Password instruction execution method and device, processor and computer equipment

By introducing a packaged key structure into the cryptographic instruction set, including the ciphertext key, integrity tag, and additional key information, the security risk of plaintext key input in the traditional cryptographic instruction set is resolved, the secure storage and use of the key within the processor is achieved, and data security is improved.

CN120675703APending Publication Date: 2025-09-19HYGON YUNXIN INTEGRATED CIRCUIT DESIGN (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510735006.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In traditional cryptographic instruction sets, keys are entered in plain text, which poses a security risk of being stolen through malware attacks or physical detection, resulting in a high risk of data leakage.

Method used

A packaged key structure is used, including a ciphertext key, an integrity tag, and additional key information. The original key is encrypted using the key package key inside the processor, and integrity calculation is performed to generate a packaged key, which is only unsealed and used inside the processor.

Benefits of technology

It improves the security of keys during storage, transmission and use, prevents keys from being tampered with and used without authorization, and enhances the security protection capabilities during the execution of cryptographic instructions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675703A_ABST
    Figure CN120675703A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a password instruction execution method and device, a processor and computer equipment, and the method comprises the steps: obtaining a current password instruction in a password instruction set of the processor, the current password instruction corresponding to a current operation demand of the processor, and the current operation demand comprises the generation of a packaged key or the use of the packaged key; wherein the packaged secret key comprises a ciphertext secret key, an integrity label and secret key additional information; the ciphertext key is obtained by encrypting an original key of a plaintext based on a key packaging key of the processor, and the original key is used for data encryption or data decryption; the integrity label is obtained by performing integrity calculation on the original key, the key additional information and the key authorization code based on the key encapsulation key, and the key authorization code is a use permission certificate of the encapsulated key; and executing an instruction execution process of the current password instruction to generate an encapsulated key or use the encapsulated key. According to the embodiment of the invention, the security of the key in the password instruction execution process can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of processor technology, and specifically to a method, apparatus, processor, and computer device for executing cryptographic instructions. Background Art

[0002] A cryptographic instruction set is a collection of instructions used by processors like the CPU (Central Processing Unit) to perform cryptographic operations like encryption and decryption. Cryptographic instructions are the specific instructions within a cryptographic instruction set. Keys, as the core confidential information in cryptographic algorithms, are fundamental to ensuring encryption and decryption security. In traditional cryptographic instruction sets, keys are typically input as plaintext instructions, along with the data, during each cryptographic operation. While this approach is simple to implement, the plaintext nature of the key makes it vulnerable to interception or theft through threats like malware attacks or physical detection, posing a significant security risk.

[0003] Therefore, although cryptographic instruction sets are widely used in data encryption and decryption, their traditional design presents security risks due to the key input method. A key leak directly leads to data exposure. Therefore, protecting the key during instruction execution is crucial for improving data security. Therefore, improving the design of cryptographic instruction sets to enhance the key security during cryptographic instruction execution has become a pressing technical challenge for those skilled in the art. Summary of the Invention

[0004] In view of this, embodiments of the present application provide a method, apparatus, processor, and computer device for executing cryptographic instructions to enhance the security of keys during the execution of cryptographic instructions.

[0005] To achieve the above objectives, the embodiments of the present application provide the following technical solutions.

[0006] In a first aspect, an embodiment of the present application provides a method for executing a cryptographic instruction, comprising:

[0007] Obtaining a current cryptographic instruction in a cryptographic instruction set of the processor, the current cryptographic instruction corresponding to a current computational requirement of the processor, the current computational requirement including generating or using a packaged key; wherein the packaged key includes a ciphertext key, an integrity tag, and key additional information; the ciphertext key is obtained by encrypting a plaintext original key based on a key encapsulation key within the processor, the original key being used for data encryption or data decryption; the integrity tag is obtained by performing integrity calculation on the original key, key additional information, and a key authorization code based on the key encapsulation key, the key authorization code corresponding to the packaged key and being a credential for permission to use the packaged key;

[0008] Execute the instruction execution flow of the current cryptographic instruction to generate a wrapping key or use a wrapping key.

[0009] In a second aspect, an embodiment of the present application provides a device for executing a cryptographic instruction, comprising:

[0010] An instruction acquisition module is configured to acquire a current cryptographic instruction from a cryptographic instruction set of a processor, the current cryptographic instruction corresponding to a current computational requirement of the processor, the current computational requirement including generating or using a packaged key; wherein the packaged key includes a ciphertext key, an integrity tag, and key additional information; the ciphertext key is obtained by encrypting a plaintext original key based on a key encapsulation key within the processor, the original key being used for data encryption or data decryption; the integrity tag is obtained by performing integrity calculation on the original key, key additional information, and a key authorization code based on the key encapsulation key; the key authorization code corresponds to the packaged key and is a credential for permission to use the packaged key;

[0011] The instruction execution module is used to execute the instruction execution process of the current cryptographic instruction to generate a packaged key or use the packaged key.

[0012] In a third aspect, an embodiment of the present application provides a processor having a cryptographic instruction set, wherein when the cryptographic instructions in the cryptographic instruction set are executed by the processor, the method for executing the cryptographic instructions as described in the first aspect above is implemented; or, the processor includes an execution device for the cryptographic instructions as described in the second aspect above.

[0013] In a fourth aspect, an embodiment of the present application provides a computer device, comprising a processor, wherein the processor is the processor as described in the third aspect above; the computer device also includes a memory, wherein the memory stores a cryptographic instruction set, and when the cryptographic instructions in the cryptographic instruction set are executed by the processor, the execution method of the cryptographic instructions as described in the first aspect above is implemented.

[0014] It can be seen that the cryptographic instructions in the cryptographic instruction set provided by the embodiment of the present application support the generation of encapsulated keys or the use of encapsulated keys, and the encapsulated keys cannot be used directly and must undergo integrity verification before they can be used; specifically, the encapsulated key includes a ciphertext key, an integrity label and key additional information; the ciphertext key is obtained by encrypting the original plaintext key based on the key encapsulation key, wherein the original key is used for data encryption or data decryption, so that the ciphertext key is not stored or transmitted in plaintext form, but is encrypted based on the key encapsulation key inside the processor and can only be unsealed inside the processor; at the same time, the integrity label is obtained by performing integrity calculation on the original key, key additional information and key authorization code based on the key encapsulation key, and the key authorization code corresponds to the encapsulated key, which is the permission certificate for the use of the encapsulated key. That is to say, the embodiment of the present application deeply binds the authorization check and integrity verification of the key authorization code in the encapsulated key structure, effectively improving the key security during the execution of the cryptographic instructions. Specifically, when generating the encapsulated key, the key encapsulation key is used to encrypt the original key to form a ciphertext key, and the integrity calculation is performed on the original key, key additional information and key authorization code to generate an integrity tag. Since the integrity tag is bound to the information of the key authorization code, when unsealing or using the encapsulated key, as long as the integrity check of the integrity tag passes, it means that the key authorization code provided when using the encapsulated key is correct. On the contrary, if the key authorization code provided when using the encapsulated key is wrong, even if the encapsulated key has not been tampered with, it cannot pass the integrity check, which can prevent the unauthorized and illegal use of the encapsulated key. The embodiment of the present application can achieve dual verification of the content consistency and usage authority of the encapsulated key based on the integrity verification of the integrity tag without leaking the plaintext key, ensuring the non-forgeability and non-tamperability of the key encapsulation during storage, transmission and use, and enhancing the security protection capability during the execution of cryptographic instructions.

[0015] At the same time, the key encapsulation and usage process is controlled by cryptographic instructions, which isolates external interference and improves anti-attack capabilities. That is to say, the entire encapsulation or unsealing process is integrated into the processor's cryptographic instruction execution process, and the key encapsulation key, decryption process and integrity verification logic cannot be accessed from the outside. This instruction-level encapsulation limits the key lifecycle management to the trusted boundary. Even if the attacker obtains the encapsulated key, due to the lack of the key encapsulation key and the correct key authorization code, it is impossible to pass the integrity check or restore the plaintext key, thus forming a protective barrier for key protection and improving the security level of key management.

