Data scrambling method and device based on secure storage

By performing multiple rounds of transformation and exclusive OR processing on address parameters, data to be encrypted and key parameters, the problem of insufficient security performance of data encryption in the prior art is solved, and higher encryption reliability and data security are achieved.

CN120358013APending Publication Date: 2025-07-22ALLWINNER TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410090652.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the prior art, the data encryption method of storage devices has poor security performance, and there is a greater risk of leakage of user data.

Method used

By performing multiple rounds of transformation and exclusive OR processing on address parameters, data to be encrypted and key parameters, a complex interference process is formed to improve encryption reliability.

Benefits of technology

Improves the security performance of encrypted data and reduces the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358013A_ABST
    Figure CN120358013A_ABST
Patent Text Reader

Abstract

The invention discloses a data scrambling method and device based on secure storage, and the method comprises the steps: carrying out the first conversion operation of to-be-encrypted data and an address parameter according to the obtained to-be-encrypted data and the address parameter, obtaining the first converted data, and carrying out the second conversion operation of the key parameter according to the key parameter, obtaining second transformed data; according to the first transformed data and the second transformed data, performing XOR processing on the first transformed data and the second transformed data to obtain target XOR data; and according to the target XOR post-data, carrying out third transformation operation on the target XOR post-data to obtain third transformed data, and taking the third transformed data as encrypted data corresponding to the to-be-encrypted data. It can be seen that the address parameters, the to-be-encrypted data and the key parameters can be interfered synchronously, the encryption reliability and effectiveness of the to-be-encrypted data can be improved, and therefore the safety performance of the encrypted data can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data encryption, and in particular, to a data scrambling method and device based on secure storage. Background Art

[0002] Secure storage is an increasingly important topic in the current security and storage industries. At present, with the rapid development of Internet technology, users have higher requirements for secure storage in aspects such as privacy security, data security, and payment security.

[0003] Currently, there are various types of storage devices, and different types of storage devices correspond to different secure storage methods. For example, for data in random access memory (RAM) and flash memory, hardened secure encryption and decryption devices are generally used for secure storage, while for data in read-only memory (ROM), encryption data software is generally used for secure storage. However, in order to reduce the combinational logic on data, the above secure storage methods often simply generate a seed using an address first, and then perform an exclusive OR operation on the seed and the data to be encrypted. However, through practice, it is found that such a data encryption method has poor security performance, and there is still a large risk of data leakage for users' data. Therefore, it is particularly important to provide a method that can improve the security of data encryption. Summary of the Invention

[0004] The present invention provides a data scrambling method and device based on secure storage, which can synchronously interfere with address parameters, data to be encrypted, and key parameters, which is beneficial to improving the encryption reliability and effectiveness of the data to be encrypted, and thus is beneficial to enhancing the security performance of the encrypted data.

[0005] To solve the above technical problems, a first aspect of the present invention discloses a data scrambling method based on secure storage, and the method includes:

[0006] Obtaining target parameters for encrypting data to be encrypted; the target parameters include address parameters and key parameters;

[0007] Performing a first transformation operation on the data to be encrypted and the address parameters according to the data to be encrypted and the address parameters to obtain first-transformed data, and performing a second transformation operation on the key parameters according to the key parameters to obtain second-transformed data;

[0008] Performing an exclusive OR operation on the first-transformed data and the second-transformed data according to the first-transformed data and the second-transformed data to obtain target exclusive-OR data;

[0009] Perform a third transformation operation on the target XORed data to obtain third-transformed data, which serves as the encrypted data corresponding to the data to be encrypted according to the target XORed data.

[0010] As an alternative implementation, in the first aspect of the present invention, the performing a first transformation operation on the data to be encrypted and the address parameter to obtain first-transformed data includes:

[0011] Perform an address transformation operation on the address parameter to obtain a transformed address parameter according to the address parameter;

[0012] Perform an XOR operation on the transformed address parameter and the data to be encrypted according to the transformed address parameter and the data to be encrypted to obtain first-XORed data;

[0013] Perform multiple rounds of transformation operations on the first-XORed data to obtain transformed XOR data, which serves as the first-transformed data corresponding to the data to be encrypted and the address parameter.

[0014] As an alternative implementation, in the first aspect of the present invention, the performing an address transformation operation on the address parameter to obtain a transformed address parameter includes:

[0015] Determine the bit width parameter of the data to be encrypted, and determine the bit width transformation requirement parameter corresponding to the address parameter according to the bit width parameter;

[0016] Perform a bit width transformation operation on the address parameter according to the bit width transformation requirement parameter to obtain a bit width-transformed address parameter;

[0017] Perform a bit scrambling operation on the bit width-transformed address parameter to obtain a bit-scrambled address parameter, which serves as the transformed address parameter corresponding to the address parameter.

[0018] As an alternative implementation, in the first aspect of the present invention, the performing multiple rounds of transformation operations on the first-XORed data to obtain transformed XOR data, which serves as the first-transformed data corresponding to the data to be encrypted and the address parameter, includes:

[0019] Determine the round execution order parameter corresponding to each of the preset multiple first target transformation methods; all of the first target transformation methods at least include a first bit scrambling transformation method, a second bit scrambling transformation method, a first row transformation method, and a first column transformation method, and the input data bit width parameter corresponding to the first bit scrambling transformation method is different from the input data bit width parameter corresponding to the second bit scrambling transformation method;

[0020] Perform multiple rounds of transformation operations on the first XORed data according to the round execution order parameters corresponding to all of the first target transformation methods to obtain transformed XORed data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0021] As an optional implementation manner, in the first aspect of the present invention, the key parameter includes a register transfer level key parameter, a netlist level fixed key parameter, and a chip identification parameter;

[0022] Wherein, the performing a second transformation operation on the key parameter according to the key parameter includes:

[0023] Perform a fusion operation on the netlist level fixed key parameter and the chip identification parameter according to the netlist level fixed key parameter and the chip identification parameter to obtain a fused parameter;

[0024] Perform an XOR process on the fused parameter and the register transfer level key parameter according to the fused parameter and the register transfer level key parameter to obtain a second XORed data;

[0025] Perform a bit scrambling operation on the second XORed data according to the second XORed data to obtain bit-scrambled key data;

[0026] Perform a constant transformation operation on the bit-scrambled key data according to a preset first constant table and the bit-scrambled key data to obtain a constant-transformed key data, which is used as the second transformed data corresponding to the key parameter.

