 is the count value of plaintext block 1;

[0100] 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0002 is the count value of plaintext block 2;

[0101] 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0003 is the count value of plaintext block 3;

[0102] 128’h18E3_D83F_A0CB_1937_0000_0000_0000_0004 is the count value of plaintext block 4.

[0103] And so on. The count values generated in the above way are different each time. Therefore, the key streams obtained by encrypting the count values in each block are also different, that is, a random bit sequence is generated using a block cipher, and the randomness of this sequence is better than that of directly input random numbers from the outside.

[0104] As Figure 4B shown, a key stream is generated by the AES encryption algorithm from the key K and the count values Counter1 to Counter N, and then XOR (exclusive OR) operations are performed with the plaintext blocks P1 to P N respectively to obtain the ciphertext blocks C1 to C N . Since the execution of the AES encryption algorithm does not rely on the input of the plaintext and only requires the key K and the count values, pre-computation of generating the key stream can be performed. When the plaintext is input, only the XOR operations need to be performed on the plaintext blocks P1 to P N and the corresponding key streams respectively to quickly obtain the ciphertext blocks C1 to C N .

[0105] Optionally, the encryption algorithm used in the encryption process of this solution is the AES symmetric encryption algorithm with strong security. The main steps of the algorithm include: byte substitution, row shift, column mixing, and round key addition. The algorithm description is as follows:

[0106] 1. Both the block length and the key length are variable and can be independently specified as 128, 192, or 256 bits respectively;

[0107] 2. The intermediate results of the algorithm also need to be grouped, which is called the state. The state can be represented by a matrix array with bytes as elements. This array has 4 rows, and the number of columns N b is the block length divided by 32;

[0108] 3. The seed key is described by a matrix array with bytes as elements. The array has 4 rows and the number of columns N k is the key length divided by 32;

[0109] 4. The input, output, and seed key of the algorithm can be regarded as one-dimensional arrays composed of bytes. Among them, the subscript ranges of the input and output are: 0 -> 4N b –1, and the subscript range of the seed key is: 0 -> 4N k –1.

[0110] The main structure of the above algorithm includes:

[0111] 1. Byte substitution

[0112] The S-box for byte substitution (SubBytes) is as follows: when the input is 8’h8a, the output is 8’h7e.

[0113] 2. Row shift

[0114] The rows of the state array are circularly shifted. The shift amounts of different rows are different. Among them, the 0th row remains fixed, and the shift amounts of the remaining rows 1 to 3 can be determined according to the following table.

[0115] <![CDATA[N b > C1 C2 C3 4 1 2 3 6 1 2 3 8 1 3 4

[0116] N b represents the value of the block length divided by 4 bytes. C1, C2, and C3 respectively represent the number of bytes circularly shifted to the left for the 1st, 2nd, and 3rd rows.

[0117] 3. Column mixing

[0118] Each column of the state array is regarded as a polynomial over GF(2 8 ) and multiplied modulo x 4 +1 by a fixed polynomial c(x), denoted as

[0119] c(x) is an invertible polynomial modulo x 4 +1, c(x) = ‘03’x3 + ‘01’x2 + ‘01’x + ‘02’ (the coefficients are represented in hexadecimal);

[0120] The column mixing operation can also be written as the multiplication of a fixed matrix. Let Then there is the following matrix multiplication:

[0121]

[0122] 4. Round key addition

[0123] The round key is exclusive-ored bit by bit with the state;

[0124] The round key is obtained from the seed key through the key scheduling algorithm;

[0125] The round key length is the same as the block length;

[0126] Key scheduling refers to the process of obtaining round keys from a seed key, which consists of two parts: key expansion and round key selection. The basic principles are as follows:

[0127] The number of bits of the round key is equal to the block length multiplied by the number of rounds plus 1; for example, to encrypt a 128-bit plaintext through 10 rounds of encryption, a total of (10 + 1) * 128 = 1408 bits of key are required.

[0128] The seed key is expanded into an expanded key;

[0129] The round keys are taken from the expanded key, where the round key for the first round takes the first N b words, the round key for the second round takes the next N b words, and so on.

[0130] Optionally, the decryption process in CTR mode is exactly the same as the encryption process, except that the order of the XOR operations is reversed. For each ciphertext block C1~C N , use the same counter values (Counter1~Counter N) as in encryption and the key K to generate key stream blocks. If there is enough secure memory, these key stream blocks can be pre-computed during the encryption process, and then the ciphertext blocks are XORed with the key stream blocks to quickly obtain the plaintext blocks P1~P n .