[0016] Therefore, the embodiments of the present application can improve the security of the key during the execution of cryptographic instructions. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.

[0018] Figure 1 The following is the execution flow chart of the key encapsulation instruction.

[0019] Figure 2 This is an example diagram of the execution of the key encapsulation instruction.

[0020] Figure 3 Another execution flow chart of the key encapsulation instruction.

[0021] Figure 4 Another example diagram of executing the key encapsulation instruction.

[0022] Figure 5 Example graph for key wrapping key generation.

[0023] Figure 6 The execution flow chart of the data encryption instruction.

[0024] Figure 7 This is an example diagram of the execution of data encryption instructions.

[0025] Figure 8 Execution flow chart of the data decryption instruction.

[0026] Figure 9 An example diagram of the execution of the data decryption instruction.

[0027] Figure 10 A flowchart of a method for executing a password instruction.

[0028] Figure 11 A block diagram of a device for executing cryptographic instructions. DETAILED DESCRIPTION

[0029] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0030] Traditional cryptographic instruction sets are essentially stateless functions. Each time a program uses a cryptographic instruction to perform a cryptographic operation, it must pass a plaintext key and data as instruction inputs. These plaintext keys and data are then passed into the processor as operands for execution, exposing the risk of key theft. For ease of understanding, Table 1 below illustrates an example diagram of a data encryption instruction, using data encryption instructions as an example. A data encryption instruction is a type of cryptographic instruction in a cryptographic instruction set used to perform data encryption operations.

[0031] Command name Input operand 1 Input operand 2 Output operands Data Enc Plaintext data Plaintext key Ciphertext data

[0032] Table 1

[0033] As shown in Table 1, the Data Encryption instruction (Data Enc), a cryptographic instruction set, requires two input operands: the plaintext data to be encrypted and the plaintext key required to perform the encryption operation. These two operands serve as input parameters to the processor's internal cryptographic execution unit. After processing using a specific encryption algorithm, the output operands are the encrypted ciphertext data.

[0034] The design of traditional cryptographic instruction sets presents significant security risks. First, the key, as an input operand, is typically stored in plaintext in registers or memory before execution. This poses the risk of being read by malicious programs or intercepted by operating system-level attacks before it is loaded into the processor. Attackers can access these registers or memory areas through debugging interfaces, system vulnerabilities, or high-privilege malicious code, directly obtaining sensitive key information.

[0035] Furthermore, during the execution of cryptographic instructions, the processor's key processing path (such as data bus transfer from registers to execution units) can be exploited by side-channel attacks (such as power consumption analysis and electromagnetic radiation analysis), thereby inferring the key content. Furthermore, modern processors may have microarchitecture-level vulnerabilities, allowing attackers to obtain residual key information in the cache across processes or virtual machines, further increasing the risk of key leakage. Therefore, traditional cryptographic instructions that use plaintext keys as instruction input have security flaws and are not suitable for direct use in high-security scenarios.

[0036] Based on this, the embodiments of the present application consider improving the design of the cryptographic instruction set and using the wrapped key (WK) as the operand of the cryptographic instruction instead of the plaintext key. The wrapped key consists of the following three parts: the ciphertext key, the integrity tag, and the key additional information;

[0037] A ciphertext key is a key in ciphertext form obtained by encrypting a plaintext key using an encryption algorithm (such as a cryptographic algorithm with authentication). Even if an attacker intercepts the ciphertext key, they cannot decrypt it to obtain the plaintext key.

[0038] The integrity tag is used to verify whether the encapsulated key has been tampered with during storage or transmission. The integrity tag can be generated through integrity calculation (such as message authentication code, hash check value or digital signature). Only the encapsulated key that passes the integrity verification of the integrity tag can be used legally, thus preventing man-in-the-middle attacks or tampering.

[0039] Key additional information is used to identify the key usage context and policy restrictions, such as key usage identifier, algorithm type, key ID, version number, etc. This additional information will not be encrypted, but will be verified together with the authentication data when the key is used to ensure that the key is called in the correct usage scenario.

[0040] By encapsulating the key in the above structure and participating in the execution of cryptographic instructions, the key security at the instruction level can be improved. Specifically, the key is stored and transmitted in an encrypted state in the cryptographic instruction, avoiding the exposure of the key in plain text during instruction input, register loading or bus transmission, thereby effectively preventing side-channel attacks, memory scanning and the exploitation of microarchitecture vulnerabilities; secondly, the integrity label ensures the authenticity and non-tampering of the key content, preventing illegal calculations or information leakage caused by malicious tampering with instruction input; finally, the key is attached with information to achieve usage scenario binding and context limitation. Even if the key encapsulation content is copied, it cannot be abused outside the original usage environment.

[0041] Therefore, introducing the encapsulated key as the operand of the cryptographic instruction not only meets the functional integrity requirements, but also structurally establishes a full-link security protection mechanism from the key source to the key transfer to the key use, thereby improving the key protection capability during the execution of the cryptographic instruction.

[0042] In an optional implementation, the cryptographic instruction set provided in the embodiments of the present application may include multiple cryptographic instructions, including but not limited to: key encapsulation instructions, data encryption instructions, and data decryption instructions. The cryptographic encapsulation instructions are used to generate an encapsulated key, with the encapsulated key as the output operand. Based on the different sources of the original key encapsulated by the cryptographic encapsulation instructions, the cryptographic encapsulation instructions can be divided into direct key encapsulation instructions and key generation and encapsulation instructions, which will be explained in detail later. The data encryption instructions and data decryption instructions are cryptographic instructions that use the encapsulated key to encrypt and decrypt data, with the encapsulated key as the input operand.

[0043] To facilitate understanding of the key encapsulation process, the following describes the composition of the key encapsulation instruction and the key encapsulation process.

[0044] The key encapsulation instruction is an instruction in the cryptographic instruction set provided in the embodiment of the present application, which is used to encapsulate the original key (such as a plaintext key) to generate a security-guaranteed encapsulated key, so that the encapsulated key can be safely used by cryptographic instructions such as data encryption instructions and data decryption instructions that use the encapsulated key.

[0045] The raw key encapsulated by the key encapsulation instruction refers to the key content in a plaintext state. The raw key may include, but is not limited to, an externally input plaintext key or a random plaintext key generated by the processor's internal random number generator (TRNG). In other words, the raw key can be obtained in two ways: the first is an externally input plaintext key, such as a raw key provided in plaintext by a user program or system interface, referred to as an externally input plaintext key; the second is generated by a TRNG module integrated within the processor, using a random number generated by the TRNG as the raw key, referred to as a random plaintext key. The aforementioned random plaintext key approach achieves closed-loop control of unpredictability and ciphertext encapsulation during the key generation phase. Compared to the external plaintext input method, the key generated by the TRNG does not pass through an externally accessible path, thus further enhancing key security when combined with the encapsulation mechanism. Since the raw key is in plaintext, it can be represented as a PK (Plaintext Key), i.e., the raw key in plaintext form, which has not been encrypted, encapsulated, or otherwise protected.

[0046] For ease of explanation, the key wrapping instruction that wraps an externally input plaintext key is called a direct key wrapping instruction (Key Wrap). In this case, the processor does not need to generate the original key internally. Instead, the original key is provided by the external input. The processor then executes the key wrapping instruction directly based on the original key provided by the external input to achieve key wrapping. The key wrapping instruction that wraps a random plaintext key is called a key generation and wrapping instruction (Key Gen Wrap). In this case, the processor first generates a random plaintext key internally through a TRNG and then performs the key wrapping.

[0047] Taking the direct key wrap instruction (Key Wrap) as an example, the following Table 2 exemplarily shows an example diagram of the structure of the direct key wrap instruction.