[0027] As an optional implementation manner, in the first aspect of the present invention, the performing a third transformation operation on the target XORed data according to the target XORed data to obtain a third transformed data, which is used as the encrypted data corresponding to the data to be encrypted, includes:

[0028] Determine the round execution order parameter corresponding to each of the preset multiple second target transformation methods; all of the second target transformation methods at least include a second row transformation method, a second column transformation method, and a constant table transformation method;

[0029] Perform multiple rounds of transformation operations on the target XORed data according to the round execution sequence parameters corresponding to all the second target transformation methods, to obtain third transformed data, which is used as the encrypted data corresponding to the data to be encrypted.

[0030] As an optional implementation manner, in the first aspect of the present invention, the method further includes:

[0031] Perform multiple rounds of inverse transformation operations on the encrypted data according to the encrypted data and the round execution sequence parameters corresponding to all the second target transformation methods, to obtain first inverse transformed data;

[0032] Perform XOR processing on the first inverse transformed data and the second transformed data according to the first inverse transformed data and the second transformed data, to obtain third XORed data;

[0033] Perform multiple rounds of inverse transformation operations on the third XORed data according to the third XORed data and the round execution sequence parameters corresponding to all the first target transformation methods, to obtain second inverse transformed data;

[0034] Perform XOR processing on the second inverse transformed data and the first transformed data according to the second inverse transformed data and the first transformed data, to obtain fourth XORed data, which is used as the decrypted data corresponding to the encrypted data.

[0035] The second aspect of the present invention discloses a data scrambling device based on secure storage, and the device includes:

[0036] An acquisition module, configured to acquire target parameters for encrypting data to be encrypted; the target parameters include an address parameter and a key parameter;

[0037] A first transformation module, configured to perform a first transformation operation on the data to be encrypted and the address parameter according to the data to be encrypted and the address parameter, to obtain first transformed data;

[0038] A second transformation module, configured to perform a second transformation operation on the key parameter according to the key parameter, to obtain second transformed data;

[0039] A data XOR module, configured to perform XOR processing on the first transformed data and the second transformed data according to the first transformed data and the second transformed data, to obtain target XORed data;

[0040] A third transformation module, configured to perform a third transformation operation on the target XORed data according to the target XORed data, to obtain third transformed data, which is used as the encrypted data corresponding to the data to be encrypted.

[0041] As an alternative implementation manner, in the second aspect of the present invention, the manner in which the first transformation module performs a first transformation operation on the data to be encrypted and the address parameter according to the data to be encrypted and the address parameter to obtain the first transformed data specifically includes:

[0042] Perform an address transformation operation on the address parameter according to the address parameter to obtain a transformed address parameter;

[0043] Perform an exclusive-OR process on the transformed address parameter and the data to be encrypted according to the transformed address parameter and the data to be encrypted to obtain a first exclusive-OR data;

[0044] Perform multiple rounds of transformation operations on the first exclusive-OR data according to the first exclusive-OR data to obtain a transformed exclusive-OR data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0045] As an alternative implementation manner, in the second aspect of the present invention, the manner in which the first transformation module performs an address transformation operation on the address parameter according to the address parameter to obtain a transformed address parameter specifically includes:

[0046] Determine the bit width parameter of the data to be encrypted, and determine the bit width transformation requirement parameter corresponding to the address parameter according to the bit width parameter;

[0047] Perform a bit width transformation operation on the address parameter according to the bit width transformation requirement parameter to obtain a bit width transformed address parameter;

[0048] Perform a bit scrambling operation on the bit width transformed address parameter according to the bit width transformed address parameter to obtain a bit scrambled address parameter, which is used as the transformed address parameter corresponding to the address parameter.

[0049] As an alternative implementation manner, in the second aspect of the present invention, the manner in which the first transformation module performs multiple rounds of transformation operations on the first exclusive-OR data according to the first exclusive-OR data to obtain a transformed exclusive-OR data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter specifically includes:

[0050] Determine the round execution sequence parameter corresponding to each first target transformation manner according to a variety of preset first target transformation manners; all the first target transformation manners at least include a first bit scrambling transformation manner, a second bit scrambling transformation manner, a first row transformation manner, and a first column transformation manner, and the input data bit width parameter corresponding to the first bit scrambling transformation manner is different from the input data bit width parameter corresponding to the second bit scrambling transformation manner;

[0051] Perform multi-round transformation operations on the first XORed data according to the round execution sequence parameters corresponding to all the first target transformation methods, and obtain the transformed XOR data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0052] As an optional implementation manner, in the second aspect of the present invention, the key parameters include register transfer level key parameters, netlist level fixed key parameters, and chip identification parameters;

[0053] Among them, the manner in which the second transformation module performs a second transformation operation on the key parameters according to the key parameters to obtain the second transformed data specifically includes:

[0054] Perform a fusion operation on the netlist level fixed key parameter and the chip identification parameter according to the netlist level fixed key parameter and the chip identification parameter to obtain a fused parameter;

[0055] Perform an XOR process on the fused parameter and the register transfer level key parameter according to the fused parameter and the register transfer level key parameter to obtain the second XORed data;

[0056] Perform a bit scrambling operation on the second XORed data according to the second XORed data to obtain the bit-scrambled key data;

[0057] Perform a constant transformation operation on the bit-scrambled key data according to a preset first constant table and the bit-scrambled key data to obtain the constant-transformed key data, which is used as the second transformed data corresponding to the key parameters.

[0058] As an optional implementation manner, in the second aspect of the present invention, the manner in which the third transformation module performs a third transformation operation on the target XORed data according to the target XORed data to obtain the third transformed data, which is used as the encrypted data corresponding to the data to be encrypted, specifically includes:

[0059] Determine the round execution sequence parameters corresponding to each of the second target transformation methods according to a plurality of preset second target transformation methods; all the second target transformation methods at least include a second row transformation method, a second column transformation method, and a constant table transformation method;

[0060] Perform multi-round transformation operations on the target XORed data according to the round execution sequence parameters corresponding to all the second target transformation methods, and obtain the third transformed data, which is used as the encrypted data corresponding to the data to be encrypted.