[0131] Optionally, generating the authentication code includes: the authentication code P N+1 is the XOR of N C i corresponding to the N-bit random 0 / 1 bit string vector V. The N-bit random 0 / 1 bit string vector V selects the corresponding bit values of the ciphertext groups C1~C N corresponding to the block sequence numbers, as shown in the formula:

[0132] V = {C N [N - 1], C N-1 [N - 2], …, C2[1], C1[0]}

[0133] If the i - 1 bit of the ciphertext C i corresponding to the vector V is 1, then perform the XOR operation, otherwise do not perform the XOR operation. For example, if C1[0] is 1, C2[1] is 1, C N-1 [N - 2] is 0, and C N [N - 1] is 1, then C1, C2, and C N participate in the XOR operation. That is, the authentication code P N+1 is equal to C iThe ciphertext block C corresponding to [i - 1] being 1 i is the exclusive OR.

[0134] After encrypting the count value Counter N + 1 with the key K and then performing an exclusive OR operation with the authentication code P N+1 to generate the last ciphertext C N+1 . During decryption, the count value Counter N + 1 and the key K are also used to first decrypt C N+1 , and the decryption result is compared with the authentication code P N+1 . After successful comparison, the ciphertext group C1 to C N is decrypted. Otherwise, it is not decrypted and a system exception is reported.

[0135] In summary, the above examples of the present disclosure have the following beneficial effects.

[0136] 1. High security: The authenticable CTR encryption device combines the AES encryption algorithm with high security, and the counter value is random, unpredictable, and different in different encryption tasks, enhancing the security of data storage.

[0137] 2. High correctness: An authentication code is added on the basis of the CTR mode with high security, enabling the identification of tampered stored data. The selection of the authentication code does not depend on the plaintext, and the random sequence required for generating the authentication code is not made public, preventing plaintext leakage. On the basis of ensuring security, the correctness of data storage is enhanced.

[0138] 3. High parallelism: Since the encryption and decryption of each plaintext block can be performed independently without relying on the results of other blocks, the CTR encryption device has high parallelism and is very efficient in processing a large amount of data.

[0139] 4. High throughput: Since the execution of the AES encryption algorithm does not rely on the input of plaintext or ciphertext, only the key K and the count value are required, so pre-computation of generating the key stream can be performed. When the plaintext or ciphertext is input, only an exclusive OR operation is needed, which greatly improves the operation throughput.

[0140] 5. High random accessibility: In the CTR mode, after authentication, any block in the ciphertext can be randomly accessed without decrypting the previous blocks, providing high random access ability.

[0141] 6. Simplicity: Different from other modes, the encryption algorithm and decryption algorithm of the CTR mode are the same, that is, only the encryption algorithm and the exclusive OR operation need to be implemented. For algorithms such as AES with essentially different encryption and decryption, this simplification is huge.

[0142] Figure 5Schematic diagram of a cryptographic device 500 provided by an embodiment of the present disclosure. As Figure 5 shown, the device includes: a first processing unit 510, configured to encrypt data to be encrypted to obtain at least one first ciphertext block; a second processing unit 520, configured to generate an authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block, where the authentication code is used to identify whether the at least one first ciphertext block has been modified; and a third processing unit 530, configured to encrypt the authentication code to obtain a second ciphertext block of the data to be encrypted.

[0143] In some embodiments, the first processing unit is further configured to obtain a key corresponding to the data to be encrypted; divide the data to be encrypted into at least one data segment to be encrypted; and encrypt the at least one data segment to be encrypted using the key to obtain at least one first ciphertext block corresponding to the at least one data segment to be encrypted.

[0144] In some embodiments, the first processing unit is further configured to, for any one of the at least one data segment to be encrypted, generate a first count value corresponding to the data segment to be encrypted according to the sequence number of the data segment to be encrypted; encrypt the first count value using the key corresponding to the data to be encrypted to obtain a first key stream corresponding to the data segment to be encrypted; and determine a first ciphertext block corresponding to the data segment to be encrypted according to the first key stream and the data segment to be encrypted.

[0145] In some embodiments, the second processing unit is further configured to determine an attribute value of the at least one first ciphertext block; determine a plurality of first ciphertext blocks among the at least one first ciphertext blocks whose attribute value is a first value, and determine an authentication code corresponding to the data to be encrypted according to the plurality of first ciphertext blocks whose attribute value is the first value.