[0048]

[0049] Table 2

[0050] It can be seen that the direct key wrap instruction (Key Wrap) includes 3 input operands and 1 output operand; the 3 input operands include the external input plaintext key, key additional information (AAD, Associated Authenticated Data), and key authorization code (AC, Authorization Code), and the output operand includes the wrapped key (WK).

[0051] Among them, the key additional information is auxiliary data related to the key usage context, including key purpose, algorithm type, key ID, version number and other information. This information will not be encrypted, but will be bound to the key encapsulation structure for integrity verification and context constraints.

[0052] The key authorization code is the credential information used to control and protect the usage rights of the encapsulated key. That is, the key authorization code corresponds to the encapsulated key, is the usage permission credential of the encapsulated key, and plays the role of access control of the encapsulated key. For example, each encapsulated key can be bound to a corresponding key authorization code. When the user or program subsequently wants to use the encapsulated key to perform cryptographic operations such as encryption and decryption, the correct key authorization code bound to the encapsulated key must be provided in the instruction call, otherwise the processor will refuse to execute the operation to ensure that the encapsulated key will not be abused without authorization.

[0053] Taking the key generation and packaging instruction (Key Gen Wrap) as an example, the following Table 3 exemplarily shows an example diagram of the composition of the key generation and packaging instruction.

[0054] Command name Input operand 1 Input operand 2 Output operands Key Gen Wrap Key additional information Key authorization code Wrapped key

[0055] Table 3

[0056] In the Key Gen Wrap instruction, the original key is not provided by external input, but is dynamically generated by the TRNG integrated inside the processor. Therefore, the original key generated by the TRNG can be directly passed to the processor's encapsulation logic as intermediate data, and together with the key additional information (AAD) and key authorization code (AC) as input operands to complete the key encapsulation. Therefore, the Key Gen Wrap instruction does not need to provide the original key as an input operand; thus, this design realizes the integrated processing of key generation and encapsulation, avoids the transmission or exposure of the original key in plaintext form in external paths, improves the security of the key life cycle from the source, and has more security advantages than the method of external plaintext key input.

[0057] As an optional implementation, during the execution of a key wrapping instruction, the processor may use an internal key wrapping key (KWK, Key Wrapping Key) to encrypt the original key to obtain a ciphertext key; use the key wrapping key to perform integrity calculation on the original key, key additional information, and key authorization code to obtain an integrity tag; and thereby form a wrapped key based on the ciphertext key, the integrity tag, and the key additional information as the output operand of the key wrapping instruction.

[0058] Among them, the key encapsulation key (KWK) is a core key inside the processor used to encrypt and protect the original key (PK). The key encapsulation key (KWK) is not visible to the user and cannot be directly controlled or read by the user. Instead, it is automatically generated and managed by the processor.

[0059] In an optional implementation, a key wrapping key (KWK) may be generated based on chip secret (CS) information and platform secret (PS) information; the chip secret information is referred to as chip secret (CS) and the platform secret information is referred to as platform secret (PS);

[0060] Chip Secret (CS) is a highly secure secret information embedded within the chip by the chip manufacturer during the chip manufacturing phase. Once the chip leaves the factory, CS cannot be altered and cannot be accessed or read from outside. It can only be used for key-related operations within the processor. As part of the source of the Key Wrapping Key (KWK), CS ensures that key operations on each chip are device-bound and tamper-resistant. Furthermore, if multiple chips need to support key migration or shared use (e.g., supporting a certain type of key across the same series of devices), chip manufacturers can design the same CS for the same model of chip. Because CS is hardware-invisible and read-only, it is an important component for implementing functions such as wrapping key security and hardware-authenticated root of trust.

[0061] Platform Secrets (PS) are key information set by the platform administrator in the system firmware or protected storage to identify the platform or system. PS is not accessible to ordinary users and cannot be read or modified by user programs.

[0062] When PS and CS participate together in the key encapsulation key (KWK) generation process, a platform- and chip-specific key encapsulation key (KWK) can be generated. This allows the key encapsulation key (KWK) to be bound to a specific platform environment and chip environment. Even if the chip is the same, the KWKs on different platforms are different, further enhancing key usage control, preventing forgery of the encapsulation process or reconstruction of valid key encapsulation in an illegal environment, and improving platform credibility and system integrity protection capabilities.

[0063] For ease of understanding, take the direct key wrap instruction (Key Wrap) as an example. Figure 1 An exemplary flowchart of the execution of the key encapsulation instruction is shown in FIG. Figure 1 , the process may include the following steps.

[0064] Step S110: Obtain a direct key encapsulation instruction, where the direct key encapsulation instruction includes a plurality of input operands, and the plurality of input operands include an external input plaintext key, key additional information, and a key authorization code.

[0065] Step S120: Use the processor's internal key encapsulation key to encrypt the external input plaintext key to obtain a ciphertext key.

[0066] Step S130: Use the key encapsulation key to perform integrity calculation on the external input plaintext key, key additional information and key authorization code to obtain an integrity tag.

[0067] Step S140: Based on the ciphertext key, the integrity tag, and the key additional information, a packaged key is formed as an output operand of the direct key package instruction.

[0068] The key wrapping key (KWK) plays two main roles in the key wrapping process:

[0069] Encrypt the original key (PK), for example, using a cryptographic algorithm with authentication such as GCM (Galois Counter Mode) to generate a ciphertext key. This way, even if the encryption key is obtained externally, the original key PK cannot be restored unless the KWK is obtained.

[0070] Generate an integrity tag. KWK is used to calculate the integrity tag. The integrity tag is calculated based on PK, key additional information (AAD) and key authorization code (AC) to ensure the correctness and authorization security of the entire encapsulation result.

[0071] Due to the existence of the KWK, the embodiments of the present application can fundamentally isolate the channel between external accessors and the plaintext key. Specifically, the key encapsulation process is completed within the chip, and the KWK never leaves the chip. Even if an attacker masters the encapsulation logic, the KWK cannot be reconstructed. The KWK generated based on CS and PS can ensure that the key encapsulation on each device is platform-unique and cloning-resistant. Even if the key WK is disclosed after encapsulation, the attacker cannot decrypt or forge the key structure without the KWK, which greatly improves the overall security level.

[0072] It should be noted that the Key Authorization Code (AC) is a secret credential used to control the use of the wrapped key (WK). Only users or programs holding the correct AC can use the WK to perform encryption and decryption operations. During encapsulation, although the AC participates in the calculation of the integrity check (for example, AC participates in the generation of the integrity tag in GCM mode), it is not encrypted or packaged into the final output WK. This is because the AC is a security credential and should not be disclosed. If the AC is included in the WK, since the WK is publicly available, any attacker with access to the WK can also obtain the AC, thereby bypassing permission verification. Therefore, the AC is designed not to appear in the WK, and the integrity tag is calculated in conjunction with the AC. Therefore, even if an attacker obtains the contents of the WK, they cannot determine the AC, and thus cannot use the WK to perform encryption and decryption operations without authorization. In other words, excluding the AC from the WK and associating it with the calculation of the integrity tag ensures that the WK can be safely disclosed while keeping the AC invisible and uninferable, thereby achieving a strong security separation between permission control and key use.

[0073] For example, take the direct key wrap instruction (Key Wrap) as an example, Figure 2 The following example shows the execution example of the key encapsulation instruction, which can be used for reference. Figure 2 As shown in the figure, the external inputs PK, AC, and ADD serve as the input operands of Key Wrap. When executing Key Wrap, the processor uses KWK to encrypt the external input PK to generate a ciphertext key. KWK is then used to perform integrity calculation on ADD, AC, and the external input PK to generate an integrity tag. Thus, ADD, the integrity tag, and the ciphertext key form WK, which serves as the output operand of Key Wrap, completing the execution of Key Wrap.