[0061] As an optional implementation manner, in the second aspect of the present invention, the device further includes:

[0062] An inverse transformation module, configured to perform multi-round inverse transformation operations on the encrypted data according to the encrypted data and the round execution sequence parameters corresponding to all the second target transformation methods, so as to obtain first inverse-transformed data;

[0063] The data XOR module is further configured to perform XOR processing on the first inverse-transformed data and the second transformed data according to the first inverse-transformed data and the second transformed data, so as to obtain third XORed data;

[0064] The inverse transformation module is further configured to perform multi-round inverse transformation operations on the third XORed data according to the third XORed data and the round execution sequence parameters corresponding to all the first target transformation methods, so as to obtain second inverse-transformed data;

[0065] The data XOR module is further configured to perform XOR processing on the second inverse-transformed data and the first transformed data according to the second inverse-transformed data and the first transformed data, so as to obtain fourth XORed data as the decrypted data corresponding to the encrypted data.

[0066] A third aspect of the present invention discloses another data scrambling device based on secure storage, and the device includes:

[0067] A memory storing executable program code;

[0068] A processor coupled to the memory;

[0069] The processor calls the executable program code stored in the memory and executes the data scrambling method based on secure storage disclosed in the first aspect of the present invention.

[0070] A fourth aspect of the present invention discloses a computer storage medium, and the computer storage medium stores computer instructions, which are used to execute the data scrambling method based on secure storage disclosed in the first aspect of the present invention when called.

[0071] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0072] In an embodiment of the present invention, according to the obtained data to be encrypted and the address parameter, a first transformation operation is performed on the data to be encrypted and the address parameter to obtain the first transformed data, and according to the key parameter, a second transformation operation is performed on the key parameter to obtain the second transformed data; according to the first transformed data and the second transformed data, an exclusive OR operation is performed on the first transformed data and the second transformed data to obtain the target exclusive OR data; according to the target exclusive OR data, a third transformation operation is performed on the target exclusive OR data to obtain the third transformed data, which is used as the encrypted data corresponding to the data to be encrypted. It can be seen that implementing the present invention can synchronously interfere with the address parameter, the data to be encrypted, and the key parameter, which is beneficial to improving the encryption reliability and effectiveness of the data to be encrypted, and thus is beneficial to enhancing the security performance of the encrypted data. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0074] Figure 1 is a schematic flowchart of a data scrambling method based on secure storage disclosed in an embodiment of the present invention;

[0075] Figure 2 is a schematic flowchart of another data scrambling method based on secure storage disclosed in an embodiment of the present invention;

[0076] Figure 3 is a schematic structural diagram of a data scrambling device based on secure storage disclosed in an embodiment of the present invention;

[0077] Figure 4 is a schematic structural diagram of another data scrambling device based on secure storage disclosed in an embodiment of the present invention;

[0078] Figure 5 is a schematic structural diagram of yet another data scrambling device based on secure storage disclosed in an embodiment of the present invention;

[0079] Figure 6 is a schematic flowchart of a data encryption process based on secure storage disclosed in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0080] To enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0081] In the specification and claims of the present invention and the above-mentioned accompanying drawings, the terms "first", "second", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or terminal including a series of steps or units is not limited to the listed steps or units, but optionally further includes unlisted steps or units, or optionally further includes other steps or units inherent to these processes, methods, products or terminals.

[0082] Referring to "embodiments" herein means that the specific features, structures or characteristics described in connection with the embodiments may be included in at least one embodiment of the present invention. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0083] The present invention discloses a data scrambling method and device based on secure storage, which can synchronously scramble address parameters, data to be encrypted, and key parameters, facilitating the improvement of the encryption reliability and effectiveness of the data to be encrypted, and thus conducive to enhancing the security performance of the encrypted data.

[0084] Embodiment 1

[0085] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a data scrambling method based on secure storage disclosed in the embodiments of the present invention. Among them, Figure 1 The described data scrambling method based on secure storage can be applied to encrypt various types of data to be encrypted, such as RAM data to be encrypted, ROM data to be encrypted, Flash data to be encrypted, etc., which are not limited in the embodiments of the present invention. Optionally, the method can be implemented by a data intelligent encryption device, which can be integrated in an electronic device (such as a smart computer, a smart tablet), and when the data intelligent encryption device exists independently, it can also be a local server or a cloud server, etc. for processing the encryption process of the data to be encrypted, which is not limited in the embodiments of the present invention. As Figure 1As shown, the data scrambling method based on secure storage may include the following operations:

[0086] 101. Obtain target parameters for encrypting the data to be encrypted.

[0087] In an embodiment of the present invention, the target parameters include an address parameter and a key parameter. Further, the key parameter includes a register transfer level key parameter (Rtl_fix_key), a netlist level fixed key parameter (Gate_level_key), and a chip identification parameter (CHIPID).

[0088] 102. According to the data to be encrypted and the address parameter, perform a first transformation operation on the data to be encrypted and the address parameter to obtain first transformed data, and according to the key parameter, perform a second transformation operation on the key parameter to obtain second transformed data.

[0089] In an embodiment of the present invention, optionally, the first transformation operation may include a bit width transformation operation, a bit scrambling operation, a row transformation operation, a column transformation operation, an exclusive OR processing, etc., and the second transformation operation may include a data fusion operation, a bit scrambling operation, a constant transformation operation (which may also be other transformation operations with the same bit width), an exclusive OR processing, etc.

[0090] 103. According to the first transformed data and the second transformed data, perform an exclusive OR processing on the first transformed data and the second transformed data to obtain target exclusive OR data.

[0091] 104. According to the target exclusive OR data, perform a third transformation operation on the target exclusive OR data to obtain third transformed data, which is the encrypted data corresponding to the data to be encrypted.