[0147] In some embodiments, the second processing unit is further configured to, for any one of the at least one first ciphertext block, determine the sequence number of the first ciphertext block; and determine the value of a first bit included in the first ciphertext block as the attribute value of the first ciphertext block, where the sequence number of the first bit is equal to the sequence number of the first ciphertext block.

[0148] In some embodiments, the third processing unit is further configured to determine a second count value corresponding to the authentication code according to at least one sequence number of the at least one data segment to be encrypted; encrypt the second count value using the key corresponding to the data to be encrypted to obtain a second key stream corresponding to the authentication code; and determine a second ciphertext block corresponding to the data to be encrypted according to the second key stream and the authentication code.

[0149] In summary, the cryptographic device 500 can generate an authentication code using the encrypted ciphertext blocks, avoid leakage of unencrypted data, and can use the authentication code to identify whether the data has been modified during storage, which can improve the security and correctness of data storage.

[0150] Figure 6 The structural schematic diagram of a decryption device 600 provided by an embodiment of the present disclosure is shown as Figure 6 follows. The device includes: a first processing unit 610, configured to decrypt a second ciphertext block to obtain a decryption result; a second processing unit 620, configured to compare the decryption result with an authentication code corresponding to data to be encrypted, where the authentication code is used to identify whether at least one first ciphertext block has been modified, and the at least one first ciphertext block is obtained by encrypting the data to be encrypted; a third processing unit 630, configured to decrypt at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one first ciphertext block when the comparison is successful.

[0151] In some embodiments, the first processing unit is further configured to determine a second key stream corresponding to the second ciphertext block; and determine the decryption result according to the second key stream and the second ciphertext block.

[0152] In some embodiments, the first processing unit is further configured to determine a second count value corresponding to the second ciphertext block according to at least one serial number of at least one first ciphertext block; obtain a key corresponding to the data to be encrypted; and encrypt the second count value with the key corresponding to the data to be encrypted to obtain a second key stream corresponding to the second ciphertext block.

[0153] In some embodiments, the third processing unit is further configured to, for any one of the at least one first ciphertext blocks, generate a first count value corresponding to the first ciphertext block according to the serial number of the first ciphertext block; encrypt the first count value with the key corresponding to the data to be encrypted to obtain a first key stream corresponding to the first ciphertext block; and determine a data segment to be encrypted corresponding to the first ciphertext block according to the first key stream and the first ciphertext block.

[0154] In summary, in the above decryption device of the present disclosure, when performing decryption, the ciphertext corresponding to the authentication code is preferentially decrypted. When the decryption result is successfully compared with the authentication code, the ciphertext block corresponding to the data is continuously decrypted. When the comparison is unsuccessful, decryption is not performed, and an exception message can be generated to remind that the data has changed during storage, which can ensure the correctness of the data storage process and avoid the tampered data from affecting data security.

[0155] In the above embodiments provided by the present application, the methods and devices provided by the embodiments of the present application are introduced. To implement each function in the methods provided by the embodiments of the present application, an electronic device may include a hardware structure and software modules, and implement the above functions in the form of a hardware structure, a software module, or a combination of a hardware structure and a software module. A certain function among the above functions may be executed in the form of a hardware structure, a software module, or a combination of a hardware structure and a software module.

[0156] Figure 7FIG. 0 is a block diagram of an electronic device 700 for implementing the above method according to an exemplary embodiment. For example, the electronic device 700 may be a mobile phone, a computer, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0157] Referring Figure 7 , the electronic device 700 may include one or more of the following components: a processing component 702, a memory 704, a power component 706, a multimedia component 708, an audio component 710, an input / output (I / O) interface 712, a sensor component 714, and a communication component 716.

[0158] The processing component 702 generally controls the overall operation of the electronic device 700, such as operations associated with display, telephone calls, data communications, camera operations, and recording operations. The processing component 702 may include one or more processors 720 to execute instructions to complete all or part of the steps of the above method. In addition, the processing component 702 may include one or more modules to facilitate the interaction between the processing component 702 and other components. For example, the processing component 702 may include a multimedia module to facilitate the interaction between the multimedia component 708 and the processing component 702.

[0159] The memory 704 is configured to store various types of data to support the operation of the electronic device 700. Examples of such data include instructions for any application or method operating on the electronic device 700, contact data, phone book data, messages, pictures, videos, etc. The memory 704 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0160] The power component 706 provides power to the various components of the electronic device 700. The power component 706 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 700.