[0074] In an optional implementation, the processor may use a cryptographic algorithm with authentication to complete the encryption of the external input PK based on KWK, as well as the integrity calculation of ADD, AC, and the external input PK; wherein, the cryptographic algorithm with authentication refers to a cryptographic algorithm that provides both confidentiality and integrity authentication; that is, the cryptographic algorithm with authentication can not only perform encryption and decryption, but also generate an authentication tag to verify whether the data has been tampered with or forged.

[0075] For ease of understanding, let's take the key generation and packaging instruction (Key Gen Wrap) as an example. Figure 3 Another execution flow chart of the key encapsulation instruction is shown as an example. Figure 3 , the process may include the following steps.

[0076] Step S310: Obtain a key generation and encapsulation instruction, wherein the key generation and encapsulation instruction includes multiple input operands, and the multiple input operands include key additional information and a key authorization code.

[0077] Step S320: Use the random number generator inside the processor to generate a random number as a random number plaintext key.

[0078] Step S330: Use the key encapsulation key inside the processor to encrypt the random number plaintext key to obtain the ciphertext key.

[0079] Step S340: Use the key encapsulation key to perform integrity calculation on the random number plaintext key, key additional information, and key authorization code to obtain an integrity tag.

[0080] Step S350: Based on the ciphertext key, the integrity tag, and the key additional information, an encapsulated key is formed as the output operand of the key generation and encapsulation instruction.

[0081] For example, take the key generation and packaging instruction (Key Gen Wrap) as an example, Figure 4 Another example diagram of the execution of the key encapsulation instruction is shown as an example, which can be used for reference. Figure 4 As shown in the figure, AC and ADD serve as the input operands of Key Gen Wrap. When executing Key Gen Wrap, the processor uses TRNG to generate a random number as the random number PK. The processor then uses KWK to encrypt the random number PK to generate a ciphertext key. KWK is used to perform integrity calculation on ADD, AC, and the random number PK to generate an integrity tag. Thus, ADD, the integrity tag, and the ciphertext key form WK, which serves as the output operand of Key Gen Wrap, completing the execution of Key Gen Wrap.

[0082] As can be seen, compared to Key Wrap, Key Gen Wrap is a key encapsulation instruction that does not rely on external plaintext keys. Key Gen Wrap uses the processor's internal random number generator to automatically generate an unpredictable random key (i.e., a random number PK). The random key is then encrypted and protected using an algorithm such as a cryptographic algorithm with authentication. The random key, along with key additional information AAD and key authorization code AC, is integrity-protected using an algorithm such as a cryptographic algorithm with authentication, ultimately generating a structurally complete and securely encapsulated encapsulated key WK. Compared to Key Wrap, which requires external plaintext key input, Key Gen Wrap can further enhance the security of key generation and management because the key is never transmitted through an external path.

[0083] The following describes the process of generating the key encapsulation key (KWK). Figure 5 The following diagram shows an example of how to generate a key encapsulation key, which can be used for reference. Figure 5 As shown, the chip secret CS and the platform secret PS can generate a key wrapping key (KWK) through a key derivation function such as KDF (Key Derivation Function).

[0084] In an embodiment of the present application, the generation process of the key encapsulation key (KWK) is a key step in ensuring the security of the key encapsulation mechanism. In order to prevent the KWK from being leaked or exposed to external access paths, the embodiment of the present application generates the key encapsulation key (KWK) inside the processor through the chip secret CS and the platform secret PS through a key derivation function (such as KDF). In other words, the generation process of the key encapsulation key (KWK) depends on two high-security input sources: the chip secret (CS) and the platform secret (PS). Specifically, CS and PS are used as inputs, and KWK is output after KDF calculation. Since KWK is always generated inside the processor and is not exposed in any external storage or interface, the anti-attack capability of the entire system is greatly improved.

[0085] It should be noted that the chip secret (CS) is an identifier preset inside the chip by the chip manufacturer during the chip production process. It remains unchanged during the life cycle of the chip and cannot be read or modified from outside the chip. Due to its extremely high security, CS can provide a trusted chip-level root for the derivation of the key encapsulation key. At the same time, in order to support the shared use of the encapsulated key (WK) between devices of the same manufacturer or the same chip series, the chip manufacturer can choose to preset the same CS in a batch of chips (such as the same model chip). The platform secret (PS) is a sensitive configuration information in the device firmware controlled by the platform. It cannot be modified or accessed by the user and is used to introduce system-level differences. The embodiment of the present application can ensure that even if the attacker has platform management privileges, he cannot derive the KWK by modifying the PS. This is guaranteed by the consistency and unidirectionality of the key derivation function. Specifically, the same KWK can only be generated when the combination of CS and PS used for derivation is exactly the same as before; if any input (CS or PS) changes, the derived KWK will be completely different from the original. At the same time, the design of KDF ensures that changes in PS will not leak any information about CS, further strengthening the protection of chip-level secrets and making the KWK generation process highly resistant to analysis and reverse engineering.

[0086] The embodiment of the present application can further use the encapsulated key to encrypt and decrypt data, so that the cryptographic instruction set provided by the embodiment of the present application can further include data encryption instructions and data decryption instructions.

[0087] The following describes the composition and execution process of the data encryption instruction (Data Enc).

[0088] Taking the data encryption instruction as an example, the following Table 4 exemplarily shows an example diagram of the composition of the data encryption instruction, wherein the data encryption instruction is used to encrypt data using the encapsulated key.

[0089]

[0090] Table 4

[0091] The plaintext data (PT) is the plaintext that is expected to be encrypted by the data encryption instruction (Data Enc), such as the plaintext to be encrypted;

[0092] The key authorization code is used to verify whether the caller of the data encryption instruction has the right to use the encapsulated key (WK). The key authorization code corresponds to the encapsulated key. Only users or programs holding the correct key authorization code can call the encapsulated key (WK) to encrypt data.

[0093] The relevant contents of the encapsulated key can refer to the previous description, which mainly includes the ciphertext key, integrity tag and key additional information.

[0094] In the data encryption instruction, plaintext data, key authorization code and encapsulated key are used as input operands. When executing the data encryption instruction, the processor can first verify the integrity label of the encapsulated key to ensure that the encapsulated key has not been tampered with. Since the key authorization code is associated with the generation of the integrity label of the encapsulated key, as long as the integrity verification passes, it means that the encapsulated key has not been tampered with, and it also means that the key authorization code in the data encryption instruction is correct and has the permission to use the encapsulated key, so the authorization verification of the encapsulated key passes; at this time, the original key (PK) obtained by decapsulating the encapsulated key using the key encapsulation key (KWK) inside the processor can be used to encrypt the plaintext data to obtain ciphertext data (CT). The encryption process of the plaintext data can be implemented using standard encryption algorithms such as AES. For example, the key additional information in the encapsulated key indicates the algorithm type for encrypting the plaintext data; then, the ciphertext data is returned as the output operand of the data encryption instruction to complete the execution of the data encryption instruction.

[0095] For further understanding, Figure 6 The execution flow chart of the data encryption instruction is shown as an example. Figure 6 , the process may include the following steps.

[0096] Step S610: Obtain a data encryption instruction, where the data encryption instruction includes a plurality of input operands, and the plurality of input operands include plaintext data, a key authorization code, and an encapsulated key.

[0097] Step S620: Based on the key authorization code and the encapsulated key in the data encryption instruction, perform integrity verification on the integrity tag in the encapsulated key.

[0098] Step S630: Determine whether the integrity verification is passed. If so, execute step S640; if not, execute step S650.

[0099] During the creation process of the encapsulated key, the embodiment of the present application uses the key encapsulation key to perform integrity calculation on the original key, key additional information and key authorization code to obtain an integrity tag, so that the integrity tag is carried in the encapsulated key; during the data encryption process, the embodiment of the present application can perform integrity verification on the integrity tag in the encapsulated key of the data encryption instruction to identify whether the encapsulated key has been tampered with after creation, and at the same time identify whether the key authorization code of the data encryption instruction is legal.