[0092] In an embodiment of the present invention, optionally, the third transformation operation may include a constant transformation operation (which may also be other transformation operations with the same bit width), a row transformation operation, and a column transformation operation, etc.

[0093] It can be seen that implementing the embodiments of the present invention can synchronously interfere with the address parameter, the data to be encrypted, and the key parameter through corresponding transformation operations, exclusive OR processing, etc. of the address parameter, the data to be encrypted, and the key parameter, which is beneficial to improving the encryption reliability and effectiveness of the data to be encrypted, and thus is beneficial to enhancing the security performance of the encrypted data.

[0094] Embodiment 2

[0095] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of another data scrambling method based on secure storage disclosed in an embodiment of the present invention. Among them, Figure 2The described data scrambling method based on secure storage can be applied to encrypt various types of data to be encrypted, such as RAM data to be encrypted, ROM data to be encrypted, Flash data to be encrypted, etc., and the embodiments of the present invention do not limit this. Optionally, this method can be implemented by a data intelligent encryption device, which can be integrated in an electronic device (such as a smart computer, a smart tablet). When the data intelligent encryption device exists independently, it can also be a local server or a cloud server, etc., for processing the encryption process of the data to be encrypted, and the embodiments of the present invention do not limit this. As Figure 2 shown, the data scrambling method based on secure storage may include the following operations:

[0096] 201. Obtain target parameters for encrypting the data to be encrypted.

[0097] 202. According to the address parameter, perform an address transformation operation on the address parameter to obtain a transformed address parameter.

[0098] In the embodiments of the present invention, it is necessary to first transform the address parameter into a parameter with the same data bit width as the data to be encrypted, and then interfere with the address parameter after the bit width transformation, so as to perform an exclusive OR operation on the interfered address parameter and the data to be encrypted.

[0099] 203. According to the transformed address parameter and the data to be encrypted, perform an exclusive OR operation on the transformed address parameter and the data to be encrypted to obtain a first exclusive OR data.

[0100] 204. According to the first exclusive OR data, perform multiple rounds of transformation operations on the first exclusive OR data to obtain transformed exclusive OR data, as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0101] In the embodiments of the present invention, it can be understood that multiple rounds of interference operations are performed on the first exclusive OR data through row transformation, column transformation, bit confusion operation, etc., so as to obtain the first transformed data corresponding to the data to be encrypted and the address parameter.

[0102] 205. According to the key parameter, perform a second transformation operation on the key parameter to obtain a second transformed data.

[0103] 206. According to the first transformed data and the second transformed data, perform an exclusive OR operation on the first transformed data and the second transformed data to obtain a target exclusive OR data.

[0104] 207. According to the target exclusive OR data, perform a third transformation operation on the target exclusive OR data to obtain a third transformed data, as the encrypted data corresponding to the data to be encrypted.

[0105] In the embodiments of the present invention, for other descriptions of steps 201, 205 - 207, please refer to the detailed descriptions of steps 101 - 104 in Embodiment 1, and the embodiments of the present invention will not elaborate herein.

[0106] It can be seen that implementing the embodiments of the present invention can first perform preliminary interference on the address parameter, and then perform exclusive - OR processing on the interfered address parameter and the data to be encrypted. Thus, multiple rounds of interference operations are performed on the obtained first exclusive - OR data. In this way, through a series of linear and non - linear transformation processes on the data to be encrypted and the address parameter, it is beneficial to improve the reliability and effectiveness of the data interference operation between the address parameter and the data to be encrypted. Furthermore, it is beneficial to improve the encryption reliability and effectiveness of the data to be encrypted, thereby effectively reducing the probability of the encrypted data being leaked.

[0107] In an alternative embodiment, the above - mentioned step 202 of performing an address transformation operation on the address parameter according to the address parameter to obtain a transformed address parameter includes:

[0108] Determine the bit - width parameter of the data to be encrypted, and determine the bit - width transformation requirement parameter corresponding to the address parameter according to the bit - width parameter;

[0109] Perform a bit - width transformation operation on the address parameter according to the bit - width transformation requirement parameter to obtain a bit - width - transformed address parameter;

[0110] Perform a bit - scrambling operation on the bit - width - transformed address parameter according to the bit - width - transformed address parameter to obtain a bit - scrambled address parameter as the transformed address parameter corresponding to the address parameter.

[0111] In this alternative embodiment, for example, as Figure 6 shown, Figure 6 is a schematic diagram of a data encryption process based on secure storage disclosed in the embodiments of the present invention. Among them, when the bit - width parameter of the address parameter is 32 bits and the bit - width parameter of the data to be encrypted is 128 bits, at this time, the bit - width parameter of the address parameter needs to be extended to 128 bits, and then a bit - scrambling operation is performed on the bit - width - transformed address parameter to smoothly implement the interference on the address parameter and subsequent exclusive - OR processing operations on the data.

[0112] Optionally, the bit - scrambling operation can be, for each input of the 128 - bit bit - width - transformed address parameter with a 64 - bit bit - width, perform this transformation on the high 64 bits and the low 64 bits of the 128 - bit bit - width - transformed address parameter respectively; or for each input of the 128 - bit bit - width - transformed address parameter, directly perform this transformation on the 128 - bit bit - width - transformed address parameter; or other similar transformation operations.

[0113] It can be seen that this optional embodiment can first perform a bit-width transformation operation on the address parameter, and then perform a bit scrambling operation on the address parameter after the bit-width transformation to obtain the transformed address parameter. In this way, it is beneficial to improve the interference reliability and effectiveness of the address parameter, and further beneficial to improve the reliability and effectiveness of the subsequent data interference operation between the transformed address parameter and the data to be encrypted, thereby being beneficial to enhancing the security performance of the encrypted data obtained subsequently.