[0161] The multimedia component 708 includes a screen that provides an output interface between the electronic device 700 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of touch or swipe actions but also detect the duration and pressure associated with the touch or swipe operations. In some embodiments, the multimedia component 708 includes a front camera and / or a rear camera. When the electronic device 700 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0162] The audio component 710 is configured to output and / or input audio signals. For example, the audio component 710 includes a microphone (MIC) that is configured to receive external audio signals when the electronic device 700 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 704 or transmitted via the communication component 716. In some embodiments, the audio component 710 further includes a speaker for outputting audio signals.

[0163] The I / O interface 712 provides an interface between the processing component 702 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, etc. These buttons can include, but are not limited to: a home button, a volume button, a power button, and a lock button.

[0164] The sensor component 714 includes one or more sensors for providing status assessments of various aspects of the electronic device 700. For example, the sensor component 714 can detect the on / off state of the electronic device 700, the relative positioning of components, such as the display and the keypad of the electronic device 700. The sensor component 714 can also detect a change in the position of the electronic device 700 or a component of the electronic device 700, the presence or absence of user contact with the electronic device 700, the orientation or acceleration / deceleration of the electronic device 700, and a change in the temperature of the electronic device 700. The sensor component 714 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 714 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 714 can further include an acceleration sensor, a gyro sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0165] The communication component 716 is configured to facilitate communication between the electronic device 700 and other devices in a wired or wireless manner. The electronic device 700 can access a communication standard-based wireless network, such as WiFi, 2G or 3G, 4G LTE, 5G NR (New Radio), or a combination thereof. In an exemplary embodiment, the communication component 716 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 716 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0166] In an exemplary embodiment, the electronic device 700 can be implemented by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above-described method.

[0167] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 704 including instructions, and the above instructions can be executed by a processor 720 of the electronic device 700 to complete the above-described method. For example, the non-transitory computer-readable storage medium can be a ROM, Random Access Memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0168] Embodiments of the present disclosure also propose a non-transitory computer-readable storage medium storing computer instructions, where the computer instructions are used to cause a computer to execute the method described in the above embodiments of the present disclosure.

[0169] Figure 8 FIG. is a schematic structural diagram of a chip 800 for implementing the above method shown according to an exemplary embodiment. Referring to Figure 8 , the chip 800 includes a communication interface 801 and at least one processor 802. The communication interface 801 is configured to receive a signal input to the chip 800 or a signal output from the chip 800, and the processor 802 communicates with the communication interface 801 and implements the method described in the above embodiments of the present disclosure through logic circuits or by executing code instructions.

[0170] It should be noted that the terms "first", "second", etc. in the description of the present disclosure, the claims and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described herein can be implemented in an order different from those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0171] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "schematic embodiments", "examples", "specific examples" or "some examples", etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in at least one embodiment or example.

[0172] Any process or method description, whether in a flowchart or otherwise described herein, can be understood to represent a module, segment or portion of code including one or more executable instructions for implementing a specific logical function or process. The scope of the preferred embodiments of the present invention includes additional implementations, where the functions can be executed in a manner that is not shown or discussed, including in a substantially simultaneous manner or in a reverse order according to the functions involved, which should be understood by those skilled in the technical field to which the embodiments of the present invention belong.

[0173] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processing module, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or used in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection portion having at least one wiring (control method), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, a computer-readable medium can even be paper or other suitable media on which a program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then storing it in a computer memory.

[0174] It should be understood that each part of the embodiments of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0175] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the methods of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0176] In addition, each functional unit in various embodiments of the present invention may be integrated into one processing module, or each unit may exist physically alone, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium. The above-mentioned storage medium may be a read-only memory, a magnetic disk, an optical disc, or the like.

[0177] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A cryptographic method, characterized in that, The method includes: Encrypting the data to be encrypted to obtain at least one first ciphertext block; Generating an authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block, where the authentication code is used to identify whether the at least one first ciphertext block has been modified; Encrypting the authentication code to obtain a second ciphertext block of the data to be encrypted.

2. The method according to claim 1, characterized in that, The encrypting the data to be encrypted to obtain at least one first ciphertext block includes: Obtaining a key corresponding to the data to be encrypted; Dividing the data to be encrypted into at least one data segment to be encrypted; Using the key to encrypt the at least one data segment to be encrypted to obtain the at least one first ciphertext block corresponding to the at least one data segment to be encrypted.