[0100] In an optional implementation, the embodiment of the present application can use a cryptographic algorithm with authentication (such as GCM) to decrypt the ciphertext key in the encapsulated key of the data encryption instruction using the key encapsulation key inside the processor to obtain a decrypted key; then, through a cryptographic algorithm with authentication (such as GCM), use the key encapsulation key to recalculate the integrity of the decrypted key, the key authorization code of the data encryption instruction, and the key additional information in the encapsulated key of the data encryption instruction to obtain a regenerated integrity tag; the regenerated integrity tag is compared with the integrity tag in the encapsulated key; if the comparison is consistent, the integrity verification is passed, indicating that the encapsulated key has not been tampered with and the key authorization code of the data encryption instruction is legal (a legal key authorization code indicates that the user has the permission to use the encapsulated key), and the subsequent data encryption process can continue; if the comparison is inconsistent, the integrity verification fails, indicating that the encapsulated key has been tampered with and / or the key authorization code of the data encryption instruction is illegal. At this time, the data encryption instruction can be exited (i.e., the execution of the data encryption instruction is terminated) and an error message is returned.

[0101] It should be noted that, during the creation of the encapsulated key, the embodiment of the present application uses the plaintext original key, key additional information, and key authorization code to generate an integrity tag using a cryptographic algorithm with authentication, such as GCM. During the integrity verification phase, the embodiment of the present application extracts the ciphertext key, integrity tag, and key additional information from the encapsulated key, decrypts the ciphertext key using the key encapsulation key, and obtains the decrypted key (if the encapsulated key has not been tampered with, the decrypted key should be consistent with the original key used in the creation of the encapsulated key). The key encapsulation key is then used to recalculate the integrity tag using the decrypted key, the key additional information in the encapsulated key, and the key authorization code in the data encryption instruction. If the recalculated integrity tag is consistent with the integrity tag in the encapsulated key, it indicates that the integrity tag is generated by the same input (i.e., the original key, key additional information, and cryptographic authorization code), indicating that the encapsulated key has not been tampered with, and the key authorization code in the data encryption instruction is consistent with the cryptographic authorization code used in the creation of the encapsulated key. At this time, the data encryption instruction has the right to use the encapsulated key for data encryption processing.

[0102] In other words, the calculation of the integrity tag is bound to the key additional information and the key authorization code. If the integrity tag verification is successful, it means that the encapsulated key has not been modified, and the key authorization code of the data encryption instruction is consistent with the key authorization code used during encapsulation, indicating that the data encryption instruction has the right to use the encapsulated key.

[0103] Step S640: Use the decrypted key to encrypt the plaintext data to obtain ciphertext data as the output operand of the data encryption instruction; wherein the decrypted key is obtained by decrypting the ciphertext key in the encapsulated key using the key encapsulation key.

[0104] If the integrity verification passes, the authorization verification of the encapsulated key passes. The embodiment of the present application can decrypt the ciphertext key in the encapsulated key based on the key encapsulation key to obtain the decrypted key (consistent with the original key of the plaintext), perform encryption processing on the plaintext data, and obtain the ciphertext data as the output operand of the data encryption instruction, thereby completing the processing of the data encryption instruction.

[0105] Step S650: Exit the data encryption instruction and return an error message.

[0106] If the integrity verification fails, it means that the encapsulated key has been tampered with and / or the key authorization code of the data encryption instruction is illegal (an illegal key authorization code means that the user does not have permission to use the encapsulated key). The system terminates the execution of the encryption instruction and returns an error to prevent data leakage or illegal encryption of data.

[0107] For example, Figure 7The following example shows the execution example of the data encryption instruction, which can be used for reference. Figure 7 As shown, plaintext data PT, encapsulated key WK and key authorization code AC are input into the processor as input operands of the data encryption instruction; the processor uses the key encapsulation key KWK to decrypt the ciphertext key in the encapsulated key WK with a cryptographic algorithm with authentication to obtain a decrypted key; the decrypted key, the additional key information ADD in the encapsulated key WK, and the key authorization code AC in the data encryption instruction are used to regenerate an integrity tag based on the key encapsulation key KWK with a cryptographic algorithm with authentication; the regenerated integrity tag is compared with the integrity tag in the encapsulated key WK for integrity verification; if the integrity verification fails, the data encryption instruction is terminated and an error is returned; if the integrity verification passes, the decrypted key is used to encrypt the plaintext data PT to obtain ciphertext data CT as the output operand of the data encryption instruction.

[0108] The composition and execution process of the data decryption instruction are explained below.

[0109] Taking the data decryption instruction (Data Dec) as an example, the following Table 5 exemplarily shows an example diagram of the structure of the data decryption instruction, wherein the data decryption instruction is used to decrypt data using the encapsulated key.

[0110]

[0111] Table 5

[0112] The ciphertext data is ciphertext that is expected to be decrypted by the data decryption instruction, such as the ciphertext to be decrypted;

[0113] The key authorization code is used to verify whether the caller of the data decryption instruction has the right to use the encapsulation key (WK). The key authorization code corresponds to the encapsulation key. Only the data decryption instruction with the correct key authorization code can call the encapsulation key to perform data decryption processing;

[0114] The relevant contents of the encapsulated key can refer to the previous description, which mainly includes the ciphertext key, integrity tag and key additional information.

[0115] In the data decryption instruction, the ciphertext data, the key authorization code and the encapsulated key are used as input operands. When executing the data decryption instruction, the processor can first verify the integrity label of the encapsulated key to ensure that the encapsulated key has not been tampered with. Since the key authorization code is associated with the generation of the integrity label of the encapsulated key, as long as the integrity verification passes, it means that the encapsulated key has not been tampered with, and it also means that the key authorization code in the data decryption instruction is correct, so that the use authorization verification of the encapsulated key passes; at this time, the processor's internal key encapsulation key (KWK) can be used to decapsulate the encapsulated key to obtain the original key (PK), decrypt the ciphertext data, and obtain the plaintext data, and then return the plaintext data as the output operand of the data decryption instruction to complete the execution of the data decryption instruction.

[0116] For further understanding, Figure 8 The execution flow chart of the data decryption instruction is shown as an example. Figure 8 , the process may include the following steps.

[0117] Step S810: Obtain a data decryption instruction, where the data decryption instruction includes a plurality of input operands, and the plurality of input operands include ciphertext data, a key authorization code, and an encapsulated key.

[0118] Step S820: Based on the key authorization code and the encapsulated key in the data decryption instruction, perform integrity verification on the integrity tag in the encapsulated key.

[0119] Step S830: Determine whether the integrity verification is passed. If so, execute step S840; if not, execute step S850.

[0120] In an optional implementation, the embodiment of the present application can use a cryptographic algorithm with authentication (such as GCM) to decrypt the ciphertext key in the encapsulated key of the data decryption instruction using the key encapsulation key inside the processor to obtain a decrypted key; then, through a cryptographic algorithm with authentication (such as GCM), use the key encapsulation key to recalculate the integrity of the decrypted key, the key authorization code of the data decryption instruction, and the key additional information in the encapsulated key of the data decryption instruction to obtain a regenerated integrity tag; the regenerated integrity tag is compared with the integrity tag in the encapsulated key; if the comparison is consistent, the integrity verification is passed, indicating that the encapsulated key has not been tampered with and the key authorization code of the data decryption instruction is legal, and the subsequent data decryption process can continue; if the comparison is inconsistent, the integrity verification fails, indicating that the encapsulated key has been tampered with and / or the key authorization code of the data decryption instruction is illegal, and the data decryption instruction can be exited and an error message is returned.

[0121] Step S840: Use the decrypted key to decrypt the ciphertext data to obtain plaintext data as the output operand of the data decryption instruction; wherein the decrypted key is obtained by decrypting the ciphertext key in the encapsulated key using the key encapsulation key.

[0122] Step S850: Exit the data decryption instruction and return an error message.