[0114] In another optional embodiment, the step of performing multiple rounds of transformation operations on the first XORed data according to the first XORed data in step 204 to obtain the transformed XOR data as the first transformed data corresponding to the data to be encrypted and the address parameter includes:

[0115] Determine the round execution order parameter corresponding to each first target transformation method according to a variety of preset first target transformation methods;

[0116] Perform multiple rounds of transformation operations on the first XORed data according to the round execution order parameters corresponding to all the first target transformation methods to obtain the transformed XOR data as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0117] In this optional embodiment, optionally, all the first target transformation methods at least include a first bit scrambling transformation method, a second bit scrambling transformation method, a first row transformation method, and a first column transformation method, and may also include other linear / nonlinear transformation methods that can achieve the above transformation effects. Among them, the input data bit-width parameter corresponding to the first bit scrambling transformation method is different from the input data bit-width parameter corresponding to the second bit scrambling transformation method (for example, the input data bit-width parameter of the former is 64 bits, and that of the latter is 128 bits).

[0118] It should be noted that, as Figure 6 shown, Figure 6 Steps 4 - 7 in Figure 6 correspond to the above-mentioned various first target transformation methods, and the round execution order parameter of each first target transformation method is not limited, that is, it can be that Step 4 in Figure 6 corresponds to the first bit scrambling transformation method, Step 5 corresponds to the first row transformation method, Step 6 corresponds to the first column transformation method, and Step 7 corresponds to the second bit scrambling transformation method, or it can be that Step 4 corresponds to the first row transformation method, Step 5 corresponds to the first bit scrambling transformation method, Step 6 corresponds to the first column transformation method, and Step 7 corresponds to the second bit scrambling transformation method, and so on.

[0119] It can be seen that the optional embodiment can perform multiple rounds of transformation on the first XORed data according to the determined round execution sequence parameters corresponding to all the first target transformation methods, so as to obtain the first transformed data corresponding to the data to be encrypted and the address parameters. In this way, the flexibility of the transformation of the first XORed data can be improved, and then the interference reliability and effectiveness of the first XORed data can be improved, so as to enhance the data encryption performance between the address parameters and the data to be encrypted.

[0120] In another optional embodiment, the step of performing a second transformation operation on the key parameter according to the key parameter in step 205 includes:

[0121] Fusing the netlist-level fixed key parameter and the chip identification parameter to obtain a fused parameter;

[0122] XORing the fused parameter and the register transfer level key parameter according to the fused parameter to obtain a second XORed data;

[0123] Performing a bit scrambling operation on the second XORed data according to the second XORed data to obtain a bit-scrambled key data;

[0124] Performing a constant transformation operation on the bit-scrambled key data according to a preset first constant table and the bit-scrambled key data to obtain a constant-transformed key data, which is used as the second transformed data corresponding to the key parameter.

[0125] In this optional embodiment, optionally, the bit scrambling operation may be to perform this transformation on the high 64 bits and the low 64 bits of the 128-bit second XORed data respectively for each input of 64-bit second XORed data; or it may be to directly perform this transformation on the 128-bit second XORed data for each input of 128-bit second XORed data; or it may be other similar this transformation operations.

[0126] It can be seen that the optional embodiment can perform XOR processing on the corresponding key parameter, and then perform bit scrambling and constant transformation operations on the obtained second XORed data to obtain the second transformed data corresponding to the key parameter. In this way, it is beneficial to improve the interference reliability and effectiveness of the key parameter, and further beneficial to improve the reliability and effectiveness of the subsequent data interference operation between the first transformed parameter and the second transformed parameter, so as to further enhance the security performance of the subsequent obtained encrypted data and reduce the occurrence of data leakage.

[0127] In yet another optional embodiment, the third transformation operation on the target XORed data in step 207 to obtain the third transformed data as the encrypted data corresponding to the data to be encrypted includes:

[0128] Determine the round execution order parameters corresponding to each second target transformation method according to a plurality of preset second target transformation methods;

[0129] Perform a multi-round transformation operation on the target XORed data according to the round execution order parameters corresponding to all the second target transformation methods to obtain the third transformed data as the encrypted data corresponding to the data to be encrypted.

[0130] In this optional embodiment, optionally, all the second target transformation methods at least include a second row transformation method, a second column transformation method, and a constant table transformation method, and may also include other linear / non-linear transformation methods that can achieve the above transformation effects.

[0131] Similarly, it should be noted that, as Figure 6 shown, Figure 6 Steps 8 - 10 in correspond to the above-mentioned multiple second target transformation methods, and the round execution order parameters of each second target transformation method are not limited, that is, it can be that Figure 6 Step 8 in corresponds to the constant table transformation method, Step 9 corresponds to the second row transformation method, and Step 10 corresponds to the second column transformation method, or it can be that Step 8 corresponds to the constant table transformation method, Step 9 corresponds to the second column transformation method, and Step 10 corresponds to the second row transformation method, and so on.

[0132] Moreover, further, the shift transformation parameters corresponding to the second row transformation method, such as the specific number of rows to be shifted, the shift direction, the number of bytes to be shifted, etc., may be the same as or different from the shift transformation parameters corresponding to the foregoing first row transformation method (the same is true for the shift transformation parameters corresponding to the second column transformation method and the foregoing first column transformation method). For example, if the second row transformation method is that in each transformation cycle, the first row remains unchanged, the second row is cyclically shifted left by one byte, the third row is cyclically shifted left by two bytes, and the fourth row is cyclically shifted left by three bytes, while the first row transformation method is that in each transformation cycle, the first row remains unchanged, the second row is cyclically shifted right by one byte, the third row is cyclically shifted right by two bytes, and the fourth row is cyclically shifted right by three bytes, and so on.

[0133] It can be seen that this optional embodiment can perform multiple rounds of transformations on the target XOR data according to the round execution order parameters corresponding to all the determined second target transformation methods, and obtain encrypted data corresponding to the data to be encrypted. In this way, the transformation flexibility of the target XOR data can be improved, and then the interference reliability and effectiveness of the target XOR data can be improved, so as to improve the security performance of the obtained encrypted data and reduce the risk of leakage; at the same time, the data scrambling method based on secure storage has good compatibility and can be applied to various types of bus data processing (such as adding the above-mentioned data scrambling logic to the bus path), and also reflects a good avalanche effect, with good timing convergence performance and excellent safety performance.