3. The method according to claim 2, wherein The using the key to encrypt the at least one data segment to be encrypted to obtain the at least one first ciphertext block corresponding to the at least one data segment to be encrypted includes: For any one of the at least one data segments to be encrypted, generating a first count value corresponding to the data segment to be encrypted according to the sequence number of the data segment to be encrypted; Using the key corresponding to the data to be encrypted to encrypt the first count value to obtain a first key stream corresponding to the data segment to be encrypted; Determining the first ciphertext block corresponding to the data segment to be encrypted according to the first key stream and the data segment to be encrypted.

4. The method according to claim 1, wherein The generating the authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block includes: Determining the attribute values of the at least one first ciphertext block; Determining multiple first ciphertext blocks with the attribute value being a first value among the at least one first ciphertext blocks, and determining the authentication code corresponding to the data to be encrypted according to the multiple first ciphertext blocks with the attribute value being the first value.

5. The method according to claim 4, wherein The determining the attribute values of the at least one first ciphertext block includes: For any one of the at least one first ciphertext blocks, determining the sequence number of the first ciphertext block; Determining the value of the first bit included in the first ciphertext block as the attribute value of the first ciphertext block, where the sequence number of the first bit is equal to the sequence number of the first ciphertext block.

6. The method according to claim 2, characterized in that, The encrypting the authentication code to obtain a second ciphertext block of the data to be encrypted includes: Determining a second count value corresponding to the authentication code according to at least one sequence number of the at least one data segment to be encrypted; Using the key corresponding to the data to be encrypted to encrypt the second count value to obtain a second key stream corresponding to the authentication code; Determining the second ciphertext block corresponding to the data to be encrypted according to the second key stream and the authentication code.

7. A decryption method, characterized in that, The method includes: Decrypting the second ciphertext block to obtain a decryption result; Comparing the decryption result with the authentication code corresponding to the data to be encrypted, where the authentication code is used to identify whether the at least one first ciphertext block has been modified, and the at least one first ciphertext block is obtained by encrypting the data to be encrypted; In the case of successful comparison, decrypting the at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one first ciphertext block.

8. The method according to claim 7, wherein The decrypting the second ciphertext block to obtain a decryption result includes: Determine the second key stream corresponding to the second ciphertext block; Determine the decryption result according to the second key stream and the second ciphertext block.

9. The method according to claim 8, wherein The determining the second key stream corresponding to the second ciphertext block includes: Determine the second count value corresponding to the second ciphertext block according to at least one serial number of the at least one first ciphertext block; Obtain the key corresponding to the data to be encrypted; Encrypt the second count value using the key corresponding to the data to be encrypted to obtain the second key stream corresponding to the second ciphertext block.

10. The method according to claim 8, wherein In the case of successful comparison, decrypt the at least one first ciphertext block to obtain at least one data segment to be encrypted corresponding to the at least one ciphertext block includes: For any one of the at least one first ciphertext blocks, generate a first count value corresponding to the first ciphertext block according to the serial number of the first ciphertext block; Encrypt the first count value using the key corresponding to the data to be encrypted to obtain the first key stream corresponding to the first ciphertext block; Determine the data segment to be encrypted corresponding to the first ciphertext block according to the first key stream and the first ciphertext block.

11. An encryption device, characterized in that, The device includes: A first processing unit, configured to encrypt the data to be encrypted to obtain at least one first ciphertext block; A second processing unit, configured to generate an authentication code corresponding to the data to be encrypted according to the at least one first ciphertext block, where the authentication code is used to identify whether the at least one first ciphertext block has been modified; A third processing unit, configured to encrypt the authentication code to obtain a second ciphertext block of the data to be encrypted.

12. A decryption device, characterized in that, The device includes: A first processing unit, configured to decrypt the second ciphertext block to obtain a decryption result; A second processing unit, configured to compare the decryption result with an authentication code corresponding to the data to be encrypted, where the authentication code is used to identify whether at least one first ciphertext block has been modified, and the at least one first ciphertext block is obtained by encrypting the data to be encrypted; A third processing unit, configured to decrypt the at least one first ciphertext block in the case of successful comparison to obtain at least one data segment to be encrypted corresponding to the at least one first ciphertext block.

13. An electronic device, characterized in that, Includes: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1-6, or execute the method according to any one of claims 7-10.

14. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to execute the method according to any one of claims 1-6, or execute the method according to any one of claims 7-10.

15. A chip, characterized in that, Includes at least one processor and a communication interface; the communication interface is used to receive signals input to the chip or signals output from the chip, and the processor communicates with the communication interface and implements the method according to any one of claims 1 to 6, or executes the method according to any one of claims 7-10 through logic circuits or by executing code instructions.