[0123] For example, Figure 9 The following example shows the execution example of the data decryption instruction, which can be used for reference. Figure 9 As shown, the ciphertext data CT, the encapsulated key WK, and the key authorization code AC serve as input operands to the data decryption instruction and are input to the processor. The processor uses the key encapsulation key KWK to decrypt the ciphertext key in the encapsulated key WK using an authentication-based cryptographic algorithm to obtain the decrypted key. The decrypted key, the additional key information ADD in the encapsulated key WK, and the key authorization code AC in the data decryption instruction are then used to regenerate an integrity tag using an authentication-based cryptographic algorithm based on the key encapsulation key KWK. The regenerated integrity tag is compared with the integrity tag in the encapsulated key WK for integrity verification. If the integrity verification fails, the data decryption instruction is terminated and an error is returned. If the integrity verification passes, the ciphertext data CT is decrypted using the decrypted key to obtain the plaintext data PT as the output operand of the data decryption instruction. As can be seen, the execution process of the data decryption instruction is similar to that of the data encryption instruction, except that the data decryption instruction decrypts the ciphertext data, while the data encryption instruction encrypts the plaintext data.

[0124] In summary, the cryptographic instruction set provided in the embodiment of the present application may include a variety of cryptographic instructions, including: key encapsulation instructions, data encryption instructions, and data decryption instructions;

[0125] Among them, the key encapsulation instruction is used to generate the encapsulated key; the data encryption instruction is used to use the encapsulated key to encrypt data; the data decryption instruction is used to use the encapsulated key to decrypt data;

[0126] More specifically, key encapsulation instructions can be divided into: direct key encapsulation instructions and key generation and encapsulation instructions; among them, direct key encapsulation instructions use the external input plaintext key as the original key to achieve the generation of the encapsulated key; key generation and encapsulation instructions use the random number plaintext key generated by the random number generator inside the processor as the original key to achieve the generation of the encapsulated key.

[0127] That is to say, the cryptographic instructions in the cryptographic instruction set provided in the embodiment of the present application support the generation of encapsulated keys or the use of encapsulated keys, depending on the specific computing requirements of the processor. Based on this, in an optional implementation, Figure 10 The flowchart of the execution method of the password instruction provided in the embodiment of the present application is shown as an example. Figure 10 , the process may include the following steps.

[0128] Step S01: Obtain the current cryptographic instruction in the cryptographic instruction set of the processor, where the current cryptographic instruction corresponds to the current computing requirement of the processor, and the current computing requirement includes generating or using a packaged key; wherein the packaged key includes a ciphertext key, an integrity tag, and key additional information; the ciphertext key is obtained by encrypting the plaintext original key based on the key encapsulation key inside the processor, and the original key is used for data encryption or data decryption; the integrity tag is obtained by performing integrity calculation on the original key, key additional information, and key authorization code based on the key encapsulation key, and the key authorization code corresponds to the packaged key and is a credential for the use permission of the packaged key.

[0129] In the embodiment of the present application, the current cryptographic instruction refers to the specific cryptographic instruction that the processor selects to execute based on the current actual task. The current cryptographic instruction matches the current computing requirements of the processor. The computing requirements of the processor mainly include two categories:

[0130] Generate a wrapped key, that is, securely generate an encrypted and authorized key;

[0131] Using the encapsulation key, for example, encrypting or decrypting data using the encapsulation key.

[0132] Specifically, when the current computing requirement of the processor is to generate a wrapped key, the current cryptographic instruction can be a key wrapping instruction, which is used to trigger the key wrapping process: using the key wrapping key inside the processor to encrypt the plaintext original key to obtain a ciphertext key, wherein the original key is used for data encryption or data decryption, thereby encrypting the original key to obtain a ciphertext key and wrapping it in the wrapped key, so that the ciphertext key is not stored or transmitted in plaintext form; at the same time, based on the key wrapping key, the integrity of the plaintext original key, key additional information, and key authorization code (the key authorization code corresponds to the wrapped key and is a credential for the use permission of the wrapped key) is calculated to generate an integrity tag, so that the key authorization code, which serves as a credential for the use permission of the wrapped key, can be associated and bound with the integrity tag, and then the integrity tag is wrapped in the wrapped key, so that subsequent dual verification of the content consistency and use permission of the wrapped key based on the integrity tag can be achieved; then, the ciphertext key, integrity tag, and key additional information together constitute the wrapped key, which is used for subsequent authorization control and key call.

[0133] For more specific details about the key encapsulation instruction, please refer to the previous description and will not be expanded here.

[0134] When the current computing requirement of the processor is to use the encapsulated key, the current cryptographic instruction can be a data encryption instruction or a data decryption instruction, depending on the current purpose of the processor using the encapsulated key; the relevant content of the data encryption instruction and the data decryption instruction can be referred to the previous description and will not be expanded here.

[0135] Step S02: Execute the instruction execution process of the current cryptographic instruction to generate an encapsulated key or use the encapsulated key.

[0136] After calling the current cryptographic instruction, the embodiment of the present application can execute the instruction execution process of the current cryptographic instruction, thereby generating a packaged key or using the packaged key to adapt to the current computing requirements of the processor.

[0137] If the current cryptographic instruction is a direct key encapsulation instruction, the current cryptographic instruction is executed according to the instruction execution process of the direct key encapsulation instruction to generate an encapsulated key as the output operand of the direct key encapsulation instruction. The relevant content of the instruction execution process of the direct key encapsulation instruction can be referred to the previous description and will not be expanded here.

[0138] If the current cryptographic instruction is a key generation and encapsulation instruction, the current cryptographic instruction is executed according to the instruction execution flow of the key generation and encapsulation instruction to generate an encapsulated key as the output operand of the key generation and encapsulation instruction. The relevant content of the instruction execution flow of the key generation and encapsulation instruction can be referred to the previous description and will not be expanded here.

[0139] If the current cryptographic instruction is a data encryption instruction, the current cryptographic instruction is executed according to the instruction execution process of the data encryption instruction to encrypt the plaintext data using the encapsulated key, and the ciphertext data is obtained as the output operand of the data encryption instruction. The relevant content of the instruction execution process of the data encryption instruction can be referred to the previous description and will not be expanded here.

[0140] If the current cryptographic instruction is a data decryption instruction, the current cryptographic instruction is executed according to the instruction execution process of the data decryption instruction, and the ciphertext data is decrypted using the encapsulated key to obtain the plaintext data as the output operand of the data decryption instruction; the relevant content of the instruction execution process of the data decryption instruction can be referred to the previous description and will not be expanded here.

[0141] It can be seen that the cryptographic instructions in the cryptographic instruction set provided by the embodiment of the present application support the generation of encapsulated keys or the use of encapsulated keys, and the encapsulated keys cannot be used directly and must undergo integrity verification before they can be used; specifically, the encapsulated key includes a ciphertext key, an integrity label and key additional information; the ciphertext key is obtained by encrypting the original plaintext key based on the key encapsulation key, wherein the original key is used for data encryption or data decryption, so that the ciphertext key is not stored or transmitted in plaintext form, but is encrypted based on the key encapsulation key inside the processor and can only be unsealed inside the processor; at the same time, the integrity label is obtained by performing integrity calculation on the original key, key additional information and key authorization code based on the key encapsulation key, and the key authorization code corresponds to the encapsulated key, which is the permission certificate for the use of the encapsulated key. That is to say, the embodiment of the present application deeply binds the authorization check and integrity verification of the key authorization code in the encapsulated key structure, effectively improving the key security during the execution of the cryptographic instructions. Specifically, when generating the encapsulated key, the key encapsulation key is used to encrypt the original key to form a ciphertext key, and the integrity calculation is performed on the original key, key additional information and key authorization code to generate an integrity tag. Since the integrity tag is bound to the information of the key authorization code, when unsealing or using the encapsulated key, as long as the integrity check of the integrity tag passes, it means that the key authorization code provided when using the encapsulated key is correct. On the contrary, if the key authorization code provided when using the encapsulated key is wrong, even if the encapsulated key has not been tampered with, it cannot pass the integrity check, which can prevent the unauthorized and illegal use of the encapsulated key. The embodiment of the present application can achieve dual verification of the content consistency and usage authority of the encapsulated key based on the integrity verification of the integrity tag without leaking the plaintext key, ensuring the non-forgeability and non-tamperability of the key encapsulation during storage, transmission and use, and enhancing the security protection capability during the execution of cryptographic instructions.