[0134] In yet another optional embodiment, the method further includes:

[0135] According to the encrypted data and the round execution order parameters corresponding to all the second target transformation modes, multiple rounds of inverse transformation operations are performed on the encrypted data to obtain first inverse transformed data;

[0136] According to the first inverse transformed data and the second transformed data, performing XOR processing on the first inverse transformed data and the second transformed data to obtain third XOR data;

[0137] According to the third XOR data and the round execution order parameters corresponding to all the first target transformation modes, performing multiple rounds of inverse transformation operations on the third XOR data to obtain second inverse transformed data;

[0138] According to the second inverse transformed data and the first transformed data, an XOR process is performed on the second inverse transformed data and the first transformed data to obtain fourth XOR data as decrypted data corresponding to the encrypted data.

[0139] In this optional embodiment, the decrypted data corresponding to the encrypted data is the initially input data to be encrypted. Furthermore, the data decryption process described in this embodiment is similar to the aforementioned data encryption process, except that the order of data processing is different. It can be understood as a reverse deduction process, wherein the row transformation process, column transformation process, bit confusion process and constant transformation process, etc. in the encryption process are forward operation forms, while the multiple rounds of inverse transformation operations in the decryption process are reverse operation forms opposite to the aforementioned process.

[0140] It can be seen that this optional embodiment can perform a decryption operation on the encrypted data based on the round execution order parameters corresponding to all second target transformation modes and all first target transformation modes in the encryption process to obtain the original data to be encrypted. In this way, it can not only meet the user's needs for data encryption and decryption processing of various types of data, but also improve the processing efficiency of various types of data, so as to comprehensively enhance the security performance of various types of data.

[0141] Embodiment III

[0142] Please refer to Figure 3 , Figure 3 , which is a schematic structural diagram of a data scrambling device based on secure storage disclosed in an embodiment of the present invention. As Figure 3 shown, the data scrambling device based on secure storage may include:

[0143] An acquisition module 301, configured to acquire target parameters for encrypting data to be encrypted;

[0144] A first transformation module 302, configured to perform a first transformation operation on the data to be encrypted and the address parameter according to the data to be encrypted and the address parameter, to obtain first-transformed data;

[0145] A second transformation module 303, configured to perform a second transformation operation on the key parameter according to the key parameter, to obtain second-transformed data;

[0146] A data XOR module 304, configured to perform an XOR process on the first-transformed data and the second-transformed data according to the first-transformed data and the second-transformed data, to obtain target XORed data;

[0147] A third transformation module 305, configured to perform a third transformation operation on the target XORed data according to the target XORed data, to obtain third-transformed data, as the encrypted data corresponding to the data to be encrypted.

[0148] In this optional embodiment, the target parameters include an address parameter and a key parameter.

[0149] It can be seen that the data scrambling device based on secure storage described in the implementation Figure 3 can synchronously interfere with the address parameter, the data to be encrypted, and the key parameter through corresponding transformation operations, XOR processing, etc. on the address parameter, the data to be encrypted, and the key parameter, which is beneficial to improving the encryption reliability and effectiveness of the data to be encrypted, and thus is beneficial to enhancing the security performance of the encrypted data.

[0150] In an optional embodiment, the manner in which the first transformation module 302 performs a first transformation operation on the data to be encrypted and the address parameter according to the data to be encrypted and the address parameter to obtain first-transformed data specifically includes:

[0151] Performing an address transformation operation on the address parameter according to the address parameter to obtain a transformed address parameter;

[0152] Performing an XOR process on the transformed address parameter and the data to be encrypted according to the transformed address parameter and the data to be encrypted to obtain first XORed data;

[0153] Based on the first XORed data, perform multiple rounds of transformation operations on the first XORed data to obtain the transformed XOR data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0154] It can be seen that implementing Figure 4 the described data scrambling device based on secure storage can first perform preliminary interference on the address parameter, and then perform XOR processing on the interfered address parameter and the data to be encrypted, so as to perform multiple rounds of interference operations on the obtained first XORed data. In this way, through a series of linear and non-linear transformation processes on the data to be encrypted and the address parameter, it is beneficial to improve the reliability and effectiveness of the data interference operation between the address parameter and the data to be encrypted, and further beneficial to improve the encryption reliability and effectiveness of the data to be encrypted, thereby effectively reducing the occurrence probability of the encrypted data being leaked.

[0155] In another alternative embodiment, the specific manner in which the first transformation module 302 performs an address transformation operation on the address parameter according to the address parameter to obtain the transformed address parameter includes:

[0156] Determine the bit width parameter of the data to be encrypted, and determine the bit width transformation requirement parameter corresponding to the address parameter according to the bit width parameter;

[0157] Perform a bit width transformation operation on the address parameter according to the bit width transformation requirement parameter to obtain the address parameter after bit width transformation;

[0158] Perform a bit scrambling operation on the address parameter after bit width transformation according to the address parameter after bit width transformation to obtain the address parameter after bit scrambling, which is used as the transformed address parameter corresponding to the address parameter.

[0159] It can be seen that implementing Figure 4 the described data scrambling device based on secure storage can first perform a bit width transformation operation on the address parameter, and then perform a bit scrambling operation on the address parameter after bit width transformation to obtain the transformed address parameter. In this way, it is beneficial to improve the interference reliability and effectiveness of the address parameter, and further beneficial to improve the reliability and effectiveness of the subsequent data interference operation between the transformed address parameter and the data to be encrypted, thereby being beneficial to enhancing the security performance of the subsequent obtained encrypted data.

[0160] In yet another alternative embodiment, the specific manner in which the first transformation module 302 performs multiple rounds of transformation operations on the first XORed data according to the first XORed data to obtain the transformed XOR data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter, includes:

[0161] Determine the round execution sequence parameter corresponding to each first target transformation method according to a variety of preset first target transformation methods;

[0162] Perform multiple rounds of transformation operations on the first XORed data according to the round execution sequence parameters corresponding to all the first target transformation methods, to obtain the transformed XOR data, which is used as the first transformed data corresponding to the data to be encrypted and the address parameter.

[0163] In this optional embodiment, all the first target transformation methods at least include the first bit scrambling transformation method, the second bit scrambling transformation method, the first row transformation method, and the first column transformation method, and the input data bit width parameter corresponding to the first bit scrambling transformation method is different from the input data bit width parameter corresponding to the second bit scrambling transformation method.

[0164] It can be seen that implementing Figure 4 The described data scrambling device based on secure storage can perform multiple rounds of transformation on the first XORed data according to the round execution sequence parameters corresponding to all the determined first target transformation methods, to obtain the first transformed data corresponding to the data to be encrypted and the address parameter. In this way, the transformation flexibility of the first XORed data can be improved, and further, the interference reliability and effectiveness of the first XORed data can be improved, so that the data encryption performance between the address parameter and the data to be encrypted can be enhanced.

[0165] In another optional embodiment, the key parameter includes a register transfer level key parameter, a netlist level fixed key parameter, and a chip identification parameter;

[0166] Among them, the specific manner in which the second transformation module 303 performs a second transformation operation on the key parameter according to the key parameter to obtain the second transformed data includes:

[0167] Perform a fusion operation on the netlist level fixed key parameter and the chip identification parameter according to the netlist level fixed key parameter and the chip identification parameter, to obtain a fused parameter;

[0168] Perform an XOR process on the fused parameter and the register transfer level key parameter according to the fused parameter and the register transfer level key parameter, to obtain the second XORed data;

[0169] Perform a bit scrambling operation on the second XORed data according to the second XORed data, to obtain the bit-scrambled key data;

[0170] Perform a constant transformation operation on the bit-scrambled key data according to a preset first constant table and the bit-scrambled key data, to obtain the constant-transformed key data, which is used as the second transformed data corresponding to the key parameter.

[0171] It can be seen that implementing Figure 4The described data scrambling device based on secure storage can perform exclusive OR processing on corresponding key parameters, and then perform bit confusion and constant transformation operations on the obtained second exclusive OR data to obtain the second transformed data corresponding to the key parameters. In this way, it is beneficial to improve the interference reliability and effectiveness of the key parameters, and further beneficial to improve the reliability and effectiveness of subsequent data interference operations between the first transformed parameter and the second transformed parameter, thereby being beneficial to further enhance the security performance of the subsequent encrypted data and reduce the occurrence of data leakage.

[0172] In yet another alternative embodiment, the third transformation module 305 performs a third transformation operation on the target exclusive OR data according to the target exclusive OR data to obtain the third transformed data, and the specific manner of using the third transformed data as the encrypted data corresponding to the data to be encrypted includes:

[0173] Determine the round execution order parameters corresponding to each second target transformation method according to a variety of preset second target transformation methods;

[0174] Perform multiple rounds of transformation operations on the target exclusive OR data according to the round execution order parameters corresponding to all second target transformation methods to obtain the third transformed data, and use the third transformed data as the encrypted data corresponding to the data to be encrypted.

[0175] In this alternative embodiment, all second target transformation methods at least include a second row transformation method, a second column transformation method, and a constant table transformation method.

[0176] It can be seen that implementing Figure 4 The described data scrambling device based on secure storage can perform multiple rounds of transformation on the target exclusive OR data according to the round execution order parameters corresponding to all determined second target transformation methods to obtain the encrypted data corresponding to the data to be encrypted. In this way, the transformation flexibility of the target exclusive OR data can be improved, and further, the interference reliability and effectiveness of the target exclusive OR data can be improved, thereby the security performance of the obtained encrypted data can be enhanced and the leakage risk can be reduced; at the same time, this data scrambling method based on secure storage has good compatibility and can be applied to various bus data processing (such as adding the above data scrambling logic on the bus path), and also exhibits a good avalanche effect, with good timing convergence performance and excellent security performance.

[0177] In yet another alternative embodiment, the device further includes:

[0178] An inverse transformation module 306, configured to perform multiple rounds of inverse transformation operations on the encrypted data according to the encrypted data and the round execution order parameters corresponding to all second target transformation methods to obtain the first inverse transformed data;

[0179] The data exclusive-OR module 304 is further configured to perform an exclusive-OR operation on the first inverse-transformed data and the second transformed data according to the first inverse-transformed data and the second transformed data, so as to obtain third exclusive-OR data.

[0180] The inverse transformation module 306 is further configured to perform multiple rounds of inverse transformation operations on the third exclusive-OR data according to the third exclusive-OR data and the round execution sequence parameters corresponding to all the first target transformation methods, so as to obtain second inverse-transformed data.

[0181] The data exclusive-OR module 304 is further configured to perform an exclusive-OR operation on the second inverse-transformed data and the first transformed data according to the second inverse-transformed data and the first transformed data, so as to obtain fourth exclusive-OR data, which is used as the decrypted data corresponding to the encrypted data.

[0182] It can be seen that implementing Figure 4 the described data scrambling device based on secure storage can decrypt the encrypted data based on all the second target transformation methods and the round execution sequence parameters corresponding to all the first target transformation methods during the encryption process, so as to obtain the original data to be encrypted. In this way, it can not only meet the user's requirements for data encryption and decryption processing of various types of data, but also improve the processing efficiency of various types of data, so as to comprehensively improve the security performance of various types of data.

[0183] Embodiment 4

[0184] Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of another data scrambling device based on secure storage disclosed in an embodiment of the present invention. As Figure 5 shown, the data scrambling device based on secure storage may include:

[0185] A memory 401 storing executable program code;

[0186] A processor 402 coupled to the memory 401;

[0187] The processor 402 calls the executable program code stored in the memory 401 and executes the steps in the data scrambling method based on secure storage described in Embodiment 1 or Embodiment 2 of the present invention.

[0188] Embodiment 5

[0189] An embodiment of the present invention discloses a computer storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute the steps in the data scrambling method based on secure storage described in Embodiment 1 or Embodiment 2 of the present invention.

[0190] Embodiment 6

[0191] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute the steps in the data scrambling method based on secure storage described in Embodiment 1 or Embodiment 2.

[0192] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.

[0193] Through the specific description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other computer-readable medium capable of carrying or storing data.