[0142] At the same time, the key encapsulation and usage process is controlled by cryptographic instructions, which isolates external interference and improves anti-attack capabilities. That is to say, the entire encapsulation or unsealing process is integrated into the processor's cryptographic instruction execution process, and the key encapsulation key, decryption process and integrity verification logic cannot be accessed from the outside. This instruction-level encapsulation limits the key lifecycle management to the trusted boundary. Even if the attacker obtains the encapsulated key, due to the lack of the key encapsulation key and the correct key authorization code, it is impossible to pass the integrity check or restore the plaintext key, thus forming a protective barrier for key protection and improving the security level of key management.

[0143] Therefore, the embodiments of the present application can improve the security of the key during the execution of cryptographic instructions.

[0144] The following is an introduction to the execution device of the cryptographic instructions provided in the embodiment of the present application. The execution device of the cryptographic instructions can be regarded as a functional device corresponding to the execution method of the cryptographic instructions provided in the embodiment of the present application. The description below can be referenced in correspondence with the description above.

[0145] As an optional implementation, Figure 11 An exemplary block diagram of a cryptographic instruction execution device provided in an embodiment of the present application is shown. The device can be applied to a processor, referring to FIG. Figure 11 , the apparatus may include:

[0146] The instruction acquisition module 100 is configured to acquire a current cryptographic instruction from a processor's cryptographic instruction set. The current cryptographic instruction corresponds to a current computational requirement of the processor, which includes generating or using a packaged key. The packaged key includes a ciphertext key, an integrity tag, and key additional information. The ciphertext key is obtained by encrypting a plaintext original key based on a key encapsulation key within the processor. The original key is used for data encryption or decryption. The integrity tag is obtained by performing integrity calculation on the original key, key additional information, and a key authorization code based on the key encapsulation key. The key authorization code corresponds to the packaged key and is a credential for permission to use the packaged key.

[0147] The instruction execution module 200 is used to execute the instruction execution process of the current cryptographic instruction to generate an encapsulated key or use the encapsulated key.

[0148] In an optional implementation, the cryptographic instruction set includes a plurality of cryptographic instructions, the plurality of cryptographic instructions including: a key encapsulation instruction, a data encryption instruction, and a data decryption instruction;

[0149] The key encapsulation instruction is used to generate an encapsulated key; the key encapsulation instruction is divided into a direct key encapsulation instruction and a key generation and encapsulation instruction; the direct key encapsulation instruction uses an external input plaintext key as the original key, and the key generation and encapsulation instruction uses a random number plaintext key generated by a random number generator inside the processor as the original key;

[0150] The data encryption instruction is used to encrypt data using the encapsulated key; the data decryption instruction is used to decrypt data using the encapsulated key.

[0151] In an optional implementation, the current cryptographic instruction is a direct key encapsulation instruction, the direct key encapsulation instruction including a plurality of input operands, the plurality of input operands including an external input plaintext key, key additional information, and a key authorization code;

[0152] The instruction execution module 200 is used to execute the instruction execution process of the current password instruction, including:

[0153] Use the key encapsulation key to encrypt the external input plaintext key to obtain the ciphertext key;

[0154] Use the key encapsulation key to perform integrity calculation on the external input plaintext key, key additional information and key authorization code to obtain the integrity label;

[0155] Based on the ciphertext key, the integrity tag, and the key additional information, a packaged key is formed as the output operand of the direct key package instruction.

[0156] In an optional implementation, the current cryptographic instruction is a key generation and encapsulation instruction, the key generation and encapsulation instruction includes a plurality of input operands, the plurality of input operands including key additional information and a key authorization code;

[0157] The instruction execution module 200 is used to execute the instruction execution process of the current password instruction, including:

[0158] Use the random number generator inside the processor to generate a random number as the random number plaintext key;

[0159] Use the key encapsulation key to encrypt the random number plaintext key to obtain the ciphertext key;

[0160] Use the key encapsulation key to perform integrity calculation on the random number plaintext key, key additional information, and key authorization code to obtain the integrity tag;

[0161] Based on the ciphertext key, the integrity tag, and the key additional information, an encapsulated key is formed as the output operand of the key generation and encapsulation instruction.

[0162] In an optional implementation, the current cryptographic instruction is a data encryption instruction, the data encryption instruction including a plurality of input operands, the plurality of input operands including plaintext data, a key authorization code, and an encapsulated key;

[0163] The instruction execution module 200 is used to execute the instruction execution process of the current password instruction, including:

[0164] Based on the key authorization code and the encapsulated key in the data encryption instruction, the integrity tag in the encapsulated key is verified for integrity;

[0165] Determine whether the integrity verification passes;

[0166] If the integrity verification passes, the encapsulated key has not been tampered with and the key authorization code of the data encryption instruction is valid. The decrypted key is used to encrypt the plaintext data to obtain the ciphertext data as the output operand of the data encryption instruction. The decrypted key is obtained by decrypting the ciphertext key in the encapsulated key using the key encapsulation key.

[0167] If the integrity verification fails, the encapsulated key has been tampered with and / or the key authorization code of the data encryption instruction is illegal. The data encryption instruction is exited and an error message is returned.

[0168] In an optional implementation, the instruction execution module 200 is configured to perform integrity verification on the integrity tag in the encapsulated key based on the key authorization code and the encapsulated key in the data encryption instruction, including:

[0169] Decrypting the ciphertext key in the encapsulated key of the data encryption instruction using the key encapsulation key to obtain a decrypted key;

[0170] Using the key encapsulation key, recalculate the integrity of the decrypted key, the key authorization code of the data encryption instruction, and the key additional information in the encapsulated key of the data encryption instruction to obtain a regenerated integrity tag;

[0171] The regenerated integrity tag is compared with the integrity tag in the encapsulated key; if the comparison is consistent, the integrity verification passes; if the comparison is inconsistent, the integrity verification fails.

[0172] In an optional implementation, the current cryptographic instruction is a data decryption instruction, the data decryption instruction includes a plurality of input operands, the plurality of input operands including ciphertext data, a key authorization code, and an encapsulated key;

[0173] The instruction execution module 200 is used to execute the instruction execution process of the current password instruction, including:

[0174] Based on the key authorization code and the encapsulated key in the data decryption instruction, the integrity tag in the encapsulated key is verified;

[0175] Determine whether the integrity verification passes;

[0176] If the integrity verification passes, the decrypted key is used to decrypt the ciphertext data to obtain the plaintext data as the output operand of the data decryption instruction; wherein the decrypted key is obtained by decrypting the ciphertext key in the encapsulated key using the key encapsulation key;

[0177] If the integrity verification fails, the data decryption instruction is exited and an error message is returned.

[0178] In a further optional implementation, the key encapsulation key is a platform- and chip-specific key encapsulation key; the cryptographic instruction execution device provided in the embodiment of the present application may also be used to:

[0179] A key encapsulation key is generated based on the chip secret information and platform secret information. The chip secret information is an identifier preset inside the chip by the chip manufacturer during the chip production process. The same chip secret information is preset in chips of the same model. The platform secret information is key information set by the platform administrator in the system firmware or protected storage to represent the identity of the platform or system.

[0180] In a further optional implementation, an embodiment of the present application also provides a processor having a cryptographic instruction set. When the cryptographic instructions in the cryptographic instruction set are executed by the processor, the execution method of the cryptographic instructions provided by the embodiment of the present application is implemented; or, the processor provided by the embodiment of the present application may include the execution device of the cryptographic instructions provided above in the embodiment of the present application.