[0194] Finally, it should be noted that: The data scrambling method and device based on secure storage disclosed in the embodiments of the present invention only disclose the preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than limiting them; Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data scrambling method based on secure storage, characterized in that, The method includes: Obtaining target parameters for encrypting data to be encrypted; the target parameters include an address parameter and a key parameter; Performing a first transformation operation on the data to be encrypted and the address parameter according to the data to be encrypted and the address parameter to obtain first-transformed data, and performing a second transformation operation on the key parameter according to the key parameter to obtain second-transformed data; Performing an exclusive OR process on the first-transformed data and the second-transformed data according to the first-transformed data and the second-transformed data to obtain target exclusive-OR data; Performing a third transformation operation on the target exclusive-OR data according to the target exclusive-OR data to obtain third-transformed data as the encrypted data corresponding to the data to be encrypted.

2. The data scrambling method based on secure storage according to claim 1, wherein The performing a first transformation operation on the data to be encrypted and the address parameter according to the data to be encrypted and the address parameter to obtain first-transformed data includes: Performing an address transformation operation on the address parameter according to the address parameter to obtain a transformed address parameter; Performing an exclusive OR process on the transformed address parameter and the data to be encrypted according to the transformed address parameter and the data to be encrypted to obtain first exclusive-OR data; Performing multiple rounds of transformation operations on the first exclusive-OR data according to the first exclusive-OR data to obtain transformed exclusive-OR data as the first-transformed data corresponding to the data to be encrypted and the address parameter.

3. The data scrambling method based on secure storage according to claim 2, wherein The performing an address transformation operation on the address parameter according to the address parameter to obtain a transformed address parameter includes: Determining a bit width parameter of the data to be encrypted, and determining a bit width transformation requirement parameter corresponding to the address parameter according to the bit width parameter; Performing a bit width transformation operation on the address parameter according to the bit width transformation requirement parameter to obtain a bit width-transformed address parameter; Performing a bit scrambling operation on the bit width-transformed address parameter according to the bit width-transformed address parameter to obtain a bit-scrambled address parameter as the transformed address parameter corresponding to the address parameter.

4. The data scrambling method based on secure storage according to claim 2, wherein The performing multiple rounds of transformation operations on the first exclusive-OR data according to the first exclusive-OR data to obtain transformed exclusive-OR data as the first-transformed data corresponding to the data to be encrypted and the address parameter includes: Determining a round execution order parameter corresponding to each first target transformation method according to a plurality of preset first target transformation methods; all the first target transformation methods at least include a first bit scrambling transformation method, a second bit scrambling transformation method, a first row transformation method, and a first column transformation method, and the input data bit width parameter corresponding to the first bit scrambling transformation method is different from the input data bit width parameter corresponding to the second bit scrambling transformation method; Performing multiple rounds of transformation operations on the first exclusive-OR data according to the round execution order parameters corresponding to all the first target transformation methods to obtain transformed exclusive-OR data as the first-transformed data corresponding to the data to be encrypted and the address parameter.

5. The data scrambling method based on secure storage according to claim 4, wherein The key parameters include register transfer level key parameters, netlist level fixed key parameters, and chip identification parameters; Among them, the second transformation operation on the key parameters according to the key parameters to obtain the second transformed data includes: Performing a fusion operation on the netlist level fixed key parameters and the chip identification parameters according to the netlist level fixed key parameters and the chip identification parameters to obtain a fused parameter; Performing an exclusive OR (XOR) operation on the fused parameter and the register transfer level key parameters according to the fused parameter and the register transfer level key parameters to obtain the second XORed data; Performing a bit scrambling operation on the second XORed data according to the second XORed data to obtain scrambled key data; Performing a constant transformation operation on the scrambled key data according to a preset first constant table and the scrambled key data to obtain the constant transformed key data, which is used as the second transformed data corresponding to the key parameters.

6. The data scrambling method based on secure storage according to claim 5, wherein The third transformation operation on the target XORed data according to the target XORed data to obtain the third transformed data as the encrypted data corresponding to the data to be encrypted includes: Determining the round execution order parameters corresponding to each of the second target transformation methods according to a plurality of preset second target transformation methods; all the second target transformation methods at least include a second row transformation method, a second column transformation method, and a constant table transformation method; Performing a multi-round transformation operation on the target XORed data according to the round execution order parameters corresponding to all the second target transformation methods to obtain the third transformed data as the encrypted data corresponding to the data to be encrypted.

7. The data scrambling method based on secure storage according to claim 6, wherein The method further includes: Performing a multi-round inverse transformation operation on the encrypted data according to the encrypted data and the round execution order parameters corresponding to all the second target transformation methods to obtain the first inverse transformed data; Performing an XOR operation on the first inverse transformed data and the second transformed data according to the first inverse transformed data and the second transformed data to obtain the third XORed data; Performing a multi-round inverse transformation operation on the third XORed data according to the third XORed data and the round execution order parameters corresponding to all the first target transformation methods to obtain the second inverse transformed data; Performing an XOR operation on the second inverse transformed data and the first transformed data according to the second inverse transformed data and the first transformed data to obtain the fourth XORed data as the decrypted data corresponding to the encrypted data.

8. A data scrambling device based on secure storage, characterized in that, The device includes: An acquisition module, configured to acquire target parameters for encrypting data to be encrypted; the target parameters include address parameters and key parameters; A first transformation module, configured to perform a first transformation operation on the data to be encrypted and the address parameters according to the data to be encrypted and the address parameters to obtain the first transformed data; A second transformation module, configured to perform a second transformation operation on the key parameters according to the key parameters to obtain the second transformed data; A data exclusive-OR module, configured to perform an exclusive-OR operation on the first transformed data and the second transformed data according to the first transformed data and the second transformed data, so as to obtain target exclusive-OR data; A third transformation module, configured to perform a third transformation operation on the target exclusive-OR data according to the target exclusive-OR data, so as to obtain third transformed data, which is used as the encrypted data corresponding to the data to be encrypted.

9. A data scrambling device based on secure storage, characterized in that, The device includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory and executes the data scrambling method based on secure storage according to any one of claims 1-7.

10. A computer storage medium, characterized in that, The computer storage medium stores computer instructions, which are used to execute the data scrambling method based on secure storage according to any one of claims 1-7 when being called.