[0181] In a further optional implementation, the embodiment of the present application also provides a computer device, such as a terminal device or a server device, which may include the processor provided above in the embodiment of the present application; further, the computer device provided in the embodiment of the present application may also include a memory, which stores a cryptographic instruction set. When the cryptographic instructions in the cryptographic instruction set are executed by the processor, the execution method of the cryptographic instructions provided in the embodiment of the present application is implemented.

[0182] The above describes multiple embodiment schemes provided by the embodiments of the present application. The various optional methods introduced in each embodiment scheme can be combined and cross-referenced with each other without conflict, thereby extending a variety of possible embodiment schemes, which can all be considered as embodiment schemes disclosed and open in the embodiments of the present application.

[0183] Although the embodiments of the present application are disclosed above, the present application is not limited thereto. Any person skilled in the art may make various changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims.

Claims

1. A method for executing a cryptographic instruction, characterized in that: include: Obtaining a current cryptographic instruction in a cryptographic instruction set of the processor, the current cryptographic instruction corresponding to a current computational requirement of the processor, the current computational requirement including generating or using a packaged key; wherein the packaged key includes a ciphertext key, an integrity tag, and key additional information; the ciphertext key is obtained by encrypting a plaintext original key based on a key encapsulation key within the processor, the original key being used for data encryption or data decryption; the integrity tag is obtained by performing integrity calculation on the original key, key additional information, and a key authorization code based on the key encapsulation key, the key authorization code corresponding to the packaged key and being a credential for permission to use the packaged key; Execute the instruction execution flow of the current cryptographic instruction to generate a wrapping key or use a wrapping key.

2. The method according to claim 1, characterized in that The cryptographic instruction set includes multiple cryptographic instructions, and the multiple cryptographic instructions include: key encapsulation instructions, data encryption instructions, and data decryption instructions; The key encapsulation instruction is used to generate an encapsulated key; the key encapsulation instruction is divided into a direct key encapsulation instruction and a key generation and encapsulation instruction; the direct key encapsulation instruction uses an external input plaintext key as the original key, and the key generation and encapsulation instruction uses a random number plaintext key generated by a random number generator inside the processor as the original key; The data encryption instruction is used to encrypt data using the encapsulated key; the data decryption instruction is used to decrypt data using the encapsulated key.

3. The method according to claim 2, characterized in that The current cryptographic instruction is a direct key encapsulation instruction, the direct key encapsulation instruction includes a plurality of input operands, the plurality of input operands including an external input plaintext key, key additional information, and a key authorization code; The instruction execution process of executing the current password instruction includes: Use the key encapsulation key to encrypt the external input plaintext key to obtain the ciphertext key; Use the key encapsulation key to perform integrity calculation on the external input plaintext key, key additional information and key authorization code to obtain the integrity label; Based on the ciphertext key, the integrity tag, and the key additional information, a packaged key is formed as the output operand of the direct key package instruction.

4. The method according to claim 2, characterized in that The current cryptographic instruction is a key generation and encapsulation instruction, which includes a plurality of input operands, and the plurality of input operands include key additional information and a key authorization code; The instruction execution process of executing the current password instruction includes: Use the random number generator inside the processor to generate a random number as the random number plaintext key; Use the key encapsulation key to encrypt the random number plaintext key to obtain the ciphertext key; Use the key encapsulation key to perform integrity calculation on the random number plaintext key, key additional information, and key authorization code to obtain the integrity tag; Based on the ciphertext key, the integrity tag, and the key additional information, an encapsulated key is formed as the output operand of the key generation and encapsulation instruction.

5. The method according to claim 2, characterized in that The current cryptographic instruction is a data encryption instruction, and the data encryption instruction includes a plurality of input operands, and the plurality of input operands include plaintext data, a key authorization code, and an encapsulated key; The instruction execution process of executing the current password instruction includes: Based on the key authorization code and the encapsulated key in the data encryption instruction, the integrity tag in the encapsulated key is verified for integrity; Determine whether the integrity verification passes; If the integrity verification passes, the encapsulated key has not been tampered with and the key authorization code of the data encryption instruction is valid. The decrypted key is used to encrypt the plaintext data to obtain the ciphertext data as the output operand of the data encryption instruction. The decrypted key is obtained by decrypting the ciphertext key in the encapsulated key using the key encapsulation key. If the integrity verification fails, the encapsulated key has been tampered with and / or the key authorization code of the data encryption instruction is illegal, and the data encryption instruction is exited and an error message is returned.

6. The method according to claim 5, characterized in that The integrity verification of the integrity tag in the encapsulated key based on the key authorization code and the encapsulated key in the data encryption instruction includes: Decrypting the ciphertext key in the encapsulated key of the data encryption instruction using the key encapsulation key to obtain a decrypted key; Using the key encapsulation key, recalculate the integrity of the decrypted key, the key authorization code of the data encryption instruction, and the key additional information in the encapsulated key of the data encryption instruction to obtain a regenerated integrity tag; The regenerated integrity tag is compared with the integrity tag in the encapsulated key; if the comparison is consistent, the integrity verification passes; if the comparison is inconsistent, the integrity verification fails.

7. The method according to claim 2, characterized in that The current cryptographic instruction is a data decryption instruction, and the data decryption instruction includes a plurality of input operands, and the plurality of input operands include ciphertext data, a key authorization code, and an encapsulated key; The instruction execution process of executing the current password instruction includes: Based on the key authorization code and the encapsulated key in the data decryption instruction, the integrity tag in the encapsulated key is verified for integrity; Determine whether the integrity verification passes; If the integrity verification passes, the decrypted key is used to decrypt the ciphertext data to obtain the plaintext data as the output operand of the data decryption instruction; wherein the decrypted key is obtained by decrypting the ciphertext key in the encapsulated key using the key encapsulation key; If the integrity verification fails, the data decryption instruction is exited and an error message is returned.

8. The method according to any one of claims 1 to 7, characterized in that The key encapsulation key is a key encapsulation key specific to a platform and a chip; and the method further includes: A key encapsulation key is generated based on the chip secret information and platform secret information. The chip secret information is an identifier preset inside the chip by the chip manufacturer during the chip production process. The same chip secret information is preset in chips of the same model. The platform secret information is key information set by the platform administrator in the system firmware or protected storage to represent the identity of the platform or system.

9. A device for executing a cryptographic instruction, characterized in that: include: An instruction acquisition module is used to acquire the current cryptographic instruction in the cryptographic instruction set of the processor, wherein the current cryptographic instruction corresponds to the current operation requirement of the processor, and the current operation requirement includes generating a packaged key or using a packaged key; wherein the packaged key includes a ciphertext key, an integrity tag, and key additional information; the ciphertext key is obtained by encrypting the plaintext original key based on the key encapsulation key inside the processor, and the original key is used for data encryption or data decryption; the integrity tag is obtained by performing integrity calculation on the original key, key additional information and key authorization code based on the key encapsulation key, and the key authorization code corresponds to the encapsulated key and is the permission certificate for the encapsulated key; The instruction execution module is used to execute the instruction execution process of the current cryptographic instruction to generate a packaged key or use the packaged key.

10. A processor, characterized in that: The processor has a cryptographic instruction set, and when the cryptographic instructions in the cryptographic instruction set are executed by the processor, the cryptographic instruction execution method according to any one of claims 1 to 8 is implemented; or the processor includes the cryptographic instruction execution device according to claim 9.

11. A computer device, characterized in that: The computer device includes a processor, wherein the processor is the processor according to claim 10; the computer device also includes a memory, wherein the memory stores a cryptographic instruction set, and when the cryptographic instructions in the cryptographic instruction set are executed by the processor, the execution method of the cryptographic instructions according to any one of claims 1 to 8 is implemented.